IT Requirements for Medical and Allied Health Practices in Australia

IT Requirements for Medical and Allied Health Practices in Australia

A medical practice holds the most sensitive data a small business can hold, and the law treats it that way. The small-business exemption in the Privacy Act does not apply to anyone providing a health service, so a two-physio clinic in Robina carries the same obligations as a hospital. This is the technology baseline for a general practice, specialist rooms or an allied health clinic in 2026.

It follows the same shape as our baselines for law firms and accounting practices: the obligations, the controls that meet them, and the places practices get caught.


What the law expects

Obligation What it means for the practice’s IT
Privacy Act and the APPs
All health service providers, any turnover
Health information is “sensitive information” under APP 3, so collection needs consent and a reason. APP 11 requires reasonable steps to secure it, and the OAIC’s view of reasonable for health data includes encryption, access controls, MFA and staff training. APP 8 covers sending data offshore, which catches overseas transcription services and virtual assistants.
Notifiable Data Breaches scheme A breach likely to cause serious harm must be assessed within 30 days and reported to the OAIC and to the affected patients. Health providers report more breaches than any other sector every year, mostly from phished email accounts and misdirected results. You need logs that can tell you what was accessed.
My Health Record Act A registered healthcare provider organisation must have a written security and access policy covering who can access the system, how staff are trained, and how access is revoked when they leave. The Digital Health Agency can audit it. Breaches of the My Health Record system are reported to the Agency as well as the OAIC.
Privacy reforms, 2024 to 2026 A statutory tort for serious invasions of privacy, so a patient whose records leak can sue the practice directly. New OAIC infringement powers for smaller breaches that used to go unpenalised. From late 2026, privacy policies must explain automated decision-making, which reaches AI scribes and triage tools.
Cyber Security Act 2024
Turnover over $3 million
Any ransomware payment must be reported to the government within 72 hours. Larger group practices are in scope. Everyone else should still know the rule exists, because the day it matters is not the day to read it.
RACGP Standards and accreditation
General practice
The 5th edition Standards require a documented IT security policy, backups that are tested, access controls, and business continuity for the clinical software. Accreditors ask to see the policy and the last backup test. The RACGP’s Information Security in General Practice guide is the yardstick they use.
Record retention Seven years from the last entry for adults; for a child, until they turn 25. That is longer than most practice software vendors keep a departed practice’s data, and longer than any laptop lasts. Retention is a backup design question.

The baseline

Every control below is one an accreditor, an insurer or the OAIC will ask about after an incident. None of them is exotic.

Identity and access

MFA on everything that can do it

Microsoft 365, the practice software’s cloud login, PRODA, the secure messaging provider, the bank, the remote access. Phished email accounts are the number one source of reported health breaches, and MFA stops almost all of them. Authenticator app or passkey; SMS only where nothing else is offered.

One login per person

The shared “reception” account in Best Practice or Cliniko means the audit log cannot tell you who opened a record. Named accounts, role-based permissions, and a clinician’s login that cannot see the practice’s bank feed.

Offboarding the same day

A locum who finished in March and still has a working practice-software login in September is a breach waiting for a reason. Access removal goes on the same checklist as the parking pass, and the My Health Record policy requires you to document it.

Admin rights held by nobody who reads email

The practice manager’s everyday account should not be a global admin in Microsoft 365 or a local admin on the desktops. Separate admin accounts, used only for admin, with their own MFA. This is Essential Eight “restrict admin privileges” and it is the control ransomware relies on being absent.

Devices and the network

Encrypted, managed, supported

BitLocker or FileVault on every laptop and desktop, so a stolen machine is a hardware loss rather than a notifiable breach. Windows 11 Pro on supported hardware (see Windows 10 end of support). Phones and tablets that touch patient data enrolled in Intune or equivalent, with remote wipe.

Patching that is measured

Operating system and browser updates within two weeks, sooner for anything the ACSC flags as exploited. Practice software updates on the vendor’s schedule. A monthly report showing which machines are behind, because “we have auto-update on” is not evidence.

Clinical network separate from everything else

Patient Wi-Fi, the smart TV in the waiting room, the ultrasound machine that runs Windows 7 and cannot be updated, and the staff laptops all on different VLANs. The imaging device gets internet access to its vendor only. See the Wi-Fi article for the build.

Endpoint protection with someone watching it

An EDR product, not just the free antivirus, with alerts going to a person who responds. A practice does not need a security operations centre; it needs the alert about the reception PC to reach someone before the weekend.

Data

Backups you have restored from

The practice database, the document store, Microsoft 365, and the scanned correspondence, on the 3-2-1 pattern with one copy immutable. Retention long enough to satisfy the seven-year and age-25 rules. A restore test each quarter, logged, because accreditors ask for the log.

Results and referrals over secure messaging

HealthLink, Argus, Medical Objects or the practice software’s built-in channel. Never plain email, and never the free fax-to-email service the specialist’s receptionist set up. A referral emailed to the wrong address is a notifiable breach and one of the most common ones.

Know where the cloud is

Cloud practice software, telehealth platforms, AI scribes and transcription services each store patient data somewhere. If it is outside Australia, APP 8 applies and the privacy policy has to say so. Ask each vendor, in writing, where the data sits and who can see it. Several popular AI scribe tools could not answer that question in 2025.

Email that cannot be spoofed

SPF, DKIM and DMARC on the practice domain, so an attacker cannot send “your results are attached” to your patients from your address. Ten minutes of DNS work, covered in our email authentication article.


The written parts

Accreditation and the My Health Record rules both want documents, and the OAIC’s first question after a breach is “show me your policy”. Four pages cover a small practice.

Document Contents
Information security policy Who has access to what, password and MFA rules, device rules, how access is granted and removed, how staff are trained and how often. This is also the My Health Record security and access policy if you write it to cover that system.
Privacy policy and collection notice Public-facing. What you collect, why, who sees it, whether it leaves Australia, how a patient asks for their record. Updated when you add an AI scribe or change telehealth platforms.
Data breach response plan Who decides, who they call, the 30-day assessment clock, the OAIC form, the patient notification template. Our incident response template is a starting point.
Business continuity plan What the practice does when the clinical software is down for a day: paper consult notes, the printed appointment list, how scripts are written, how it gets keyed back in. Tested once a year by running a morning on it.

Where practices get caught

× The practice manager’s phished mailbox. No MFA, six years of correspondence, and an attacker who read it for three weeks before anyone noticed. Notifiable, and every patient who ever emailed the practice is on the list.
× The server under the desk with no offsite copy. Ransomware on a Friday. The vendor’s “backup” was a nightly copy to the same machine. The practice reopened on paper for eleven days.
× The offshore virtual assistant with full software access. Cheaper reception, and a cross-border disclosure of every patient record with no contract clause covering it and no mention in the privacy policy.
× The departed doctor’s laptop. Unencrypted, unmanaged, patient letters in Downloads, sold on Marketplace.
× The AI scribe nobody asked about. A clinician trialled it on their own account. Consult audio went to a server in the United States. The privacy policy said nothing, and a patient asked.

Need a hand?

Accreditation-ready IT for your practice

We look after general practices, specialist rooms and allied health clinics across the Gold Coast: Best Practice and MedicalDirector servers, cloud practice software, secure messaging, the network, the backups and the written policies the accreditor asks for. Start with a gap review against this baseline; you get a clear list before someone else asks for one.

Book a review
Talk to us first

Call 1300 644 588  ·  office@mobiletechs.com.au