All insights

How should a general practice protect patient records?

4 min readBy Brendon Whiting, Founder · 9 June 2026

Protect patient records with the Australian Government's Essential Eight: multi-factor authentication on every login, tested backups, prompt patching, and control over which applications run and who holds admin rights. Add the Privacy Act, My Health Record and RACGP Standards obligations on top, and the job becomes governance as much as technology, and entirely manageable.

Patient records are worth protecting carefully because they are worth stealing. A clinical database holds identity documents, Medicare numbers, addresses and health histories, and a practice that loses access to it cannot safely consult. That is the risk, stated once. Everything else in this article is about the fact that the defences are known, published by the Government, and within reach of an ordinary practice.

You do not need to invent a security standard, because the Australian Signals Directorate already publishes one. The Essential Eight is eight controls: application control, patching applications, configuring Microsoft Office macro settings, hardening user applications, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Each is measured at Maturity Levels 1 to 3, so a practice can name where it stands and where it is going, in language any provider or insurer understands.

Translated into a clinic's Monday morning, the list is concrete. Multi-factor authentication means a stolen password alone cannot open Best Practice, MedicalDirector or the practice's email; tools such as DUO handle this without slowing doctors down. Patching means clinical software updates and Windows updates applied promptly, out of hours. Application control, with tools such as ThreatLocker, means unapproved software simply does not run on a machine that holds patient data. Restricting admin rights means reception is not browsing the web with an account that can install anything. The remaining controls, sensible Microsoft Office macro settings and hardened browsers, close the doors that commodity malware actually uses to get in.

Backups deserve their own paragraph, because they are the control that decides whether a bad day is an inconvenience or a catastrophe. The standard is not having backups; it is having tested restores, on a schedule, with a copy that ransomware on the network cannot reach. A backup that has never been restored is a hope, not a control, and the difference is only ever discovered at the worst possible moment.

Identity ties the technology together. In most practices, the same login opens email, documents and the clinical system, so managing who can log in to what, through Entra ID, is managing record security itself. Access should follow roles, and when a staff member leaves, their access should end the same day, not at the end of the month when someone remembers. The same discipline applies to third parties: locum accounts, the after-hours service, the bookkeeper. Anyone who can reach the records is part of the security picture, whether or not they are on the payroll.

Then there is the governance layer, which is where practices are examined. The Privacy Act treats health information as sensitive information with elevated obligations, the Notifiable Data Breaches scheme requires assessment and notification when a breach is likely to cause serious harm, My Health Record participation carries its own security requirements, and the RACGP Standards for general practices (5th edition) expect documented information security practices at accreditation. None of this is technical, but all of it must be written down, owned by someone, and rehearsed. A one-page response plan with names and phone numbers on it beats a thick policy nobody has read.

The honest caveats: perfect security does not exist, and nobody selling it is telling the truth. Maturity Level 1 is designed to stop the commodity attacks that make up most incidents, not a determined, well-resourced adversary, and for most general practices that is the right trade-off; very few clinics need Maturity Level 3. If you already have multi-factor authentication everywhere and a restore you have actually tested, you are ahead of a surprising share of Australian businesses, and your next steps are refinement, not rescue.

If you want to know exactly where your practice stands against the Essential Eight, our Cyber Security Scorecard is free and puts the answer in writing; it takes minutes to request and measures you against the same list this article works from. Or call us on 1800 456 567.

Find out where your practice actually stands.

The free Essential Eight Cyber Security Scorecard measures you against the same eight controls this article works from, and puts the answer in writing.

Frequently asked questions

It can be safer than a server in the storeroom, which is a single point of failure that can be stolen, flooded or simply die. Cloud hosting done properly means encrypted storage, multi-factor authentication, managed access and tested backups on infrastructure such as AWS or Azure. Done casually, it just moves the risk somewhere you cannot see it.

Under the Privacy Act's Notifiable Data Breaches scheme, a practice must assess a suspected breach quickly, and if serious harm to patients is likely, notify the OAIC and the affected individuals. The practical preparation is a written response plan agreed before anything happens, because the worst time to design a process is during the incident.

Yes. The Privacy Act applies to health information regardless of medium, so archive boxes, printed results and referral letters sitting on desks carry the same obligations as the clinical database. Physical security, a clean-desk habit at reception, secure destruction of old records and a plan for scanned backlogs all belong in the same policy.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.