How should a general practice protect patient records?
Protect patient records with the Australian Government's Essential Eight: multi-factor authentication on every login, tested backups, prompt patching, and control over which applications run and who holds admin rights. Add the Privacy Act, My Health Record and RACGP Standards obligations on top, and the job becomes governance as much as technology, and entirely manageable.
Patient records are worth protecting carefully because they are worth stealing. A clinical database holds identity documents, Medicare numbers, addresses and health histories, and a practice that loses access to it cannot safely consult. That is the risk, stated once. Everything else in this article is about the fact that the defences are known, published by the Government, and within reach of an ordinary practice.
You do not need to invent a security standard, because the Australian Signals Directorate already publishes one. The Essential Eight is eight controls: application control, patching applications, configuring Microsoft Office macro settings, hardening user applications, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Each is measured at Maturity Levels 1 to 3, so a practice can name where it stands and where it is going, in language any provider or insurer understands.
Translated into a clinic's Monday morning, the list is concrete. Multi-factor authentication means a stolen password alone cannot open Best Practice, MedicalDirector or the practice's email; tools such as DUO handle this without slowing doctors down. Patching means clinical software updates and Windows updates applied promptly, out of hours. Application control, with tools such as ThreatLocker, means unapproved software simply does not run on a machine that holds patient data. Restricting admin rights means reception is not browsing the web with an account that can install anything. The remaining controls, sensible Microsoft Office macro settings and hardened browsers, close the doors that commodity malware actually uses to get in.
Backups deserve their own paragraph, because they are the control that decides whether a bad day is an inconvenience or a catastrophe. The standard is not having backups; it is having tested restores, on a schedule, with a copy that ransomware on the network cannot reach. A backup that has never been restored is a hope, not a control, and the difference is only ever discovered at the worst possible moment.
Identity ties the technology together. In most practices, the same login opens email, documents and the clinical system, so managing who can log in to what, through Entra ID, is managing record security itself. Access should follow roles, and when a staff member leaves, their access should end the same day, not at the end of the month when someone remembers. The same discipline applies to third parties: locum accounts, the after-hours service, the bookkeeper. Anyone who can reach the records is part of the security picture, whether or not they are on the payroll.
Then there is the governance layer, which is where practices are examined. The Privacy Act treats health information as sensitive information with elevated obligations, the Notifiable Data Breaches scheme requires assessment and notification when a breach is likely to cause serious harm, My Health Record participation carries its own security requirements, and the RACGP Standards for general practices (5th edition) expect documented information security practices at accreditation. None of this is technical, but all of it must be written down, owned by someone, and rehearsed. A one-page response plan with names and phone numbers on it beats a thick policy nobody has read.
The honest caveats: perfect security does not exist, and nobody selling it is telling the truth. Maturity Level 1 is designed to stop the commodity attacks that make up most incidents, not a determined, well-resourced adversary, and for most general practices that is the right trade-off; very few clinics need Maturity Level 3. If you already have multi-factor authentication everywhere and a restore you have actually tested, you are ahead of a surprising share of Australian businesses, and your next steps are refinement, not rescue.
If you want to know exactly where your practice stands against the Essential Eight, our Cyber Security Scorecard is free and puts the answer in writing; it takes minutes to request and measures you against the same list this article works from. Or call us on 1800 456 567.
Find out where your practice actually stands.
The free Essential Eight Cyber Security Scorecard measures you against the same eight controls this article works from, and puts the answer in writing.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business