IT & Cybersecurity for Medical Clinics
Six things worth understanding
Who can get to clinic systems and patient information?
Who is actually looking after them?
Is there more to it than getting the internet on?
Who makes it all work together?
Isn't antivirus enough?
Could you recover if something failed tomorrow?
Why does this matter?
See what the OAIC expects
APP 11.1 requires an entity to take reasonable steps to protect the information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
The OAIC guidance groups the reasonable steps an organisation should consider into nine areas:
- Governance, culture and training
- Internal policies, procedures and systems
- ICT security
- Access security
- Third party providers, including cloud computing
- Data breaches
- Physical security
- Destruction and de-identification
- Standards
Only a couple of those are mainly technical. The rest come down to who can do what, what the clinic has written down, and what happens when something goes wrong.
How prepared is your clinic?
Is antivirus enough?
What the Digital Health Agency actually suggests
The Agency's cyber security fundamentals page sets out practical steps for healthcare providers: keep software up to date and don't allow unapproved or unverified software on your networks, use strong passphrases and turn on multi-factor authentication, back up your data regularly, never respond to phishing, and don't pay a ransom if you're hit with ransomware.
Worth noticing: antivirus isn't one of those five.
Where My Health Record applies, the Agency's participation guidance does give examples of a cybersecurity measure that include installing and maintaining antivirus and malware protection, along with strong passwords or MFA, keeping systems up to date with security patches, and monitoring systems for unusual or suspicious activity.
Microsoft 365 isn't just Word and Outlook
A word on private email
What evidence should we keep for accounts?
- A current list of users
- Confirmation that MFA is on
- Records of accounts being created and removed
- A record of who can access what
- A note of when access was last reviewed
The internet connection and the clinic network are two different things
What should we have in place?
- A firewall somebody actually manages, with a known configuration
- Secure clinic Wi-Fi, and a guest network that can't reach clinic systems
- Some visibility of what's connected
- Managed switches and access points, so changes don't need a site visit
- A network diagram, even a rough one
Using Bp Premier?
See Best Practice's requirements
Best Practice Software's system requirements state that Bp Premier is designed for use between a client and server on a local network, and that the network connection between the client and server must therefore be of local network latency, under 3 ms, for Bp Premier to perform optimally. A gigabit network connection is recommended between the client and server.
Other clinical systems publish their own requirements. This is an example of why clinic IT needs planning, not a universal rule for every medical application.
Having a backup isn't the same as knowing you can recover
What evidence should we keep for backups?
- Backup reports
- Failure alerts, and a named person who gets them
- Retention settings
- A record of a completed restore test, with the date
What if our doctors are contractors?
My Health Record and people under contract
For organisations registered with My Health Record, the Australian Digital Health Agency states that the organisation must comply with its security and access policy and must ensure the following people comply with it as well: the organisation's employees, linked individual healthcare providers, and those to whom the organisation supplies services under contract.
The Agency also states the policy must be communicated to all employees, including contractors, and to any healthcare providers to whom the organisation provides services under contract.
That's a My Health Record participation requirement for registered organisations. It isn't a general statement about employment law.
Using My Health Record?
The part most clinics haven't thought about
Saying it is one thing. Showing it is another.
| Saying it | Showing it |
|---|---|
| Our computers are updated. | A patch management report showing the computers are up to date. |
| Everyone uses MFA. | A report showing MFA is enabled for the relevant accounts. |
| We have backups. | Backup reports plus a record of a successful restore test. |
| Staff receive cyber training. | Training records showing who completed it and when. |
