Business systems and technology for Australian businesses

Call 1300 540 271
HPCR home
HPCR home
A plain-English guide

IT & Cybersecurity for Medical Clinics

Setting up a medical clinic involves more technology than most people realise.
Your clinical software may be at the centre of the practice, but it depends on the computers, accounts, network, internet, security and backups around it.
A TYPICAL CLINIC NEEDS TO THINK ABOUT
People & accounts
Computers
Network & internet
Clinical systems
Security
Backup & recovery
A reliable clinic depends on more than its clinical software.
Computers, accounts, email, networking, security, backups and clinical systems all need to work together. If one part is overlooked, it can affect the reliability or security of the whole practice.
HOW TO READ THIS PAGE
Legal and participation requirements are labelled, with the source named. Everything else is good practice or what HPCR would normally recommend.
The short version

Six things worth understanding

You can read just this part and have the gist of it.
PEOPLE & ACCOUNTS

Who can get to clinic systems and patient information?

Everyone who needs access should have their own account. Access should be controlled, and it should be removable the day somebody leaves.
COMPUTERS

Who is actually looking after them?

Clinic computers need updates, security, encryption and monitoring. Buying them and setting them up once isn't the same as looking after them.
NETWORK & INTERNET

Is there more to it than getting the internet on?

Yes. Getting a connection into the building is one job. Reliable networking between the computers, clinical systems, printers and everything else is another.
CLINICAL SYSTEMS

Who makes it all work together?

Practice management software usually has to talk to Medicare, PRODA, pathology, appointments, payments, printers and scanners. That's several vendors, and somebody has to own the whole picture.
SECURITY

Isn't antivirus enough?

Antivirus is useful, but it isn't the whole security system. Accounts, MFA, updates, monitoring, encryption and access control all matter too.
BACKUP & RECOVERY

Could you recover if something failed tomorrow?

Backups should be monitored, stored safely and tested. A backup nobody has restored from is a guess.
The regulatory bit

Why does this matter?

Medical clinics hold sensitive personal and health information.
Australian Privacy Principle 11 requires organisations covered by the Privacy Act to take reasonable steps to protect personal information.
That doesn't mean there's a law telling a clinic which firewall, antivirus product or Microsoft licence to buy. It means the clinic needs safeguards that suit its circumstances.
The OAIC talks about areas including IT security, controlling access, staff training, internal policies, third-party providers and preparing for data breaches.
IN NORMAL ENGLISH
Know who can access patient information, protect the computers and accounts they use, keep systems updated, maintain reliable backups, and know what you'll do if something goes wrong.
See what the OAIC expects

APP 11.1 requires an entity to take reasonable steps to protect the information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.

The OAIC guidance groups the reasonable steps an organisation should consider into nine areas:

  • Governance, culture and training
  • Internal policies, procedures and systems
  • ICT security
  • Access security
  • Third party providers, including cloud computing
  • Data breaches
  • Physical security
  • Destruction and de-identification
  • Standards

Only a couple of those are mainly technical. The rest come down to who can do what, what the clinic has written down, and what happens when something goes wrong.

Read the OAIC guidance

A conversation starter

How prepared is your clinic?

Go through these with whoever looks after your technology. Nothing is sent anywhere and nothing is saved.
People
Everyone has their own account
MFA is enabled
Access can be removed when somebody leaves
Staff know how to report something suspicious
Computers
Computers are centrally managed
Security updates are monitored
Endpoint security is monitored
Drives are encrypted
Users don't have administrator access they don't need
Network
Clinical computers have reliable connectivity
Guest Wi-Fi is separated
Network equipment is managed
Somebody knows the firewall configuration
Backups
Backups are monitored
There is an off-site copy
Backup failures raise an alert
Restores are tested
Governance
Security responsibilities are written down
Security and access policies exist where required
Training records are kept
User access is reviewed
There is a data breach response process

0 confirmed 22 still to confirm 0 need discussion

This checklist is a conversation starter, not a compliance assessment.

Is antivirus enough?

No.
Antivirus is useful, but it only deals with part of the problem.
Antivirus is worth having. It just covers one item on that list, and it's worth knowing who handles the rest.
ANTIVIRUS HELPS WITH
Malware protection
BUT WHO IS LOOKING AFTER
Security updates
Application updates
User accounts
MFA
Encryption
Backups
Monitoring
Access
Recovery
What the Digital Health Agency actually suggests

The Agency's cyber security fundamentals page sets out practical steps for healthcare providers: keep software up to date and don't allow unapproved or unverified software on your networks, use strong passphrases and turn on multi-factor authentication, back up your data regularly, never respond to phishing, and don't pay a ransom if you're hit with ransomware.

Worth noticing: antivirus isn't one of those five.

Where My Health Record applies, the Agency's participation guidance does give examples of a cybersecurity measure that include installing and maintaining antivirus and malware protection, along with strong passwords or MFA, keeping systems up to date with security patches, and monitoring systems for unusual or suspicious activity.

Read the cyber security fundamentals

Accounts

Microsoft 365 isn't just Word and Outlook

For a business, Microsoft 365 can also be the system that gives the clinic control over its users and computers.
Who are you?
Your account
How do we know it's you?
MFA
What can you access?
Permissions
Which computers belong to the clinic?
Device management
Are those computers protected?
Security policies
HPCR RECOMMENDATION, NOT A LEGAL REQUIREMENT
HPCR commonly uses Microsoft 365 Business Premium for this. It's one practical way to get those capabilities in one place, not the only way, and no licence of any kind is required by law.

A word on private email

Plenty of clinics run on a mix of clinic email and whatever address somebody already had. It's rarely a decision, it just happens.
When clinic business goes through a privately controlled account, the clinic has less control over it, and when that person moves on the information tends to go with them.
What evidence should we keep for accounts?
  • A current list of users
  • Confirmation that MFA is on
  • Records of accounts being created and removed
  • A record of who can access what
  • A note of when access was last reviewed
Network

The internet connection and the clinic network are two different things

The internet connection is the service that reaches the building. The network is the equipment inside it that connects your computers to each other, to the clinical server and out to that service.
ISP equipment is perfectly adequate in some clinics. Whether it suits yours depends on what was supplied and what the practice needs, so it's worth checking rather than assuming.
What should we have in place?
  • A firewall somebody actually manages, with a known configuration
  • Secure clinic Wi-Fi, and a guest network that can't reach clinic systems
  • Some visibility of what's connected
  • Managed switches and access points, so changes don't need a site visit
  • A network diagram, even a rough one
HOW IT FITS TOGETHER
Internet / NBN
Firewall / gateway
Managed network
Clinic computers / server
AND ALONGSIDE IT
Wi-Fi
Clinic wireless devices
Guest Wi-Fi
Internet only, separated from clinic systems

Using Bp Premier?

Best Practice recommends gigabit networking between the server and client computers, and specifies very low local network latency for optimal performance.
For a new fitout, HPCR would normally recommend wiring fixed Bp workstations rather than designing the practice around Wi-Fi.
See Best Practice's requirements

Best Practice Software's system requirements state that Bp Premier is designed for use between a client and server on a local network, and that the network connection between the client and server must therefore be of local network latency, under 3 ms, for Bp Premier to perform optimally. A gigabit network connection is recommended between the client and server.

Other clinical systems publish their own requirements. This is an example of why clinic IT needs planning, not a universal rule for every medical application.

Bp Premier system requirements

Backups

Having a backup isn't the same as knowing you can recover

Backups fail quietly. A job that stopped eight months ago looks much the same as one that's working, unless somebody checks.
WORTH BEING ABLE TO ANSWER
What is being backed up?
How often?
Where is the backup stored?
Is there an off-site copy?
Is it encrypted?
Who knows when a backup fails?
Has anybody actually tested restoring it?
A backup report tells you a job ran. A restore test tells you whether you can get the data back.
What evidence should we keep for backups?
  • Backup reports
  • Failure alerts, and a named person who gets them
  • Retention settings
  • A record of a completed restore test, with the date
People

What if our doctors are contractors?

That's common. From an IT security point of view, the important question is what clinic systems and patient information they can access.
If somebody can access clinic information, the practice should know who they are, what they can access, and how that access will be removed when they stop working with the clinic.
None of that says anything about employment status, and it doesn't mean every contractor needs a Microsoft 365 licence.
Using My Health Record? There are additional access and record-keeping requirements.
My Health Record and people under contract

For organisations registered with My Health Record, the Australian Digital Health Agency states that the organisation must comply with its security and access policy and must ensure the following people comply with it as well: the organisation's employees, linked individual healthcare providers, and those to whom the organisation supplies services under contract.

The Agency also states the policy must be communicated to all employees, including contractors, and to any healthcare providers to whom the organisation provides services under contract.

That's a My Health Record participation requirement for registered organisations. It isn't a general statement about employment law.

ONLY APPLIES IF YOUR ORGANISATION PARTICIPATES IN MY HEALTH RECORD
Only if it applies to you

Using My Health Record?

PARTICIPATION REQUIREMENT
From 1 October 2026, all healthcare provider organisations registered with My Health Record must make sure their security and access policy complies with the My Health Records Rules 2026. That includes organisations that already wrote a policy under the 2016 rule.
In plain English: you need a written policy covering who gets into My Health Record and how. Keep it current, tell staff about it, follow it. The Agency says it's required under Rule 21 whatever the size of the organisation, and however rarely the system is used.

The part most clinics haven't thought about

Rule 45 also requires records. The Agency says a registered organisation must keep a record of each of the following, and these retention periods are the Agency's.
How the organisation authorises access, including user accounts created, changed, suspended or deactivated
RETAIN FOR
Five years
Training given before access, annually, and after significant changes to the system or the legislation
RETAIN FOR
Five years
How the organisation can identify someone who requested access and tell the System Operator who they were, for example audit logs
RETAIN FOR
Two years
How the organisation identifies, manages and responds to My Health Record data breaches
RETAIN FOR
Two years
How physical security, information security, cybersecurity and technical and organisational measures have been implemented, and when
RETAIN FOR
Two years
Evidence

Saying it is one thing. Showing it is another.

This catches a lot of practices out, and it's usually easy to fix once somebody names it.
Saying itShowing it
Our computers are updated.A patch management report showing the computers are up to date.
Everyone uses MFA.A report showing MFA is enabled for the relevant accounts.
We have backups.Backup reports plus a record of a successful restore test.
Staff receive cyber training.Training records showing who completed it and when.
That's what we mean by evidence.
New practices

Setting up a new clinic?

Roughly this order, and the order matters more than the speed.
01
Understand what already exists
02
Confirm people and access
03
Check the internet and network
04
Set up accounts and computers
05
Build the clinical systems
06
Connect the other providers
07
Set up backups
08
Test everything
09
Document it
10
Monitor it after opening
Getting the technology right before opening is much easier than fixing it afterwards.
A little planning upfront helps make sure the network, computers, accounts, security, backups and clinical systems are ready to work together from day one.

Not sure what you already have?

HPCR can review the clinic with you and separate everything into three groups.
01
Already in place
02
Needed before opening
03
Can be improved later
SOURCES
Office of the Australian Information Commissioner
Australian Privacy Principle 11: security of personal information ↗
Australian Digital Health Agency
Cyber security fundamentals ↗
Australian Digital Health Agency
My Health Record participation obligations ↗
This page provides general technology and cybersecurity information and is not legal advice. Requirements vary depending on the services, systems and regulatory programs used by your practice.