Cyber security for Australian medical and allied health practices

A three-clinician practice turning over well under a million dollars is covered by the Privacy Act in full. Most practice managers have been told the opposite, and the correction usually arrives at the worst possible moment.

A stethoscope resting on a notebook beside a laptop

The exemption that does not apply to you

The Privacy Act exempts many small businesses with an annual turnover of $3 million or less. It is the single most quoted fact in Australian small business privacy, and for health practices it is wrong.

The Act removes that exemption for organisations that provide a health service and hold health information. Turnover is irrelevant. A solo psychologist, a two-chair dental practice, a mobile physiotherapist, a small allied health clinic — all covered by the Australian Privacy Principles in full, with the same obligations as a large provider, scaled to what is reasonable for their size.

"Health service" is also broader than most people assume. It reaches well beyond general practice into allied health, psychology, dental, complementary therapies and a range of services that would not describe themselves as medical. If you assess, maintain or improve someone's health and you keep records about it, work on the assumption that you are in scope and confirm it, rather than the reverse.

Separately, and regardless of the Privacy Act, most practices are also carrying state health records legislation and professional obligations from their registration body. The practical effect is that the "we're too small for this" position is not available.

Why health information sits in a higher category

Health information is classified as sensitive information, which is the most protected category in the Act. Collection generally requires consent, use and disclosure are more tightly constrained, and the expectations around securing it are correspondingly higher.

The reason is not bureaucratic. Health data cannot be reissued. A compromised credit card is cancelled and replaced within days; a disclosed mental health history, a fertility record, a HIV status or a record of family violence is permanent, and the harm is reputational and personal rather than financial. That difference is why health breaches attract the attention they do, and it is worth stating plainly to a practice owner weighing up whether any of this is proportionate.

There is also a newer exposure. Since mid-2025 there has been a statutory cause of action for serious invasions of privacy in Australia, which allows an individual to bring a claim directly. We covered what that means for smaller organisations separately — for a practice holding sensitive health records, it is the more relevant development of the two.

Why practices get targeted specifically

Health providers are attractive to attackers for reasons that have nothing to do with the size of the practice.

The data is valuable and re-sellable. The operational pressure is extreme — a practice that cannot access records cannot safely see patients, which makes it far more likely to pay a ransom than a business that can work off paper for a day. Clinical staff are busy, mobile, and reasonably trained to be helpful rather than suspicious. And the IT is frequently a practice management system chosen for clinical features, running on hardware nobody has audited, supported by whoever set it up years ago.

None of that is a criticism of how practices are run. It is an accurate description of why the risk is concentrated, and why the controls below are the ones that matter rather than a generic checklist.

The practice management system and who can see everything

Almost every practice we assess has the same finding, and it is rarely the firewall.

It is that the practice management system has one shared login used at reception, or that every staff member's account can view every patient record regardless of whether they are involved in that person's care, or that the account belonging to a receptionist who left in 2023 still works. Clinical software is often designed with the assumption that everyone in the practice is trusted, and it is usually configured with that assumption turned up to maximum.

Three questions to put to whoever administers yours:

  • Does every person have their own named login? Shared accounts make it impossible to answer "who accessed this record", which is exactly the question asked after a complaint.
  • Is access limited by role? Reception generally does not need clinical notes. Most systems support this and most deployments do not use it.
  • Is there an access log, and has anyone ever looked at it? Inappropriate access by an insider — looking up a neighbour, an ex-partner, a public figure — is a realistic scenario in a small community practice and is invisible without logging.

The controls worth funding first

In rough order of benefit per dollar, for a practice starting from a typical position:

  • Multi-factor authentication on email and on remote access to the practice system. Email compromise is the most common way in, and MFA remains the single highest-value control — though it is not the finish line it is often sold as.
  • Backups you have actually restored from. Not "backups run nightly" — a tested restore, including the practice management database, with a copy that ransomware cannot reach from the network. This is the control that decides whether an incident is a bad week or an existential event.
  • Named accounts and role-based access in the clinical system, plus a documented process for removing access the day someone leaves.
  • Managed, encrypted devices — particularly the laptops and tablets that leave the building, and the phones with clinical email on them. A lost unencrypted device holding health information is a notifiable breach in a way an encrypted one usually is not.
  • Patching, on the clinical software as well as the operating system. Practice systems are often left on old versions because an upgrade is disruptive during clinic hours. Schedule it rather than deferring it indefinitely.
  • A written security and access policy, which is also an expectation for organisations connected to My Health Record and a common accreditation requirement.

If your practice is accredited, the standards your accreditation body applies will include information security criteria, and they are a reasonable baseline to work against. Check the current version rather than the one in the folder from the last cycle.

Your suppliers are inside your obligation

A practice's data does not stay in the practice. It moves to the practice management vendor's cloud, to pathology and imaging providers, to secure messaging services, to the billing platform, to the transcription tool a clinician started using because it saves twenty minutes a day.

Outsourcing the processing does not outsource the obligation. If a supplier holding your patient data is breached, you are the one with a relationship to the patient and, generally, with the notification obligation. Three things are worth knowing about each supplier: where the data is stored, what happens to it if you leave, and how quickly they will tell you if they are breached. That last one matters most, because your assessment clock is driven by when you become aware, and a supplier who takes three weeks to notify you has spent most of your window.

Transcription and AI scribe tools deserve a specific mention, because adoption in Australian practices has run well ahead of governance. Before a clinician records a consultation into a third-party tool, somebody needs to have established what the vendor does with the audio, whether it trains models on it, where it is stored, and whether the patient has been told. Those are answerable questions, and the time to answer them is before the tool is in daily use.

What happens on the day it goes wrong

If health information is involved, assume from the outset that the incident is likely to be notifiable, and that the affected individuals will be your patients — people you will see again, in a waiting room, next week. That changes how the response should be run.

Decide now who makes the call to notify, who speaks to patients, who speaks to the registration body and insurer, and who instructs IT to stop and preserve rather than "clean it up and get us running". A practice that has walked through the scenario once, in a two-hour session, responds materially better than one discovering the sequence live.

The single most useful preparation is unglamorous: know what data you hold, where it is, and who has access to it. Almost every difficult question in the first forty-eight hours is a variation on that one.

Questions

Our practice turns over less than $3 million. Are we really covered?

Yes. The small business exemption in the Privacy Act does not apply to organisations that provide a health service and hold health information, regardless of turnover. This is the most common misunderstanding we encounter in practices, and it is worth confirming with your own adviser rather than taking anyone's word for it — including ours.

Does a cloud practice management system make this the vendor's problem?

It moves some of the technical work and none of the accountability. You remain responsible for who you grant access to, whether those accounts are removed on departure, how staff authenticate, and the devices the system is reached from — which is where most incidents actually originate.

How long do we have to keep patient records?

Retention is set by state and territory legislation and by your professional obligations, not by the Privacy Act, and the periods differ — including longer periods for records of patients who were children at the time of treatment. Check the rules for your jurisdiction and profession. From a security standpoint, the relevant point is that long retention means a large archive, and the archive needs protecting as carefully as the live system.

Is cyber insurance worth it for a practice our size?

Frequently yes, and the application process is itself useful because it forces an honest inventory of your controls. Be careful answering it: the questions are treated as conditions of cover, and an inaccurate answer discovered during a claim is a worse position than a higher premium. We wrote about what the questionnaire is really testing.

General information about privacy and security obligations commonly applying to Australian health service providers, not legal advice. Obligations vary by state, profession and circumstance — confirm your own position with a qualified adviser and your registration body.

An assessment that speaks practice, not just IT

Where your patient data actually sits, who can reach it, and the shortest path to defensible — sized for a practice rather than a hospital.