Skip to content
Medical & allied health · Australia

A patient record is worth more than a credit card. Protect it accordingly.

Patient information and connected clinical systems make medical practices a high-consequence target. We map your practice's security to applicable privacy, health-record and professional obligations, then document the controls.

Dossier 02 / 10

Medical & Allied Health

Health records sell for more than credit cards. A breach here is a patient-safety and registration risk.

  • AHPRA obligations
  • My Health Records Act 2012
  • Privacy Act 1988 / APPs
Named obligations

What the obligation actually requires of you.

  1. 01

    AHPRA obligations

    Registered practitioners and their staff have professional confidentiality and privacy obligations. A serious incident may require separate advice about registration, privacy and health-record duties.

  2. 02

    My Health Records Act 2012

    Connected systems carry specific security and unauthorised-access obligations under the My Health Records Act, with real penalties for non-compliance.

  3. 03

    Privacy Act 1988 / APPs

    Patient records are sensitive information under the Privacy Act, held to a materially higher standard of protection than ordinary personal information.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Allied health group, VIC

A ransomware attempt targeting patient files.

Illustrative scenario — In this example, A phishing email delivered a ransomware payload to a reception workstation at a multi-site allied health group. The payload attempted to encrypt shared drives, including the folder synced from the practice-management database.

Example response — A suitable response is to isolate affected devices, preserve clinical-system evidence, reset credentials and test restoration from protected backups before reconnecting systems.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, then see the priorities.

Review each practical control, assign an owner, and get an educational action list before you request a prepared follow-up.

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Medical & Allied Health Cybersecurity Checklist

0 / 7 reviewed0%

MFA enforced on practice-management and My Health Records system access

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: MFA enforced on practice-management and My Health Records system access.

Immutable, tested backups of the patient-record database

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Immutable, tested backups of the patient-record database.

A documented notifiable-breach process aligned to the Privacy Act and the My Health Records Act

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: A documented notifiable-breach process aligned to the Privacy Act and the My Health Records Act.

Role-based access so reception, clinical and admin staff see only what their role requires

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Role-based access so reception, clinical and admin staff see only what their role requires.

Endpoint protection on every device that touches patient records

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Endpoint protection on every device that touches patient records.

An audit log of who accessed which patient record, and when

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: An audit log of who accessed which patient record, and when.

An incident escalation path aligned to applicable privacy, health-record and professional obligations, documented and rehearsed

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: An incident escalation path aligned to applicable privacy, health-record and professional obligations, documented and rehearsed.

Complete each control to see your prioritised plan before submitting.

Request a prepared action plan

Share business details so GMAN IT can prepare a useful follow-up by email and with the team.

Optional business context

Your submitted details and checklist answers are shared with GMAN IT to prepare the plan and follow up. Read our Privacy Policy. If a delivery link is generated, it expires after 7 days.

Before you call us

The questions this vertical always asks.

Find out exactly where your patient data is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au