Most GP practices don't have one IT problem; they have five separate vendors, each responsible…

Why IT Support for Clinics Must Prioritise Patient Privacy and System Uptime
What privacy and uptime mean in a clinic
Security professionals describe information protection with three ideas: confidentiality, integrity, and availability. In a clinic, they translate into questions.
| Idea | The clinic question | What failure looks like |
| Confidentiality (privacy) | Can only the right people see this record? | A receptionist browses clinical notes; a stolen password exposes a mailbox; a departed locum still has a login. |
| Integrity | Is the record accurate and unaltered? | Ransomware or a failed update corrupts a database, or an unrecorded change alters a medication list. |
| Availability (uptime) | Can the right clinician open it while the patient is in the chair? | The server is down, the NBN drops, or a certificate expires and e-prescribing stops. |
Why do privacy and uptime fail together?
Many people picture data breach and a system outage as separate events. In practice, one incident often causes both. Ransomware in healthcare typically encrypts files (uptime lost) after copying them out (privacy lost). A failed backup turns a simple disk fault into permanent loss of records. A hurried fix, such as a vendor-given remote access at 6 p.m. with a shared password, restores service and opens a door at the same time.
The scale of the problem is documented. The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in 2025, the highest annual total since the scheme began in 2018. Health service providers were the most affected sector, with 225 notifications (19%), and malicious or criminal activity accounted for 716 of the total. Not every incident involves an outside attacker, either: the OAIC attributed 37% of notifications in the first half of 2025 to human error.
The practical lesson is that security and reliability cannot be managed in isolation. Whether one provider handles both or several providers share responsibility, ownership, escalation paths and recovery procedures need to be clearly defined in advance.
What Australian law and standards expect from a clinic in 2026
1. The Privacy Act and Australian Privacy Principle 11
Most small businesses with turnover of $3 million or less fall outside the Privacy Act. Private health service providers do not: if you provide a health service and hold health information, the Act applies to you regardless of size. Australian Privacy Principle (APP) 11 requires “reasonable steps” to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. What is reasonable depends on the sensitivity of the information and the consequences of a breach, and health information sits at the top of that scale.
Enforcement is real. The maximum penalty for serious interference with privacy is now the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. In October 2025, the Federal Court approved a $5.8 million penalty against Australian Clinical Labs over the 2022 Medlab Pathology breach, the first civil penalty under the Privacy Act. That penalty was set under the older regime, with a lower maximum. Since December 2024, the OAIC also has lower-tier civil penalties and infringement notices, so it no longer must prove a “serious” interference before acting.
2. Notifiable data breaches
If a breach is likely to cause serious harm, you must notify the OAIC and the affected individuals. If you only suspect a breach, you are expected to assess it promptly, within 30 days at most. A clinic that cannot tell which records were accessed, because it has no audit trail, cannot make that assessment properly.
3. My Health Record, ransomware reporting and state laws
- My Health Record. The My Health Records Rules 2026 require registered healthcare provider organisations to maintain and enforce a security and access policy covering access to My Health Record. From 1 October 2026, all registered healthcare provider organisations must ensure their policy complies with the 2026 rules.
- Ransomware payments. Since 30 May 2025, businesses with annual turnover above $3 million must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours. Larger multi-site groups should check whether they are caught.
- Statutory privacy tort. From 10 June 2025, individuals can sue for a serious invasion of privacy, but only where the conduct was intentional or reckless. For a clinic, the practical relevance is a staff member deliberately snooping on a record, which is one more reason audit logs matter.
- State health records laws. New South Wales, Victoria and the ACT have their own health records legislation alongside the federal Act.
Where privacy and uptime pull against each other
Most IT provider websites promise both goals in one sentence. Few admit that the controls for one can damage the other when they are done badly. These six trade-offs come up in real clinics, and a good provider will raise them before you do.
| Trade-off | If privacy loses | If uptime loses | A better approach |
| Multi-factor authentication (MFA) | A stolen password opens email and remote access. | A lost phone locks a GP out at 8 a.m. with patients waiting. | Roll out after hours, offer a second method that does not depend on one phone, and keep a securely stored emergency account. |
| Patching | Known vulnerabilities stay open for months. | An update reboots the server mid-session or breaks the clinical database. | Fixed maintenance windows outside clinic hours, vendor compatibility checked first, tested rollback for practice software updates. |
| Screen locks and timeouts | Records stay open on unattended screens. | Aggressive timeouts slow consults, so staff disable locks or share logins. | Fast sign-in (badge tap or biometric) rather than long timeouts. |
| Vendor remote access | A permanent remote tool with a weak password is an open door. | Refusing all remote access prolongs an outage. | Time-limited, logged, MFA-protected sessions agreed before an emergency. |
| Restoring after an incident | Restoring over an infected system can destroy evidence and reinfect. | Waiting for forensics extends downtime. | Rebuild into a clean environment, preserve affected systems where practical, and decide the order in advance. |
| Failover internet | A 4G/5G backup that bypasses the firewall is an unmonitored path. | No failover means an NBN fault stops eScripts and claiming. | Route the failover link through the same firewall and policies as the main connection. |
Protecting patient privacy:
The Australian Signals Directorate’s Essential Eight, which includes MFA, patching, restricting administrator privileges and regular backups, is a sensible way to prioritise. For a clinic, the following controls do most of the work. Medical IT Services’ cybersecurity solutions are organised around the same priorities.
1. Unique logins and least privilege
Every person gets their own login to the clinical software, with access matched to their role. Reception does not need to read consultation notes. A shared “front desk” account means that, after an incident, nobody can say who opened which record. Leavers and locums are disabled on the day they finish. Clinical software audit logs are only useful if people log in as themselves.
2. MFA where it matters
Start with multi-factor authentication for healthcare on email, remote access, cloud portals and every administrator account. Those are the doors attackers use most. Add MFA to consulting-room logins only if your provider can show it will not slow the clinic.
3. Encryption and device hygiene
Laptops, USB drives and backups should be encrypted, so a lost device is an inconvenience rather than a notifiable breach. Clinical photos taken on personal phones need a written policy: RACGP guidance exists on this, and the common failure is photos syncing automatically into a personal cloud album.
4. Secure messaging, not email
Referrals and results should travel through secure messaging services such as HealthLink, Argus or Medical Objects rather than ordinary email. If patients email you, your email policy (C6.4 F) should tell them the risks and record their consent.
5. Training that targets real mistakes
With human error behind more than a third of notifications, a short annual talk is not enough. Practice the three moments that cause most harm: phishing emails, sending a document to the wrong person, and giving information to a caller who is not who they say they are.
6. Third parties on paper
Your IT provider, cloud host, transcription service, and software vendors can all touch patient information. RACGP guidance expects external IT providers to sign an agreement stating their commitment to your continuity and privacy plan. Ask where your data is hosted and who can access it.
When ransomware strikes, privacy and uptime are lost together
A ransomware incident tests every point above at once. A sensible response sequence, agreed before anything happens, looks like this:
- Isolate affected devices from the network. Do not wipe them out yet.
- Call for help. Contact your IT provider or incident response firm and your cyber insurer, if you have one. Keep a printed contact list; your normal system may be unavailable.
- Preserve evidence. Restore into a clean environment where possible so you can still establish what was accessed.
- Assess notification. Work out whether an eligible data breach has occurred and start the OAIC assessment, seeking privacy advice early.
- Check payment reporting. If a payment is ever made and your business exceeds the $3 million turnover threshold, the 72-hour report to ASD applies.
- Tell patients. Clear, honest communication protects trust more than silence does.
Your provider should have an incident response plan for a medical practice that maps these steps, and you should have read it before you need it.
Conclusion
Patient privacy and system uptime are not competing priorities. There are two views of the same responsibility: the right clinician, the right record, at the right time, and nobody else. Good IT support for clinics therefore looks less like a help desk and more like a small governance function. It sets recovery targets with your clinicians, tests backups, controls access, plans maintenance around consulting hours, and can show you evidence after an incident. Start with the 30-day plan above, ask your provider the eight questions on the table, and treat any promise of perfect uptime as a warning sign.
