Cybercrime reports from small businesses rose sharply in the past financial year, and unplanned downtime…

Finding Reliable IT Support for GP Practices That Understands Bulk Billing and Medicare Compliance
It is 9.40 am, the waiting room is full, and the practice management system has just frozen mid-claim. For a professional services firm, this can be an inconvenience. For a GP practice, it is a clinical workflow-stopping and a Medicare claim disappearing at the same moment. That difference is exactly why choosing IT support for a general practice is not the same as choosing IT support for a law firm or a retail chain, and why so many practices end up with a provider who can fix a printer but cannot explain what RACGP Criterion C6.4 requires.
This guide sets out what it means for an IT provider to understand the technical requirements of Medicare claiming, healthcare compliance and RACGP accreditation, why that matters and what to ask before signing with a provider.
Why Generic IT Support Falls Short in General Practice
Most managed service providers are built around a playbook that works well for professional services: patch software, manage a firewall, respond to tickets within a business-hours SLA. That playbook handles most problems a law firm or accounting practice will ever throw at it.
General practice breaks that playbook, not because the technology is different, but because downtime costs so much. A practice management system (PMS) like Best Practice, Medical Director, or Genie is not simply an admin tool; it holds the patient record the GP is looking at, it is the interface the receptionist uses to check in the next patient, and it is the system that submits the Medicare claim the moment the consultation ends. When it goes down, three things stop at once: clinical workflow, patient flow, and billing. A generalist IT provider without healthcare context will usually treat that outage as a standard priority-two ticket. A provider that understands general practice treats it as the emergency it is.
Understanding Medicare Compliance for an IT Provider
1. It Isn’t Billing Advice — It’s the Technical Layer Underneath It
An IT provider is not your accountant and should not be giving billing advice. What it should be doing is making sure the technical layer that Medicare claiming depends on remains reliable: the PMS, internet connectivity, authentication, Medicare claiming interfaces and access to relevant services Australia systems such as HPOS. It should also ensure the clinical and business data supporting those workflows is appropriately backed up and recoverable if the system fails.
2. My Medicare and the Bulk Billing Practice Incentive Program (BBPIP)
From 1 November 2025, the federal government expanded Medicare bulk billing incentives to every Medicare-eligible patient and introduced the Bulk Billing Practice Program (BBPIP) for practices willing to bulk bill every general practice non-referred attendance. Participating practices receive an additional 12.5 per cent loading on the MBS benefit for every eligible bulk-billed service, split evenly between the GP and the practice, paid quarterly and calculated automatically by Services Australia. Registration is via My Medicare, and the first payments began flowing in early 2026.
The IT implication is direct and, for many practices, new: because the incentive is calculated automatically from billing data your systems report, a claiming error, a missed sync, or downtime during a billing run is no longer just an inconvenience; it is a quantifiable dent in an incentive payment that did not exist in this form before November 2025. An IT provider who has never heard of BBPIP or My Medicare cannot help you protect that revenue, because they do not know it is at stake.
RACGP Accreditation: The Specific IT Criteria a Surveyor Will Check
General practices are accredited against the RACGP Standards for general practices. Practices are currently assessed against the 5th edition. The RACGP released its 6th edition on 26 August 2026, but the Australian Commission on Safety and Quality in Health Care has not yet published a transition timetable, so practices should keep meeting the 5th edition while beginning a structured gap analysis against the new criteria rather than switching over immediately.
Under the current standards, Criterion C6.4 deals specifically with information security, and a surveyor can reasonably expect your practice and, by extension, your IT provider to produce evidence of it: backup logs, access control records, and a documented information security policy, not a verbal assurance that “we back things up.” Criterion C5.3 requires a documented process for safe clinical handover within the practice and to external providers, and Criterion C6.3 requires that patient health information be transferred in a timely, authorised and secure manner. The RACGP itself has flagged that many practices still rely on unencrypted email, fax or post to send patient records externally, a security risk that a healthcare-literate IT provider should be proactively closing with secure clinical messaging, not waiting to be asked.
Why healthcare remains one of Australia’s Most Affected sectors
The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications across the 2025 calendar year under the Notifiable Data Breaches scheme, the highest annual total since the scheme began in 2018, and an 8 per cent rise on the 1,112 notifications recorded in 2024. Malicious or criminal attack was the leading cause, responsible for 716 of those notifications. Health service providers were the single most affected sector for the year, accounting for 225 notifications, 19 per cent of the national total, and comfortably ahead of financial services in second place.
The lesson for a small GP practice is not comforting, but it is important: attacker interest is driven by the sensitivity and resale value of patient data, not by the size of the clinic holding it. A practice with a handful of GPs and a few thousand patient files is not too small to be worth it. An IT provider serving healthcare should already be building around that reality: multi-factor authentication on clinical software and email as standard, endpoint detection rather than antivirus alone, backups that are tested through an actual restore rather than assumed to be working, and a documented incident response plan that accounts for the OAIC’s statutory notification timeframes.
Red Flags: Signs a Provider Doesn’t Understand Healthcare
- They can’t clearly explain the trade-offs between on-premises and cloud-hosted practice management software.
- RACGP Standards and My Health Record don’t come up naturally in the first conversation — you must raise them yourself.
- Response-time commitments are written for general office issues, with nothing specific for “the PMS is down, and patients are in the waiting room.”
- There is no written incident response plan, or the one they show you was clearly not written for a health service provider.
- Backup and security claims are made verbally with nothing you could hand to an accreditation surveyor as evidence.
Why This Matters More Now Than It Did Two Years Ago
Three things have moved at once. The Bulk Billing Practice Incentive Program has put a direct, quarterly, automatically calculated dollar figure behind billing-system reliability. The RACGP’s 6th edition standards have just been released, with practices needing to begin gap analysis even before a transition date is confirmed. And 2025 delivered the highest number of data breach notifications since national reporting began, with health services the single most affected sector. Individually, each of these would be a reason to take IT support more seriously. Together, they mean that “good enough” generalist IT support now carries a measurable cost on the compliance, security, and revenue sides of the practice simultaneously.
A Practical Due Diligence Checklist Before You Sign
Use this as a starting list of questions for any prospective IT provider; the strength of their answers tells you as much as the answers themselves.
| Question to ask | What a strong answer sounds like |
| Which practice management systems do you actively support today? | Names Best Practice, Medical Director, or Genie specifically, with recent, named examples. |
| What happens if the PMS goes down during a Thursday morning clinic? | A defined, faster response tier for clinical-hours outages, not the standard SLA. |
| When did you last test-restore a backup, not just run one? | A specific recent date and a described process. |
| Can you talk me through RACGP Criterion C6.4? | A clear, specific explanation — not a redirect to “we handle compliance.” |
| How would you support us through a data breach notification? | A documented process referencing the OAIC Notifiable Data Breaches scheme. |
| Do you understand how BBPIP and MyMedicare affect our claiming reliability? | A direct, informed answer, not a blank look. |
Conclusion
IT support for a GP practice is a healthcare decision as much as a technology one. The right provider protects clinical workflow, Medicare billing reliability and RACGP accreditation evidence at the same time because in general practice, those three things break together, not separately.
Medical IT Services specialises in supporting GP practices, specialists, allied health clinics and healthcare groups across Australia, supporting the clinical software you already run and the compliance obligations that come with it. If you’re evaluating your current IT support or you’ve never quite had a straight answer on how ready your practice is for a RACGP review or a Medicare claiming outage, talk to a team that works in healthcare IT every day, not occasionally.
