Skip to main content
Resource Guide — Updated August 2026

GP Practice Cybersecurity Guide

Australian general practices are among the highest-value targets for cybercriminals. This guide covers every critical control your practice needs to protect patient records, secure Medicare billing, and meet Privacy Act obligations.

Why GP Practices Are Prime Targets

Australian general practices hold an extraordinarily concentrated collection of high-value data. A single practice with 5,000 active patients holds Medicare card numbers, healthcare identifiers, prescription histories, mental health notes, and financial billing data — all in one place. On the dark web, a complete Australian health record sells for between $200 and $1,000 AUD, far more than a credit card number (typically under $10). This makes your patient management system one of the most profitable targets a cybercriminal can attack.

The structural vulnerabilities of Australian GP practices make them attractive targets beyond just the data value. Most practices run with no dedicated IT staff. A busy two-GP practice in suburban Melbourne typically relies on a generalist IT support person who visits quarterly, leaves default passwords on servers, and has never tested the backup system. Software is often years out of date because updating clinical systems requires downtime that interrupts patient care.

Allied health staff — physiotherapists, psychologists, and nurses who use the same network under a shared-services arrangement — frequently bring personal devices. A physiotherapist's personal iPad connecting to the practice Wi-Fi to check a patient file can introduce malware that spreads to the clinical server within minutes.

The Office of the Australian Information Commissioner (OAIC) consistently reports healthcare as one of the top two most breached sectors in Australia. Understanding why your practice is a target is the first step toward building a credible defence.

The Specific Threats Facing Australian GPs

Ransomware on Clinical Systems

Ransomware targeting Best Practice Software, Medical Director, and Cliniko is the highest-impact threat facing Australian GPs. Attackers encrypt the patient database and demand payment — typically $50,000 to $200,000 AUD — to restore access. Modern ransomware operators also exfiltrate data before encrypting, threatening to publish patient records publicly unless payment is made (double extortion). A GP practice that cannot access its appointment book or clinical notes cannot safely operate; this operational urgency is exactly what ransomware attackers exploit.

Medicare Billing Phishing (ATO/Services Australia Impersonation)

Attackers send convincing emails impersonating Services Australia or the ATO, directing practice managers to update banking details for Medicare reimbursements through fake portals. Once credentials are captured, attackers access the practice's Medicare Online and lodge fraudulent bulk-billing claims, redirect payment to attacker-controlled accounts, or manipulate billing records. These attacks are highly targeted — attackers research the practice's billing volume, locate the practice manager's name from the website, and craft personalised phishing emails that look identical to legitimate government correspondence.

BYOD Risks from Allied Staff and Locums

Bring-your-own-device (BYOD) arrangements are common in general practice, particularly where allied health providers (physios, dietitians, podiatrists) operate from the same premises. Personal devices are rarely encrypted, are often used for personal browsing and social media (which can expose them to malware), and may have outdated operating systems. Locum GPs connecting with their personal laptops to access the clinical network introduce the same risk. Without a formal BYOD policy enforced through mobile device management (MDM), a single compromised personal device can give an attacker a foothold in your clinical network.

Securing Your Patient Management System

Australia's three dominant GP practice management systems — Best Practice Software, Medical Director (owned by Telstra Health), and Cliniko — each have specific security configurations that must be correctly implemented.

Best Practice Software typically runs on a Windows Server in your practice. This means patch management, Windows Server updates, and regular database backups must be actively managed. Best Practice's database backup function should be configured to export daily backups to an encrypted external drive and a separate cloud destination. Ensure the server hosting Best Practice is not accessible via Remote Desktop Protocol (RDP) directly from the internet — RDP is the most common entry point for ransomware in Australian healthcare.

Medical Director integrates with various health network services. Ensure that all Medical Director user accounts use individual login credentials — shared accounts make audit logging useless and prevent forensic investigation if a breach occurs. Review the list of user accounts quarterly and immediately deactivate accounts for staff who have left the practice.

Cliniko is cloud-based, which shifts many security responsibilities to the vendor, but does not eliminate your obligations. You remain responsible for ensuring that every user account has multi-factor authentication enabled, that departed staff are removed promptly, and that third-party integrations (booking widgets, SMS providers) are reviewed for data access permissions annually.

For all three systems: ensure that audit logs are enabled and retained for a minimum of 12 months. Log who accessed which patient records and when. Under the Privacy Act, you may be required to produce these logs in the event of an OAIC investigation.

Critical Security Controls for GP Practices

MFA on Microsoft 365

Enable multi-factor authentication on every Microsoft 365 account in your practice — GPs, nurses, admin staff. A GP email account with a weak password and no MFA is the most common initial access point for attackers. Microsoft Authenticator is free and takes 15 minutes to deploy across a small practice.

Offline Backups Tested Monthly

Follow the 3-2-1 rule: 3 copies of patient data, on 2 different media types, with 1 copy offsite or offline. Test your recovery every month by actually restoring a sample database. An untested backup is not a backup — it is hope.

Patch Management

Apply critical security patches within 14 days of release. Windows updates, Best Practice/Medical Director updates, and browser patches are all critical. Consider a patch management tool like Action1 (free for under 100 devices) to automate and track this.

Encrypted Devices

Enable BitLocker encryption on every Windows computer and laptop in the practice. Enable FileVault on Macs. For mobile devices and tablets, ensure device encryption is on (it is default on modern iPhones and Android devices — but confirm it is not disabled). Any device that contains or can access patient data must be encrypted.

Medicare Billing System Protection

Medicare billing fraud is a direct financial threat to your practice. Beyond the financial loss, a compromised Medicare account can result in fraudulent claims being lodged under your provider number — which may trigger a compliance audit from Services Australia and potential repayment demands even after you've reported the fraud.

1

MFA on PRODA/myGov Business

Services Australia's PRODA system supports MFA. Enable it immediately. Every person who accesses Medicare Online on behalf of the practice should use their own PRODA account — never share login credentials.

2

Callback Verification for Payment Changes

If you receive any email or call requesting a change to your Medicare payment bank account details, call Services Australia directly on the published number (132 150) to verify before making any changes. Never use contact details provided in the suspicious message.

3

Monitor Claims Regularly

Designate a staff member to review Medicare bulk-billing submissions and remittance advice weekly. Unusual claims — particularly for patients not seen — are a red flag for fraudulent use of your provider number.

4

Separate Billing Network

Where feasible, conduct Medicare billing from a dedicated workstation that is not used for general browsing or email. This dramatically reduces the risk of a phishing-borne credential theft targeting your billing systems.

Privacy Act APP 11 Obligations for GP Practices

Under APP 11 of the Privacy Act 1988, every Australian GP practice must take reasonable steps to protect patient health information from misuse, loss, and unauthorised access. The OAIC's guidance makes clear that "reasonable steps" for healthcare providers — who hold sensitive information — means a higher bar than for most other sectors.

In practice, this means: your clinical server must be encrypted; patient data must not be stored on unencrypted USB drives or personal Google Drive accounts; staff must be trained in privacy obligations; and you must have a documented incident response plan that covers how you will notify the OAIC within 30 days of discovering a breach.

Failure to comply with APP 11 can result in OAIC investigations, enforceable undertakings, public reports naming your practice, and — for serious or repeated breaches — civil penalties. Learn more at our dedicated Privacy Act health data compliance guide.

Staff Training: Your First and Last Line of Defence

The majority of successful cyberattacks on Australian GP practices begin with a human error — a staff member clicking a phishing link, entering credentials on a fake Services Australia portal, or plugging in a USB drive found in the car park. Technical controls reduce risk, but staff training is irreplaceable.

Phishing Recognition

Run simulated phishing tests quarterly. Teach staff to hover over links before clicking, to be suspicious of urgency and authority cues, and to verify unexpected requests by calling the sender on a known number.

Clean Desk Policy

Patient information on paper must never be left visible on desks when staff step away. Lock screens when leaving workstations. Reception desks are particularly high-risk given patient foot traffic.

No USB Rule

Ban the use of unknown USB drives in clinical computers. USB drives are a vector for malware, and attackers deliberately leave infected USB drives in car parks near GP practices. Implement USB port control software if enforcement is a challenge.

Incident Response: If Ransomware Hits Your Practice

A ransomware attack on a GP practice is a clinical emergency, not just an IT problem. The following response steps should be printed and kept at reception — not stored only on the computer that may be encrypted.

1

Isolate immediately

Disconnect the affected computer or server from the network (unplug the Ethernet cable). Do not turn off the device — forensic evidence may be preserved in memory. Disconnect Wi-Fi on any device showing symptoms.

2

Do not pay the ransom

Paying does not guarantee file recovery. It funds future attacks on healthcare organisations. The ACSC strongly advises against paying.

3

Call your cybersecurity provider

Contact your IT or cybersecurity provider immediately. If you do not have one, call the ACSC 24/7 hotline on 1300 CYBER1 (1300 292 371) for urgent assistance.

4

Activate your backup restoration

Your offline, tested backup is the path to recovery. A practice with a current, tested offline backup can typically restore operations within 4–8 hours. A practice without one may be offline for days or weeks.

5

Notify the OAIC

If patient data was accessed or exfiltrated, you have a Notifiable Data Breach obligation. You must notify the OAIC and affected patients within 30 days of becoming aware of the breach.

6

Notify patients

Prepare a clear, plain-language communication explaining what happened, what information was affected, and what steps you are taking. The OAIC has published template notification letters you can adapt.

The 3-2-1 Backup Rule for Patient Records

The 3-2-1 backup rule is the gold standard for protecting critical data. For a GP practice, it means:

3
Three Copies

Your live database, one backup on a local device, and one offsite or cloud backup. If ransomware encrypts your server, you still have two other copies.

2
Two Media Types

Store backups on different media — for example, a NAS device in the practice AND a cloud service like Azure Backup or Veeam Cloud Connect.

1
One Offline Copy

At least one copy must be offline or air-gapped — meaning ransomware cannot reach it even if it has full control of your network. A daily backup to an encrypted external drive that is disconnected after backup is sufficient.

Test your backup by performing a full restoration once per month. Document the restoration date and the staff member who performed it. This documentation will be critical if the OAIC ever investigates your practice's security practices.

ACSC Essential Eight Priority Order for Resource-Constrained Clinics

The ACSC Essential Eight is a set of eight cybersecurity strategies that, when implemented together, prevent the vast majority of cyberattacks. For a GP practice with limited IT budget and no dedicated IT staff, implement them in this priority order:

1
Multi-Factor AuthenticationStops credential phishing attacks — the most common initial access vector.
2
Patch Operating SystemsEliminates the vulnerabilities ransomware exploits to move through your network.
3
Regular BackupsYour recovery capability when prevention fails. Non-negotiable for clinical operations.
4
Patch ApplicationsBrowser, PDF reader, and Office vulnerabilities are commonly exploited by malware.
5
Restrict Administrative PrivilegesIf an attacker compromises a limited account, they cannot install ransomware without admin rights.
6
Application ControlPrevents unauthorised software (including ransomware) from running on clinical computers.
7
Configure Microsoft Office Macro SettingsBlocks macro-based malware delivered via email attachments — a common attack vector.
8
User Application HardeningDisables risky features in browsers and applications that attackers exploit.

For a detailed Essential Eight implementation guide tailored to healthcare, see our Essential Eight for healthcare compliance page.

Related Resources

Is Your GP Practice Cyber Secure?

ShieldForce specialises in cybersecurity for Australian healthcare. Book a free assessment and we'll identify your practice's top three risks within 24 hours.

Book a Free Practice Assessment