Foundations of general practice standard

F8 – Information security


      1. F8 – Information security

F8 | Information security


Consumer expectation statement: I expect that my information is securely managed to protect my privacy.

F8.A The practice has an information and communication technology (ICT) continuity, protection, and recovery plan.

The practice:

  • maintains, documents, and regularly tests an ICT continuity, protection, and recovery plan that includes a cyber security incident response plan
  • has a backup log operated by the practice or contracted provider
  • maintains up-to-date antivirus protection and hardware/software firewalls
  • has secure retention and backup of information in offsite or cloud storage locations and the ability to restore information from chosen backup locations
  • has procedures to inform patients of any instance where there has been a data breach affecting their personal information.

F8.B The practice has secure electronic systems and ICT.

The practice:

  • has at least one person (a member of the practice team or contracted provider) with primary responsibility for the security of the practice’s electronic systems and ICT
    • if the above person is an external contracted provider, the practice has at least one member of the practice team who has primary responsibility for digital governance
  • documents its policies for the storage of, and access to, health information in the practice’s privacy policy, including remote access if applicable.

F8.C The practice uses digital communications in a way that protects the privacy of patients and the practice team.

F8.D The practice uses social media in a way that protects the privacy of patients and the practice team.

F8.E The practice has procedures for the storage, retention, and destruction of records.

The practice:

  • documents procedures for the storage, retention, and destruction of records, both digital and hard copy (physical).

Aspirational criterion

F8.F The practice informs patients about the digital communication tools it uses to support their care.

The practice:

  • informs patients about any communication products or platforms used for communication between the practice and patients to support the delivery of care.


Maintaining a secure, functional, and reliable ICT system is critical for general practices to deliver safe, continuous patient care. Robust planning to achieve ICT continuity, information protection, and recovery allows the practice to respond quickly to disruptions such as cyberattacks, hardware failures, and natural disasters. Similarly, clear procedures that address the storage, retention, and destruction of data, as well as communication protect patient privacy, support compliance with legal obligations, and strengthen patient trust.


Table 6 describes the components that are to be included in the practice’s ICT continuity, protection, and recovery plan.

Table 6 What to include in the practice’s ICT continuity, protection, and recovery plan

Component

Description

Cyber security incident response plan A cyber security incident response plan outlines how the practice will respond to and manage a data breach, including the following actions:
Detection and analysis
  • Measure the scope of data breaches
  • Engage ICT providers or forensic specialists
Containment and eradication
  • Stop further malicious activity (for example, by blocking compromised accounts or disabling affected access).
  • Isolate affected systems to prevent spread of the incident.
  • Engage ICT/cyber security experts to remove malicious software and restore system integrity.
Recovery
  • Access essential systems and information to continue providing care
Communication to patients/service users
  • Notify patients and stakeholders
  • Notify relevant authorities
Post-incident analysis
  • Review the incident and implement necessary improvements.Daily backup procedures
  Daily (or more frequent) backups of critical operational data (for example, appointments, billing, patient health info) that are ideally automated.
Backup testing schedule Regular tests to confirm that backups are correctly created, accessible, and readable.
Secure offsite/cloud backup Use secure offsite or cloud-based storage with verified ability to restore data.
Third party provider agreements Standard letters of agreement signed by ICT providers that clarify their obligations relating to security.
Malicious software protection Active and updated antivirus/malware protection on all systems.
Email security The process that scans incoming emails and their attachments for potentially malicious software or links to potentially malicious websites.
Automatic updates Processes for timely and automatic updates of antivirus signature files and software patches.
Staff training Ongoing training for team members about cyber safety, malware prevention, and incident reporting procedures.
Software updates and maintenance Updates and installations, preferably run outside of practice hours, to minimise disruption.
Remote access If the practice allows clinicians and other users to access its systems remotely, its documented policies will address remote access. Refer to the RACGP’s Information security in general practice for further information about remote access.


The practice needs to:

  • know its legal obligations in the event of a cyber security incident
  • be aware of the authorities that govern cyber security in Australia and know who to contact in the event of a cyber security emergency. Relevant bodies include:
    • the Australian Signals Directorate
    • police (state and federal)
    • Department of Home Affairs.


The practice needs to have at least one person who has primary responsibility for the security of its electronic systems and ICT. This person may be a qualified member of the practice team or a contracted ICT professional. If an external contracted provider, the practice needs to have at least one member of the practice team with primary responsibility for digital governance, who:

  • knows when and how to escalate ICT issues
  • distributes contact details of external experts to relevant members of the practice team
  • educates the practice team on data security
  • monitors the practice team’s compliance with security policies
  • oversees procurement and maintenance of ICT systems
  • aligns ICT practices with the overall strategic plan.

The designated member of the practice team could facilitate education and training about the practice’s ICT continuity, protection, and recovery plan, or whole-practice training to support mutual learning and the identification of any barriers to implementing these ICT processes.


When contracting an external ICT provider, the practice needs to confirm that:

  • the contracted provider understands and complies with the practice’s data security policies
  • the contracted provider is experienced in handling sensitive health data
  • any contract specifies obligations, including for remote access.

The RACGP’s Information security in general practice provides advice on which factors to consider when developing a contractual agreement with a technical service provider or cloud service provider.


Wherever possible, store health information and other data (including backups) in Australia, to avoid burdensome legal and regulatory issues associated with overseas storage. Data stored in Australia is subject to protections afforded by the Privacy Act 1988 and the Australian Privacy Principles (APPs). If the practice stores data outside of Australia, its privacy policy will include relevant details and require that the practice informs patients that their health information is stored overseas.


The practice needs to:

  • keep and securely store health records of both active and inactive patients in accordance with all applicable privacy and health information laws
  • retain health information for the minimum periods required under Commonwealth and state or territory legislation
  • maintain both digital and hard copy records securely during the retention period
  • seek advice where necessary to confirm compliance with retention periods and any restrictions on destruction when records may be subject to legal proceedings.


The practice needs to:

  • securely destroy or permanently de-identify health information when it is no longer required for any authorised purpose, in accordance with applicable laws
  • have documented processes for the safe disposal of hard drives and other storage media, whether managed internally or by an external provider
  • wipe all information from devices such as hard drives, printers, and photocopiers before recycling or disposal
  • confirm that destruction methods meet privacy and security requirements to prevent unauthorised access or data recovery.
 

Advertising