Back to Blog
    Healthcare Compliance

    IT Checklist for Brisbane Healthcare Practices

    16 July 2026
    6 min read

    Healthcare IT Compliance in Brisbane

    Healthcare practices in Brisbane are subject to a range of compliance obligations that have direct IT implications: the Privacy Act 1988, the Australian Privacy Principles, the Notifiable Data Breach scheme, the My Health Records Act, and AHPRA registration standards for clinical practitioners. Meeting these obligations requires more than good intentions — it requires specific IT controls.

    This checklist applies to GP practices, medical specialists, allied health providers, and private hospital services in the Brisbane and SE Queensland region.

    Internet and Connectivity

    • [ ] Business-grade NBN or fibre connection with a Static IP
    • [ ] Seamless failover (4G/5G or Starlink) for telehealth continuity
    • [ ] QoS configured to prioritise telehealth and video traffic
    • [ ] Clinical systems network isolated from guest Wi-Fi

    Identity and Access

    • [ ] Individual user accounts for all staff — no shared logins to clinical systems or email
    • [ ] MFA enabled on Microsoft 365, Google Workspace, or practice email accounts
    • [ ] MFA enabled on practice management software (Medical Director, Best Practice, Cliniko, etc.)
    • [ ] MFA enabled on PRODA and Medicare Online accounts
    • [ ] Access permissions reviewed — staff can only access records relevant to their role
    • [ ] Offboarding process documented — accounts deactivated on last day of employment

    Device Security

    • [ ] All computers on Windows 11 or macOS Ventura or later
    • [ ] Endpoint Detection and Response (EDR) on all devices
    • [ ] Drive encryption active (BitLocker / FileVault)
    • [ ] Automatic screen lock after maximum 5 minutes on clinical computers
    • [ ] Mobile devices enrolled in MDM with remote wipe capability

    Email and Communication

    • [ ] SPF, DKIM, and DMARC configured for your domain
    • [ ] Email filtering and phishing protection active
    • [ ] Staff trained on recognising phishing — healthcare is a targeted sector
    • [ ] Secure file transfer solution in place for sending patient documents

    Backup and Data Protection

    • [ ] Automated daily backup of all clinical and administrative data
    • [ ] Separate backup from practice management software built-in storage
    • [ ] Offsite or cloud backup copy (3-2-1 rule)
    • [ ] Backup tested — last test date documented
    • [ ] Data retention policy documented and aligned with AHPRA / Medicare requirements

    Privacy and Compliance

    • [ ] Privacy policy current and on display / accessible to patients
    • [ ] Notifiable Data Breach response procedure documented
    • [ ] Staff trained on Privacy Act obligations
    • [ ] Patient consent documented for My Health Records access
    • [ ] Incident register maintained for any data or security incidents

    Facilities

    • [ ] Computer screens oriented so patient information cannot be viewed by other patients in the waiting room
    • [ ] Printed records stored securely — not left unattended in public areas
    • [ ] Secure disposal of printed patient records (cross-cut shredding)
    Getting Help

    The Brisbane Healthcare IT Compliance Gap

    The gap between what Brisbane healthcare practices believe their IT compliance looks like and what an independent audit finds is consistently larger than practice owners expect. The reasons are understandable: clinical IT is not anyone's day job in a small practice, the team is focused on patient care, and IT problems are addressed reactively when they occur rather than proactively.

    The compliance gap matters because regulators — the OAIC, AHPRA, and the NDIS Commission for registered providers — assess practices against an objective standard of "reasonable steps", not against what was intended.

    The most common gaps found in Brisbane healthcare IT audits:

    MFA not enabled. The single most common gap. A practice that believes it is on Microsoft 365 "properly" is often running without MFA because Security Defaults were not enabled when the tenancy was set up, or because a user complained that MFA was inconvenient and it was disabled. This leaves the entire Microsoft 365 environment vulnerable to credential-based attack.

    Backup not tested. Many practices have a backup configured but have never tested recovery. A backup that has never been tested has an unknown probability of actually working when needed.

    Outdated devices. Computers running Windows 10 past the October 2025 end-of-support date, or outdated macOS versions. These devices receive no security patches and accumulate permanent vulnerabilities.

    Former staff account access not revoked. Staff turnover is significant in healthcare. Accounts for former employees are often not disabled promptly. This is both a security and a Privacy Act obligation — former staff should not have access to patient records after leaving.

    No documented access controls. Access to patient records is not documented by role. There is no policy on which staff should access which records. When asked to demonstrate access control in an audit, the practice cannot show the control exists.

    The Workforce Identity Challenge in Healthcare

    Healthcare practices have specific identity management challenges compared to other businesses:

    High staff turnover. Casual and part-time clinical staff, student placements, and regular locum coverage create a constantly changing workforce with frequent account provisioning and deprovisioning requirements.

    Multiple practice locations. Group practices with more than one site need consistent account management across sites. Staff moving between sites should not require separate accounts or experience access inconsistencies.

    Practitioner vs support staff access. Clinical staff need access to patient records, clinical systems, and Medicare claiming tools. Administrative staff need access to scheduling and billing systems but not necessarily to clinical notes. This distinction needs to be reflected in system permissions, not just policy.

    Contractor and locum access. Regular locums who visit the practice may need temporary access to specific systems. This access should be time-limited, granted at the start of each engagement, and revoked at the end — not left open indefinitely between visits.

    The practical implementation for most Brisbane practices: individual Microsoft 365 accounts for every person (no shared logins), role-based access groups configured in Azure AD, and a documented onboarding/offboarding checklist that connects HR processes to IT provisioning.

    Telehealth Compliance for Brisbane Practices

    Brisbane healthcare practices providing telehealth through Medicare-funded channels have specific platform and infrastructure requirements:

    Platform requirements. Medicare-funded telehealth must use end-to-end encrypted video platforms. Acceptable platforms include Healthdirect Video, Coviu, and telehealth modules built into major practice management platforms. Consumer platforms without healthcare-grade security (standard FaceTime, Zoom consumer tier) are not appropriate for Medicare-funded telehealth.

    Internet connectivity requirements. Simultaneous telehealth sessions from multiple clinicians require sufficient upload bandwidth and stable connectivity. NBN Business Class with QoS configuration is the recommended baseline for practices with more than two clinicians running concurrent telehealth.

    Record-keeping. Medicare has specific documentation requirements for telehealth consultations — the consultation type (video, phone), that the appropriate technology requirements were met, and that the clinical content meets the same standard as an in-person consultation. Ensure your practice management software records telehealth consultation type for audit purposes.

    Privacy disclosure. Patients should be informed about the telehealth platform being used and how their health information is handled during the consultation. This is good clinical practice and also a Privacy Act obligation regarding transparency about data handling.

    Netluma IT provides IT compliance reviews specifically for Brisbane healthcare practices. Call 1300 521 162 to book a review of your specific setup and get a clear list of priorities.

    Netluma IT provides healthcare-specific IT services for Brisbane and SE Queensland practices. Call 1300 521 162 for a free IT review against this checklist.

    Need Healthcare-Compliant IT?

    NDIS audit-ready, My Health Record compliant, and Privacy Act covered. IT built specifically for allied health and healthcare providers.

    Related Services

    96% first-hour resolution
    Local Gold Coast team