ZIP IT Solutions

Guides & Checklists

Cyber Security Checklist for Allied Health

A working checklist covering the accounts, devices, backups, and habits that actually reduce cyber risk for a small allied health practice, without needing a security background to use it.

Ethan Cook

Ethan Cook · 28 June 2026 · 1 min read

The Cyber Security Checklist Every Allied Health Practice Should Run Through

Most of the cyber security advice aimed at small practices is either too vague to act on ("stay vigilant") or written for enterprise IT teams with resources a solo clinic doesn't have. This is meant to sit in between: specific enough to check off, realistic enough to actually get done.

Health service providers are bound by the Privacy Act regardless of turnover, and the sector has topped the OAIC's data breach notifications for years running (OAIC), so this isn't a theoretical exercise for allied health businesses. Work through each section below and note anything you can't confidently tick off.

Accounts and access

Shared logins and reused passwords are behind a large share of the breaches we see in small practices.

  • Multi-factor authentication is enabled on every account that supports it, especially email and your practice management system
  • Every staff member has their own login, nobody is sharing a single reception account
  • Admin rights are limited to the one or two people who genuinely need them, not everyone by default
  • Former staff accounts are disabled the day someone leaves, not weeks later

Devices

  • Every laptop and phone used for practice work is known to you, there's no "shadow" personal device quietly checking practice email
  • Devices are enrolled in mobile device or app management (see our guide to endpoint management) so a lost device can be wiped remotely
  • Full disk encryption and a screen lock are enforced on all devices
  • Operating systems that are past their support end date have been retired or upgraded

Backups

  • Backups run automatically, not manually, and not only when someone remembers
  • At least one copy is offline or otherwise isolated from your main network, so ransomware can't reach it
  • A restore has actually been tested in the last twelve months, not just confirmed to be "running"
  • Retention covers enough history to recover from an incident discovered weeks after it happened

Patching

  • Operating systems and applications are set to update automatically wherever possible
  • Critical vulnerabilities, the kind vendors flag as allowing remote access without user interaction, are patched within 48 hours rather than waiting for a routine cycle
  • Software that's no longer supported by its vendor has been identified and has a replacement plan

Email and phishing

  • SPF, DKIM, and DMARC are configured for your domain (see our email authentication guide if you're not sure)
  • Staff know what a phishing attempt typically looks like and have somewhere simple to report one
  • Any request to change bank details, transfer funds, or share sensitive information is verified by phone, using a number you already have on file, not one supplied in the request itself

Privacy and compliance basics

  • A current, accurate privacy policy is published and reflects what your practice actually does with patient information
  • Someone in the practice can explain, in a sentence, what an eligible data breach is and the 30-day assessment obligation that follows suspecting one
  • Security safeguards are documented well enough that you could show an assessor what you do, not just tell them

Incident readiness

  • There's a short, written plan for what happens in the first hour of a suspected breach or ransomware event, who's called, who's told, what gets isolated
  • You know who you'd call for IT support outside business hours if something happened on a weekend
  • Cyber insurance, if you have it, has actually been read, so you know what it covers and what it requires of you to remain valid

Using this checklist

If you went through this and ticked most boxes, that's a genuinely good sign. If several sections raised more questions than confident answers, that's normal too, and it's exactly what a structured cyber health check is designed to work through properly: mapping your practice against a recognised framework like the Essential Eight, prioritising the gaps that matter most, and giving you a clear, realistic plan rather than a long list of everything at once.

Want to apply this to your practice?

We can walk through what this means for your environment on a short call, or start with a Health Check.