The Cyber Security Checklist Every Allied Health Practice Should Run Through
Most of the cyber security advice aimed at small practices is either too vague to act on ("stay vigilant") or written for enterprise IT teams with resources a solo clinic doesn't have. This is meant to sit in between: specific enough to check off, realistic enough to actually get done.
Health service providers are bound by the Privacy Act regardless of turnover, and the sector has topped the OAIC's data breach notifications for years running (OAIC), so this isn't a theoretical exercise for allied health businesses. Work through each section below and note anything you can't confidently tick off.
Accounts and access
Shared logins and reused passwords are behind a large share of the breaches we see in small practices.
- Multi-factor authentication is enabled on every account that supports it, especially email and your practice management system
- Every staff member has their own login, nobody is sharing a single reception account
- Admin rights are limited to the one or two people who genuinely need them, not everyone by default
- Former staff accounts are disabled the day someone leaves, not weeks later
Devices
- Every laptop and phone used for practice work is known to you, there's no "shadow" personal device quietly checking practice email
- Devices are enrolled in mobile device or app management (see our guide to endpoint management) so a lost device can be wiped remotely
- Full disk encryption and a screen lock are enforced on all devices
- Operating systems that are past their support end date have been retired or upgraded
Backups
- Backups run automatically, not manually, and not only when someone remembers
- At least one copy is offline or otherwise isolated from your main network, so ransomware can't reach it
- A restore has actually been tested in the last twelve months, not just confirmed to be "running"
- Retention covers enough history to recover from an incident discovered weeks after it happened
Patching
- Operating systems and applications are set to update automatically wherever possible
- Critical vulnerabilities, the kind vendors flag as allowing remote access without user interaction, are patched within 48 hours rather than waiting for a routine cycle
- Software that's no longer supported by its vendor has been identified and has a replacement plan
Email and phishing
- SPF, DKIM, and DMARC are configured for your domain (see our email authentication guide if you're not sure)
- Staff know what a phishing attempt typically looks like and have somewhere simple to report one
- Any request to change bank details, transfer funds, or share sensitive information is verified by phone, using a number you already have on file, not one supplied in the request itself
Privacy and compliance basics
- A current, accurate privacy policy is published and reflects what your practice actually does with patient information
- Someone in the practice can explain, in a sentence, what an eligible data breach is and the 30-day assessment obligation that follows suspecting one
- Security safeguards are documented well enough that you could show an assessor what you do, not just tell them
Incident readiness
- There's a short, written plan for what happens in the first hour of a suspected breach or ransomware event, who's called, who's told, what gets isolated
- You know who you'd call for IT support outside business hours if something happened on a weekend
- Cyber insurance, if you have it, has actually been read, so you know what it covers and what it requires of you to remain valid
Using this checklist
If you went through this and ticked most boxes, that's a genuinely good sign. If several sections raised more questions than confident answers, that's normal too, and it's exactly what a structured cyber health check is designed to work through properly: mapping your practice against a recognised framework like the Essential Eight, prioritising the gaps that matter most, and giving you a clear, realistic plan rather than a long list of everything at once.
.jpg&w=3840&q=75)