Act now: make cyber security a practice priority

A recent cyber security incident affecting Australian medical clinics is a timely reminder that health care remains a highly targeted sector. General practices hold sensitive patient, clinical, business and financial information. Making cyber security a priority for every team member is critical to safe, reliable everyday practice.

Why practices need to pay attention

  • Health service providers were the most commonly affected sector in 2025, accounting for 19% of all data breach notifications in Australia (Office of the Australian Information Commissioner)
  • Ransomware incidents against the Australian health care sector doubled in 2024–25 compared with 2023–24, increasing risks to patient safety and service continuity (Australian Signals Directorate)
  • Practice managers play a key role in ensuring staff recognise, understand and act on cyber security messages
  • Cyber incidents can disrupt appointments, prescribing, billing, communications and access to clinical information

What to reinforce with your team

  • Pause before clicking: Stop and check unexpected or suspicious emails, links, attachments and urgent requests before acting
  • Protect access: Use strong, unique passwords, avoid shared accounts and enable multi-factor authentication (MFA) wherever possible
  • Review permissions: Remove system access promptly when staff leave or change roles, and regularly review administrator access
  • Report quickly: Encourage staff to immediately report suspicious emails, unusual system behaviour or possible data exposure

Priority actions for practices

  • Regularly reinforce cyber security messages through team meetings, huddles and onboarding
  • Confirm MFA is enabled for key systems where supported, including email, clinical platforms, remote access and administrator accounts
  • Keep operating systems, applications and devices up to date, and replace hardware and software that is no longer supported or can no longer be updated
  • Ensure critical data is securely backed up and backups are tested regularly
  • Keep an incident response contact list visible and up to date, including the 24/7 Australian Cyber Security Hotline: 1300 CYBER1 (1300 292 371)

Key message

Cyber security is a whole-of-practice responsibility and should be treated as a priority. Share key messages with your team, reinforce safe everyday behaviours and act promptly on any risks or concerns. Protecting patient information helps maintain patient trust, practice continuity and the reputation of the whole team.

Stay connected to the latest primary health news

Gippsland PHN produces a range of informative newsletters designed to keep you in the loop with industry news, important updates, insights, training and events opportunities, and much more.

Subscribe or update your preferences below.