Most practices we meet believe their IT is in reasonable shape. There is antivirus on the machines, the clinical software is supported, and someone set things up a few years ago. On paper, it looks handled.
Then we look properly, and the same gaps appear again and again. Not because anyone was careless, but because a medical practice holds the most sensitive data category there is: patient health records. That comes with real privacy obligations and a busy clinical environment where security can quietly slip. If you have read our guide to IT for medical practices, this is the practical list of where practices actually fall short.
Gap 1: Patient Health Records Exposed
Health information is sensitive information under the Privacy Act, which means a breach carries notification obligations and a serious loss of patient trust. Yet patient records are often more accessible inside the practice than anyone intended, reachable by reception, clinical, and admin staff alike with little distinction.
The fix is to know where patient data lives, in the clinical system, in backups, and anywhere it has been exported, and restrict access by role so people see only what their job requires. A receptionist does not need full clinical histories, and limiting access limits the damage if any one account is compromised.
Gap 2: Practice Management Software Without MFA
Your clinical and practice management system holds every patient record, appointment, and clinical note in the business. We routinely find multi-factor authentication switched on for Microsoft 365 email but missing from the very system that holds the patient data.
An attacker looks for the one login still protected by a password alone. The fix is to confirm MFA is enforced on the clinical system, any patient portal, and remote access, not just email, with no exceptions for a senior clinician who finds the extra step inconvenient at a busy clinic.

Gap 3: Shared Clinical Devices Left Logged In
Consult rooms, nurses’ stations, and reception often share computers, and in the flow of a busy clinic those machines get left logged in between patients. A screen showing one patient’s record while the next walks in is both a privacy breach and an open door.
The fix fits clinical reality rather than fighting it: automatic screen locks after a short idle period, fast individual sign-in so staff are not tempted to share one always-on account, and a habit of locking the screen when stepping away. The goal is that an unattended device does not expose patient data.
Gap 4: Locum and Temp Access Not Removed
Practices bring in locums, temporary nurses, and agency reception staff regularly, and they move on once the shift or the cover period ends. Each arrival and departure is a small security event, and in a busy roster it is the one most likely to be missed.
The common gap is access that never gets removed. A locum who covered a fortnight keeps a login to the clinical system long after they have gone. Months later, that forgotten account is a quiet way in. The fix is unglamorous: access granted for the period needed, reviewed regularly, and revoked promptly when a locum or temp finishes.
Gap 5: Untested Backups of Clinical Data
Backups are “running”, the dashboard is green, and everyone assumes the clinical database is safe. Then an incident hits, someone tries to restore, and the files are incomplete, corrupted, or, in a ransomware case, encrypted along with everything else.
For a practice, losing access to patient records would halt consultations and put patient safety at risk, not just productivity. A backup you have never restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete. You can read more in our guide to immutable backup.
Gap 6: Weak Email Security on Referrals
Practices send and receive referrals, results, and specialist correspondence by email all day, which makes the mailbox the front door for most incidents. A compromised account exposes patient information and lets an attacker send convincing messages from a trusted clinical address.
The fix is strong email security: MFA on every mailbox, good filtering to catch malicious attachments and phishing, and secure channels for genuinely sensitive patient information rather than plain email where the practice can avoid it. Staff who can recognise a suspicious message catch what filtering misses.
Gap 7: Ageing, Unpatched Systems
Medical software and the machines that run it tend to stay in place for years, and practices are understandably cautious about changing anything that works. The result is often an unsupported operating system or an application that has not been updated in a long time.
Most attacks use a known flaw that already had a fix available, so an unpatched system is an open invitation. The fix is to actively manage and report on patch status rather than assume auto-update is handling it, and to plan replacement of any system that is no longer supported, before it becomes the way in.
Closing the Gaps
None of these are exotic. They are the everyday shortfalls that turn a preventable incident into a real one, and most of them map straight to Essential Eight, the baseline published by the Australian Cyber Security Centre. The hard part is knowing which ones apply to you, because they stay invisible until someone looks.
Where to Start
If you recognised your practice in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.
Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.
We are a Sydney-based team in Bella Vista, and we work with medical practices across the metro area. We understand the privacy obligations and the pace of a working clinic, and we secure your practice without getting in the way of patient care. No jargon, no scare tactics, just the basics done properly.