Skip to main content

Seven Cyber Gaps in Sydney Medical Practices

18 August 2026 | By Birender Chahal

Most practices we meet believe their IT is in reasonable shape. There is antivirus on the machines, the clinical software is supported, and someone set things up a few years ago. On paper, it looks handled.

Then we look properly, and the same gaps appear again and again. Not because anyone was careless, but because a medical practice holds the most sensitive data category there is: patient health records. That comes with real privacy obligations and a busy clinical environment where security can quietly slip. If you have read our guide to IT for medical practices, this is the practical list of where practices actually fall short.

Gap 1: Patient Health Records Exposed

Health information is sensitive information under the Privacy Act, which means a breach carries notification obligations and a serious loss of patient trust. Yet patient records are often more accessible inside the practice than anyone intended, reachable by reception, clinical, and admin staff alike with little distinction.

The fix is to know where patient data lives, in the clinical system, in backups, and anywhere it has been exported, and restrict access by role so people see only what their job requires. A receptionist does not need full clinical histories, and limiting access limits the damage if any one account is compromised.

Gap 2: Practice Management Software Without MFA

Your clinical and practice management system holds every patient record, appointment, and clinical note in the business. We routinely find multi-factor authentication switched on for Microsoft 365 email but missing from the very system that holds the patient data.

An attacker looks for the one login still protected by a password alone. The fix is to confirm MFA is enforced on the clinical system, any patient portal, and remote access, not just email, with no exceptions for a senior clinician who finds the extra step inconvenient at a busy clinic.

Female doctor with stethoscope at desk with laptop
In a medical practice, the patient record is the prize.

Gap 3: Shared Clinical Devices Left Logged In

Consult rooms, nurses’ stations, and reception often share computers, and in the flow of a busy clinic those machines get left logged in between patients. A screen showing one patient’s record while the next walks in is both a privacy breach and an open door.

The fix fits clinical reality rather than fighting it: automatic screen locks after a short idle period, fast individual sign-in so staff are not tempted to share one always-on account, and a habit of locking the screen when stepping away. The goal is that an unattended device does not expose patient data.

Gap 4: Locum and Temp Access Not Removed

Practices bring in locums, temporary nurses, and agency reception staff regularly, and they move on once the shift or the cover period ends. Each arrival and departure is a small security event, and in a busy roster it is the one most likely to be missed.

The common gap is access that never gets removed. A locum who covered a fortnight keeps a login to the clinical system long after they have gone. Months later, that forgotten account is a quiet way in. The fix is unglamorous: access granted for the period needed, reviewed regularly, and revoked promptly when a locum or temp finishes.

Gap 5: Untested Backups of Clinical Data

Backups are “running”, the dashboard is green, and everyone assumes the clinical database is safe. Then an incident hits, someone tries to restore, and the files are incomplete, corrupted, or, in a ransomware case, encrypted along with everything else.

For a practice, losing access to patient records would halt consultations and put patient safety at risk, not just productivity. A backup you have never restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete. You can read more in our guide to immutable backup.

Gap 6: Weak Email Security on Referrals

Practices send and receive referrals, results, and specialist correspondence by email all day, which makes the mailbox the front door for most incidents. A compromised account exposes patient information and lets an attacker send convincing messages from a trusted clinical address.

The fix is strong email security: MFA on every mailbox, good filtering to catch malicious attachments and phishing, and secure channels for genuinely sensitive patient information rather than plain email where the practice can avoid it. Staff who can recognise a suspicious message catch what filtering misses.

Gap 7: Ageing, Unpatched Systems

Medical software and the machines that run it tend to stay in place for years, and practices are understandably cautious about changing anything that works. The result is often an unsupported operating system or an application that has not been updated in a long time.

Most attacks use a known flaw that already had a fix available, so an unpatched system is an open invitation. The fix is to actively manage and report on patch status rather than assume auto-update is handling it, and to plan replacement of any system that is no longer supported, before it becomes the way in.

Closing the Gaps

None of these are exotic. They are the everyday shortfalls that turn a preventable incident into a real one, and most of them map straight to Essential Eight, the baseline published by the Australian Cyber Security Centre. The hard part is knowing which ones apply to you, because they stay invisible until someone looks.

Where to Start

If you recognised your practice in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.

Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.

We are a Sydney-based team in Bella Vista, and we work with medical practices across the metro area. We understand the privacy obligations and the pace of a working clinic, and we secure your practice without getting in the way of patient care. No jargon, no scare tactics, just the basics done properly.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.