What are the RACGP IT requirements for accreditation?
For accreditation, the RACGP Standards for general practices (5th edition) expect a practice to demonstrate sound information security: individual logins with role-based access to the clinical system, multi-factor authentication, patched and supported systems, backups that have actually been restored, a written business continuity plan, and privacy processes covering the Privacy Act and My Health Record obligations.
The useful way to prepare is to think in evidence rather than intentions, because that is how the exercise works in practice: for each expectation, something printable should exist that shows it is true. This article walks the list item by item with the evidence each one produces. One orientation note before the list: the Standards themselves are the authority, they are updated over time, and where precision matters you should work from the current published edition rather than any article, including this one.
Individual logins with role-based access. Every person in the practice has their own account in the clinical system, whether that is Best Practice, MedicalDirector, Zedmed or Genie, with access matched to their role: reception sees what reception needs, not what a doctor sees. The shared front-desk login is the classic failure here, because it makes the audit trail fiction. Evidence: a user list export showing named accounts and roles, and a leavers check confirming departed staff are gone the day they leave.
Multi-factor authentication, especially on anything reachable from outside the practice: remote access to the clinical system, email, and cloud services. A stolen password should not be enough to open patient records from a stranger's laptop, and tools such as DUO and Entra ID make this routine rather than burdensome. Evidence: an enrolment export showing which accounts have it, with remote-capable and administrative accounts checked first.
Patching and supported systems. The operating systems and applications the practice depends on are current, and nothing in a consult room runs a Windows version that no longer receives security fixes. This is unglamorous and it is where quiet risk accumulates, because an unpatched known hole is the cheapest door an intruder can use. Evidence: a patch report with dates, and an inventory confirming everything on it is still supported by its maker.
Backups that have been restored, and a continuity plan. A backup that has never been restored is a hope, not a control, and the difference only ever surfaces on the worst day. The expectation worth holding yourself to: backups run on schedule, a copy sits beyond the reach of anything nasty on the practice network, and a test restore has been performed and logged recently. Alongside it, a written business continuity plan answers the practical question, what does the practice do while systems are down, in a page or two with names on it. Adelaide City General Practice is the cautionary shape here: before its migration, the clinical systems ran on one server where a single motherboard failure would have meant at least a full business day without patient records. Evidence: the restore log, and the dated plan.
Privacy processes. The Privacy Act treats health information as sensitive, the Notifiable Data Breaches scheme requires a practice to assess a suspected breach and notify where serious harm is likely, and My Health Record participation carries its own security obligations. What this asks of a practice is less technology than documented habit: a written process for handling and reporting a suspected breach, staff who know it exists, and privacy practices that match what your policy claims. Evidence: the documents themselves, current and dated.
If that list feels familiar, there is a reason: most of it is the Australian Government's Essential Eight wearing clinical clothing. Access control, multi-factor authentication, patching and tested backups are the core of Essential Eight Maturity Level 1, which is why a practice already at Level 1 walks into accreditation with the technical evidence substantially in hand, and why we build our plans around that framework. The goal state is worth naming plainly: accreditation IT evidence should be a printout, not a project, because the documentation is maintained continuously rather than reconstructed in the panicked fortnight before a survey.
The honest caveats. The Standards are the authority, they change, and nothing here is a substitute for reading the current edition or for the guidance of your accrediting body. Accreditation covers far more than IT, and no provider can do it for you. And a practice can meet every expectation above with any competent provider, not just us; what matters is that someone owns the evidence continuously. If you want to know where your practice stands today, the Essential Eight Cyber Security Scorecard is free, or call 1800 456 567.
Evidence as a printout, not a project
Our managed plans keep the access lists, patch reports, restore logs and continuity documents current all year, so accreditation time is a folder, not a scramble.
Other questions we are asked about this, answered the same way.
- 5 min
How long does an Essential Eight assessment and uplift take?
Days to weeks for the measurement, weeks to months for the climb, and the biggest variable is decision speed, not technology.
Read the article - 2 min
Can you do your own Essential Eight assessment?
Yes for direction, no for proof. How to self-assess credibly, where it goes wrong, and when independent eyes become non-negotiable.
Read the article - 2 min
Does an accounting firm need the Essential Eight?
Not by law, and the controls happen to match exactly what goes wrong in practices: compromised mailboxes and ransomware.
Read the article
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business