Essential Eight

What are the RACGP IT requirements for accreditation?

5 min readBy Brendon Whiting, Founder · 27 February 2026

For accreditation, the RACGP Standards for general practices (5th edition) expect a practice to demonstrate sound information security: individual logins with role-based access to the clinical system, multi-factor authentication, patched and supported systems, backups that have actually been restored, a written business continuity plan, and privacy processes covering the Privacy Act and My Health Record obligations.

The useful way to prepare is to think in evidence rather than intentions, because that is how the exercise works in practice: for each expectation, something printable should exist that shows it is true. This article walks the list item by item with the evidence each one produces. One orientation note before the list: the Standards themselves are the authority, they are updated over time, and where precision matters you should work from the current published edition rather than any article, including this one.

Individual logins with role-based access. Every person in the practice has their own account in the clinical system, whether that is Best Practice, MedicalDirector, Zedmed or Genie, with access matched to their role: reception sees what reception needs, not what a doctor sees. The shared front-desk login is the classic failure here, because it makes the audit trail fiction. Evidence: a user list export showing named accounts and roles, and a leavers check confirming departed staff are gone the day they leave.

Multi-factor authentication, especially on anything reachable from outside the practice: remote access to the clinical system, email, and cloud services. A stolen password should not be enough to open patient records from a stranger's laptop, and tools such as DUO and Entra ID make this routine rather than burdensome. Evidence: an enrolment export showing which accounts have it, with remote-capable and administrative accounts checked first.

Patching and supported systems. The operating systems and applications the practice depends on are current, and nothing in a consult room runs a Windows version that no longer receives security fixes. This is unglamorous and it is where quiet risk accumulates, because an unpatched known hole is the cheapest door an intruder can use. Evidence: a patch report with dates, and an inventory confirming everything on it is still supported by its maker.

Backups that have been restored, and a continuity plan. A backup that has never been restored is a hope, not a control, and the difference only ever surfaces on the worst day. The expectation worth holding yourself to: backups run on schedule, a copy sits beyond the reach of anything nasty on the practice network, and a test restore has been performed and logged recently. Alongside it, a written business continuity plan answers the practical question, what does the practice do while systems are down, in a page or two with names on it. Adelaide City General Practice is the cautionary shape here: before its migration, the clinical systems ran on one server where a single motherboard failure would have meant at least a full business day without patient records. Evidence: the restore log, and the dated plan.

Privacy processes. The Privacy Act treats health information as sensitive, the Notifiable Data Breaches scheme requires a practice to assess a suspected breach and notify where serious harm is likely, and My Health Record participation carries its own security obligations. What this asks of a practice is less technology than documented habit: a written process for handling and reporting a suspected breach, staff who know it exists, and privacy practices that match what your policy claims. Evidence: the documents themselves, current and dated.

If that list feels familiar, there is a reason: most of it is the Australian Government's Essential Eight wearing clinical clothing. Access control, multi-factor authentication, patching and tested backups are the core of Essential Eight Maturity Level 1, which is why a practice already at Level 1 walks into accreditation with the technical evidence substantially in hand, and why we build our plans around that framework. The goal state is worth naming plainly: accreditation IT evidence should be a printout, not a project, because the documentation is maintained continuously rather than reconstructed in the panicked fortnight before a survey.

The honest caveats. The Standards are the authority, they change, and nothing here is a substitute for reading the current edition or for the guidance of your accrediting body. Accreditation covers far more than IT, and no provider can do it for you. And a practice can meet every expectation above with any competent provider, not just us; what matters is that someone owns the evidence continuously. If you want to know where your practice stands today, the Essential Eight Cyber Security Scorecard is free, or call 1800 456 567.

Evidence as a printout, not a project

Our managed plans keep the access lists, patch reports, restore logs and continuity documents current all year, so accreditation time is a folder, not a scramble.

Frequently asked questions

No provider can, and be wary of one who says otherwise. Accreditation belongs to the practice and covers far more than technology; what a good IT provider does is keep the information-security portion continuously true and continuously documented, so the IT evidence is ready whenever the survey lands. We support practices through exactly that part, and only that part.

Treat it as urgent for security reasons first and accreditation second: an out-of-support operating system stops receiving fixes for known holes, which is a live risk to patient records regardless of any survey. Practically, plan the upgrade or replacement now, document the plan and dates, and be able to show an assessor the trajectory rather than a shrug.

It covers the technical heart of them, which is why a Level 1 practice walks into accreditation well prepared: access control, multi-factor authentication, patching and tested backups all overlap directly. What sits outside the Essential Eight is the paperwork layer, the written continuity plan and the privacy processes, so treat Level 1 as the engine and add those documents deliberately.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, Suite 201, 7 James Place, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.