What's in this template?
This business continuity plan complements the Emergency Response Plan and focuses on sustained operations and recovery when a disruption prevents normal practice operations. It maps to RACGP Criterion C3.3 and covers 14 sections:
- Purpose: distinguishing BCP (sustained operations) from ERP (immediate response)
- Scope: loss of premises, IT failure, cyberattack, utility outage, key personnel loss, pandemic, supply chain disruption
- Key Contacts: BCP Coordinator, Practice Principal, Practice Manager, IT provider, insurance, landlord, accountant, MDO
- Critical Business Functions: prioritised into 4 tiers (4 hours, 24 hours, 1 week, deferrable)
- Loss of Premises: immediate actions, short-term telehealth continuity, temporary premises, Medicare/PHN notification
- IT System Failure and Cyberattack: backup details, paper-based fallback, ransomware response steps, ACSC contact, system restoration
- Extended Power or Utility Outage: cold chain protection, telehealth pivot, utility provider contacts
- Loss of Key Personnel: locum arrangements, delegation of authority, pandemic multi-staff absence
- Supply Chain Disruption: buffer stock, backup suppliers, electronic prescribing fallback
- Communication Plan: staff phone tree, patient notification channels, external spokesperson protocol
- Insurance: business insurance, cyber insurance, workers' compensation
- Testing and Maintenance: annual review, tabletop exercise, contact verification, backup testing
- Related Policies: Emergency Response, IT Security, Privacy, Cold Chain, Handover
- Review History
Editable placeholder fields
Includes fields for practice details, BCP coordinator, IT provider, insurance providers, temporary premises options, locum agencies, backup suppliers, and more.
How to customise this template
- Download and fill in all Placeholder{{placeholder}} fields
- Identify temporary premises options in advance: nearby practices, serviced offices, co-working medical suites
- Verify your backup system: confirm backup method, frequency, offsite location, and last successful test restore
- Set up your staff phone tree: document who calls whom in sequence
- Review your insurance coverage: confirm you have business interruption and consider cyber insurance
- Run a tabletop exercise: walk through a scenario (e.g. "ransomware encrypts all systems on a Monday morning") with key staff
Frequently asked questions
How is this different from the Emergency Response Plan?
The Emergency Response Plan covers immediate response: what to do in the first minutes and hours. The BCP covers sustained operations: how to keep the practice running for days or weeks during an extended disruption, and how to recover back to normal.
Do we really need cyber insurance?
Ransomware attacks on Australian healthcare practices are increasing. Cyber insurance can cover incident response costs, data breach notification, business interruption, and even ransom payments. It's worth obtaining a quote. Premiums for small practices are often reasonable.
Where should the climate risks in our scenario list come from?
From your climate risk register. The RACGP Standards 6th edition criterion F3.A asks practices to identify climate-related risks to their operations, and the risks that assessment turns up (flood, bushfire, heatwave, storm, supply chain interruption) are exactly the scenarios this plan needs to cover. Work through the Environmental Sustainability Policy template first, then bring each risk from its Appendix A register across into the BCP as a scenario. If a risk in that register has no matching scenario here, that is a gap in this plan.
Can I use this for AGPAL or QPA accreditation?
Yes. Both accrediting bodies assess against RACGP Criterion C3.3. A BCP demonstrates thorough emergency preparedness beyond the immediate response plan.
Where do the scenarios in this plan come from?
From the practice's risk register. The Practice Risk Management Policy and Risk Register (RACGP 6th edition F1.G, 5th edition C3.1C) is where operational risks such as a single internet connection, a key-person dependency or a supplier failure are identified and rated. This plan is what a realised risk triggers, so every scenario here should trace to a register entry, and any register risk rated High or Extreme should have a scenario here.
Where does the ICT recovery itself live?
In the ICT Continuity and Cyber Incident Response Plan (RACGP 6th edition F8.A, 5th edition C6.4D). This plan keeps the practice running while the systems are down, including the clinical team's paper workaround under F2.A. That plan holds the backup schedule and log, the restore tests, the cyber security incident response phases and the recovery order that brings the systems back. The two are tested together: the tabletop exercise in this plan's section 12 is the same exercise that plan records in its Appendix D.