All templates

Computer and Information Security Policy for Australian General Practices

Information security policy covering access control, password management, backup procedures, malware protection, mobile device security, and incident response. Based on the RACGP CISS framework.

RACGP 5th EditionCriterion C6.47 pagesWord formatFree

Built from: RACGP CISS Standards · Privacy Act 1988 · Notifiable Data Breaches scheme

Download this free template

Enter your email and we'll send you a download link for the Computer & Information Security Policy template in Word format.

No spam. We'll only send you compliance tips relevant to your practice. Unsubscribe any time.

What's in this template?

This computer and information security policy is designed for Australian general practices seeking accreditation under the RACGP Standards for General Practices (5th Edition). It maps directly to Criterion C6.4, Information security and is aligned with the RACGP Computer and Information Security Standards (CISS) framework.

The template covers 18 sections addressing the full scope of information security in a healthcare setting:

  1. Purpose: establishes the security framework and regulatory context (Privacy Act, NDB scheme, RACGP CISS)
  2. Scope: all IT systems, devices, staff, contractors, and third-party providers
  3. IT Security Governance: IT Security Officer role, IT support provider responsibilities
  4. Access Control: individual user accounts, least privilege principle, admin account restrictions, physical access controls, workstation locking
  5. Password Management: 12-character minimum, complexity requirements, no reuse, multi-factor authentication (MFA) requirements for clinical software, email, cloud, and remote access
  6. Email and Internet Security: phishing awareness, encrypted clinical communication, acceptable use
  7. Malware and Ransomware Protection: endpoint protection, real-time scanning, firewall, USB scanning
  8. Data Backup and Recovery: daily backup schedule, 30-day retention, offsite copy, quarterly test restores
  9. Software Updates and Patching: 14-day patch cycle (48 hours for critical), end-of-life software replacement
  10. Mobile Device and Remote Access: device security requirements, VPN/secure access, lost device protocols, BYOD policy
  11. Network Security: firewall, WPA3 Wi-Fi, guest network isolation, firmware updates
  12. Disposal and Decommissioning of IT Equipment: NIST 800-88 compliant data destruction, certificates of destruction
  13. Information Security Incident Response: contain, report, assess, notify (NDB), remediate, review
  14. Third-Party and Cloud Service Providers: security certification verification, Australian data residency, contractual obligations
  15. Staff Information Security Training: induction orientation, annual refresher, emerging threat alerts
  16. Audit, Monitoring, and Review: annual risk assessment, access reviews, backup test restores, software audits
  17. Related Policies: cross-references to Privacy, Data Breach, Business Continuity, Health Records, Training
  18. Review History: version control and approval record

Editable placeholder fields

The template includes yellow-highlighted {{placeholder}} fields:

  • Practice name{{practice_name}}, ABN{{abn}}, Practice address{{practice_address}}, Phone{{phone}}, Email{{email}}
  • It security officer name{{it_security_officer_name}}: designated IT Security Officer
  • It provider name{{it_provider_name}} and It provider phone{{it_provider_phone}}: IT support provider
  • Secure messaging platform{{secure_messaging_platform}}: your clinical messaging system (e.g. HealthLink, Argus, Medical Objects)
  • Antivirus product name{{antivirus_product_name}}: endpoint protection product
  • Backup method{{backup_method}}: your backup approach (e.g. automated cloud, local NAS + offsite)
  • Backup provider name{{backup_provider_name}}: backup service provider
  • Wifi password change frequency{{wifi_password_change_frequency}}: how often you rotate Wi-Fi passwords
  • Practice principal name{{practice_principal_name}}: for approval sign-off
  • Review date{{review_date}} and Next review date{{next_review_date}}

RACGP accreditation requirement

Criterion C6.4 of the RACGP Standards for General Practices (5th Edition) requires that:

"The practice has a system for information security"

The RACGP's Computer and Information Security Standards (CISS) provide detailed guidance on what this means in practice. Key requirements include:

  • Access control: individual user accounts with role-appropriate access levels
  • Password management: strong, unique passwords and MFA where supported
  • Data backup: regular, tested backups with offsite storage
  • Malware protection: current antivirus/endpoint protection on all devices
  • Software patching: timely application of security updates
  • Physical security: secured server/equipment areas, screen positioning
  • Incident response: procedures for handling security breaches
  • Staff training: awareness of security obligations and threats
  • Third-party management: security requirements for IT providers and cloud services

This template addresses each CISS domain with practical, implementable controls appropriate for a general practice environment.

Legislation and standards referenced

  • RACGP Standards for General Practices (5th Edition): Criterion C6.4
  • RACGP Computer and Information Security Standards (CISS): the primary framework for GP IT security
  • Privacy Act 1988 (Cth): APP 11 (security of personal information)
  • Notifiable Data Breaches scheme: Part IIIC of the Privacy Act
  • NIST 800-88: Guidelines for media sanitisation (data destruction)

How to customise this template

  1. Download the Word document and open it in Microsoft Word or Google Docs
  2. Find and replace each yellow-highlighted Placeholder{{placeholder}} with your practice-specific details
  3. Involve your IT provider: share the template with your IT support provider and have them confirm the technical controls are in place or schedule implementation
  4. Complete Section 14 (Third-Party Providers): list all IT systems and cloud services your practice uses, along with where data is stored
  5. Decide on your BYOD policy (Section 10): either specify the conditions under which personal devices may access practice systems, or state that BYOD is not permitted
  6. Set up your monitoring schedule (Section 16): assign responsibility for access reviews, backup test restores, and software audits
  7. Have the Practice Principal and IT Security Officer review and sign off
  8. Distribute to all staff and include in induction packs

Frequently asked questions

What is the RACGP CISS?

The RACGP Computer and Information Security Standards (CISS) is a framework published by the RACGP that provides practical guidance on information security for general practices. It covers areas including access control, passwords, backup, malware protection, email security, mobile devices, and incident response. CISS compliance supports meeting RACGP Criterion C6.4.

Do I need a dedicated IT Security Officer?

The RACGP recommends designating someone within the practice to be responsible for IT security. This doesn't need to be a full-time IT role. It is typically the Practice Manager, Practice Principal, or a senior staff member who liaises with the IT support provider on security matters.

How often should we test our backups?

This template recommends quarterly test restores: recovering a backup to verify that data can actually be restored. Many practices only discover their backup is corrupted when they need it. Regular test restores give you confidence that your backup is working. The backup log, the restore test record and the recovery plan itself live in the ICT Continuity and Cyber Incident Response Plan, which is the document RACGP 6th edition criterion F8.A (and 5th edition indicator C6.4D) assesses.

What about telehealth platform security?

Telehealth security is covered in our separate Privacy Policy template (Section 14). For the IT security policy, ensure your telehealth platform is listed in Section 14 (Third-Party Providers) with appropriate security verification.

Can I use this for AGPAL or QPA accreditation?

Yes. Both AGPAL and QPA assess against the RACGP Standards for General Practices (5th Edition). This template is aligned to Criterion C6.4 and the CISS framework, and is suitable for use as accreditation evidence with either accrediting body.

Does this policy cover staff use of AI tools?

Only at the baseline. This policy covers how practice systems are secured and sets general email and internet acceptable use. Which AI tools staff may use, in which tier or plan, what patient information may never be entered into them, and what patients are told, all live in the AI Acceptable Use Policy. A patched, MFA-protected laptop running an unassessed AI scribe still meets this policy while creating a privacy problem, which is the gap that document closes.

Does this policy cover which digital health technologies we adopt?

No. This policy secures the systems the practice already runs. The decision to run one in the first place, along with the assessment, costing, approval, patient consent, review and retirement that go with it, sits in the Digital Health Technology Governance Policy, which answers RACGP 6th edition criterion F10.A. The two meet at the security review: this policy's controls are what a proposed technology is assessed against before it is approved.

What if we use an outsourced IT provider for everything?

Many general practices outsource IT management. This policy still applies. It defines the practice's expectations and requirements, which the IT provider then implements. Share this policy with your IT provider so they understand what the practice requires. The IT provider should also have their own security standards and can help you complete the technical sections.

Does this policy cover what we do when an incident actually happens?

Only the first step. Section 13 sets the incident response principles (contain, report, assess, notify, remediate, review). The working plan for a cyber security incident, with the first hour checklist, the five response phases, the contact directory, the backup log and the restore test record, is the ICT Continuity and Cyber Incident Response Plan (RACGP 6th edition F8.A, 5th edition C6.4D). This policy prevents; that plan protects, recovers and responds. One ransomware event runs through both.

30-day free trial, no credit card

Be the practice the assessor compliments.

Set up your frameworks this weekend. Walk into your next visit with your evidence linked and current, and nothing left to chase.

No credit card required
Australian data residency (Sydney)
Cancel anytime