Overview

Cybersecurity is now a core operational requirement for every general practice. Patient health records, Medicare billing data and practice financial systems are high-value targets. The Australian Cyber Security Centre reports that healthcare is among the most targeted sectors, and small to medium practices are particularly exposed because they typically lack dedicated IT security resources.

This guide takes your practice team through a complete PDSA cycle focused on cybersecurity. It covers risk assessment, staff awareness training, incident response planning and policy development. The worked example shows how a real practice identified and closed its most significant gaps over a 12-week period.

The guide aligns with the ePIP (eHealth Practice Incentives Program) and maps directly to requirements 1, 2 and 5. Completing the full cycle can contribute up to 40 CPD hours across Educational Activities, Reviewing Performance and Measuring Outcomes categories.

What the guide covers

Risk assessment

Identify vulnerabilities across your practice systems including clinical software, email, remote access, backup processes and physical device security. Includes a structured risk register template.

Staff training

Build a staff awareness program covering phishing recognition, password management, secure data handling and incident reporting. Includes session plans and assessment checklists.

Policy and response

Develop a cybersecurity policy and incident response plan tailored to general practice. Covers data breach notification obligations under the Notifiable Data Breaches scheme.

CPD hours breakdown

Completing the full PDSA cycle on cybersecurity can contribute approximately 9 CPD hours. The breakdown below shows how hours are allocated across RACGP CPD categories.

Educational Activities (3 hours)

Research into cybersecurity frameworks, ePIP requirements and best-practice guidance for healthcare settings. Includes reading, webinars and vendor briefings.

Reviewing Performance (3 hours)

Audit of current practice cybersecurity controls against the risk register. Gap analysis and benchmarking against ePIP compliance requirements.

Measuring Outcomes (3 hours)

Implementation of the improvement plan, post-cycle reassessment and documentation of changes. This is the core PDSA measurement stage.

Key topics

Risk assessment and gap analysis

Staff awareness and training program

Incident response and breach notification

Policy development and documentation

ePIP alignment and compliance mapping

Who should use this guide

Dr Chris Mitchell AM

Dr Chris Mitchell AM, FAICD is co-founder of Medius Global and a Rural General Practitioner and Rural Generalist with more than 35 years of experience in Northern NSW. He is a Fellow of the Australian Institute of Company Directors and a Past President of the Royal Australian College of General Practitioners. He was previously Head of Adoption, Benefits and Change at the National eHealth Transition Authority (NEHTA). He has served on numerous health sector boards, including the RACGP, NPS MedicineWise, Therapeutic Guidelines Ltd, The Rural Doctors Network and North Coast GP Training. Chris was awarded Member of the Order of Australia (AM) in 2013 for services to general practice and received a Rural Doctors Network Rural Medical Service Award in 2025.

Read the guide

This PDSA guide is free for Australian GP practices.

Read online
Download PDF
← View all PDSA guides