Identity & Access

"Prevention is cheaper than a breach"

Secure user access and governance controls.

Who can see your patient records?

In most small practices the honest answer is: everyone. One shared login at the front desk, every staff member able to open every clinical note, and accounts still active for people who left months ago.

RACGP Standards require unique login credentials and role-based access control. The Privacy Act requires health information to be accessed only by those who need it. Neither is satisfied by a password three people at reception have memorised.

This matters beyond compliance. When a patient asks who has looked at their file after a complaint, a dispute, or a suspicion that a staff member was curious about someone they know, a shared login means you cannot answer.

Key Features

Individual accounts, with MFA

Every staff member gets their own credentials with multi-factor authentication, across email, your practice management system and cloud storage. Shared logins are removed, not just discouraged.

Role-based access

Reception sees what reception needs. Clinicians see their patients. Administrators see what they administer. Access is granted by role rather than by whoever asked.

Privileged access controlled

Administrator rights limited to the people who genuinely need them, separated from everyday accounts so a phished receptionist doesn't hand over the keys to the whole practice.

Joiner, mover, leaver process

A documented process so access is granted on day one and revoked the day someone leaves, across every system and device not discovered nine months later during an audit.

Access reviews

A quarterly review of who has access to what, with the record to prove it was done. This is the item auditors ask for most often and practices can least often produce.

Conditional access

Rules so patient systems are only reachable from managed, compliant devices closing the gap where a staff member logs into the practice from a home computer nobody has ever looked at.

Scroll to top