Mon–Fri, 8am–5pm · Brisbane time 9 Ferny Avenue, Surfers Paradise QLD 4217
Callback within 4 business hours
bcom ICT
HomeServicesIndustriesSupportAbout Get a quote Call 07 3041 8993
IT support being provided to a Gold Coast healthcare practice by bcom ICT

Health practices don't get the small business exemption

Most Australian businesses under $3 million turnover fall outside the Privacy Act. Health service providers don't — at any size. That changes what your IT has to do.

  • Privacy Act at any size
  • Police checks & Blue Cards
  • Practice software supported
  • Essential Eight aligned

bcom ICT supports medical, dental and allied health practices across the Gold Coast. Health service providers are covered by the Privacy Act regardless of annual turnover — the small business exemption does not apply to them — so practices carry obligations around patient information and notifiable data breaches that most businesses their size do not. Call 07 3041 8993.

The thing most practices don't know

The exemption that doesn't apply to you

This catches out more Gold Coast practices than any other compliance point.

Turnover is irrelevant here

The Privacy Act's small business exemption generally covers businesses under $3 million annual turnover. Health service providers are a named exception — a two-practitioner allied health clinic carries the same obligations as a hospital. Many practice owners have never been told this.

The NDB scheme applies

If patient information is accessed without authorisation and serious harm is likely, you have obligations to assess and to notify the OAIC and affected patients. That is not optional and it is not something your IT provider can discharge for you.

Sensitive information is a higher bar

Health information is 'sensitive information' under the Act, which attracts stricter handling requirements than ordinary personal information. The consequences of exposure are correspondingly worse.

Your suppliers count

Outsourced arrangements — including your IT provider and your practice software vendor — form part of your compliance picture. Which is why our own position is published rather than asserted.

What we actually do for practices

  • Practice management software kept running, backed up and updated — it is the system that stops the practice if it fails
  • Patient record backup held separately from the network, with restores tested rather than assumed
  • Access control so reception, practitioners and administrators see what their role requires and no more
  • Multi-factor authentication across email and remote access, which is the single highest-value control available
  • Screened technicians — national police checks, and Queensland Blue Cards where the site requires them
  • Secure messaging and email, including the SPF, DKIM and DMARC records that stop someone sending referrals in your name
  • Essential Eight assessment, which is what an auditor or insurer will reference

If something does happen

The first hour matters. Disconnect affected machines from the network but do not power them off — shutting down destroys evidence that helps establish what was actually accessed, and for a practice that determination decides whether you notify.

We contain, investigate and give you the factual written account you need for your assessment. The notification decision itself remains yours — see the NDB guide and incident response.

Common problems

The problems we are actually called to in practices

Six issues account for most of what we see in medical and allied health, and none of them are exotic.

“The practice software is slow every morning”

Usually the whole practice opening the day’s appointments at once against a database on an ageing server or a stretched connection. Clinical software is chattier than most business applications and far less tolerant of latency.

What we do Measure where the delay actually sits — the database, the network path, or the workstation. Practices are frequently sold a new server for a problem that lives in the link between the server and reception.

“Scanned documents aren’t reaching patient files”

Usually a scanner configured to a folder or a mailbox that changed, usually during a Microsoft 365 migration or a staff change. The scan completes, the light goes green, and the document lands nowhere anyone looks.

What we do Trace the path from the glass to the patient record and test it end to end. Referrals and results going missing silently is the version of this fault that matters clinically, and it is invisible until someone goes looking for a document.

“Secure messaging stopped delivering”

Usually a certificate expiry or a directory entry gone stale. Clinical messaging depends on a chain of things that quietly need renewing, and nothing prompts you until delivery fails.

What we do Check the certificate and directory listing rather than assuming the other practice is at fault. Failed clinical messages tend to sit unnoticed because the sender sees them as sent.

“Everyone logs in as reception”

Usually a shared account set up years ago for convenience. It works, and it means the audit log in the practice software cannot tell you who viewed a patient record.

What we do Give every person a named login. This is not bureaucracy — the ability to say who accessed a record is exactly what you need if a patient ever asks, and a shared account removes it entirely.

“Our backup is on a drive in the practice manager’s drawer”

Usually a backup routine designed before ransomware and never revisited. It also means patient data leaving the premises in a bag, which is a separate problem again.

What we do Move to encrypted backup held away from the network, with restores tested rather than assumed. Clinical data has both a recovery obligation and a privacy obligation, and a drive in a drawer satisfies neither well.

“A doctor wants to work from home”

Usually a reasonable request that is usually solved badly — remote desktop opened to the internet, or patient data copied onto a personal laptop.

What we do Set up access that keeps the data inside the practice environment and requires multi-factor authentication. Done properly this is straightforward; done casually it is how practices end up notifying the OAIC.

In practice

What this looks like in a practice

Representative engagements, drawn from real work with identifying detail removed — we don’t name clients without written permission.

Representative engagement

Six months of referrals that never arrived

The situation

A general practice reported that specialist referrals were occasionally going missing. Reception would send a document, the specialist would later say nothing had been received, and everyone assumed the other end was at fault.

What we found

The practice scanner had been configured years earlier to deposit documents into a mailbox that was decommissioned during their Microsoft 365 migration six months prior. The scanner still reported success at the panel because the scan itself completed — only the delivery failed, and nothing checked. Roughly one in nine referrals had been affected, since staff used a different route when the scanner was busy.

What we did

Reconfigured the scan path to write directly into the patient record, added delivery confirmation, and audited six months of outgoing referrals against the practice software to identify which had never been sent.

The outcome

Fourteen referrals were identified and re-sent, some for patients who had been waiting on appointments. The practice now gets a failure notification rather than a silent success, which is the difference that mattered.

Representative engagement

Proving who looked at a record, after the fact

The situation

An allied health practice received a complaint from a patient who believed a staff member had accessed their file without a clinical reason. The practice wanted to answer honestly and could not.

What we found

Reception, the practice manager and two part-time administrators all used the same login. The practice software had a complete audit trail showing exactly which records were opened and when, and every entry named the same shared account. The information needed to answer the patient existed and was useless.

What we did

Created named logins for every person, enforced multi-factor authentication, and worked with the practice on a short access policy stating that records are opened for clinical or administrative reasons only. Historic access under the shared account was disclosed to the patient as unattributable, because it was.

The outcome

The practice can now answer that question. It cost an afternoon to set up and would have cost far more had the complaint gone further — and the honest answer the first time was the uncomfortable one.

Common questions

Questions Gold Coast businesses ask us

Does the Privacy Act apply to a small medical practice?

Yes. Health service providers are a named exception to the Privacy Act's small business exemption, so the obligations apply regardless of annual turnover. A two-practitioner allied health clinic carries the same responsibilities around patient information and notifiable data breaches as a much larger provider. This catches out a great many Gold Coast practices.

What happens if patient records are exposed?

You have obligations under the Notifiable Data Breaches scheme to assess whether serious harm is likely and, if so, to notify the OAIC and the affected patients. bcom ICT provides containment, investigation and the factual technical account you need for that assessment — the notification decision itself sits with the practice.

Do your technicians have police checks?

Yes. Technicians attending client sites hold national police checks, and Queensland Blue Cards where the site requires them. For practices seeing children, that is usually a hard requirement rather than a preference.

Can you work with our practice management software?

We support the environment it runs on — the server or cloud tenancy, backups, access, updates and the network. For the application itself we work alongside your vendor's support rather than replacing it, which is usually the arrangement that works best.

What should a practice do first?

Multi-factor authentication on email, backups held separately from the network with a tested restore, and knowing where you sit against the Essential Eight. Those three cover most of what actually happens and most of what an insurer will ask about.

Do you support allied health as well as medical?

Yes — physiotherapy, psychology, dental, podiatry, optometry and similar practices. The obligations are the same and the practical problems are very similar.

Not sure where your practice stands?

A health check tells you — including whether you'd be able to answer an OAIC question about what was accessed.

Last updated: August 2026 · Reviewed by the bcom ICT team