Most small business owners assume the Privacy Act is mainly a concern for hospitals and large corporations. After all, you might run a physiotherapy clinic helping someone recover from a knee reconstruction, or a psychology practice working through anxiety with a client. You're not a medical centre.
But here's the thing: if you're collecting sensitive personal information such as health records (and you are), the same legal obligations apply to you. The Australian Privacy Principles don't care whether you have five staff or five hundred. And the security awareness training that larger organisations are told they need? You need it too.
Why Small Practices Are Targets
Patient records are often considered valuable on the black market. A credit card can be cancelled. A Medicare number, combined with a name and medical history, may create a complete identity kit that can't be reissued.
Small practices are often easier targets than large health networks. A solo psychology practice typically runs the same clinical software, the same email systems, and the same online booking platforms as a hospital, but without an IT team watching for problems. Attackers know this.
Phishing emails pretending to be from pathology labs, Medicare, or insurance providers are common. They're designed to catch busy practitioners and reception staff who are focused on patients, not email security. One wrong click and you're looking at a potential data breach.
The Privacy Act Applies to You
The Australian Privacy Principles apply to any practice handling patient health information. Under the Act, health information is classified as sensitive information, which means you're held to a stricter standard than businesses handling ordinary data.
The Notifiable Data Breaches scheme adds another layer. If patient data is exposed and the breach is likely to cause serious harm, you have a legal obligation to notify both the affected patients and the Office of the Australian Information Commissioner. Practice size doesn't exempt you from this requirement.
The Office of the Australian Information Commissioner has named healthcare as a high-risk enforcement sector for 2025-26. Recent enforcement actions have targeted organisations of varying sizes, and a solo practitioner is just as accountable as a major hospital group.
What This Means Day to Day
Meeting your Privacy Act obligations isn't about having a policy document sitting in a drawer. It requires actual measures in place:
- Access controls: Staff should only see patient records relevant to their role. Your receptionist doesn't need access to detailed clinical notes.
- Encrypted storage and transmission: Patient data sent to specialists, referring GPs, or insurance providers needs to be encrypted.
- A documented incident response plan: If something goes wrong, you shouldn't be figuring out what to do for the first time under pressure.
- Regular software updates: Most breaches exploit known vulnerabilities that were never patched.
- Employee cyber training: The biggest risk in any practice is usually a person clicking something they shouldn't, not a piece of software failing.
Staff Training Is Where Most Practices Fall Short
You can have antivirus software, a firewall, and encrypted backups, but none of that helps when your receptionist clicks a link in a convincing email that looks like it's from Medicare.
Phishing emails targeting small practices often reference familiar services: Medicare claiming portals, practice management software updates, pathology results, or referral requests. They're designed to create urgency and bypass your staff's natural caution.
Research consistently shows that security awareness training requirements set a minimum baseline, but the effectiveness depends on ongoing reinforcement, not just a one-time session during orientation. The Australian Cyber Security Centre has published guidance emphasising that regular, repeated training is more effective than annual or one-off sessions.
This is where simulated phishing attacks become useful. Instead of hoping your team remembers what they learned six months ago, you can test them with realistic scenarios and provide immediate training when someone makes a mistake.
What Good Security Looks Like for a Small Practice
A well-secured small practice isn't running exotic technology. It's running the basics properly and consistently:
- Multi-factor authentication on email and clinical software
- Backups that are actually tested, not just scheduled
- A clear understanding of who has access to what
- Regular staff training on recognising phishing attempts
- Someone (or something) actually watching for problems, not just passive antivirus running in the background
The difference between a minor incident and a full breach notification often comes down to how fast something gets noticed and shut down.
Telehealth Adds Complexity
If you're offering telehealth consultations (and many practitioners are these days), you've added privacy considerations around your internet connection and video platform configuration. The underlying data obligations remain the same as any other patient record, but you now need to ensure your video consultation platform is properly protecting patient privacy.
What You Can Do This Week
If IT security has been on your "should probably get around to that" list, two things will stop the majority of common attacks:
- Turn on multi-factor authentication for your email and practice management software. This single step blocks most account takeover attempts.
- Review who has access to what. Not every staff member needs access to every patient file.
Both of these can usually be done within a week, even if you're not particularly technical.
Making Security Training Manageable
The reason most small practices skip security training isn't that they don't care. It's that they're time-poor and don't know where to start. Running a small business is already demanding enough without adding "become a cybersecurity expert" to the list.
Automated training platforms can handle this without creating extra work. You add your staff, set how often you want them tested, and the system sends realistic phishing simulations on your schedule. When someone clicks something they shouldn't, they get immediate training explaining what they missed. No manual follow-up required.
This approach fits the reality of running a small practice: you need protection, but you don't have hours to spend managing it.
The Cost of Getting It Wrong
A data breach at a small practice carries three types of cost: regulatory fines from the Information Commissioner, the cost of remediation and notification, and reputational damage with clients who trusted you with sensitive information.
Security training is almost always cheaper than dealing with a breach after the fact. The cost of implementing proper training is typically a fraction of what you'd face in remediation, notification, and lost business.
Next Steps
If you've read this far, you probably recognise that your business should be doing more on the security front. The good news is that getting started doesn't require technical expertise or a large budget.
Sign up for a free trial and send yourself a test phishing email. You'll see exactly what your staff would experience and how the training works. Takes about two minutes to set up, and you'll have a much clearer picture of where your business actually stands.