What are the IT requirements for RACGP accreditation? A WA practice guide

Stuart working on Best Practice

RACGP accreditation requires a general practice to meet Criterion C6.4 – Information Security, which sets out how patient health information must be protected. In practice this means a practice needs a named person responsible for its electronic systems, individual password-protected access to clinical software, secure storage that keeps patient information out of public view, a documented business continuity and information recovery plan, and proper procedures for storing, retaining and destroying records. These requirements are drawn from the RACGP’s Computer and Information Security Standards (CISS) framework.

Everything below breaks down each part of C6.4, what it means day to day, and how a practice actually satisfies it.

Why does RACGP accreditation include IT requirements at all?

Accreditation exists to protect patients from harm, and in a modern practice most patient information lives in software — your clinical system, your Medicare integrations, your backups, your email. If that information is lost, exposed, or accessed by the wrong person, patients are harmed and the practice breaches its legal obligations under the Privacy Act 1988 and the Notifiable Data Breaches scheme.

Information security in general practice is best understood as a fixed cost of doing business rather than an optional extra. Criterion C6.4 is where the RACGP Standards make that concrete. Accreditation is assessed by an approved agency — in Australia that’s typically AGPAL or Quality Practice Accreditation (QPA) — and both assess against the 5th edition Standards.

What does Criterion C6.4 actually require? (The five indicators)

C6.4 is broken into five sub-indicators, C6.4A through C6.4E. Each is a separate thing your practice must be able to demonstrate to an assessor. Here’s what each one means and how it’s met.

  • C6.4A — A named person responsible for electronic systems

The requirement: Your practice must have a team member with primary responsibility for the security of its electronic systems and the information they hold.

What this means in practice: An assessor wants to see that information security isn’t nobody’s job. Someone has to own it — usually a practice manager or principal GP internally, working with your IT support provider who carries the technical responsibility. Many practices formalise this by naming their external IT provider as the party responsible for the technical security function in their support agreement.

How Bluebird IT helps: As your managed IT provider, we fill the technical side of this role. Our service agreements formally name Bluebird IT as your practice’s IT support provider, so when an assessor asks who is responsible for your electronic systems, you have a documented answer — an accountable, contactable, WA-based provider rather than an ad-hoc arrangement.

  • C6.4B — Patient information kept out of public view

The requirement: Your practice must not store or leave patient personal health information where members of the public could see or access it.

What this means in practice: This is both physical and digital. Screens at reception angled away from the waiting room, workstations that lock automatically when unattended, no patient data on unsecured shared drives, and no records left visible on desks or printers in public areas.

How Bluebird IT helps: We configure automatic screen locking, set up workstations so clinical software isn’t left exposed, and design your network so patient data is only accessible to authorised staff — closing the digital side of this indicator while your team handles the physical layout.

  • C6.4C — Individual password-protected access to clinical software

The requirement: Your clinical software must be accessible only via unique individual passwords, giving each person access to information according to their level of authorisation.

What this means in practice: No shared logins. Every staff member has their own account, and what they can see and do is controlled by their role — reception staff, nurses, and GPs have different levels of access. This creates an audit trail and enforces the “least privilege” principle: people can access what they need for their job, and no more.

How Bluebird IT helps: We set up and manage individual user accounts across your clinical software (Best Practice, Medical Director and others) and your wider systems, configure role-based access levels, and enforce password policies — so every login is traceable to a person and access matches authorisation.

  • C6.4D — A business continuity and information recovery plan

The requirement: Your practice must have a documented business continuity and information recovery plan.

What this means in practice: If your server fails, your clinical system goes down, or you’re hit by ransomware, you need a written, tested plan for how the practice keeps operating and how information is recovered. Backups are central to this — but a backup nobody has ever tested restoring is not a recovery plan.

How Bluebird IT helps: We implement and monitor backup systems for your clinical and business data, and — critically — we test that those backups actually restore, so recovery is proven rather than assumed. We help document the continuity plan an assessor expects to see, covering how the practice functions during an outage and how systems are brought back.

  • C6.4E — Procedures for storage, retention and destruction of records

The requirement: Your practice must have appropriate procedures for the storage, retention and destruction of records.

What this means in practice: Health records have legal retention periods, and when records are disposed of — including old hardware, drives and backups — the data must be destroyed securely, not simply deleted or thrown out. This covers the full lifecycle of information, from how it’s stored to how it’s ultimately and permanently removed.

How Bluebird IT helps: We ensure records are stored securely for their required retention period and that when hardware is decommissioned, drives are securely wiped or destroyed so no patient data can be recovered from retired equipment.

What IT documentation does an accreditation assessor want to see?

Assessors look for evidence, not just assurances. For the information security criterion, that typically includes a written computer and information security policy, a documented business continuity and recovery plan, evidence that backups are performed and tested, records showing individual user accounts and access levels, and a clear statement of who holds responsibility for electronic systems. The RACGP publishes a Computer and Information Security policy template and an “Information Security in General Practice” resource that many practices use as their starting point.

A practice doesn’t need to produce all of this from scratch at audit time. Most of it should already exist as part of running securely day to day — which is the point of the criterion.

Do we need to write our own information security policy?

Yes — your practice needs a documented computer and information security policy, and it needs to reflect how your practice actually operates rather than being a generic template with the practice name dropped in. The RACGP provides a policy template mapped to C6.4 that gives you the structure and required sections.

Bluebird IT supports this by making sure the technical realities described in your policy are the ones actually implemented — that the access controls, backup routines and security measures your policy commits to are genuinely in place and verifiable. The policy and the practice have to match; an assessor will check.

How long does it take to get our practice's IT ready for accreditation?

It depends entirely on your starting point. A practice with individual logins, tested backups, and secure workstations already in place may need little more than documentation tidy-up. A practice with shared passwords, an untested backup, and no continuity plan needs remediation work first, and that can take weeks depending on scope.

The practical advice: don’t leave IT to the final weeks before an accreditation cycle. The technical controls behind C6.4 — proper access control, proven backups, secure record handling — are things that should be running continuously, and are far cheaper to maintain than to scramble into place under deadline.

Getting your practice's IT accreditation-ready in WA

Bluebird IT provides specialist managed IT support to general practices across Western Australia, and RACGP accreditation is a core part of what we help practices navigate. We implement and maintain the technical controls behind Criterion C6.4 — individual access control, tested backups and recovery, secure record handling, and screen and workstation security — and we act as the named IT support provider that C6.4A asks practices to have in place.

If your practice has an accreditation cycle approaching, or you simply want the confidence that your information security genuinely meets the Standards rather than hoping it does, [get in touch with our WA healthcare IT team].

*This guide is general information about the IT-related requirements of RACGP accreditation and is not a substitute for the current RACGP Standards for General Practices (5th edition) or advice from your accrediting agency. Always refer to the current Standards and your assessor for the definitive requirements.*

Your next steps

1
2
3
Bluebird IT healthcare IT specialist meeting with client

Let's talk

We'll learn about your organisation, your clinical systems, and what's keeping you up at night.

Bluebird IT technician providing managed IT support for WA healthcare providers

Choose your plan

If we're the right fit, you'll select the IT service agreement that best suits your organisation.

Bluebird IT providing managed IT support for WA healthcare providers

Focus on patient care

With Bluebird IT managing your technology, your team can do what they do best — delivering outstanding care to your patients.