Essential Eight for general practice: what actually applies to you

Bluebird IT technician at a healthcare provider reception desk

The Essential Eight comes up constantly in general practice IT conversations, usually with the implication that your practice is failing to meet something it is legally required to meet. That framing is wrong, and it leads practices to spend money in the wrong order.

This guide sets out what the Essential Eight actually is, whether it applies to you, which parts genuinely matter in a general practice, and how it lines up with the accreditation requirements you are already assessed against.

Does the Essential Eight legally apply to a private general practice?

No. The Essential Eight is guidance published by the Australian Signals Directorate, not legislation. The obligation to reach a specific maturity level applies to non-corporate Commonwealth entities, which must meet Maturity Level Two as a minimum under the Protective Security Policy Framework. A privately owned general practice is not a Commonwealth entity and carries no such obligation.

ASD is also explicit that there is no requirement to have an Essential Eight implementation certified by an independent party. Assessment by a third party only comes into play where a government directive, a regulator, or a contract requires it.

What does bind your practice: the Privacy Act 1988, the Notifiable Data Breaches scheme, and the RACGP Standards you are accredited against. Anyone telling you the Essential Eight is mandatory for your practice is either mistaken or selling something.

If it is not mandatory, why does it keep coming up?

Because it has become the common language for cyber security in Australia. Insurers score against it. Larger organisations ask about it in contracts. Incident reviews map back to it. When a health service or a government program asks about your security posture, the Essential Eight is usually the vocabulary the question is written in.

There is also a practical argument. The eight strategies were chosen because they address the attack methods ASD actually observes, drawn from its incident response and penetration testing work. They are a defensible starting point even for a practice with no external obligation at all.

The useful reframing: treat the Essential Eight as a checklist you choose to use because it is good, not a standard you are failing. That changes what you spend and in what order.

Which maturity level should a general practice aim for?

The model defines four levels, Maturity Level Zero through Maturity Level Three. Zero means minimally aligned with the intent of a strategy. Three means fully aligned. The levels are designed to correspond to increasing adversary capability, so Three is built for targeted attackers with time and resources.

For a general practice with no contractual obligation, Maturity Level One is the sensible target. It addresses the bulk of opportunistic attacks, which is what actually threatens a practice. Chasing Level Three in a ten-person clinic means spending heavily against a threat model that does not match who is attacking you.

The rule that catches people out: ASD applies the strategies as a package. Organisations are advised to reach a consistent level across all eight before moving up. Seven strategies at Level Two and one at Level Zero is not “nearly Level Two” — the weakest control sets your position.

What are the eight strategies, and what does each mean in a practice?

The eight strategies are summarised below in the order a practice should work through them, then covered in full in ASD’s order.

Where to startStrategyWhat it means in your practice
1Multi-factor authenticationA second factor on email and remote access, where most opportunistic compromises begin.
2Regular backupsBackups proven by actually restoring them, with the result written down.
3Restrict administrative privilegesDay-to-day work does not happen from an account that can change anything.
4Restrict Microsoft Office macrosMacros from the internet disabled. Most practices have no legitimate need for them.
5Patch applicationsClinical system, browsers and PDF readers kept current, including the forgotten long tail.
6Patch operating systemsNo machines running past their support date, or isolated where they cannot be replaced.
7User application hardeningBrowser and Office features that are commonly exploited and rarely needed, turned off centrally.
8Application controlOnly approved software runs. Demanding to maintain, and rarely proportionate in a small clinic.

Sequencing is our recommendation for general practice, not an ASD ranking — ASD treats the eight as a package.

Bluebird IT providing managed IT support for WA healthcare providers

How does the Essential Eight line up with RACGP Criterion C6.4?

This is the connection worth making, because it turns optional guidance into work you have to do anyway.

Criterion C6.4 requires individual password-protected access to clinical software with access matched to authorisation. That is the same ground as restricting administrative privileges, and multi-factor authentication strengthens it. C6.4 requires a business continuity and information recovery plan with backups behind it. That is the regular backups strategy almost exactly. C6.4 requires patient information to be kept out of public view, which depends on workstation configuration that user application hardening and privilege restriction both support.

Four of the eight strategies do double duty as accreditation evidence. If you are working toward accreditation anyway, you are already partway to Maturity Level One without having framed it that way.

The mapping runs the other way too — if you have not worked through the accreditation side yet, start there. We covered all five sub-indicators in our guide to the IT requirements for RACGP accreditation.

Which of the eight are hardest in a general practice?

Two stand out, for different reasons.

Application control is the most technically demanding and the least proportionate for a small clinic. It requires knowing and approving everything that runs, and maintaining that as software changes. In a practice of fifteen people it usually costs more attention than the risk justifies.

Patching operating systems is hard for a different reason: equipment. A practice may have a machine that cannot be updated because it drives a device whose vendor never supported anything newer. That is not a technical failure, it is a procurement constraint, and the answer is isolation and a replacement plan rather than pretending the risk is not there.

The other six are largely achievable with configuration and discipline rather than significant spend.

Where should a practice start if it is doing none of this?

In this order, because it puts risk reduction ahead of completeness:

  • Multi-factor authentication on email and remote access. Highest reduction in risk for the least disruption.
  • Backups that have been restored at least once, with the result written down.
  • Remove administrative rights from accounts used for daily work.
  • Disable Office macros from the internet.
  • Get patching onto a schedule for both applications and operating systems.
  • Apply hardened browser and Office configuration.
  • Consider application control last, and only if something external requires it.

The first three address most of what actually happens to practices. The rest is worth doing, but not before those.

How do we prove any of this to an assessor or insurer?

Evidence, not assertion. For each strategy you should be able to produce something showing the control operates: a patching report, a list of accounts with administrative rights and when it was last reviewed, a record of a completed restore test, the configuration applied to Office and browsers.

Insurers increasingly ask about the Essential Eight by name on renewal questionnaires. Answering those accurately matters — a claim can turn on whether the controls you attested to were actually in place.

Worth noting: ASD does not certify implementations, and no one can sell you an official Essential Eight certificate. What you can have is a documented, honest assessment of where you sit against each strategy.

Getting your practice to a defensible baseline

The Essential Eight is not a legal obligation for your practice, and treating it as one leads to spending in the wrong order. Treated properly, it is a well-evidenced checklist that overlaps substantially with accreditation work you already have to do.

Bluebird IT works exclusively with healthcare organisations across Western Australia, and general practice is a core part of that work. We support Best Practice and Medical Director environments, and our clients reach us with a typical response time of under 5 minutes during business hours.

If you would like an honest assessment of where your practice sits against each of the eight strategies — written so it can go to your insurer or your accreditation assessor — we can work through it with you. You can read more about our IT support for WA GP practices and medical centres.

If your practice runs Best Practice, we cover the clinical software side as well — see our Bp Premier support for WA practices for what that includes.

Your next steps

1
2
3
Bluebird IT healthcare IT specialist meeting with client

Let's talk

We'll learn about your organisation, your clinical systems, and what's keeping you up at night.

Bluebird IT technician providing managed IT support for WA healthcare providers

Choose your plan

If we're the right fit, you'll select the IT service agreement that best suits your organisation.

Bluebird IT providing managed IT support for WA healthcare providers

Focus on patient care

With Bluebird IT managing your technology, your team can do what they do best — delivering outstanding care to your patients.