Key takeaways
- RACGP Criterion C6.4 expects a business continuity and information recovery plan, not just a backup that runs.
- Follow the 3-2-1 rule: three copies, on two types of storage, with one off-site.
- Document how often backups run, the media and rotation, encryption, testing and where copies are stored.
- A backup you haven't test-restored is an assumption. Schedule restores and record the results.
Why backups are an accreditation issue
The RACGP Standards for general practices (5th edition) cover information security under Criterion C6.4. One of its indicators is that the practice has a business continuity and information recovery plan, and the RACGP notes that you must maintain and test it.
In other words, a surveyor is looking for evidence that you can get your clinical and business data back, not a backup icon in the system tray.
Standards update: the RACGP released the 6th edition of the Standards for general practices on 26 August 2026. Practices continue to be assessed against the 5th edition until transition arrangements are published, so references here are to the 5th edition. Many requirements carry over to the 6th edition, but they have been reorganised.
Start with the 3-2-1 rule
- Three copies of your data: the live system plus two backups.
- Two types of storage, for example a local backup device and cloud storage.
- One copy off-site, so fire, theft or flood at the practice can't take out every copy.
Ransomware changes the picture. If a backup is permanently connected and writable, malware can encrypt it too. At least one copy should be offline or immutable, meaning it can't be changed or deleted for a set period.
What to document
The RACGP's Information security in general practice resource recommends documented backup procedures that cover:
- how often backups are run
- the type of backup, media type and rotation
- the use of encryption
- reliability testing and restoration checking
- where the backups are stored.
Add who is responsible. Criterion C6.4 also expects a team member with primary responsibility for electronic systems and computer security. That person, or your IT provider on their behalf, should own the backup log.
Clinical software needs special care
Practice management and clinical systems run on databases. Copying database files while they're in use can produce a backup that won't open. Use the backup method your software vendor supports, and confirm it also captures scanned documents, letters, and any imaging or dictation files stored outside the database.
Test restores, then record them
A common approach is a test restore every quarter, plus one after any major change such as a server replacement or software upgrade. Restore to a separate location, open the clinical software against the restored data, and confirm recent records are present.
Record the date, what was restored, how long it took and who checked it. That record is exactly the evidence an accreditation surveyor wants to see.
Monitor every night
Backups fail quietly: a full disk, an expired cloud password, a USB drive left unplugged. Set up alerts that go to someone who will act on them, and review a weekly summary. External monitoring is one of the protection layers we use for medical clients.
Quick checklist
- Three copies, two types of storage, one off-site
- At least one offline or immutable copy
- Backups encrypted in transit and at rest
- Vendor-supported backup for clinical software databases
- Failure alerts reaching a named person
- A restore tested and logged in the last three months
- A written recovery plan you can reach even if the server is down
- Backup power with automated shutdown, so an outage doesn't corrupt data
Common questions
How often should a medical practice back up?
At least daily for clinical and practice data, and more often if losing a day's work isn't acceptable. The right frequency depends on how much data you could afford to re-enter.
Is cloud backup enough on its own?
Cloud backup is an excellent off-site copy, but restoring a whole server over the internet can take a long time. Most practices are best served by a fast local backup plus a cloud copy.
What will an accreditation surveyor want to see?
Typically a written backup and recovery procedure, evidence that backups run, such as logs, and records showing restores have been tested.
Reviewed by Graham Graieg and Dane, Triad Networking Services. Graham and Dane look after IT, phones and security for Triad's medical and business clients across South East Queensland. Meet the team.
Sources
- RACGP, Criterion C6.4 – Information security
- RACGP, About backups
- RACGP, Information security in general practice (PDF)
- EMPHN, RACGP releases Standards for general practices, 6th edition (8 September 2026)
- QPA, Preparing for the 6th edition (16 September 2026)
General information only, current as of 6 October 2026. It isn't legal or compliance advice for your specific situation.
