Key takeaways

  • Criterion C6.4 of the RACGP Standards (5th edition) has seven indicators, labelled A to G.
  • Most of them need both a written policy and an IT control behind it.
  • Collect evidence as you go: logs, screenshots and signed policies make a survey far smoother.

Standards update: the RACGP released the 6th edition of the Standards for general practices on 26 August 2026. Practices continue to be assessed against the 5th edition until transition arrangements are published, so references here are to the 5th edition. Many requirements carry over to the 6th edition, but they have been reorganised.

How to use this checklist

Criterion C6.4 deals with information security. Below, each indicator is paired with the IT measures that typically support it and the evidence worth keeping. Wording is paraphrased; refer to the RACGP Standards for the exact text, and to the RACGP's Information security in general practice resource for templates.

A: A responsible team member

The practice has a team member with primary responsibility for electronic systems and computer security.

  • Name the person in your policy, with a deputy
  • Record what your IT provider handles on their behalf
  • Keep a contact sheet for after-hours incidents

B: Patient information out of public view

Personal health information isn't stored or left where members of the public could see or access it.

  • Screens angled away from the waiting room, or privacy filters fitted
  • Automatic screen lock after a short idle period
  • Printers and fax machines out of public reach

C: Individual access to clinical software

Clinical software is accessible only via unique individual identification, with access matched to each person's role.

  • No shared logins, including for locums and students
  • Role-based permissions reviewed when staff change roles
  • Accounts disabled promptly when staff leave
  • Multi-factor authentication wherever the software supports it

D: Business continuity and information recovery

The practice has a business continuity and information recovery plan, which should be maintained and tested.

  • Documented backups with an off-site copy
  • Test restores recorded with date, scope and result
  • A downtime plan staff can follow without the clinical system

E: Storage, retention and destruction

The practice has appropriate procedures for storing, retaining and destroying records.

  • Encrypted storage on servers, laptops and backups
  • Secure disposal of old drives and devices, with certificates kept
  • Paper records shredded securely

F and G: Email and social media policies

The practice has a policy on the use of email, and one on social media.

  • Email policy covering when patient information may be emailed, and when secure messaging must be used
  • Email filtering and multi-factor authentication on all mailboxes
  • Social media policy covering who can post and what must never be shared

Common questions

What is RACGP Criterion C6.4?

It is the information security criterion in the RACGP Standards for general practices (5th edition), covering responsibility for IT security, privacy of patient information, individual access to clinical software, business continuity, records management, and email and social media policies.

Does my IT provider make us compliant?

Your IT provider can implement and evidence many technical controls, but the practice remains responsible for its policies, staff behaviour and accreditation.

Reviewed by Graham Graieg and Dane, Triad Networking Services. Graham and Dane look after IT, phones and security for Triad's medical and business clients across South East Queensland. Meet the team.