Key takeaways
- Criterion C6.4 of the RACGP Standards (5th edition) has seven indicators, labelled A to G.
- Most of them need both a written policy and an IT control behind it.
- Collect evidence as you go: logs, screenshots and signed policies make a survey far smoother.
Standards update: the RACGP released the 6th edition of the Standards for general practices on 26 August 2026. Practices continue to be assessed against the 5th edition until transition arrangements are published, so references here are to the 5th edition. Many requirements carry over to the 6th edition, but they have been reorganised.
How to use this checklist
Criterion C6.4 deals with information security. Below, each indicator is paired with the IT measures that typically support it and the evidence worth keeping. Wording is paraphrased; refer to the RACGP Standards for the exact text, and to the RACGP's Information security in general practice resource for templates.
A: A responsible team member
The practice has a team member with primary responsibility for electronic systems and computer security.
- Name the person in your policy, with a deputy
- Record what your IT provider handles on their behalf
- Keep a contact sheet for after-hours incidents
B: Patient information out of public view
Personal health information isn't stored or left where members of the public could see or access it.
- Screens angled away from the waiting room, or privacy filters fitted
- Automatic screen lock after a short idle period
- Printers and fax machines out of public reach
C: Individual access to clinical software
Clinical software is accessible only via unique individual identification, with access matched to each person's role.
- No shared logins, including for locums and students
- Role-based permissions reviewed when staff change roles
- Accounts disabled promptly when staff leave
- Multi-factor authentication wherever the software supports it
D: Business continuity and information recovery
The practice has a business continuity and information recovery plan, which should be maintained and tested.
- Documented backups with an off-site copy
- Test restores recorded with date, scope and result
- A downtime plan staff can follow without the clinical system
E: Storage, retention and destruction
The practice has appropriate procedures for storing, retaining and destroying records.
- Encrypted storage on servers, laptops and backups
- Secure disposal of old drives and devices, with certificates kept
- Paper records shredded securely
F and G: Email and social media policies
The practice has a policy on the use of email, and one on social media.
- Email policy covering when patient information may be emailed, and when secure messaging must be used
- Email filtering and multi-factor authentication on all mailboxes
- Social media policy covering who can post and what must never be shared
Common questions
What is RACGP Criterion C6.4?
It is the information security criterion in the RACGP Standards for general practices (5th edition), covering responsibility for IT security, privacy of patient information, individual access to clinical software, business continuity, records management, and email and social media policies.
Does my IT provider make us compliant?
Your IT provider can implement and evidence many technical controls, but the practice remains responsible for its policies, staff behaviour and accreditation.
Reviewed by Graham Graieg and Dane, Triad Networking Services. Graham and Dane look after IT, phones and security for Triad's medical and business clients across South East Queensland. Meet the team.
Sources
- RACGP, Criterion C6.4 – Information security
- RACGP, Information security in general practice (PDF)
- EMPHN, RACGP releases Standards for general practices, 6th edition (8 September 2026)
- QPA, Preparing for the 6th edition (16 September 2026)
General information only, current as of 6 October 2026. It isn't legal or compliance advice for your specific situation.
