Key takeaways

  • Reception is where patient information, phones, email and the public all meet.
  • RACGP Criterion C6.4 expects individual logins for clinical software and patient information kept out of public view.
  • Many incidents start with a click, a call or an unattended screen, so habits matter as much as technology.

Standards update: the RACGP released the 6th edition of the Standards for general practices on 26 August 2026. Practices continue to be assessed against the 5th edition until transition arrangements are published, so references here are to the 5th edition. Many requirements carry over to the 6th edition, but they have been reorganised.

The 10 habits

  1. Lock your screen every time you step away. On Windows, press the Windows key + L.
  2. Use your own login. Clinical software should be accessible only through unique individual identification. Shared logins make it impossible to see who accessed what.
  3. Keep screens and paperwork out of public view. Angle monitors away from the waiting room, consider privacy filters, and don't leave referrals, scripts or day sheets on the counter.
  4. Verify before you disclose. Confirm a caller's identity using details on file before sharing patient information, and call back on a known number if something feels off.
  5. Pause on unexpected links and attachments. Invoices, delivery notices and shared-document emails are common phishing lures. If it's unexpected, check with the sender by phone.
  6. Use multi-factor authentication on email and online portals, so a stolen password alone isn't enough.
  7. Never plug in unknown USB drives, even ones handed in at the desk.
  8. Send clinical information securely. Use secure messaging for clinical documents rather than ordinary email, and follow your practice's email policy.
  9. Report mistakes immediately. A misdirected email or suspicious click is far easier to contain in the first hour. See what to do in the first 30 days.
  10. Know the downtime plan. Know who to call and how to keep booking patients if the clinical system or phones go down.

Make it stick

Short, regular refreshers work better than a one-off session. Add these habits to induction for new reception staff, and revisit them at team meetings. Staff training and awareness is one of the protection layers we recommend for every practice.

Common questions

Do reception staff need cyber security training?

Yes. Reception handles patient information, phone enquiries and email all day. Short, regular training helps staff spot phishing and handle information safely.

What are common security risks at reception?

Common risks include unlocked unattended screens, phishing emails, patient information visible to the waiting room, and details given to callers who haven't been verified.

Reviewed by Graham Graieg and Dane, Triad Networking Services. Graham and Dane look after IT, phones and security for Triad's medical and business clients across South East Queensland. Meet the team.

Sources

  1. RACGP, Criterion C6.4 – Information security
  2. EMPHN, RACGP releases Standards for general practices, 6th edition (8 September 2026)
  3. QPA, Preparing for the 6th edition (16 September 2026)

General information only, current as of 6 October 2026. It isn't legal or compliance advice for your specific situation.