Key takeaways
- RACGP Criterion C6.4 expects every practice to have a policy on the use of email.
- Secure clinical messaging delivers documents to verified recipients, and is generally safer than ordinary email for clinical information.
- Most patient information incidents involving email come down to the wrong recipient, so build in checks.
Standards update: the RACGP released the 6th edition of the Standards for general practices on 26 August 2026. Practices continue to be assessed against the 5th edition until transition arrangements are published, so references here are to the 5th edition. Many requirements carry over to the 6th edition, but they have been reorganised.
The problem with ordinary email
Email is fast and universal, but a typo in an address, an autocomplete mistake or a compromised mailbox can send health information to the wrong person. A misdirected email containing health information may even be an eligible data breach under the Notifiable Data Breaches scheme.
What secure messaging does differently
Secure clinical messaging services exchange referrals, results and discharge summaries between registered healthcare providers. Messages are addressed to verified providers rather than typed email addresses, and are integrated with clinical software so documents land in the right patient file. Our team supports practices using secure messaging tools such as Medical Objects.
When email is used
- Multi-factor authentication on every mailbox
- A check of the recipient address before sending health information
- Encryption or password-protected attachments where appropriate, with the password sent separately
- Patient consent recorded where patients ask to receive information by email
- A clear process if something is sent to the wrong person
What your email policy should cover
Cover who may send patient information by email and when, when secure messaging must be used instead, how patient consent is recorded, how staff verify recipients, and how to report mistakes. The RACGP's Information security in general practice resource includes policy templates.
Common questions
Is it okay to email patient results?
It may be, with patient consent and appropriate safeguards, but secure clinical messaging is generally safer for provider-to-provider communication. Follow your practice's email policy.
What should we do if we email patient information to the wrong person?
Try to recall the message and ask the recipient to delete it, record what happened, and assess whether it is an eligible data breach under the NDB scheme.
Reviewed by Graham Graieg and Dane, Triad Networking Services. Graham and Dane look after IT, phones and security for Triad's medical and business clients across South East Queensland. Meet the team.
Sources
- RACGP, Criterion C6.4 – Information security
- RACGP, Information security in general practice (PDF)
- OAIC, Part 4: Notifiable Data Breach (NDB) Scheme
- EMPHN, RACGP releases Standards for general practices, 6th edition (8 September 2026)
- QPA, Preparing for the 6th edition (16 September 2026)
General information only, current as of 6 October 2026. It isn't legal or compliance advice for your specific situation.
