Compliance · MHR Rules 2026

RACGP accreditation is next year. Your IT evidence trail doesn't exist.

Under My Health Records Rules 2026, practices must produce security policies, access logs and incident records within 7 days of an OAIC request. Most clinics have a policy template. Almost none can produce the evidence. That's what regulators now examine.

Not ready to book? Self-assess with the free Post-1 July Compliance Checklist →

Best PracticeMedical DirectorZedmedGenieGentu
25+ years IT managementMajor Melbourne public hospitalNational research healthcare environmentMy Health Record implementationEssential Eight · ITIL · CCNA

Could your practice pass the 7-Day Test?

Under the My Health Records Rules 2026, every registered practice must hold, enforce and annually review a written security and access policy — and produce it within 7 days if the System Operator or OAIC asks. Not just the document: evidence that your practice actually follows it. Access records. Patch status. Staff acknowledgments. Incident logs.

From 1 July 2026, new Medicare assignment of benefit rules also require completed agreements to be kept for two years and produced on audit. And Privacy Act penalties are no longer theoretical — a $5.8 million penalty has already been issued, with maximums of $50 million or 30% of turnover.

Most practices have a policy template. Almost none can produce the evidence. That gap is what regulators, accreditation surveyors and cyber insurers now examine.

Non-compliance is currently live, not future.

Not sure where your practice stands?

The free Post-1 July 2026 Compliance Checklist takes 5 minutes and tells you exactly which boxes you can't tick.

Get the free checklist →

Managed IT with a compliance evidence layer.

We don't just keep your systems running — we build and maintain the documented record your accreditation body expects.

Managed IT & helpdesk

Remote and onsite support, 30-minute response during clinic hours. Deep expertise in Zedmed, Best Practice, MedicalDirector, and pathology integrations — not a generic IT provider learning on your time.

Compliance documentation

Monthly audit logs, backup verification records, access reviews, and incident documentation. Everything your accreditation body asks for, ready before you need it.

Disaster recovery planning

A written DR plan scoped to your practice, plus an annual walkthrough with staff. When something goes wrong, your team knows what to do — and you can prove that to your accreditor.

How we get started.

From first conversation to a fully documented, managed environment — here's what to expect.

01

Book a Compliance Gap Assessment

A fixed-fee, two-week assessment of your practice's IT environment — systems, backups, access controls, compliance documentation. You leave with a written report and prioritised roadmap. The fee is credited in full if you engage us within 60 days.

02

We map your current gaps

We document exactly what's missing versus what RACGP accreditation, the Privacy Act, and My Health Records Rules 2026 actually require. Most practices are closer than they think — and a few surprises usually surface.

03

We fix and document everything

We remediate the gaps, implement the missing controls, and build out your evidence library. Everything is documented as we go — not scrambled together before your next audit.

04

Ongoing managed service

Monthly compliance reports, continuous monitoring, and an IT partner who knows your practice. You stay focused on patients; we keep the evidence trail current.

Who we work with.

We work with GP groups, medical centres, and specialist practices across Metropolitan Melbourne and regional Victoria. Multi-site groups are welcome — each location gets its own documented evidence trail managed centrally.

Start with a Gap Assessment
Practice sizeGP groups, medical centres, specialist practices — single site to multi-location
LocationMelbourne metro & regional Victoria
SoftwareBest Practice, Medical Director, Zedmed, Genie, Gentu (Magentus)
Compliance focusRACGP accreditation, Privacy Act, My Health Records Rules 2026
What they needOne trusted contact who knows their practice — and can prove it to an auditor
About

I've seen practices fail accreditation audits for IT gaps I could fix in an afternoon.

I'm Joe — I've spent 25+ years in IT management and infrastructure, including senior roles at major Melbourne public hospitals and national healthcare research organisations. I've implemented My Health Record integrations, built HL7 pipelines, and managed the IT environments that clinicians actually depend on every day.

I started ClinicGuard IT because medical practices deserve an IT provider who understands clinical workflows — not one who treats your practice like a small office. Every clinic I work with gets a documented, compliant IT environment and a direct line to someone who knows their systems inside out.

More about my background →

Common questions.

What is a Compliance Gap Assessment?

A fixed-fee, two-week assessment across 10 domains — MHR Rule 21 readiness, access controls, backup and recovery, Essential Eight posture, incident response, and more. You receive a written RAG scorecard, a 7-Day Test verdict, and a prioritised remediation roadmap. The fee is credited in full against onboarding if you engage us within 60 days.

We already have an IT provider — do we have to switch?

No. The Gap Assessment is independent of who manages your IT — it assesses your environment, not your provider. Many practices find it surfaces gaps their current provider hasn't addressed. After the assessment, if you decide to move to ClinicGuard IT, we handle the transition — access handover, documentation, and continuity planning — so there's no disruption to the practice.

Do I need to sign a long-term contract?

No lock-in contracts. We work on a month-to-month basis after an initial 90-day setup period. The 90 days is so we can properly document and remediate your environment — not so we can trap you.

Can you support multiple clinic locations?

Yes. We work with practices from single-location clinics to multi-site groups. Each location gets its own documented IT register, and we manage patching, monitoring, and compliance evidence across all sites centrally.

Do you work with Zedmed and Best Practice?

Yes. Our primary platforms are Best Practice, Medical Director, Zedmed, Genie, and Gentu. We've worked with all of them in depth: upgrades, integrations, pathology link configuration, and the edge cases that break things on a Monday morning.

What happens when something breaks?

You contact us directly — not a helpdesk or ticket queue. During clinic hours (Mon–Sat 7am–7pm AEST) we aim to respond within 30 minutes. For critical issues we stay on it until it's resolved, and we document the incident for your compliance record.

More questions? Read the full FAQ or get in touch.

Start with a Compliance Gap Assessment.

A fixed-fee, two-week assessment of your practice's IT environment across 10 compliance domains. You receive a written report and prioritised roadmap — whether we work together or not. Fee credited in full if you engage us within 60 days.

Book a Gap Assessment

Founding clients receive preferential terms — pricing locked at today's rate as ClinicGuard IT grows.