Skip to main content

PRACTICE MANAGER JOURNAL_JUN 26

Page 1


The Practice Manager

JUNE 2026

AAPM Member Benefits

AAPM’s supports and promotes members’ personal and professional growth through a system of:

CORE PRINCIPLES

ADVOCACY

AAPM representation on government and industry advisory groups.

HR ADVISORY SERVICE

Comprehensive HR support and advice through telephone, email, website resources and templates.

MEMBER ASSISTANCE PROGRAM

Confidential assistance to support health and wellbeing of members.

PULSE+IT SUBSCRIPTION

Asia Pacific’s eHealth and Health IT digital platform.

MEMBERSHIP BADGE

Recognition of AAPM membership.

THE PRACTICE SPACE

Dedicated fortnightly eNewsletter providing latest industry updates.

THE PRACTICE MANAGER JOURNAL

AAPM’s national journal, delivered electronically to members each quarter.

AAPM EDUCARE

Access to AAPM’s Educare program at member rates. Includes a series of webinars and face-to-face event delivery.

NATIONAL CONFERENCE

Premier annual conference for Practice Management professionals at member rates.

NETWORKING MEETINGS

Share knowledge and information. Connect with, and support your peers.

ONLINE LEARNING MODULES

Self-guided learning through Practice Management topics.

SCHOLARSHIPS

Expand your skills through AAPM funded scholarships delivered though UNE Partnerships.

PRACTICE MANAGEMENT AWARDS

Prestigious national industry awards program that recognises acknowledges Practice Management professionals.

CONTINUAL PROFESSIONAL DEVELOPMENT

CERTIFIED PRACTICE MANAGER (CPM)

Cerification membership to recognise experience and skills in the profession of Practice Management.

FELLOWSHIP

A prestigious honour in recognition of significant commitment and contribution to the profession of Practice Management.

CORPORATE PARTNERS

Exclusive access to resources, savings and benefits from AAPM’s corporate partners.

DEDICATED ONLINE MEMBERS FORUM

Dedicated and exclusive member only forum to share ideas, insights, information and support.

AUSDOC SUBSCRIPTION

Free subscription to AusDoc. The leading communication platform for Australian Doctors.

WEBSITE ACCESS

Access latest news, industry information, and member-only resources.

National President's Message

Managing Conflicts of Interest: A Whole-ofOrganisation Responsibility

Conflicts of interest, we all know they exist, but how often do we really stop to think about where they show up in our organisations, and whether we’re managing them well?

Most people’s first thought is a doctor referring patients to a service they part-own, or a supplier offering a nice dinner in exchange for future business. Those are fair examples, but the reality is much broader. While my experience is primarily in general practice, including as a practice director for 15 years, board director of AAPM for 5 years, and other board and advisory roles across the wider health sector, I’ve encountered and managed conflicts of interest in many forms, and the lessons apply right across the industry.

Think about your reception and administrative team. They’re booking appointments, handling patient data, and dealing with external suppliers every day, such as IT vendors, cleaning

contractors, service providers of all kinds. A manager who gives a contract to a family member’s business, or a team member who quietly bumps friends to the top of the appointment list, is facing the same fundamental problem as a doctor swayed by a supplier’s hospitality. The names change; the dynamic doesn’t. It’s not just admin, clinical team members can have connections to equipment reps, training organisations, or allied health services that are equally worth declaring.

Trust is really what’s at stake. Patients and consumers need to know that decisions made on their behalf, referrals, recommendations, resource choices, are made for the right reasons. Conflicts of interest could sit within the broader ethical dilemmas that organisations are expected to consider under relevant accreditation and professional standards. Quality improvement frameworks are a practical place to start building your own response, clear policies, a gifts and benefits register, and a disclosure process that everyone actually understands and uses.

Some scenarios worth keeping on your radar include, a doctor with equity in a service they routinely refer to; a manager engaging a relative’s business for maintenance or IT; team members receiving gifts or hospitality from suppliers; a clinical team member referring patients to a service they have a financial connection to; and gifts from patients such as a box of chocolates is usually fine, but cash, expensive items, or anything recurring deserves a clear and consistent response. None of this is about assuming

the worst of people. Most of the time there’s no wrongdoing, just a relationship or interest that needs to be named and managed openly.

It’s also worth reflecting on your own position beyond your organisation. Many health industry leaders sit on advisory committees, association boards, or government working groups. Those roles come with their own fiduciary responsibilities to act in that organisation’s best interest, not your own, your employer’s, or your friends’ and colleagues’. Perceived conflicts matter here just as much as actual ones. If it could reasonably look like your judgement was compromised, it needs to be declared, even if you know it wasn’t. Stepping out of a discussion or recusing yourself from a vote isn’t a weakness, it’s good governance.

Ultimately, you’re often the person best placed to see where interests and decisions quietly intersect across your organisation. A genuine culture of disclosure, a register, a standing item at team meetings, a clear path for raising concerns will do far more good than a policy document nobody reads. It’s not about suspicion. It’s about making sure the good decisions you’re already making can be seen to be good decisions.

From the CEO's Desk

As we approach the midpoint of 2026, I would like to take the opportunity to reflect on the significant work undertaken by the Australian Association of Practice Management (AAPM) over the past few months and acknowledge the ongoing commitment of our members across the healthcare sector. The period from April to June has been one of strong engagement, growth and collaboration as we continue to strengthen the profession of Practice Management and support our members in navigating an increasingly complex healthcare environment.

A key focus for AAPM during this period has been the delivery of high-quality professional development opportunities. Through our webinar program, members have accessed timely education on topics including workforce management, compliance, leadership, business operations, funding reforms and emerging challenges facing healthcare practices. These webinars ensure that Practice Managers remain equipped with the knowledge and skills required to lead successful and sustainable healthcare practices. AAPM participated in Australian Healthcare Week, one of the nation's leading healthcare events. This provided an important opportunity to engage with healthcare leaders, policy makers, industry partners and innovators, while showcasing the critical role that Practice Managers play in supporting

quality patient care and efficient healthcare delivery.

Throughout this period, we have also continued to strengthen relationships with key stakeholders across government and industry partners. These partnerships are essential in ensuring that the voice of Practice Management is represented in discussions relating to healthcare reform, workforce development and the future of primary and specialist healthcare services. We recognise that Practice Managers are operating in an environment characterised by workforce pressures, regulatory changes and increasing patient expectations. Through education, guidance and advisory services, AAPM remains committed to helping members meet these challenges with confidence. We have also continued to expand education opportunities for specialist learning and collaboration. Initiatives such as co-hosting the inaugural O&G Practice Managers Conference demonstrated the expertise and leadership that Practice Managers bring to specialist healthcare environments.

As we move into the second half of the year, our focus remains firmly on supporting members through education, advocacy, networking and professional recognition. We will continue to listen to member feedback, respond to emerging industry needs and create opportunities that strengthen both individual careers and the broader profession.

Telstra Health introduces Smart Connect to streamline pathology eRequesting for GPs patient and pathology providers

Telstra Health, Australia’s largest digital health technology company, has launched Smart Connect, a new pathology eRequesting capability within MedicalDirector Clinical, designed to replace manual, paper-based pathology requests with a fully digital workflow. The feature launches with Healius Pathology Network as its first integrated partner.

Smart Connect allows GPs to generate, edit, electronically sign and securely send pathology eRequests directly from within their existing workflow, without leaving the MedicalDirector Clinical solution. Requests can be sent electronically to both patients and pathology laboratories, with radiology eRequesting to be added in future releases.

The launch comes as demand for diagnostic services continues to rise. eRequesting is becoming critical to maintaining efficient clinical workflows and supporting timely patient care. According to research conducted by the Australian Institute of Health and Welfare, 59 per cent of Australians accessed Medicare -subsidised tests in 2022-23, with 91 per cent of those delivered through primary and community care.

“Too often, healthcare digitisation optimises one link in the chain, instead of supporting every stakeholder across the patient

journey,” said Dr Jennifer Beer, Product Executive at Telstra Health. “Smart Connect breaks that pattern — reducing admin for clinicians, removing paper for patients, and freeing pathology staff from manual data entry. That end-to - end impact is what truly transformative healthcare technology looks like.”

Smart Connect is powered by Telstra Health’s FHIRnative Health Information Exchange (HIE), enabling clinical information to be shared securely and in near real time between MedicalDirector Clinical and integrated pathology providers.

Following the initial launch with Healius, Telstra Health will work with additional pathology providers in the coming months to support broader adoption of eRequesting across primary care.

Healius Chief Operations Officer, Puneet Nagi, said the partnership marked a significant step forward in collaboration between pathology providers and clinicians, helping improve efficiency and patient experience.

“By enabling secure, near real-time electronic requests, we’re helping GPs reduce

administrative burden and find more time for patient care, while making it easier for patients to access and follow-up their results. This is particularly important in today’s virtual, digital-first and telehealthenabled environment,” he said.

“Through Smart Connect, our laboratories benefit from structured, legible and editable requests — helping to minimise transcription errors and reduce processing delays.”

Smart Connect is the latest addition to MedicalDirector Clinical’s suite of digital workflow tools, which also includes Smart Scribe, an AI-powered clinical documentation capability, and integrated Continuing Professional Development (CPD) activities.

“Smart Connect is just one way we’re addressing longstanding issues with siloed data and fragmented workflows, securely connecting MedicalDirector GPs with pathology providers, and soon, radiology providers,” Dr Beer said.

To find out more about Smart Connect, visit https://www. medicaldirector.com/smarter

Less tech stress, more headspace

Switch makes healthcare telecommunications simple, so you can run your practice with confidence.

✓ Voice ✓ Internet ✓ IoT ✓ Cloud ✓ Cybersecurity ✓ Managed Networks

Learn more

From 1 July, Payday Super will fundamentally change how you run payroll, manage cashflow, onboard staff, and stay compliant. This is the most significant superannuation change for employers in years.

 Practical steps you can take now to protect your practice A new era of

Watch our on-demand webinar and have your questions answered. Walk away knowing exactly what to do, what to change, and how to stay compliant.

We will guide you on:

 The new rules’ impact on practice cashflow and payroll timing

 Changes to your systems and onboarding processes

 Compliance and penalty risks for your practice

Get the clarity and confidence you need to turn compliance pressure into a competitive advantage. Watch Now >

Your Pre-30 June Tax Checklist

30 June is just around the corner, and another financial year is almost behind us. Now’s the time to get your records in shape, tidy up the books, and make sure nothing’s been missed.

To make things easier, we’ve shared a few practical tips to help you get organised and avoid lastminute stress.

For Doctors: Don’t leave these to the last minute.

Service fees are often one of your biggest expenses. Check that they’ve been paid in full and in line with your agreement before 30 June.

Prepay what you can. Things like professional memberships, subscriptions and donations may be deductible, and bringing these forward could work in your favour. Make the most of your super. You can contribute up to $30,000 in concessional contributions this financial year (inclusive of Employer contributions), just make sure your payment is received by your super fund well before the deadline. You must also lodge your Notice of Intent to claim a deduction.

You may be able to benefit from unused tax deductible contributions from the last five years where contributions have not been maximised; this needs careful consideration so plan early.

Update your logbook. If you use your car for work, a current logbook helps you claim fuel,

rego, insurance and other running costs up to your business-use percentage.

Bought any assets? Now’s the time to pull that info together while it’s fresh and easy to find.

ATO Payment Arrangements. If you have one in place, remember that as of July last year the interest is no longer tax deductible. Consider alternative ways to pay off your debt sooner rather than later to maximise your deductible debt.

For Practice Managers: These tasks are key.

End of Financial Year (EOFY) preparation is a team effort, and we know practice managers are often the ones keeping everything running behind the scenes. Here’s what to keep an eye on:

Reconcile staff wages and super. Remember, super must be paid before 30 June if you want to claim the deduction this financial year.

Prepare for Payday Super. The biggest change to super and compliance in years kick in on 1 July. It’s important your practice is taking steps now to ensure super is paid to employees in line with pay cycles, rather than quarterly. For more information on this change, read our full guide here

Review expenses. Make sure any tricky items (like entertainment, staff training or repairs) are clearly explained.

Sub-leased rooms? Now’s a great time to check that any rent reviews were completed during

the year.

STP finalisation is due by 14 July. Best to plan ahead so you’re not chasing last-minute fixes.

An important super tax update for this financial year.

Division 296 is now law and represents a significant change to how high balance superannuation accounts will be taxed from 1 July 2026. Under the new rules, earnings on super balances above $3 million will be subject to additional tax, with a tiered approach applying to larger balances. Earnings above $3 million are taxed at 15%, increasing to 25% once balances exceed $10 million. The regime applies on an indexed basis and does not tax unrealised gains.

With Division 296 now locked in, anyone approaching these thresholds should review their super and broader wealth strategy to understand the impact and plan ahead

Make the most of your tax position.

Tax is likely one of your largest outgoings, so it’s well worth taking the time to get things right and maximise your available deductions.

We’ve prepared some detailed EOFY checklists to help you stay on track. Follow the links below to access the tools that’ll help make this process easier for you and your team.

Download our Practice Manager Year End Checklist

Download our Sole Trader Year End Checklist

EOFY is the ideal time to move from reactive tax decisions to a more deliberate, long term strategy. That’s where our approach makes a real difference.

At Cutcher & Neale, we champion proactive planning so you can minimise tax, improve cash flow, and build sustainable wealth over time. If you haven’t reviewed your strategy recently or want to ensure you’re making the most of what’s available, now is the right time to start the conversation.

For personalised advice contact us on 1800 988 522 or go to www.cutcher.com.au/contact

Using Routine Requests?

Patients use it more when they know about it.

Order your free promo pack to get the word out!

Waiting room posters

Desk cards & displays

Quick-start guides for doctors

Scan the QR code to order your pack.

Plus, share a photo of the display in your practice for a chance to win a $100 eVoucher each month. T&Cs apply.

Safe AI for healthcare practices: a people problem as much as a tech problem

A secure AI setup in a clinic needs good technology, but tools alone won’t keep patient data safe. You also need habits, the kind that stop a bad day becoming a notifiable data breach, an AHPRA notification, or a Medicare audit.

You don’t need a dedicated IT department for this, just clear boundaries, approved tools, staff training, and sensible monitoring. Databox Health looks at AI security across three areas:

1. Technology: What tools are being used? Are they secure? Is patient data protected?

2. Policy: What information can clinical and admin staff put into AI? What is banned? Who approves new tools?

3. People: Do clinicians, practice managers, and reception staff understand the risks in plain English?

Miss one and the whole thing gets wobbly. A locked front door doesn’t help if everyone leaves keys under the mat, and in healthcare, the “keys” are patient records.

The AI threat map for healthcare practices

The main risks practices are facing right now. Not in scary movie language, just the real stuff.

1. Patient data leakage

This is the big one. Data leakage happens when clinical information: patient names,

Medicare numbers, consultation notes, pathology, mental health notes, prescriptions, referrals, billing items, telehealth recordings, PMS exports is entered into an AI system the practice does not control.

Under the Privacy Act 1988 and the Australian Privacy Principles (especially APP 11), health information sits in the most sensitive category. State laws, HRIPA in NSW, the Health Records Act in Victoria add another layer. The OAIC reported the health sector at 18% of all notifiable data breaches in Australia between January and June 2025, more than any other industry.

A useful rule for staff:

Treat the AI prompt box like a public noticeboard. If you wouldn’t pin a patient’s record on the waiting-room wall, don’t paste it into an AI tool.

Healthcare-grade AI tools, clinical scribes, Copilot with appropriate licensing, enterprise chatbots may offer stronger controls than free tools. But “may” is doing heavy lifting: data residency, vendor contracts, and APP 8 cross-border obligations all matter. Databox Health can help assess, configure, and manage AI tools so they meet your obligations.

2. Shadow AI in the practice Shadow AI is the use of unapproved AI tools by staff, a receptionist using ChatGPT to draft a patient letter (real names

pasted in), a clinician trialling a free-tier AI scribe without checking where audio is stored, or an allied health practitioner asking a chatbot for a treatment plan with notes pasted in.

Most Shadow AI starts with good intent. Blocking everything pushes use underground. Better: find out which tools staff are reaching for, why, and provide approved alternatives with proper privacy controls. Review any new AI tool before accounts are created.

Tell staff: “We’re not stopping you using AI. We’re making sure you use the right AI for healthcare.”

3. Hallucinations in a clinical setting

AI can sound confident and still be wrong. A hallucination might be a medication that doesn’t exist, a fabricated guideline citation, an incorrect translated dose, a scribed consult containing words never spoken, or a wrong ICD-10 or MBS item.

This is not theoretical. In late 2024, AP News reported research showing OpenAI’s Whisper model, used in many medical transcription tools, was producing hallucinations in clinical contexts, inventing words never spoken. AI is a confidence machine, not a truth machine.

If a clinical scribe, summariser, or chatbot helps produce letters, notes, or patient instructions, a clinician must review the output before it touches the record. Every time.

4. AI phishing and fake healthcare tools

Cyber criminals follow attention, and attention is on healthcare

AI. Expect fake “medical AI”

platforms, fake CPD modules, fake browser extensions, and fake login pages for scribing or PMS tools. A staff member clicks a sponsored result, signs in with practice credentials, and hands access to an attacker. Under the Notifiable Data Breaches scheme, one compromised account can become reportable.

Practical defences: MFA everywhere, single sign-on where possible, an approved app list, browser protection, healthcarespecific phishing training, and a practice-wide password manager. Not glamorous work. Effective work.

5. Agentic AI: when AI starts doing things in your practice

Agentic AI doesn’t just answer questions, it takes actions. In a clinic that may include sending patient SMS, drafting referrals into the PMS, updating notes, booking appointments, or producing billing items. Powerful, but one bad instruction can cause real damage.

Safe agentic AI needs read-only permissions by default, clinician approval before any record write or message send, activity logging tied to a named human, sandbox testing, and a human-in-the-loop for anything touching the patient. No AI should bulk message patients, alter clinical notes, or push to billing without a human clicking approve

6. Vendor risk and the AI Bill of Materials

Many platforms include AI features quietly, PMS, billing, telehealth, and patient-comms tools your practice already uses. The question becomes: what AI is sitting under the hood, and where is it processing patient data?

Ask vendors which AI models they use, where data is processed and stored, whether it is used to train models, which third parties can access it, what certifications they hold (ISO 27001, SOC 2, IRAP), and whether they meet APP 8 cross-border requirements.

Record the answers in an AI Bill of Materials (AI-BOM), like an ingredients list on a medication label. It tracks which AI tools are touching patient data across your practice, and doubles as evidence of due diligence under APP 11 if the OAIC ever asks. Start as a simple spreadsheet like the example on the next page.

How Databox helps secure AI in your practice

Databox works with practices that want the gains of AI without putting patient data, AHPRA registration, or Medicare standing at risk. Services include AI tool reviews, approved software setup, Microsoft 365 Copilot readiness, clinical scribe selection, identity controls, MFA, Shadow AI discovery, role-specific staff training, Acceptable Use Policy creation aligned to APP 11 and the RACGP Standards, AIBOM creation, breach response planning, and backup for AIconnected systems.

We translate technical and regulatory risk into plain English. If a busy clinic team doesn’t understand a rule, they won’t follow it.

The “Safety First” 10-step AI plan for clinic staff

This section is written to be shared directly with staff.

1. Stop the copy-paste habit

Never paste patient names, Medicare numbers, clinical notes, or practice documents into an unapproved AI tool. Treat the prompt box like a public noticeboard.

2. Use the front door only

Only use AI tools approved by the practice. Found a useful new one? Flag it with the practice manager before creating an account.

3. Pay the fact-check tax AI can be wrong while sounding certain. Check medications, doses, drug interactions, citations, and MBS item numbers. Always.

4. No ghost-writing without ownership

If AI helps draft a referral, summary, or note, the person who signs it owns it. Read it. Edit it. Sign it.

5. Be transparent when needed For AI-assisted documents, add a short note: “Drafted with AI assistance, reviewed and edited by [Your Name].” For consults, tell the patient and document consent.

6. Protect your login

Never share your AI account or PMS login. AI tools may store chat history and clinical context — far more than you expect.

7. Watch for fake links

AI can generate links that look real but go somewhere unsafe. Hover before clicking. Check the domain. When unsure, type the address yourself.

8. Report weird AI behaviour

If an AI tool gives strange answers, changes tone, or produces clinical content that looks off, report it. Don’t shrug it off.

9. Keep it professional Don’t vent about colleagues, patients, or private practice matters into AI tools. That data

may be stored, reviewed, or exposed later.

10. Humans decide

AI can recommend. AI can draft. Humans approve. Never allow AI to auto-send, auto-publish, or auto-update anything that affects a patient, a record, or a Medicare claim.

When AI goes wrong: real-world lessons that hit close to home

AI risk isn’t just a hospitalnetwork problem. Smaller clinics, allied health, dental, specialist, and telehealth providers are exposed.

A record-breaking Privacy Act fine

In October 2025, the Federal Court imposed a $5.8 million civil penalty on Australian Clinical Labs, the largest ever under the Privacy Act, over a 2022 ransomware breach exposing more than 223,000 individuals’ personal information. A breach is no longer just a clinical and reputational risk; it now carries serious financial consequences under the same Act that governs

every patient record in your system.

A clinic loses 700 GB of patient data

In 2025, ransomware group Termite breached IVF provider Genea and exfiltrated ~700 GB of patient data: medical history, diagnoses, pathology, insurance details. Spectrum Medical Imaging and Epworth Healthcare were hit too. Every added tool is another door.

AI scribes show up in court

In 2026, US health system Sharp HealthCare was sued over its use of AI scribe technology and patient consent, a sign that “we’ll sort the consent piece later” is now actively being litigated. Clinical researchers have documented real harms, including a transcription that recorded “no vascular flow” instead of “normal vascular flow”, triggering an unnecessary procedure, plus higher error rates for patients with non-standard accents or limited English proficiency. Columbia School of Nursing warned in late 2025 that AI scribe adoption is outpacing safety evidence.

For practices using AI scribes: document consent every consult; have a clinician review every AIgenerated note before it touches the record, test the tool with the population you actually serve, treat AI documentation as a draft, not a record.

Sources: OAIC v Australian Clinical Labs (Hogan Lovells, October 2025); Genea ransomware incident (The Record, 2025); Sharp HealthCare AI scribe lawsuit (Medscape, 2026); Columbia School of Nursing — AI scribes patient safety warning (October

2025)

So, should practices slow down on AI?

Not exactly. AI helps practices write referrals faster, summarise consults, reduce admin drag, and free clinicians to spend more time with patients.

The smarter question: how do we use AI in healthcare without putting patient data, regulatory standing, or clinical safety at risk?

Safe AI starts with knowing what your team is using, setting clear rules, and keeping humans in charge. Databox Health helps practices build that environment, no theatre, just clear policy, strong controls, and training people will actually use.

Contact Databox Solutions Today: 1300 603 505.

What your online presence reveals when enquiries begin to change

At HeartBeat Digital, we’re increasingly finding that changes in patient enquiries are not just about demand.

In the current economic climate, they often reflect shifts in how people search, compare and decide.

Take a common scenario: a patient searches for a service, opens three or four practice websites, checks reviews, and leaves without making contact. No call. No form submission. From the practice’s side, it looks like lower demand, but actually the decision was made elsewhere.

This behaviour is happening constantly. In Australia, search engines still dominate how people find healthcare providers, even as AI tools grow in earlystage research.

By looking closely at your digital channels and their data, it becomes possible to interpret these changes and understand what they’re signalling about visibility, messaging and patient intent.

In this article, we discuss

1. How patients search, compare and decide across AI and Google, plus the common types of searches to know

2. How patient behaviour is shifting

3. How financial pressure is shaping decisions and budgets

4. What this reveals about demand and visibility

5. Whether pausing digital activity is costing more than it saves

Firstly, know how patients search and decide online

Not all search and digital channels serve the same purpose. Patients move between them depending on where they are in their decision-making.

○ Search engines (Google)

Used for high-intent actions. Patients are looking to find, compare and choose a provider.

Example: “GP near me open Saturday”

○ AI tools (ChatGPT and similar)

Used for early stage understanding. Patients explore symptoms, treatment options or general advice before narrowing their search.

Example: “What are the treatment options for knee pain?”

○ Social media

Used for familiarity and reassurance. Patients may check activity, tone and credibility rather than actively search for a provider.

Example: Looking at recent posts or patient interactions

The types of searches are also interesting to know:

Most online search behaviour falls into a few key categories: Informational

Learning or understanding a condition, which is a common use for AI

Example: “What causes migraines?”

Commercial

Comparing options before choosing

Example: “Best physiotherapist in Adelaide”

Navigational

Looking for a specific practice

Example: “Smith Street Medical Centre”

Transactional (most valuable)

Ready to take action

Example: “Book dentist appointment near me”

What exactly is changing?

One of the more consistent patterns we are seeing is this: patient behaviour becomes more deliberate when financial pressure increases, but not necessarily more forgiving.

In previous tightening cycles, including during COVID and periods of rising cost-of-living pressure, two things tended to happen online:

○ Patients compared options more carefully before choosing

○ At the same time, they were quicker to leave when something didn’t meet expectations

For example, a patient may open several practice websites, scan quickly for availability, pricing signals or clarity of service, and exit just as quickly if something feels unclear or outdated. They may compare more, but they are less likely to invest time in “figuring it out”.

This is where digital performance becomes more sensitive.

A website that loads slowly, lacks clear calls to action, or feels outdated does not just underperform, it actively pushes patients toward alternatives.

Hint: A call to action (CTA) is a prompt that tells users what to do next, such as a “Read More” or “Book Appointment” button.

As we’ve seen in our audits, many sites still miss core conversion fundamentals like mobile usability, clear next steps (a big one) and trust signals.

What looks like reduced demand is often a shift in where and how decisions are being made.

We explain this in more detail in our article ‘Your Website Is Quietly Costing You Customers. Here’s How to Fix It’ and invite the AAPM community to take a look.

What your digital presence may be signalling

When enquiries begin to change, your digital presence often holds the explanation.

Visibility gaps

If SEO is not actively maintained, or if your Google Business Profile is under-optimised, you may simply be appearing less often in relevant searches. Google explains this in detail themselves here

A helpful starting point is to review what your practice currently ranks for. If you are unsure, this guide may help.

Messaging misalignment

Patients scanning multiple options are not reading deeply. They are looking for clarity.

If your website or landing pages do not quickly answer key questions such as services, availability, location or pricing expectations, you may be losing

attention early.

This is particularly relevant for commercial searches, where patients are actively comparing.

Outdated or inconsistent signals

An inactive news section, outdated service pages or inconsistent messaging across channels can introduce hesitation. We covered this in more detail here

The aim is maintaining a sense of relevance and accuracy, certainly not just pumping out content for content’s sake.

Conversion friction

Even when visibility and messaging are strong, small usability issues can affect outcomes.

Slow load times, unclear navigation, mixed messaging, or complex booking processes create friction. In a more selective market, that friction matters more.

Budgets and pausing efforts

Budgets are under closer scrutiny, with spending being zoomed in on. This often becomes more apparent as we close in on EOFY. At the same time, patient behaviour is becoming more selective.

Reducing visibility while patients are more deliberate can amplify even small drops in activity.

Digital marketing is not only about immediate returns. It also builds familiarity, trust and recall, often influencing decisions without being directly measured.

It’s something marketers are always telling accountants: it goes much further than ROI on a spreadsheet.

If budgets are being reassessed, focus on efficiency rather than absence. What is working, what is not, and what needs refining.

We discuss mothballing digital marketing in depth in our article, ‘What Happens When You Pause Your Digital Marketing’

A final thought Most practices already offer what patients are looking for: high quality healthcare services.

The challenge is ensuring your digital presence reflects that clearly and consistently at the right moment.

Since 2019, we’ve worked with healthcare practices across Australia to align those signals. When taking on new healthcare clients, looking at existing data, even if management doesn’t actively record it (it’s available with the right tools), always results in sharpened campaigns. If enquiries are shifting, it may be worth taking a closer look before assuming demand has disappeared.

If you’d like a professional set of eyes on your digital presence, you’re welcome to book a nopressure chat with Lachlan McPherson here. The goal of these chats is to discuss what’s working, and what’s not, and goals and reasons around them.

A note from Lachlan

I started HeartBeat Digital after seeing how many healthcare practices were being left behind online, not because they lacked quality, but because digital marketing felt out of reach or overly complex.

I’ve always believed it shouldn’t be that way. Digital marketing is one of the most powerful and well-aimed tools a business can use, and it should be accessible, practical and backed by real support.

What we enjoy most is helping practices make sense of what’s already happening in their data, and turning that into something clear, measurable and effective, while educating them along the way.

If you’re curious about how your current setup is performing, or where opportunities might sit, or be wasted, I’m always happy to have a conversation.

Lachlan McPherson

These unwelcome events can be stressful and costly, for you and your practice.

Avant Practice Medical Indemnity Insurance with Cyber Insurance

With Avant Practice Insurance, you’re covered for the actions of staff and claims made against the practice. And for eligible practices, we include Cyber Insurance to help protect your practice against cyber extortion, privacy liabilities and damage to digital assets.

Protection for your practice and staff avant.org.au/practiceinsurance 1800 128 268

When families get involved: who can you speak to?

Jenny calls her General Practice (GP) about a text message she received asking her to contact the practice for results. Jenny is a regular patient but is confused because she isn’t waiting on any results

The receptionist checks and explains the message is for Jenny’s 15-year-old daughter, Ava. Her patient record has Jenny’s number as the contact. Jenny says she knew nothing about it. She is asking whether her ex-husband attended the appointment with Ava and wants to know what it was for. She is insisting she has a right to know about her child’s health.

A practical way to approach it

This is a common enough scenario that can easily turn into a privacy breach.

Family relationships can be complex, especially as they’re evolving. Teenagers’ growing independence, parental separations, or older relatives’ care needs can raise questions about when it is appropriate to share patient information.

A patient may have someone support them with their health care, for example attending a consultation with them or helping them access information. However, this does not mean that person is entitled to access information about the patient’s care. There are some general principles that can help guide you on how to approach these

situations:

○ You owe patients a duty to keep their information confidential.

○ Patients can consent to their information being shared with others. If a patient is happy for someone else to be involved, this should be discussed and clearly documented, rather than assumed.

○ If a patient has capacity to make decisions about their own care, they can also decide who can and can’t access their information (subject to some exceptions).

○ Capacity is a clinical question determined by the treating doctor and applies to the specific decision being made. This means a patient can have capacity for one aspect of their care but not others.

○ When in doubt, do not disclose any information. It is always safer to pause, check the record, and escalate if needed. It may be necessary to check with the patient that they are happy for their information to be shared.

Teenagers and young people

Parents arrange and attend consultations and make treatment decisions when children are young. Staff may then become used to communicating with parents about their child’s care. As young people mature, they develop the ability to make decisions about their own care and about who can access their

health information (subject to limited exceptions in privacy legislation). This transition phase is a common context for privacy breaches, especially as staff may feel pressure to respond if a parent insists, or assume a parent is entitled to the information.

It is good practice to develop a consistent approach and ensure staff are trained appropriately.

As a young person matures, staff, the doctor or nurse should confirm with them which contact details they would like on their file. Clarify which phone number they would like appointment reminders sent to, and whether this is also the appropriate contact number for the doctor to use if follow-up is needed.

If a parent asks for information about a consultation that a young person attended alone, develop a standard response along the lines of:

“I understand you are concerned, however, as your child is getting older and to ensure we are protecting their privacy, we need to confirm what information we can share with you. Once we’ve done that, I will call you back to let you know the next steps.”

This allows time to pause to check the patient record, and/or check with the doctor involved. It helps avoid making assumptions about what information can be shared.

The conversations and the scope of any information shared should be documented in the patient’s file.

Separated parents and access to health information

Requests from separated parents can also become complex, particularly where there is a

disagreement.

Separated parents may still share responsibility for healthcare decisions. However, court orders, parenting arrangements, or other legal factors may affect who can access information or make decisions.

Inappropriately disclosing information may not only lead to privacy complaints. It could provoke disputes or even put patients at risk, for example if there are issues of family violence.

Again, taking a consistent approach to requests for information can create an opportunity to check and avoid accidentally disclosing information without appropriate consent.

In this scenario, if Ava had capacity to decide about her treatment at the appointment, she can also decide what information to release to her parents.

Even if Ava attended with her father, she may still have had the capacity to make her own treatment decisions and decide what information, if any, could be shared with her parents. This should have been discussed with the doctor and documented in the notes for that consultation.

If Ava doesn’t have capacity for the relevant treatment, one or both parents may need to be consulted. In that case staff should review the patients file, ask whether any Family Court orders exist and request a copy if relevant, and check with Ava’s doctor for guidance.

Adult children and elderly patients Caring for older patients may also raise potential privacy concerns.

Consider the scenario if Jenny’s call was about her elderly father’s treatment instead.

As older patients increasingly rely on support for their care, family members may attend appointments, manage medications and communicate regularly with your practice. Over time, staff may begin to treat them as the default point of contact. The risk is when this becomes automatic.

If a patient has decisionmaking capacity, they also can decide who has access to their information. If they agree to share information with family members, make sure this is clearly documented in their patient file. Ensure staff routinely check the file before disclosing any personal information. This reduces the risk of inadvertent privacy breaches. It also allows staff to escalate any situations where capacity is uncertain or impaired. These may require clinical input and need to be managed carefully, rather than handled at the front desk.

Tips for your practice

Privacy issues in practice often arise from everyday interactions where staff are trying to be helpful and responsive.

Follow these tips to help avoid situations where staff might make assumptions or rely on instinct:

○ Develop clear guidance and a consistent process to manage requests for information from family members.

○ Include standard wording staff can use to reduce the likelihood of inappropriate disclosure.

○ Always confirm and document consent to disclose personal information – in the notes for

the relevant consultation or if it’s broad consent, in the practice management file. Develop a process to keep this updated.

○ Make sure any concerns or restrictions such as parenting orders are clearly flagged.

○ Train your front desk team how to respond to common scenarios, particularly over the phone.

○ Encourage staff to escalate situations they are unsure about.

○ In complex situations, seek guidance from your medical indemnity insurer.

References and resources

Recommendations for patient communication via telephone and text message

Children and consent

Consent and the mature minor patient

Gillick and Marion’s case

Separated parents

Children’s care and separated parents

Implied consent or breach of privacy?

Avant for practices

PracticeHub

Quality, compliance, staff readiness and peace of mind – simply and seamlessly in one digital platform.

Designed for GPs, specialists and other healthcare practices.

From only $1,188 per year, get started with PracticeHub today to:

9 Streamline compliance

9 Simplify risk management

9 Reduce admin

Start your 15-day free trial* today or visit our website

9 Access RACGP accreditation support. Join practices across the country already saving time and staying ahead of regulatory obligations with PracticeHub. Avant for practices

Speak with our team to learn more 1800 010 236 | practicesolutions@avant.org.au

From insight to impact: Utilising data for continuous quality improvement in general practice

Continuous Quality improvement (CQI) is already embedded in everyday general practice, shaped by ongoing observation reflection and action. What’s changing is the expectation that these activities are clearly demonstrated, with data used to support both the rationale for change and achieved outcomes.

Across healthcare, there is an increasing focus on personcentred, value-based and datainformed care, where quality is demonstrated through measurable impact and patient experience. This approach has also been reflected in the RACGP Standards 6th edition.

Emerging themes within the 6th edition Standards show a stronger emphasis on demonstrating the rationale behind CQI activities and results. In this environment, data becomes a central part that drives how practices understand performance, prioritise areas of improvement, and evidence change over time.

It becomes important for practices to understand how they can move from data insight to impact, using practical approaches to embed data into everyday CQI processes.

In this article we unpack the role of data in general practice and how to utilise it to create greater impact for your patients and practice alike.

The growing role of data in continuous quality improvement

General practice operates in a busy and evolving environment, with greater demand for services, changing patient needs and ongoing pressure to deliver timely, accessible care. These factors are contributing to a stronger focus on understanding performance and demonstrating results.

Data plays a critical role as it enables practices to:

○ Understand current performance

○ Identify priority areas for improvement

○ Monitor trends over time, and

○ Demonstrate improvement.

This reflects a shift in how quality is understood and demonstrated in healthcare, with increasing emphasis on outcomes, patient experience and continuous improvement. Data plays a key role in supporting these areas, providing evidence to understand performance and guide decisionmaking.

For general practice teams, this means moving from simply collecting data to actively interpreting and applying it in ways that inform decision-making and improvement.

Understanding emerging expectations in the RACGP Standards

The RACGP Standards 6th edition indicates a stronger focus on demonstrating how

improvement activities are planned, implemented and evaluated over time. There is also increasing integration of consumer expectation statements across the Standards, reinforcing the importance of incorporating patient perspectives into improvement processes.

Practices are expected to utilise a range of data sources such as clinical data, operational information and patient feedback to inform activities and assess their impact. Patient experience data, including Patient Reported Experience Measures (PREMs), is becoming increasingly important in this context, as it provides insight into how care is experienced and what matters most to patients.

While there are no specific tools or methods, practices are expected to interpret and apply data across the improvement process. This represents a change, as it is expected that practices demonstrate how improvement activities are informed and evaluated, supported by data and patient feedback.

Identifying and using key data sources

General practices have access to a wide range of data which can support continuous quality improvement. This includes clinical data, practice performance and operational data, and patient experience and feedback data captured in Patient Reported Experience Measures (PREMs).

Each data source can provide a different perspective. Clinical data can provide insight into care delivery and outcomes, while operational data reflects how the practice is functioning and patient experience data provides insight into how care is experienced, including systems, communication and access.

Patient feedback is critical, as it helps practices understand variations in care, identify opportunities for improvement, evaluate the effectiveness of changes and demonstrate outcomes for accreditation. It also supports a more patientcentred approach, ensuring that improvement activities reflect what matters most to patients.

A more structured approach to collecting and using patient feedback can strengthen how that information is applied. It supports practices to capture representative feedback, generate meaningful insights and identify trends as they emerge. Approaches that combine point-in-time feedback with more regular insights, can further support practices to monitor patient experience more consistently and use that data to inform improvement and demonstrate changes in care delivery.

Bringing these data sources together supports a more informed and structured approach to CQI, helping practices move from collecting data to using it to guide actions and showcase impact.

Using data across the continuous quality improvement cycle

CQI is already a part of general practice with increasing focus on how this work is supported and demonstrated using data.

The Plan-Do-Study-Act (PDSA) cycle remains one of the most recognised approaches to

continuous quality improvement. Within this cycle, data plays an important role across each stage, helping to identify where to focus, supporting the changes being introduced and reviewing whether those changes are making a difference. It also informs decisions about what to refine or adjust over time.

Using data in this way helps shift it from being simply collected to being actively used to guide improvement.

For example, a practice may identify through clinical data that cervical screening participation rates are lower than expected among eligible patients aged 25–49 years. Baseline data can be extracted to understand current participation rates and identify gaps in recall systems. The practice may then implement a targeted SMS reminder process and provide staff education around opportunistic screening discussions. Follow-up data over several months can be used to assess whether participation rates improve, while patient feedback may provide insight into whether communication and access arrangements supported engagement. This information can then be used to demonstrate the rationale for change, actions undertaken and measurable outcomes achieved through the CQI process.

This enables practices to demonstrate why a change was introduced, what was done and what impact it had.

Demonstrating improvement for accreditation

As accreditation continues to evolve, practices are increasingly required to demonstrate how continuous quality improvement activities are informed, implemented and evaluated. This includes showing why a change was made, what was done and what impact it had.

Data plays an important role in supporting this, helping practices demonstrate change, performance and results. Patient feedback is also an important part of this evidence, contributing to identifying areas for improvement, and demonstrating how changes are experienced in practice.

Clear documentation, supported by data, helps practices present a consistent and credible picture of improvement, supporting both accreditation and ongoing development.

Using data to support and demonstrate impact

Data on its own does not drive improvement, it becomes valuable when it’s used to inform decisions, guide action and demonstrate outcomes.

By using data consistently across CQI activities, practices can strengthen how they plan, implement and evaluate change. This also supports a more structured and transparent approach to continuous quality improvement, where outcomes and impact are demonstrated over time.

Practices that build confidence in using data in this way will be well positioned to meet accreditation expectations, being equipped to deliver care that is responsive, evidence-based and centres on patient needs.

Moving from insight to impact focuses on using existing data more effectively to support improvement, demonstrate outcomes and strengthen the quality of care.

For any queries or personalised accreditation support, contact our team via: P: 1300 362 111 E: info@agpal.com.au

Accreditation support, backed by real people

At AGPAL, we believe accreditation provides a strong foundation for continuous quality improvement, helping practices strengthen systems, elevate patient experience and support safe, high-quality care.

With a dedicated Client Liaison Team by your side, your practice will have access to personalised support and guidance as you prepare for the RACGP 6th edition Standards.

As the exclusive provider involved in piloting the new Standards, AGPAL has gained valuable insight into how the 6th edition is applied in practice. We’re here to share that knowledge and support practices as they move confidently into the next chapter of accreditation.

Keep an eye on your AGPAL client communications and follow us on social media for:

• 6th edition insights and transition updates

• Accreditation tips and guidance

• Quality improvement resources

• Webinars and new client offerings

• Industry news and updates

The AGPAL team is always here to support you throughout your accreditation journey at no additional cost - it’s all part of the service. Contact them via the details below:

362 111 info@agpal.com.au

Leading IT Services for Medical Practices

Calls to the DMS helpdesk are answered literally within seconds, most issues are resolved within minutes.

Guaranteed Level 2 or Level 3 technicians with extensive experience in Australian medical software problem resolution.

Extensive experience and expertise in Australian medical software ecosystems.

87% of helpdesk calls resolved on the same day.

81% of helpdesk calls resolved on the first call.

Managed Cyber Security expertise. Security first approach with Cyber Security qualified staff.

Proactive Managed IT that is fully customised for Australian medical clinics, with high attention to detail.

DMS Private Cloud located in Melbourne and Sydney at leading Tier 4 data centres with latest high performance, and high capacity host servers.

“We have been very pleased with the IT support provided by DMS IT. We highly recommend their services to any healthcare organisation seeking reliable and efficient IT support.”

Cyber Risk in 2026: Part 2: Cyber

Security and Privacy Compliance Assessments

Healthcare Practice Managers and directors have been alerted to the enforcement of cyber security and privacy compliance legal obligations in recent Federal Court judgements that have imposed significant penalties against organisations for cyber security and privacy breach failures.

ASIC, the regulator of the Corporations Act 2001(Cth), and the OAIC, (AIC, the Privacy Commissioner), the regulator of the Privacy Act 1988 (Cth), have both obtained judgements in the Federal Courts which will likely be reference cases for any future court action for cyber security and privacy non-compliance. 1

In the healthcare data breach case, AIC v Australian Clinical Labs Limited (ACL) (2025), after 86 gigabytes of health data of more than 223,000 individuals was published on the Dark Web by cyber criminals, ACL was penalised $5,800,000 for contraventions of the Privacy Act, plus $400,000 for the AIC’s legal costs.

This is a landmark case with the first civil penalties imposed under the Privacy Act. 2

Australian healthcare practices deliver care in a cyber threat environment where cyber attacks and incidents are common, disruptive and increasingly aimed at healthcare. Every year since the introduction of the Notifiable Data Breach Scheme in 2018 under the Privacy Act,

the OAIC has reported that the healthcare sector is the highest sector reporting Notifiable Data Breaches.

Even when a practice is not specifically targeted, cyber attackers routinely succeed by finding and exploiting vulnerabilities, using repeatable weaknesses: unpatched systems, exposed remote access, weak authentication, and recoverability gaps.

Ensuring the continuing cyber security and the privacy of Personally Identifiable Information (PII) and Protected Health Information (PHI) held by Australian healthcare providers is not just about managing and mitigating operational risks, i.e., clinical safety, and business continuity, but also about meeting Privacy Act and Corporations Act compliance and obligations. (and My Health records Act 2012 (Cth), etc.

The Privacy Act 1988 (Cth) includes 13 mandatory Australian Privacy Principles (APPs) which apply to all organisations known as APP entities.

Healthcare organisations are APP entities.

APP 11 requires APP entities to take “active measures” and “reasonable steps” to protect personal information, including health information;

a. from misuse, interference, loss; and

b. unauthorised access, modification or disclosure.

It is crucial for practice managers and directors to understand the key details of the APP requirements in order to be in alignment with them. The OAIC has published the Australian Privacy Principles guidelines, which are a good resource to clarify the Act requirements and provide us with clearly understandable descriptions and examples on what are considered ‘reasonable steps’.

For example, the guidelines in APP 11.9 summarises what is expected; 3

“11.9 In all cases, reasonable steps should include taking steps and implementing strategies in relation to the following:

○ governance, culture and training

○ internal policies, procedures and systems

○ ICT security

○ access security

○ third party providers (including cloud computing)

○ data breaches

○ physical security

○ destruction and deidentification, and

○ standards.

APP 11.10 through to APP 11.15, reproduced below, explain in more detail and nuance;

“11.10 The reasonable steps an APP entity must take for the purposes of ensuring the security of personal information include both technical and organisational measures

11.11 Technical and organisational measures work together within a broader

organisational framework to protect personal information and mitigate information security and cyber security risks.

11.12 Technical measures include protecting personal information by implementing technological controls and physical measures relating to software and hardware. Examples of technical measures may include (but are not limited to) securing access to premises, encrypting data, anti-virus software and strong passwords.

11.13 Organisational measures involve implementing policies, processes and procedures to protect the security of information. Examples of organisational measures may include (but are not limited to) staff training on privacy and security obligations, developing standard operating procedures and policies for securing personal information.

11.14 Some steps may encompass a combination of technical and organisational aspects, as technical and organisational measures complement each other and overlap. For example, physical security measures such as security systems, alarms or keycards are technical measures as they involve restricting physical access to personal information. These physical security measures can also be organisational measures where there are policies, procedures and practices for managing how staff access and use physical spaces and information assets.

11.15 As part of taking reasonable steps to protect personal information (also known as ‘personal information

security’) an APP entity should implement technical and organisational measures, using a layered approach to avoid a single point of failure.”4

Note the key steps of

○ ‘governance, culture and training’, which includes ‘internal policies, procedures and systems’,

○ “technical and organisational measures”, and

○ using “a layered approach to avoid a single point of failure”.

AI and privacy compliance

the current APP guidelines do not mention AI risks, however, the OAIC has issued guidance on privacy and using AI products, noting that:

“Privacy obligations will apply to any personal information input into an AI system, as well as the output data generated by AI (where it contains personal information).” 5

So how can a practice manager know that the clinic’s information systems and sensitive data security and privacy comply with the APP 11 reasonable steps requirements?

The start point is by conducting cyber security assessments measured against an appropriate security “standard” as referred to in APP 11.9 above.

Examples of standards include:

○ ISO 27001 Information Security Management System (ISMS)6 , (93 controls)

○ ISO 42001 AI Management System (AIMS)7, (38 controls)

○ RACGP Standards for General Practice 5th Edition 8 , which include Information Management requirements

(Core Standard 6) - familiar to practice managers of GP clinics

Organisations can obtain certification against the ISO 27001 and ISO 42001 standards which are recognised worldwide. GP clinics in Australia are accredited against the RACGP Standards for General Practice 5th Edition.

The Australian Signals Directorate (ASD) has recommended the Essential Eight Maturity Model Strategies to mitigate cybersecurity incidents9

There are also cyber security guidelines such as the ISO 31000 Risk Management guidelines10 , and ‘frameworks’, such as the US National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF) 2.011 , which are not international “standards” as such, but are widely used world wide. The NIST CSF 2.0 refers to ISO standards. Security guidelines and frameworks are practically interchangeable with standards for our purposes. Following the comprehensive NIST CSF 2.0 Framework would stand up to scrutiny by regulators in Australia.

For this article we will focus on the ASD Essential Eight Maturity Model as an appropriately effective security ‘standard’ for Australian primary healthcare clinics.

The ASD Essential Eight has four Maturity Levels:

NoteControls are cumulative to the next Maturity Level

Threat mitigation effectiveness Vulnerable to commoditylevel threats with weaknesses in the overall mitigation strategy exist that adversaries could exploit.

Basic cyber hygiene in place. Mitigates adversaries who use widely available attack tools and techniques, such as script kiddies and ransomware groups.

More sophisticated controls in place. Adversaries who invest time in research and tailored exploits are significantly impeded. Appropriate for most healthcare organisations. Hardened environment providing robust protection. Addresses adversaries including advanced persistent threats (APTs) and nationstate actors targeting Australian organisations.

The ASD Essential Eight strategies are named after the following mitigations:

1. Patch applications

2. Patch operating systems

3. Multi-factor authentication (MFA) 4. Restrict administrative privileges

5. Application control

6. Restrict Microsoft Office macro settings

7. User application hardening

8. Regular backups

Organisations are expected to select a target maturity and progressively implement controls, aiming for a consistent maturity level across all eight strategies within that target maturity level (i.e., not “ML2 in one place, ML0 in another, ML1 in another”).

Aiming for ML3 at the start is a big ask – aim for ML1, then ML2, then if appropriate, ML3. Note that the ASD Essential Eight is a minimum set of preventative measures, and ASD notes that additional measures may be warranted depending on your environment.

For primary healthcare practices, the immediate goal is a defensible baseline of cyber security by achieving Maturity Level One (ML1) across all Essential Eight strategies against which to assess the organisation, then uplift to Maturity Level Two (ML2) as part of the continuous improvement process

A standards-based approach helps practices move from ad hoc IT and cyber security decisions to defensible risk management.

A good continuous improvement process to follow is to follow the Plan Do Check ACT (PDCA) cycle:

(here going anti-clockwise from Plan at the top).

A security assessment needs to:

1. Establish the current security state, i.e., the baseline - what is implemented and how effectively

2. Define the desired state, i.e., - Essential Eight ML1 requirements, and APP 11 “reasonable steps”

3. Develop and produce a prioritised mitigation plan aligned to the desired state, i.e., - Essential Eight ML1 and APP 11 with effective controls, owners, timelines, documentary evidence.

What is important in any management system is the process. Engage qualified cyber security experts to assist you in the process.

Following the ten (10) practical steps below will result in achieving the desired state of Essential Eight ML1 plus APP 11 “reasonable steps:

Step 1 — Define scope: what IT systems, data and suppliers are in your “practice environment”

A cyber security assessment will fail if scope is vague. Start by listing everything

in your “practice IT and data environment” including Personal Identifiable Information (PII) and Protected Health Information (PHI) data, i.e.; clinical information system, Practice management system, integrated pathology/imaging services, email and collaboration, secure messaging, remote access, servers, PCs, laptops endpoints, Wi- Fi, routers/firewalls, network devices, data backup repositories, cloud storage, etc. Third-party service providers are also in scope- privacy and cyber security responsibilities extend across the practice supply chain.

Step 2 — Gather evidence: cyber assessments are “evidencebased,” not opinion or verbal assurance based

Assessments should be backed up with credible evidence with documented information, i.e., policies, Incident Response Plan, system configurations, screenshots for MFA and conditional access settings, logs, patch reports, vulnerability assessments reports, application controls, backup job and test restore reports, privileged access settings, change management records, user Security Awareness Training (SAT) records., etc.

Step 3 — Establish the “current state” (baseline): rate each Essential Eight control at ML0 or ML1

Ask your IT provider for a short “ML1 evidence pack” for each control (1–2 pages each), rather than a generic security statement. The actual details matter.

Step 4 — Define the “desired state”: in this case ML1 across all Essential Eight mitigations plus APP 11 “reasonable steps”

Figure 1: PDCA cycle for cyber security assessment and uplift (adapted for healthcare practice)

The desired state should be all Essential Eight strategies at ML1 with no “weakest link” controls left at ML0.

Step 5 — Conduct a gap analysis: where ML0 state persists and where APP 11 risk is highest

A good gap analysis is not just “missing controls.” It connects gaps to:

○ Threat likelihood i.e., ransomware, credential theft, phishing, Business Email Compromise (BEC), insider threat, etc.

○ Business impact (patient care disruption, safety risk, claims interruption)

○ Privacy harm (sensitivity of health data, potential serious harm)

Step 6 — Build the mitigation plan: “controls uplift” with owners, timelines, and evidence artefacts

A mitigation plan should read like a delivery roadmap. Include the following:

○ What will change? (control uplift)

○ Who owns it? (practice manager, lead GP, IT provider, third party vendor)

○ When will it be done? (target dates)

○ How you will prove it? (evidence artefacts and test results)

○ Residual risk and any accepted exceptions? (documented with reasons)

Step 7 — Map controls to Essential Eight ML1 and APP 11: show how your uplift plan equals Essential Eight ML1 plus APP 11 “reasonable steps”

Deliverable: a one-page “APP 11 Security Controls Statement” that references your Essential Eight maturity results, policies, and evidence artefacts.

Step 8 — Add breach readiness: include consideration of Notifiable Data Breaches (NDB) capability in your cyber security assessment - Even with ML1 controls, breaches can occur. Practices need the ability to detect, assess, and respond.

Step 9 — Governance and reporting: what your final assessment pack should contain

A professional cyber assessment for a general practice should produce a pack you can use for:

○ practice governance and risk management

○ practice accreditation and assurance

○ privacy compliance evidence

○ cyber insurance and vendor negotiations

Step 10 — Make it an ongoing cycle of continuous improvement: follow the PDCA cycle

ASD notes that Essential Eight Maturity Levels are designed to be implemented progressively and reviewed, with exceptions documented and revisited.

A cyber security assessment that satisfies both Essential Eight ML1 and APP 11 obligations is not a one-off IT report. It is a structured program that develops into a continuous cycle of cyber security:

○ starts with clear scope and evidence,

○ sets ML1 as a measurable desired state,

○ connects Essential Eight uplift

to APP 11 “reasonable steps,” with

○ governance artefacts and breach-readiness capability

For Practice Managers, the key success factor is insisting on documented evidence and accountability: who owns each control, how it is validated, and how it is maintained.

Practice Managers following the above steps will create the “minimum cyber security and privacy uplift” that mitigates against cyber threats and stands up to scrutiny from the regulators in the unfortunate event the practice is hacked and is then subject to a forensic investigation that could lead to legal consequences. Implementing and maintaining effective standards based cyber security is not inexpensive – however, only having an anti-virus product on PCs will not stand up to scrutiny. Failing cyber security and privacy obligations could have very, very, expensive consequences…

Be cyber safe. More to come…

References

1 AAPM The Practice Manager, Issue 1 March 2026, Cyber Risk in 2026: Part 1 – Be Prepared, page 26

2 FCA, (2025)., Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224, retrieved from https://www.judgments. fedcourt.gov.au/judgments/Judgments/fca/ single/2025/2025fca1224

3 OAIC, (2025), Chapter 11: APP 11 Security of personal information, retrieved from https://www.oaic.gov.au/privacy/ australian-privacy-principles/australianprivacy-principles-guidelines/chapter-11app-11-security-of-personal-information

4 ibid.

5 OAIC, (2025)., Guidance on privacy and the use of commercially available AI products, retrieved from https://www.oaic.gov.au/privacy/ privacy-guidance-for-organisations-andgovernment-agencies/guidance-on-privacyand-the-use-of-commercially-available-aiproducts

6 Standards.org.au, (2023)., AS/ NZS ISO/IEC 27001:2023 Information security, cybersecurity and privacy protection — Information security management systems — Requirements, retrieved from https://store.standards.org. au/product/as-nzs-iso-iec-27001-2023

7 Standards.org.au, (2023)., AS ISO/IEC 42001:2023 Information technology - Artificial intelligenceManagement system, retrieved from https:// store.standards.org.au/product/as-isoiec-42001-2023

8 RACGP.org.au, (2020)., Standards for general practices 5th edition, retrieved from https://www.racgp.org.au/ getattachment/ece472a7-9a15-4441b8e5-be892d4ffd77/Standards-forgeneral-practices-5th-edition.aspx

9 ASD, (2023)., Essential Eight maturity model, retrieved from https:// www.cyber.gov.au/business-government/ asds-cyber-security-frameworks/essentialeight/essential-eight-maturity-model

10 Standards.org.au, (2023)., ISO 31000:2018 Risk Management Guidelines, retrieved from https://store.standards.org. au/product/as-iso-31000-2018

11 NIST.gov, (2024)., The NIST Cybersecurity Framework (CSF) 2.0, retrieved from https://nvlpubs.nist.gov/ nistpubs/CSWP/NIST.CSWP.29.pdf

Frontline Support: The critical role of Practice Managers and Reception teams in Eating Disorder Care

Most of us know someone who is struggling with food, body image or an eating disorder…or maybe we have worried about a loved one with these concerns ourselves. Despite how common these experiences are, many people still don’t know where to turn for help or how to start the conversation about seeking support.

Eating disorders are serious mental health conditions that affect physical health, emotional wellbeing, relationships and daily life. They require early identification, compassionate support, and coordinated care. While GPs and clinical teams play a critical role in treatment, practice managers and reception staff are often the first point of contact and can have significant impact on patient care.

There is a common misconception that eating disorders are rare. At least 1 in 20 Australians are currently experiencing an eating disorder, affecting an estimated 1.2 million people nationwide. Rates continue to rise, particularly among younger Australians, and eating disorders have among the highest mortality rates of all mental health conditions.

Every member of the general practice team has a role to play in helping people access timely, compassionate care.

First Contact, Lasting Impact

For many people, making the first call or walking into a clinic is incredibly difficult. Feelings of shame, fear, or uncertainty are common. A warm, respectful and non-judgemental interaction at reception can reduce anxiety, encourage disclosure and increase the likelihood a patient will follow through with disclosing their concerns and accessing care.

Creating a Supportive Environment

Practice managers play an important role in shaping systems, culture, and processes that support safe and effective care pathways. Simple measures such as protecting privacy, offering flexible appointment options, and ensuring clear patient pathways can significantly improve the experience for people living with eating disorders. Reception staff also play a vital role through respectful communication, maintaining confidentiality, and helping patients navigate appointments and follow-up care.

Together, these everyday interactions can create a sense of safety and trust, often leading to the first step towards recovery.

Supporting the Whole Care Journey

Recovery from an eating disorder is always possible. When identification and treatment occur in a timely fashion, recovery may be uncomplicated. For some

people, it can be a longer-term journey involving multiple health professionals and requiring ongoing support. Practice staff play a key role in helping patients stay connected to care by coordinating appointments, supporting care plans, facilitating communication between providers, and helping patients and families navigate the health system.

For families and carers, who often feel overwhelmed and unsure where to start, a supportive and knowledgeable practice team can provide reassurance, clarity, and continuity of care.

New Support from the InsideOut Institute

Recognising the vital role of non-clinical staff, InsideOut Institute for Eating Disorders has developed a free eLearning program specifically for practice managers and reception teams working in general practice.

This program is designed to build confidence, capability, and understanding in supporting people with eating disorders and their families.

This training also incorporates the voice of lived experience, featuring insights from people with eating disorders, families, and GPs—helping ground learning in real-world experiences.

Importantly, the course is free and provides a valuable professional development opportunity, supporting ongoing accreditation requirements.

Find out more about this training here: InsideOut eLearning Platform

Practical Tools: InsideOut GP HUB & Practice Management Toolkit

The eLearning program introduces participants to the InsideOut GP HUB, a free online resource designed to support general practice teams in caring for people with eating disorders.

The GP HUB includes a Practice Management Toolkit featuring referral pathways, care plan templates, quality improvement resources, and practical tools to

help streamline workflows and support best-practice care within everyday practice settings.

Your Role Matters, More Than You Know

As awareness of eating disorders continues to grow, so too must the recognition of the important role every member of the general practice team plays in supporting recovery. Practice managers and reception staff are often the first people patients and families encounter, helping create an environment where patients feel welcomed, respected and

supported is critical.

InsideOut Institute’s free eLearning module and GP HUB resources provide practical tools and training to help practices strengthen their approach to eating disorders care.

Because you’re not just booking appointments, you’re opening doors to recovery.

Visit the GP Hub here: InsideOut GP HUB

Best Practice Partner

I-MED e-Referrals are a smarter way to save you time, reduce clinical risk and improve communication.

Take back your time by reducing administrative burden, from faxing and follow-up calls to unnecessary paperwork.

Seamlessly integrate I-MED e-Referrals with Best Practice and MedicalDirector, and connect directly to I-MED’s online booking portal so patients can book appointments themselves, 24/7.

Contact our team about streamlining your practice today:

• call us on 1300 147 852

• email a Key Account Specialist at eReferral.Request@i-med.com.au

Gain real-time visibility into patient opportunities

Revolutionise preventitive care, with live appointment syncing and Care Prompts directly to Best Practice Premier

Scan to learn more about Gentu or book a demo today

True cloud software, built for specialist medical practices

Practice management software built for the cloud — with the speed, security and flexibility your practice needs.

Learn Gentu in hours, not days

Intuitive by design, so your team can get up and running fast

Security you can trust

ISO 27001 certified with multi-factor authentication built in

Stay organised on-the-go

Access your practice anywhere with the Gentu mobile app for iOS and Android

Keep your patients informed

Send emails, invoices, receipts and SMS, all from one place

Prescribe with confidence

Streamline prescribing, billing and claims, all without chasing

Extended your practice via the Marketplace

Connect to add-ons and apps that grow with your practice

How context-switching is quietly costing your Practice

Ask a practice manager how their day went and you'll often hear the same thing: “Busy, but I'm not sure what I actually finished.” They're not being modest, they're describing the experience of working hard across billing, scheduling, patient queries, and compliance, dashing between each task dozens of times, yet ending the day with most of them still only partly done.

There's a name for what's happening here, and a growing body of research that quantifies its cost. It's called contextswitching. In environments like specialist practice, where the work is widely varied, the stakes are high, and the systems still rarely talk to each other, it may be one of the biggest unmanaged drains on your practice's performance.

The science of switching

Researchers have spent two decades studying what happens when people rapidly move between tasks this way, and the findings should ring alarm bells.

Gloria Mark, a professor of informatics at the University of California, Irvine, found that after a single interruption, it takes an average of 23 minutes to return to the same depth of focus on the original task. Her research tracked knowledge workers switching between screens an average of 566 times per day. Each switch contributes

to cumulative cognitive load and reduced output, even when individual switches lasted only seconds.

Separately, Sophie Leroy at the University of Washington introduced the concept of "attention residue", the phenomenon where, after switching tasks, part of your cognitive capacity remains stuck on the previous task. Her experiments demonstrated that people who switched before completing a task performed measurably worse on the next one. The effect holds whether the switch is between two major projects or between a major project and a quick email check.

The implication is clear: fragmented work isn't just less efficient, it degrades the quality of every task it touches.

What this means in a specialist practice

Now apply that research to specialist practice. Each of those tasks a practice manager juggles lives in a different system, with its own interface, its own logic, its own login. Each switch carries a cognitive toll that compounds across the day.

The compounding effects are real. Claims go out with errors because the person processing them was mentally still on the phone call they just finished. Follow-up reminders slip because the task that interrupted them took longer than expected. A patient's query sits unanswered an extra day because it arrived

during a billing run and got buried. None of these failures are caused by a lack of competence or care. They're caused by a working environment that structurally prevents sustained attention.

For clinicians, the picture is equally stark. Studies have found every hour of direct patient interaction is dwarfed by nearly two additional hours on electronic records and desk work. When that administrative time is fragmented across disconnected tools the cognitive cost compounds further, eating into the clinical judgment and decision-making quality that patients rely on, and the specialist’s own wellbeing.

In our own research with Australian specialist practices, practice managers consistently described operational friction caused by disconnected systems as one of their most persistent challenges. The contextswitching research helps explain why: beyond the inconvenience, it's a measurable drain on performance.

What the research points toward

The behavioural science is unambiguous about the solution: reduce the number of transitions. Every time a practice team member can stay in context — completing a workflow without switching systems, re-entering data, or navigating to a separate tool — you reclaim cognitive capacity that would otherwise be lost to switching costs.

This is why we built Genie and Gentu as unified practice management platforms rather than point solutions. Scheduling, billing, clinical documentation, patient communications, and reporting live in one environment.

A clinician ordering pathology tests doesn't have to leave the platform; through eRequests the request goes digitally to the laboratory with real-time tracking of whether the test is pending or complete. Through eBookings, theatre bookings happen from within Genie or Gentu — no phone calls, no email chains, no re-entering patient details into a hospital portal. With Gentu, Medicare claims are processed automatically in the background, with no separate billing tool. The Gentu Marketplace extends these capabilities further, bringing data from integrated third-party tools — AI scribes, consent management, digital referrals, online bookings — into the Gentu workflow.

This is about designing technology that respects how people actually work, and what two decades of cognitive science tells us about the cost of forcing them to work to suit the technology.

The questions worth asking are straightforward. How many systems does your team use in a typical morning? How many require separate logins or duplicate data entry? Where does a task get interrupted, not by a patient need, but by a system limitation? If the answers concern you, the research says that concern is well-founded.

To learn more about how Genie and Gentu support specialist practice workflows, visit magentus.com/practicemanagement

From admin burden to integrated payments: the new era for medical practices

The role of payments in healthcare

The pressure on Practice Managers today is only increasing. From rising administrative workloads and evolving patient expectations to the ongoing challenge of maintaining financial sustainability, Practice Managers are balancing multiple responsibilities while remaining the backbone of Australia’s primary care industry.

For many, finding opportunities to innovate through operational change can feel out of reach. With so much to manage day to day, shifting processes, especially those considered “back office”, often takes a back seat.

Payments are one such area. Frequently overlooked, they are nonetheless critical to both the patient experience and practice performance. Ezidebit enables Australian practices to support the shift towards an automated, flexible, and digital-first payments model - driving greater efficiency and improved revenue outcomes.

Managing payments in modern practices

Practice Managers are navigating an increasingly complex balancing act: maintaining clinical efficiency while managing growing operational demands. Behind the scenes, many practices still rely on manual reconciliation and billing processes that consume valuable time and increase the risk of errors.

Chasing outstanding payments

can also lead to uncomfortable conversations with patients, adding further strain to already busy workloads.

Fragmented systems only compound the issue. With multiple platforms across EFTPOS, invoicing, and online payments, visibility is limited and workflows become disjointed. This fragmentation often contributes to cash flow challenges, particularly when payments are delayed or missed due to walk-outs or no shows.

At the same time, patient expectations are evolving. Today’s patients expect fast, flexible, and convenient payment options that align with their lifestyles - whether that’s online, recurring, or contactless. Practices that fail to meet these expectations risk both revenue leakage and reduced patient satisfaction.

In this environment, Practice Managers are doing more than overseeing operations, they are solving for efficiency, financial stability, and patient experience all at once. Streamlining payments is no longer just an administrative improvement; it’s a critical lever for reducing complexity, improving cash flow, and delivering a more seamless and modern patient journey.

The solution: Ezidebit

An integrated, automated payments solution does more than simplify processes - it delivers tangible outcomes for practices. With Ezidebit, payments are consolidated in one

place: EFTPOS for in-practice transactions, online payments for pre- or post-appointment billing, BPAY for flexibility, and Direct Debit for ongoing treatment plans.

Ezidebit eliminates the need to switch between systems or manually reconcile reports at the end of the day.

For practice teams, the impact is immediate. There are fewer late nights spent reconciling accounts and fewer uncomfortable follow-ups with patients. Automation significantly reduces administrative workload by automatically matching payments, improving reporting clarity, and minimising errors from manual entry.

Staff can spend less time troubleshooting discrepancies and more time supporting patients.

Perhaps the most significant benefit is the impact on cash flow. With predictable, recurring payments, practices gain improved visibility and financial stability - making it easier to plan, invest, and grow with confidence.

Ultimately, payments should operate in the background. When they do, teams gain time back, patients experience a smoother journey, and the practice runs with far less friction.

How operational benefits become patient outcomes

Flexible, patient-friendly payment options don’t just ease administration, they directly enhance the patient

experience. With options such as installment plans, card payments, online checkout, and in-clinic transactions, patients can choose how and when they pay in a way that suits their financial situation and lifestyle.

As a result, patients are more likely to proceed with recommended care and remain consistent with treatment plans. Seamless payment processes also remove the awkwardness often felt at reception. When payments are pre-arranged or handled automatically, conversations shift away from finances and back to patient care, creating a more positive, professional experience.

Better payment experiences ultimately lead to stronger relationships. Patients feel supported and understood, while practices build trust, improve treatment adherence, and deliver more consistent health outcomes, without adding pressure to front desk teams.

The power of partnerships: Ezidebit & MedicalDirector Pracsoft

A clear shift is underway in healthcare: payments are no longer a separate, timeconsuming function. Instead, they are becoming embedded within the systems practices already rely on every day.

Through its integration with MedicalDirector Pracsoft by Telstra Health, Ezidebit is helping Australian practices bring payments and practice management into a single, seamless workflow.

For Practice Managers, this means everything happens in one place. Payments, whether in-person or telehealth, can

be accepted, processed, and automatically reconciled directly within their MedicalDirector Pracsoft system. Card details can be securely captured once (with consent) and tokenised for future use, making it easy to process follow-up or remote payments instantly.

This eliminates the need to chase patients after walk-outs, send unsecured payment links, or manage missed transactions.

In busy practices, the impact is immediate. A single EFTPOS terminal can support multiple practitioners, with funds automatically routed to the correct account. This removes the need for manual splits and ensures every payment is linked to the correct consultation, dramatically reducing reconciliation time and errors.

With payments integrated directly into MedicalDirector Pracsoft, manual follow-ups are significantly reduced, freeing up staff time and minimising friction for patients.

As Cassie King, Client Manager Team Lead at MedicalDirector, explains: “...this partnership is really timely because we wanted to fill a gap in the market, where practices needed to process payments online when a patient might not be in the clinic. This is exactly what the partnership has enabled.”

This partnership reflects where the industry is heading: integrated payments that operate seamlessly in the background, supporting more efficient practices and better patient experiences.

A smarter way forward for practice payments

The future of Practice

Management is digital, connected, and increasingly patient-centric. Administrative processes that were once manual and fragmented are rapidly being replaced by integrated systems, where payments, clinical records, and operations work together seamlessly.

As this shift continues, patient expectations will continue to evolve. Flexible, seamless financial experiences will become the norm, not the exception.

For practices, this presents a clear opportunity. Those that modernise their payment processes will be better positioned to reduce administrative burden, improve cash flow predictability, and deliver a more convenient, stressfree experience for patients.

Payments are no longer just a back-office function - they are a critical part of the overall patient journey. Practices that embrace integrated, automated solutions today will gain a measurable advantage in efficiency, patient satisfaction, and long-term financial stability.

For MedicalDirector Pracsoft users looking to simplify operations and enhance patient experience, now is the time to rethink payments. Ezidebit, integrated within MedicalDirector Pracsoft, helps practices reduce administrative workload, streamline workflows, and create more predictable cash flow.

To learn how you can bring payments into the background of your practice, click here

For a copy of Ezidebit's Financial Services Guide & Product Disclosure Statement, Privacy Policy, Client Service Agreement Terms and Conditions or other legal and compliance documents, visit https://www.ezidebit.com/en-au/legal-policies

Get started with Ezidebit by 31 August and receive a $100 eGift card. T&Cs apply.

Trusted Patient Messaging Starts with Bp Comms

Hi Reuben T, Dr Frederick Findacure has reviewed your result dated 20/08/2026. Please call the practice to make an appointment. Do not reply.

With the new Assignment of Benefits requirements and ACMA Sender ID reforms, unverified SMS messages risk being flagged as spam or ignored entirely.

Bp Comms helps practices stay trusted and recognised – with integrated patient messaging, dedicated sender identification, automated reminders, and secure communication workflows built directly into Bp Premier.

Learn more about Bp Comms

Key changes to Assignment of Benefits and SMS Communications from 01 July 2026

From 1 July 2026, two important regulatory changes will come into effect that will begin to modernise a couple of outdated processes, improve security and strengthen compliance across the healthcare sector.

Change number 1 is an electronic alternative to the current paperbased system for collecting a patient’s Assignment of Medicare Benefit to the doctor delivering the service, and change number 2, we will see the introduction of the SMS Sender ID Register. This reform is being championed by the Australian Communications and Media Authority (ACMA), and is designed to crack down on scam and spam text messages across Australia. Interesting timing, wouldn’t you say?

Electronic Assignment of Benefit

Traditionally, this has required patients to physically sign a paper form confirming that they assign their Medicare rebate to the treating practitioner as full payment for the service. From July 2026, if they wish, practices will be able to use an electronic Assignment of Benefit process , allowing patients to review and approve this agreement digitally via SMS. This can occur either before the consultation (pre-assignment) or after the consultation (post-assignment). This shift reflects the same continuous move toward digitisation in healthcare that we saw during the pandemic, with the swift introduction of

eScripts. What a time to be alive! The electronic process is expected to eliminate the need to store paper records and improve the accuracy and traceability of Medicare claims. It also aligns with the evolution of telehealth and modern clinical workflows, addressing limitations identified in earlier paper-based systems. No need to worry though, paper-based options will remain available for patients who are unable or unwilling to use digital methods. However, you should anticipate workflow changes from your software vendor, including the need to manage electronic consent and ensure appropriate documentation is retained for compliance and audit purposes. For further information, practitioners should monitor updates via Department of Health and Aged Care updates or, if you’re a Bp Premier user, our Knowledge base is going to be your one stop shop.

SMS Sender ID Register

At the same time, new rules governing SMS communications will be introduced through the SMS Sender ID Register, designed to reduce scam and spam text messages. An SMS sender ID (previously known as an “alpha tag”) is the name that appears at the top of a text message, identifying the sender. From 1 July 2026, organisations that send branded SMS messages will be required to register their sender IDs through their telecommunications provider.

According to ACMA, this reform is intended to prevent scammers from impersonating trusted organisations and to improve consumer confidence in SMS communications. Once implemented:

○ Only registered sender IDs will appear as branded messages

○ Messages from unregistered sender IDs will be labelled “Unverified”

○ These messages may be grouped together, signalling potential scam activity

Healthcare practices that send SMS communications beyond simple appointment reminders (such as health awareness campaigns or clinical reminders) should be registering their sender IDs. This one is pretty important if you do plan on adopting assignment of benefit via SMS, because you definitely don’t want those being missed by your patients. There’s a bottom dollar implication there to consider. Further details are available via ACMA SMS Sender ID Register guidance

Preparing for the Changes

With both reforms commencing on the same date, you should begin preparing now. Key steps include:

○ Reviewing patient contact details and consent processes

○ Familiarising staff with the Assignment of Benefit changes

○ Monitor updates from your software vendor – If you’re a Bp Premier user, we are updating our user base regularly via our newsletter, which you can sign up to by clicking here. Team Bp are currently working on some patient-facing resources to

help you educate your patients

○ Monitoring updates from regulators and industry bodies

Staying informed and preparing early will help ensure a smooth transition when these important reforms take effect on 1 July 2026.

Meet Helen

AI powered receptionist support for GP practices 24/7

The AI Receptionist is saving our reception team time

-Grace

Helen is available for GPs. See her in action.

*Results

The strategic benefit of setting up an AI receptionist for your practice

For medical Practice Managers, it can seem like there’s an endless list of things you’ll get to “when there’s time”.

Using AI can feel like one of those things: others are always telling you to look into it … but when? There’s never time. Even for the things that, if you could just get to them, would help your team in the long-run.

If you’re already aware of the potential gains of an AI receptionist for your practice but can’t get past the level of setup they seem to require … this article is for you.

The setup process in a nutshell: What to expect

1. Define scope and boundaries for the AI receptionist

2. Verify PMS integration and reliability

3. Ensure data security and compliance

4. Test safety and escalation measures

5. Train reception staff on updated workflow

1. Define scope and boundaries

Early on, decide what the AI will handle, and more importantly, what it won’t.

AI receptionists have a lot of potential benefits, but, like most AI products, these systems work best when they’ve given clear guardrails.

You wouldn’t ask ChatGPT to do your tax return: so don’t expect your AI receptionist to wrangle complex queries or provide medical triage.

If you’re looking to reduce time wasted on routine queries or simple booking changes, the right AI receptionist could have an impact. Define the specific needs of your practice and work backwards.

2. Verify integration and reliability For GPs, a practice management system (PMS) is the standard way of managing bookings and the day-to-day workings of a clinic.

AI receptionists are only as good as their ability to connect with your existing workflows: which means confirming PMS integration.

As part of setting up an AI receptionist, you should test how it interacts with your PMS, as well as understanding what happens when the connection fails. If the PMS connection drops mid-call, what happens?

3. Ensure data security and compliance

This is the most important step in the AI receptionist set-up process, because it concerns the handling of patient data.

During the evaluation and pilot planning stages, practice managers should work off a documented data handling policy. Consider what level of access

permissions the AI receptionist asks for; set controls for patient data handling and call logs.

Whichever AI receptionist you choose, make sure data privacy comes first.

4. Test safety and escalation measures

It’s all well and good to know what AI receptionists should handle: but does this hold up when tested?

During demos, make sure the AI receptionist escalates the appropriate calls to the front desk.

When certain triggers occur, there should be a documented set of steps for AI receptionists (like Helen) to follow.

AI receptionists can help reduce the number of routine, repetitive questions for your staff: leaving more time and energy for the matters requiring a human touch.

5. Train your reception staff

AI receptionists are one of those things worth introducing once, and introducing properly.

Especially in a busy medical practice where you can’t afford to have downtime.

To put your best foot forward, create an onboarding process for training staff and handling patient adjustments to the new system. Some AI receptionists come with nothing but an invoice and a “well, good luck!”.

Other AI receptionists, like Healthengine’s Helen, include personalised service during the rollout phase, and beyond.

Healthengine’s AI receptionist frees up time and energy for Australian Practice Managers Practice Managers’ job descriptions encompass a great deal, and in the bustle of dayto-day operations, it’s natural to normalise taking on more than you should.

But now, imagine having 75 hours every week — yours to decide what to do with. For one GP clinic in Victoria, Healthengine’s AI receptionist spends this amount of time on calls weekly, on average, with the ability to assist multiple patients at once.

AI receptionists enable focus on the things requiring real consideration and empathy, which only you can provide. There’s so much that AI receptionists can’t do: the best solutions know their own strengths and weaknesses.

Discover how Healthengine’s AI receptionist can support a more streamlined front-desk workflow. Calmer operations are closer than you think.

Federal Budget Proposal Signals Major Changes for Testamentary Trusts

Discretionary Testamentary Trusts have long formed an important part of many estate plans and we have recommended them to numerous clients over many years. They remain a prudent strategy for asset protection and tax effective distribution of assets to beneficiaries under the law as it has stood for many decades.

As part of the Federal Budget released this month, the Government announced a proposal to impose a minimum tax rate of 30% on the income of discretionary testamentary trusts established from 1 July 2028. This represents a significant change in the law on the future taxation treatment of discretionary testamentary trusts. The change does not apply to other forms of testamentary trusts, including fixed testamentary trusts.

At this stage, the legislation has not yet been finalised or passed by Parliament. Accordingly, the information in this update is subject to the final form of the legislation as passed by Parliament.

It is important to note that the testamentary trusts created under a Will do not actually come into existence when the Will is signed. Rather, testamentary trusts generally only come into existence upon the death of the Will maker at the earliest and, more commonly, shortly thereafter when the executor of the estate

establishes the testamentary trusts after Probate is granted. Accordingly, testamentary trusts contemplated under a Will may not come into existence until well after 1 July 2028.

In most cases, our Wills include a provision allowing a beneficiary to direct the executor not to transfer some or all of their entitlement under the Will into a testamentary trust. This clause provides beneficiaries with flexibility to decide at the relevant time whether establishing the testamentary trust remains appropriate, taking into account the taxation and other implications applying at that time.

In some circumstances, clients have instructed us not to include this flexibility. This may occur, for example, where a beneficiary is considered too young or inexperienced to manage an inheritance independently, or where the client specifically wishes to ensure assets remain protected within a Testamentary Trust structure regardless of the beneficiary’s preference. Under the proposed changes,

discretionary testamentary trusts of this nature established after 1 July 2028 may become subject to the proposed minimum 30% tax rate.

In light of this significant proposed change to the taxation treatment of discretionary testamentary trusts, now may be an opportune time to review

your Wills and broader estate planning arrangements. We have reviewed many Wills that require assets to be transferred into a discretionary testamentary trust and therefore may not provide the same degree of flexibility under the proposed regime.

If you are uncertain whether your current arrangements may be affected, we would be pleased to review your Will and advise whether any changes should be considered. Once the proposed legislation is finalised, we will also be able to provide more specific recommendations as to whether amendments to your Estate Plan or Will may be desirable or necessary.

Key Takeaway

While the proposed changes are not yet law, they highlight the importance of ensuring your Estate Plan remains flexible and aligned with evolving taxation and succession planning considerations. Reviewing your arrangements now may help avoid unintended outcomes for beneficiaries in the future.

Exclusive to AAPM Members

Our Wills and Estates team is offering members a complimentary 30-minute online consultation to discuss the proposed testamentary trust changes announced as part of the Federal Budget and answer any questions you may have regarding your existing Will and broader Estate Planning arrangements.

As the proposed changes are not yet law, we are unable to confirm how individual arrangements may ultimately be impacted. However, we can assist you in understanding the proposed changes and discuss potential considerations relevant to your circumstances.

To arrange a confidential review or discuss your Estate Planning arrangements, please contact Anna Huang and our Wills & Estates team on (07) 3220 1144 or via email at email@hillhouse.com.au

Turn static files into dynamic content formats.

Create a flipbook
PRACTICE MANAGER JOURNAL_JUN 26 by AAPM - Issuu