IT Security
Practice information required for this page

Contents

IT Security

Each practice supplies their own information for this topic via the tailoring questionnaire.

Policy

We keep our patients' electronic health information private and secure in accordance with the Privacy Act 2020 and the Health Information Privacy Code 2020.

See also Safeguarding Patient Information and Disclosing Patient Information.

We have systems in place to protect the security of the information we hold:

The practice manager is the IT coordinator and is responsible for all IT-related system security and maintenance. This includes services provided by external IT providers.

Our IT service provider is responsible for auditing our data systems and policies:

  • [name]
  • [contact info]   

Permissions and access

We allocate unique user IDs and passwords to staff during their practice induction, which they use to access electronic information, including patient health data.

Passwords are changed every three months, or when staff leave, or when there is a security breach. In addition to password security:

We recommend that staff choose strong passwords. Use How Secure is my Password to check password strength.

Remote access

Remote access to practice systems must be authorised by the practice manager.

Staff who access practice systems from their home network are responsible for ensuring that their home IT security is robust, and that patient information cannot be seen or overheard.

When working remotely staff should be:

Cyber incidents

To report a cyber incident or get help, contact the Computer Emergency Response Team (CERT NZ) and follow the process for managing a privacy breach.

Staff working on site or remotely should be alert for known or suspected:

Any concerns should be reported to the IT coordinator as soon as possible.

Data back-up and recovery

Patient data is backed up so that it can be recovered if systems are lost. Backups are stored securely:

Backups

The daily server back-up is done by our IT service provider.

Disaster recovery

Our IT person is responsible for disaster recovery.

Platforms and tools

The platforms, software, and other tools we use ensure patient health information is kept secure:

Antivirus protection

Our IT service provides our antivirus and spyware protection. 

Digital photos

We use a practice (not personal) camera/device, and delete photos from that camera/device, and any computer files, after saving them in the PMS. 

Patient Portals

Provided by ManageMyHealth. Staff receive training on security protocols and confidentiality.

PMS

The practice manager controls and monitors access to Medtech.

 

Referrals

ERMS (Electronic Request Management System) 

Telehealth

Telephone consultation

Transferring records

GP2GP or EDI connection

Resources

Cert NZ: Critical Controls

Health New Zealand | Te Whatu Ora: Strengthen Your Digital Defence

Health New Zealand | Te Whatu Ora: Health Information Security Framework

Page Information

Last reviewed June 2024
Next review March 2027
Topic type Core content
Approved By: Key Contact
Topic ID: 9638

Site Links

Contact