Private to this computer. Everything you type stays in this browser on this computer. Nothing is sent to Medius Global or any server.
Interactive PDSA workbookPilot version
Cybersecurity in general practice
Fill this in as your practice works through a Plan-Do-Study-Act cycle on cybersecurity: a security audit with your IT provider, whole-team education and monthly phishing awareness tracking. Your answers save automatically on this computer. Come back across the learning-together meetings and pick up where you left off. Written so the practice manager can drive it.
AuthorDr Chris Mitchell AM, FAICD
CPD hoursUp to 9 (EA 3 + RP 3 + MO 3)
TimelineThree learning-together meetings, 3 to 6 months
Last savednot yet
Before you start: how this workbook saves
Type into the dashed magenta boxes. Each one shows an example answer above it. If you are not sure what to write, say the same kind of thing about your own practice.
Your answers save by themselves as you type, on this computer, in this browser. Close the tab, come back next week, everything will still be here. Check the 'Last saved' date on the cover.
Use one computer for the whole cycle, usually the practice manager's. If someone else needs to add their part, click Save to file, email them the file, and they click Load from file on their computer. Then they save to file and send it back.
Click Save to file at the end of every session. It downloads a small file. Keep it in your practice records folder. It is your backup if this computer is cleaned, replaced or reset.
When the cycle is finished, click Print / Save as PDF and choose 'Save as PDF'. That PDF is what the GPs upload as evidence to the RACGP CPD portal, and what you keep for accreditation.
One caution: clearing the browser's history or cache can delete your saved answers. The Save to file backup protects you.
This workbook is a pilot. If something is confusing or does not work on your computer, tell us via the contact page so we can fix it.
Your progress
0%
0 of 0 fields completed. This is a long activity. Do a section, close the tab, come back next week.
The four stages
PlanPick the problem. Decide what you will count and who does what.
DoRun the change. Hold the meetings. Record the numbers as you go.
StudyCompare the numbers across the weeks. Write down what you noticed.
ActKeep what worked. Drop what did not. Make the good changes permanent.
The shaded boxes show you what to write
Every question carries the answer from Dr Chris Mitchell's own cybersecurity cycle, run in a mixed rural practice over three months. You do not need to invent anything: read the example, then write the same kind of answer about your practice. The dashed magenta boxes are yours.
The learning: where your educational hours come from
Three of the nine hours are educational activities (EA). Your team earns them by reading and discussing the cybersecurity material, then applying it during the cycle. Chris wants this background on hand in every practice that runs the cycle.
The full background sits in the guide: phishing and social engineering, password and passphrase security, multi-factor authentication, the security audit domains, data breach notification obligations and the whole-team education material. Read it as a team at a practice meeting and log the time as EA.
Australian Cyber Security Centre (cyber.gov.au): the Essential Eight and small business guidance
RACGP: information security in general practice
OAIC: the Notifiable Data Breaches scheme and your obligations
Scamwatch: current phishing and scam examples to share with the team
Your IT provider's monthly security report
Your PHN, for digital health and security support
For the practice manager
Email the guide page to every GP and staff member before the education session, so the reading is done by the time everyone sits down. The hours they spend reading and discussing it count toward EA, and this workbook records the rest.
Plan
Topic, idea and plan
Example
Reducing cybersecurity risk in the practice through a security audit, whole-team education and ongoing phishing awareness.
Example
Cybersecurity is an increasing risk to our staff and patients. Recent breaches such as Medibank and MediSecure have shown how vulnerable health data is, and GP practices have fewer resources than large organisations, so structured risk reduction matters. Running a cybersecurity cycle also shows staff and prospective GPs that we take data protection seriously.
Example
Reduce risk through two parallel activities: education of the whole team and technical security measures. We ran the project over three months. Month one: a security audit with our IT provider and the first education session. Month two: begin phishing tracking and review perimeter protections. Month three: second and third learning sessions, consolidate findings and implement changes. Each doctor and staff member records the suspicious emails and texts they receive at work each month.
Example
Complete a security audit against the key domains with the IT provider. Deliver cybersecurity education to all staff and independent doctors. Build ongoing phishing awareness through monthly tracking. Agree and embed a set of practical security actions, such as complex passphrases, multi-factor authentication and no browser-stored passwords.
Do
Meeting and measurement schedule
Chris's practice ran the cycle over three months, with a security audit up front and three learning-together meetings where the team shared their phishing counts and learnings. Type your dates in as each one happens. These dates become part of the CPD evidence, so keep them accurate.
Milestone
Date
Security audit with the IT provider
Learning-together meeting 1: first education session
Phishing tracking begins (each person records suspicious emails and texts)
Perimeter protection review with the IT provider
Learning-together meeting 2
Learning-together meeting 3: consolidate and agree changes
Follow-up meeting: confirm learnings and embed actions
RACGP portal upload (GPs log their hours)
Do
Security audit with your IT provider
Work through these domains with your IT provider and record what they confirm. This is the technical half of the cycle. There are no numbers to count here, just questions to ask and answers to keep on file.
Example
We asked our IT provider to confirm each domain: software and security patches kept current; multi-factor authentication and VPN in place; antivirus and ransomware protection (Sophos Intercept X); geographic blocking of high-risk regions; USB and port security; and Wi-Fi segregation between practice and guest networks.
Study
Phishing awareness tracking
Each doctor and staff member records the suspicious emails and texts they receive at work, and the totals are shared at each learning-together meeting. Enter the practice totals for each meeting here. Numbers only in the meeting boxes (34, not '34 emails'). The change column works itself out.
Example
Across seventeen doctors, the practice collated the count of suspicious emails and texts reported at each of the three learning-together meetings. Sharing the counts kept phishing awareness front of mind and prompted people to report rather than click. The point is not a falling number, it is that everyone is looking and reporting.
What you are counting
Meeting 1
Meeting 2
Meeting 3
Change
Perimeter protection review
Example
Perimeter protection is provided by our Sophos XG Firewall v20. We reviewed how inbox spam and malicious code are handled, whether an email gateway is needed, managed detection and response options, server lockdown capability, and the monthly maintenance report.
What we learned
Example
We need to look more closely at the segmentation of our drives. We will explore Cloudflare Gateway, and consider CI-ISAC threat intelligence tailored to critical infrastructure sectors. While we were not affected by the CrowdStrike incident, it is a risk worth planning for. Sharing phishing counts across the group kept awareness high.
Act
What to keep and make permanent
Example
We issued the following to all staff and independent doctors: use a complex passphrase that is not reused; avoid storing practice passwords in a browser such as Chrome; use multi-factor authentication; do not use USBs or CDs on work computers; never provide your password; complete phishing and social engineering education; record suspicious emails and texts and submit them monthly; and share any learnings by email to the group. The practice will follow up with penetration testing and a report.
CPD hours
Count the hours each GP spent. Education meetings and reviewing the cybersecurity material count as EA. The security audit and perimeter review count as RP. Running the cycle itself, including the phishing tracking across the meetings, counts as MO. The total adds up automatically. When in doubt, the GP lead decides what to claim.
Activity type
Hours
Evidence you already have
Educational activities (EA)
The learning-together meetings and the cybersecurity education session
Reviewing performance (RP)
The security audit and the perimeter protection review with your IT provider
Measuring outcomes (MO)
This completed workbook, meeting dates, the phishing tracking figures
Total
0
GPs submit as a GP-led activity via RACGP myCPD Home
In-house education is the easiest EA time to claim, and the easiest to forget
Reviewing the cybersecurity material in the guide as a team, at a learning-together meeting, is the most direct source of EA hours in this cycle. Log the time while you are there, because it is the part practices most often forget to claim.
Reflections (the GPs write these)
The RACGP asks each GP to reflect on three areas. Hand the computer to the GP lead for this bit, or collect a sentence or two from each GP at the follow-up meeting and type them in. There is no worked example here: these have to be your own.
Participating doctors
One per line. This is for your records so nobody has to reconstruct it at portal-upload time.