Compliance

Security awareness

The annual round, in terms of this system: your account, your screen, and the handful of habits that actually cause breaches.

7 min · All staff · lesson v1

Every practice has to run security awareness training and keep a record of it. This is that training, written in terms of the system you actually use rather than in general.

Your account is you

Everything you do is recorded against your account. That is a protection — it means the record can show what you did and when — but it only works if the account is genuinely yours.

Don't share logins. Ever, for any reason, including covering for someone who is off. Under a shared login the audit trail names the wrong person, and the practice loses the ability to answer basic questions honestly.

Turn on two-factor. The system will prompt you; do it before you're forced. It is the single biggest difference between a stolen password being an inconvenience and being a breach.

If you think your account is compromised, say so immediately. An administrator can revoke your sessions everywhere and reset your authenticator in seconds. Nobody will be annoyed at a false alarm.

Your screen is a chart

  1. Sessions time out. Your administrator picks the length, and picks it shorter for machines in public areas — a front desk in a waiting room might be fifteen minutes.

    If you come back and find the sign-in card, that is the system doing its job, not a fault.

Lock or close what you're looking at when you walk away, even for a minute, even behind a counter. The people in a waiting room are closer to your screen than you think.

How data actually leaks from clinics

Not usually by hacking. By ordinary, well-meant shortcuts:

  • Photographing a document to a personal phone. Use the QR hand-off; it goes into the chart and nowhere else.
  • Emailing something to a personal address "to work on at home".
  • Discussing a patient where they can be identified — a corridor, a lift, a café near the clinic.
  • Looking up someone you know. A neighbour, a colleague, a local name in the news. This is the most common access violation in healthcare, and the system records exactly who opened which chart today.
  • Paper. Printed schedules and statements left on a desk overnight.

Suspicious messages

Faxes, portal messages and emails all arrive from outside. Two habits:

  • Don't act on a request to change bank details, send records, or reset access because a message asked you to. Verify through a number you already had.
  • If a document arrives that doesn't belong to your practice, don't file it — reject it and tell someone.

If something goes wrong

Tell your practice's administrator or privacy lead the same day. Breach obligations run on clocks, and those clocks start when the practice should have known, not when someone finally mentioned it.

Nobody is well served by a quiet mistake.

What usually goes wrong

Meaning to enrol in 2FA. Do it now; it takes two minutes.

"Just this once" with a login. There is no once.

Assuming the timeout protects you. It protects the machine after you have gone. It doesn't cover the ten minutes you were standing next to it talking.

Waiting to be sure before reporting. Report the suspicion.

Check yourself

No score, no account — just make sure you can answer these before you move on.

  1. You think someone used your account. What are the first two things to do?

    Show the answer

    Tell whoever administers the system, and change your password. An administrator can Revoke sessions to sign your account out everywhere immediately, and Reset 2FA if your authenticator is compromised. Speed matters more than certainty — a false alarm costs a few minutes.

  2. A colleague is off sick and asks you to "just use my login" to finish something. What's wrong with that?

    Show the answer

    Everything they do under your login and everything you do under theirs is recorded against the wrong person. It defeats the audit trail, it breaks the practice's ability to answer who accessed what, and it means their password is now shared. Ask an administrator for the access you need instead.

  3. Why does an unattended screen matter more in a clinic than in most offices?

    Show the answer

    Because what is on it is other people's medical information, and the room is full of members of the public. That's the whole reason for the session timeout — an administrator sets it shorter for shared front-desk machines than for a private office.