Education
5 min read

Medical Practice Policies and Procedures: An Australian Operating Guide

Published on
October 1, 2026
Violet title card reading Medical practice policies and procedures
Contributors
Lyrebird Health
Subscribe to our newsletter
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Medical practice policies and procedures turn clinical governance into work that a team can carry out consistently. For practice owners, clinical leads and practice managers, the challenge is keeping each document accurate, usable and connected to the systems where care happens. This guide sets out an Australian operating model for ownership, escalation, results handling, access control and review, with current official resources you can adapt to your practice.

Start with current standards and your actual scope

The Royal Australian College of General Practitioners (RACGP) released the Standards for general practices 6th edition in August 2026. The sixth edition supersedes the fifth, although the National General Practice Accreditation Scheme currently assesses practices against the fifth edition. Practices are encouraged to start implementing the new edition while transition arrangements are developed.

That creates a practical two-part job:

  1. Maintain evidence against the fifth edition for current accreditation.
  2. Use the sixth edition to update the systems and documents your practice will rely on next.

The exact policy set depends on your services, professions, state or territory, digital systems and participation in programs such as My Health Record. A general practice, specialist clinic and allied health service may share core controls, but one manual should never be copied across them unchanged. A practice policy also cannot narrow a practitioner's duties under legislation, registration standards or professional codes.

Three document types do different work:

DocumentThe question it answersExample
PolicyWhat is the practice's rule, purpose and accountability?All clinical information received by the practice is reviewed and acted on in a timely way.
ProcedureWho does what, in which order, including exceptions and escalation?Incoming results are routed to the requesting clinician, covered during absence, actioned and documented.
Work instruction or checklistHow is one task completed in a specific system or setting?Reconcile the unreviewed-results queue at the end of each day.

Keep the policy stable and the procedure specific enough to guide work. Put screen-by-screen instructions in a linked work instruction so a software change does not force a rewrite of the clinical rule.

Build one controlled policy register

Start with an inventory rather than an empty template. Record every policy, procedure, plan, form, register and staff checklist that the practice expects people to use. Then group them around the risks and services they control.

Control areaTopics commonly neededEvidence that the system is operating
Clinical care and follow-upTriage, informed consent, results, recalls and reminders, referrals, handover, prescribing, clinical recordsAssigned queues, review notation, contact attempts, handover records, audits
Patient rights and communicationPrivacy, collection notices, costs, interpreters, complaints, open disclosure, patient access and correctionPublished information, complaint log, response records, patient feedback
Information and technologyAccess control, digital communication, My Health Record, cyber incidents, backups, remote access, suppliers, clinical artificial intelligenceAccess register, audit logs, training, restore tests, incident reviews
Workforce and workplaceInduction, role competency, work health and safety, violence and aggression, confidentialityPosition descriptions, competency records, training and hazard logs
Clinical environmentInfection prevention, vaccine storage, emergency response, equipment and medicinesChecklists, temperature records, servicing, drills and breach records
Governance and continuityDocument control, risk, incidents, business continuity, quality improvementPolicy register, risk register, meeting actions, tests and improvement plans

You do not need a separate policy for every row. One controlled document can cover related processes if its scope and owners are clear. Keep externally maintained standards and legislation as references. Do not save an editable copy and treat it as your controlled source of truth.

For each internal document, the register should show:

  • document title and unique identifier
  • owner, clinical reviewer where relevant, and approver
  • current version, effective date and next review date
  • staff or roles affected
  • linked forms, registers, systems and external sources
  • training or acknowledgement required
  • status, including draft, current or retired
  • location of the approved copy and archived versions.

For general practices applying the RACGP sixth edition, Criterion F1.D makes document control explicit. It requires policies, procedures and operational documents to be current, accurate and accessible, reviewed at least every two years or sooner when circumstances require, with responsibility for sign-off and review assigned through version control. The full requirements sit in F1 defining and planning. Specialist and allied health practices can use the same register, but their required review cadence comes from the laws, standards, contracts and accreditation requirements that apply to their services.

Give every workflow an owner, a backup and an approver

“The practice” cannot receive an alert, cover annual leave or close an overdue task. Each procedure needs roles that can be mapped to named people on the roster.

RoleAccountability
Practice owner or governing bodyApproves the governance framework, resources and risk decisions that sit beyond delegated authority.
Clinical leadApproves clinical thresholds, decision rights, escalation paths and cover arrangements. Clinical judgement stays with an appropriately qualified clinician.
Practice manager or document controllerMaintains the register, coordinates drafting and review, publishes approved versions, withdraws old copies and keeps implementation evidence.
Workflow ownerMonitors whether the process works, reviews exceptions and reports unresolved risks.
Task ownerPerforms the assigned action by the due time and records the outcome in the designated system.
Backup or delegateTakes over when the primary owner is unavailable, with the same clear handover and recording requirements.
Privacy or security leadOversees access, privacy training, incidents and breach response. My Health Record roles must also reflect the organisation's formal responsible officer and organisation maintenance officer arrangements.

In a small clinic, one person may hold several roles. The separation still matters. It shows when that person is acting as document controller, clinical decision-maker or approver, and identifies where an independent check is needed.

Write procedures that work during a busy session

A useful procedure lets a trained team member find the right action quickly without guessing. Use the same structure throughout the manual:

  1. Trigger: what starts the procedure, such as an incoming result, patient complaint or staff departure.
  2. Scope and exclusions: which services, locations, systems and people it covers.
  3. Decision authority: who can make clinical, privacy, financial or employment decisions.
  4. Actions: short numbered steps, with the system of record named.
  5. Completion: what proves the work is finished.
  6. Escalation: the condition, destination, timeframe and backup route.
  7. Failure mode: what happens during absence, downtime or an unsuccessful contact attempt.
  8. Related material: current forms, registers, instructions and external guidance.

Before approval, walk through one ordinary case and one exception with the people who will use it. Ask them to locate the current document and act from it. If they create a side list, rely on memory or have to ask who is responsible, the procedure still has a design gap.

Use a closed-loop task and escalation model

An assigned task is still open. It closes only when the required action has occurred, the outcome is recorded and any follow-up is visible to the next responsible person.

Every clinical or operational task should carry:

  • a named owner and backup
  • a risk-based priority and due time
  • the expected action or outcome
  • the patient or operational context needed to act safely
  • a status that distinguishes new, accepted, in progress, waiting and completed
  • an escalation trigger for overdue, rejected, unclear or higher-risk work
  • a permanent record in the appropriate patient or business system.

The following is a risk-assessed operating model, not a set of universal clinical deadlines. Each practice must define timeframes and escalation destinations for its services and patient risks.

Task classTypical triggerFirst routeEscalate when
Immediate clinical riskA life-threatening result or person needing emergency responseResponsible clinician or designated urgent clinical contactThe contact does not acknowledge at once, the patient cannot be reached, or emergency action is required
Urgent, time-criticalA significant result, deteriorating patient message or urgent referral issueAssigned clinician or clinical delegateThe task nears its practice-defined deadline, the clinician is absent or the risk increases
Time-bound clinicalA recall, medication review, expected result or referral follow-upNamed clinical or administrative owner within delegated scopeThe expected item is missing, contact attempts fail or the due date passes
Routine operationalA form, stock check, training action or non-urgent correspondenceRelevant team queueThe task is overdue, blocked or exposes a recurring system gap

Do not make reception staff interpret clinical urgency beyond their training and delegated role. Give them observable triggers and a clear route to a clinician. A 2013 Australian study of 10 practices found that policies for same-day appointments were sometimes unclear, hard to find or replaced by informal staff systems. The useful lesson remains current: a written rule needs training, accessible decision support and an available escalation person.

Make results handling a visible, closed loop

Results management needs to account for received information, expected information that never arrives, clinician absence and failed patient contact. The RACGP sixth edition follow-up systems criterion sets out the core system: GPs review, notate, act on and incorporate clinical information into the patient record; the practice follows up missing results, documents patient contact attempts and manages high-risk results outside opening hours.

Closed-loop results workflow from expected result to recorded outcome, with escalation if contact fails

Build the procedure around these checkpoints:

  1. Set the expectation. Record the investigation, requesting clinician, expected result and follow-up plan. Tell the patient how and when results will be communicated, including normal results where applicable.
  2. Reconcile receipt. Identify expected results or correspondence that have not arrived. Do not rely only on the incoming inbox.
  3. Route with cover. Direct information to the requesting clinician or an authorised clinical delegate. Define cover for leave, part-time work and unexpected absence.
  4. Review and notate. The clinician records that the information was reviewed and assigns the required action and urgency.
  5. Communicate safely. Use the patient's appropriate contact channel and privacy-sensitive wording. Clinically significant information requires communication suitable to its seriousness and the patient's needs.
  6. Escalate failed contact. Set risk-based contact attempts and escalation. Record every attempt and the next decision rather than leaving an unstructured note.
  7. Close and audit. Record the outcome in the patient record. Reconcile unreviewed, unactioned and overdue items, and investigate recurring gaps.

High-risk results identified outside normal opening hours need their own policy. Give the practice's main diagnostic services a contact that can reliably receive and act on those results, and state what the clinician, delegate or after-hours service must communicate back to the practice.

Match system access to each role

For general practices, RACGP sixth edition Criterion F9.B requires unique individual identification and access according to a person's level of authorisation, with official documents stored securely. The Office of the Australian Information Commissioner (OAIC) also frames access security around “need to know” access, prompt revocation and monitoring in its security guidance.

Apply that principle across the clinical system, practice management system, shared mailboxes, secure messaging, document tools, My Health Record, templates, remote access and supplier support accounts:

  • give each person an individual account and prohibit shared credentials
  • grant the minimum permissions needed for the role
  • separate ordinary and administrator accounts
  • require multi-factor authentication where supported, especially for remote and privileged access
  • approve and log time-limited vendor access
  • review access when a person joins, changes role, goes on extended leave or leaves
  • revoke access promptly and recover practice devices at departure
  • retain logs and investigate unexpected access
  • review the access matrix on a risk-based schedule, with higher-risk and privileged access checked more often.

From 1 October 2026, organisations registered with My Health Record must comply with the My Health Records Rules 2026. Their security and access policy must be reviewed at least annually, as well as when material risks change or the System Operator requests it. The Australian Digital Health Agency provides the current security and access policy template, including user authorisation, deactivation, training and record-keeping requirements.

Set review dates by requirement and risk

A single annual review date for the whole manual creates a rushed audit and allows high-risk procedures to drift. Use rolling reviews and event triggers.

Document or controlBaseline cadenceReview earlier when
Policies, procedures and operational documents in a general practice applying RACGP sixth edition F1.DAt least every two yearsLaw, standards, services, systems, staffing or risk changes
My Health Record security and access policyAt least annually for registered organisationsA material risk changes or the System Operator requests review
High-risk clinical workflows, access permissions and incident plansPractice-defined, commonly every 6 to 12 months as a risk controlAn incident, near miss, failed audit, complaint, system change or staff change occurs
Emergency, downtime, restore and breach response proceduresTest on a practice-defined schedule, commonly annuallyA test or real event shows a gap, contacts change or dependencies change
Work instructions tied to softwareAt release or process changeScreens, permissions, integrations or vendors change

The six-to-twelve-month and annual testing cadences above are operational recommendations. Set them through the practice's risk assessment rather than presenting them as universal legal requirements.

For every scheduled review, record the source changes checked, staff consulted, incidents considered, decision made and approver. A “reviewed, no change” decision still needs a dated record.

Put digital tools inside the procedure

Software can make a controlled process easier to run, but its status indicators and audit logs need defined meaning. The practice must decide which system is the source of truth, who reviews exceptions and what evidence shows completion.

In Lyrebird, shared templates and centralised user management can support consistent documentation and access administration. Document Sorter extracts and matches incoming documents, keeps a human review step before filing and records each send. That log can evidence routing, but it does not prove that a clinician reviewed or acted on the clinical content. The results procedure still needs clinical review, follow-up and closure in the patient record.

The same boundary applies to clinical artificial intelligence (AI). Lyrebird creates draft clinical notes for clinician review and editing. Your policy should cover approved uses, patient communication or consent where required for the workflow, access, quality checks, incident reporting and clinician sign-off. Our Australian healthcare AI policy template gives this newer control area a separate, detailed starting point.

Use current Australian templates as starting points

Practices searching for a medical practice policies and procedures free download should start with the organisation that owns the relevant standard or rule. Download the current source and adapt it. Do not reproduce an old manual or adopt placeholders without checking the workflow on the floor.

Official resourceUse it forAdaptation still required
RACGP policy and procedure templatesPrivacy, confidentiality, internet and email, eHealth, patient feedback, infection-control competency and selected prescribing topicsPractice scope, state or territory duties, current sixth edition changes, owners, systems and escalation
RACGP privacy policy templatePatient-facing privacy policy under the Australian Privacy PrinciplesActual collection, storage, access, disclosure, complaints and overseas handling processes; keep the collection notice distinct
My Health Record policy templateSecurity and access policy for registered healthcare provider organisationsYour access method, responsible roles, user lifecycle, training, controls and linked policies
OAIC data breach response guideResponse roles, escalation, assessment, notification, records and post-incident reviewPractice contacts, decision authority, suppliers, insurer and other reporting obligations. The OAIC says this guide is being updated to reflect changes to the Privacy Act 1988 made by the Privacy and Other Legislation Amendment Act 2024, including Division 5 of Part IIIC, which commenced on 11 December 2024. Current legislation and OAIC updates govern legal assessment and notification.
National vaccine storage resourcesCold-chain procedures, breach actions, checks and temperature recordsEquipment, staff roles, local health department contacts and service-specific logistics

Check every downloaded document against the sixth edition Standards and mapping. The RACGP's general template page still refers to fifth edition accreditation, so its files are inputs to your controlled set rather than finished sixth edition policies.

Put the operating system in place over 30 days

Days 1 to 5: inventory. List controlled documents and unofficial workarounds. Identify duplicates, missing owners, broken links and procedures that no longer match practice.

Days 6 to 10: prioritise. Rank documents by patient harm, privacy exposure, legal or accreditation requirement, and frequency of use. Assign owners, clinical reviewers, backups and approvers.

Days 11 to 20: repair the highest-risk loops. Start with results and recalls, urgent task escalation, information access and incident response, adjusted for the practice's own risk profile. Write the normal route and the failure route.

Days 21 to 25: test and train. Run realistic scenarios with the people who do the work. Confirm that they can find the current version, use the systems, recognise their limits and escalate without delay.

Days 26 to 30: approve and control. Publish read-only current versions, withdraw superseded copies, record training, schedule rolling reviews and add unresolved risks to the practice's improvement plan.

A useful manual is visible in daily work: tasks have owners, results close safely, access follows roles and changes trigger review. Lyrebird can support controlled documentation and document handling while clinicians retain review and sign-off.

Contact us

More Resources
Continue reading
Posts
The dangers of Copy Paste Scribes
Read More
Posts
How to use an AI medical scribe
Read More
Posts
December Product Updates
Read More
Education
Healthcare Interoperability in Australia: A Practical Guide
Read More
Education
eReferral in Australia: A Practical Guide for Clinicians
Read More
Education
Medical Clearance Certificate for Work: Australian Guide
Read More
Post
5 min read

Medical Practice Policies and Procedures: An Australian Operating Guide

Published on
October 1, 2026
Violet title card reading Medical practice policies and procedures
Contributors
Lyrebird Health
Subscribe to our newsletter
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Medical practice policies and procedures turn clinical governance into work that a team can carry out consistently. For practice owners, clinical leads and practice managers, the challenge is keeping each document accurate, usable and connected to the systems where care happens. This guide sets out an Australian operating model for ownership, escalation, results handling, access control and review, with current official resources you can adapt to your practice.

Start with current standards and your actual scope

The Royal Australian College of General Practitioners (RACGP) released the Standards for general practices 6th edition in August 2026. The sixth edition supersedes the fifth, although the National General Practice Accreditation Scheme currently assesses practices against the fifth edition. Practices are encouraged to start implementing the new edition while transition arrangements are developed.

That creates a practical two-part job:

  1. Maintain evidence against the fifth edition for current accreditation.
  2. Use the sixth edition to update the systems and documents your practice will rely on next.

The exact policy set depends on your services, professions, state or territory, digital systems and participation in programs such as My Health Record. A general practice, specialist clinic and allied health service may share core controls, but one manual should never be copied across them unchanged. A practice policy also cannot narrow a practitioner's duties under legislation, registration standards or professional codes.

Three document types do different work:

DocumentThe question it answersExample
PolicyWhat is the practice's rule, purpose and accountability?All clinical information received by the practice is reviewed and acted on in a timely way.
ProcedureWho does what, in which order, including exceptions and escalation?Incoming results are routed to the requesting clinician, covered during absence, actioned and documented.
Work instruction or checklistHow is one task completed in a specific system or setting?Reconcile the unreviewed-results queue at the end of each day.

Keep the policy stable and the procedure specific enough to guide work. Put screen-by-screen instructions in a linked work instruction so a software change does not force a rewrite of the clinical rule.

Build one controlled policy register

Start with an inventory rather than an empty template. Record every policy, procedure, plan, form, register and staff checklist that the practice expects people to use. Then group them around the risks and services they control.

Control areaTopics commonly neededEvidence that the system is operating
Clinical care and follow-upTriage, informed consent, results, recalls and reminders, referrals, handover, prescribing, clinical recordsAssigned queues, review notation, contact attempts, handover records, audits
Patient rights and communicationPrivacy, collection notices, costs, interpreters, complaints, open disclosure, patient access and correctionPublished information, complaint log, response records, patient feedback
Information and technologyAccess control, digital communication, My Health Record, cyber incidents, backups, remote access, suppliers, clinical artificial intelligenceAccess register, audit logs, training, restore tests, incident reviews
Workforce and workplaceInduction, role competency, work health and safety, violence and aggression, confidentialityPosition descriptions, competency records, training and hazard logs
Clinical environmentInfection prevention, vaccine storage, emergency response, equipment and medicinesChecklists, temperature records, servicing, drills and breach records
Governance and continuityDocument control, risk, incidents, business continuity, quality improvementPolicy register, risk register, meeting actions, tests and improvement plans

You do not need a separate policy for every row. One controlled document can cover related processes if its scope and owners are clear. Keep externally maintained standards and legislation as references. Do not save an editable copy and treat it as your controlled source of truth.

For each internal document, the register should show:

  • document title and unique identifier
  • owner, clinical reviewer where relevant, and approver
  • current version, effective date and next review date
  • staff or roles affected
  • linked forms, registers, systems and external sources
  • training or acknowledgement required
  • status, including draft, current or retired
  • location of the approved copy and archived versions.

For general practices applying the RACGP sixth edition, Criterion F1.D makes document control explicit. It requires policies, procedures and operational documents to be current, accurate and accessible, reviewed at least every two years or sooner when circumstances require, with responsibility for sign-off and review assigned through version control. The full requirements sit in F1 defining and planning. Specialist and allied health practices can use the same register, but their required review cadence comes from the laws, standards, contracts and accreditation requirements that apply to their services.

Give every workflow an owner, a backup and an approver

“The practice” cannot receive an alert, cover annual leave or close an overdue task. Each procedure needs roles that can be mapped to named people on the roster.

RoleAccountability
Practice owner or governing bodyApproves the governance framework, resources and risk decisions that sit beyond delegated authority.
Clinical leadApproves clinical thresholds, decision rights, escalation paths and cover arrangements. Clinical judgement stays with an appropriately qualified clinician.
Practice manager or document controllerMaintains the register, coordinates drafting and review, publishes approved versions, withdraws old copies and keeps implementation evidence.
Workflow ownerMonitors whether the process works, reviews exceptions and reports unresolved risks.
Task ownerPerforms the assigned action by the due time and records the outcome in the designated system.
Backup or delegateTakes over when the primary owner is unavailable, with the same clear handover and recording requirements.
Privacy or security leadOversees access, privacy training, incidents and breach response. My Health Record roles must also reflect the organisation's formal responsible officer and organisation maintenance officer arrangements.

In a small clinic, one person may hold several roles. The separation still matters. It shows when that person is acting as document controller, clinical decision-maker or approver, and identifies where an independent check is needed.

Write procedures that work during a busy session

A useful procedure lets a trained team member find the right action quickly without guessing. Use the same structure throughout the manual:

  1. Trigger: what starts the procedure, such as an incoming result, patient complaint or staff departure.
  2. Scope and exclusions: which services, locations, systems and people it covers.
  3. Decision authority: who can make clinical, privacy, financial or employment decisions.
  4. Actions: short numbered steps, with the system of record named.
  5. Completion: what proves the work is finished.
  6. Escalation: the condition, destination, timeframe and backup route.
  7. Failure mode: what happens during absence, downtime or an unsuccessful contact attempt.
  8. Related material: current forms, registers, instructions and external guidance.

Before approval, walk through one ordinary case and one exception with the people who will use it. Ask them to locate the current document and act from it. If they create a side list, rely on memory or have to ask who is responsible, the procedure still has a design gap.

Use a closed-loop task and escalation model

An assigned task is still open. It closes only when the required action has occurred, the outcome is recorded and any follow-up is visible to the next responsible person.

Every clinical or operational task should carry:

  • a named owner and backup
  • a risk-based priority and due time
  • the expected action or outcome
  • the patient or operational context needed to act safely
  • a status that distinguishes new, accepted, in progress, waiting and completed
  • an escalation trigger for overdue, rejected, unclear or higher-risk work
  • a permanent record in the appropriate patient or business system.

The following is a risk-assessed operating model, not a set of universal clinical deadlines. Each practice must define timeframes and escalation destinations for its services and patient risks.

Task classTypical triggerFirst routeEscalate when
Immediate clinical riskA life-threatening result or person needing emergency responseResponsible clinician or designated urgent clinical contactThe contact does not acknowledge at once, the patient cannot be reached, or emergency action is required
Urgent, time-criticalA significant result, deteriorating patient message or urgent referral issueAssigned clinician or clinical delegateThe task nears its practice-defined deadline, the clinician is absent or the risk increases
Time-bound clinicalA recall, medication review, expected result or referral follow-upNamed clinical or administrative owner within delegated scopeThe expected item is missing, contact attempts fail or the due date passes
Routine operationalA form, stock check, training action or non-urgent correspondenceRelevant team queueThe task is overdue, blocked or exposes a recurring system gap

Do not make reception staff interpret clinical urgency beyond their training and delegated role. Give them observable triggers and a clear route to a clinician. A 2013 Australian study of 10 practices found that policies for same-day appointments were sometimes unclear, hard to find or replaced by informal staff systems. The useful lesson remains current: a written rule needs training, accessible decision support and an available escalation person.

Make results handling a visible, closed loop

Results management needs to account for received information, expected information that never arrives, clinician absence and failed patient contact. The RACGP sixth edition follow-up systems criterion sets out the core system: GPs review, notate, act on and incorporate clinical information into the patient record; the practice follows up missing results, documents patient contact attempts and manages high-risk results outside opening hours.

Closed-loop results workflow from expected result to recorded outcome, with escalation if contact fails

Build the procedure around these checkpoints:

  1. Set the expectation. Record the investigation, requesting clinician, expected result and follow-up plan. Tell the patient how and when results will be communicated, including normal results where applicable.
  2. Reconcile receipt. Identify expected results or correspondence that have not arrived. Do not rely only on the incoming inbox.
  3. Route with cover. Direct information to the requesting clinician or an authorised clinical delegate. Define cover for leave, part-time work and unexpected absence.
  4. Review and notate. The clinician records that the information was reviewed and assigns the required action and urgency.
  5. Communicate safely. Use the patient's appropriate contact channel and privacy-sensitive wording. Clinically significant information requires communication suitable to its seriousness and the patient's needs.
  6. Escalate failed contact. Set risk-based contact attempts and escalation. Record every attempt and the next decision rather than leaving an unstructured note.
  7. Close and audit. Record the outcome in the patient record. Reconcile unreviewed, unactioned and overdue items, and investigate recurring gaps.

High-risk results identified outside normal opening hours need their own policy. Give the practice's main diagnostic services a contact that can reliably receive and act on those results, and state what the clinician, delegate or after-hours service must communicate back to the practice.

Match system access to each role

For general practices, RACGP sixth edition Criterion F9.B requires unique individual identification and access according to a person's level of authorisation, with official documents stored securely. The Office of the Australian Information Commissioner (OAIC) also frames access security around “need to know” access, prompt revocation and monitoring in its security guidance.

Apply that principle across the clinical system, practice management system, shared mailboxes, secure messaging, document tools, My Health Record, templates, remote access and supplier support accounts:

  • give each person an individual account and prohibit shared credentials
  • grant the minimum permissions needed for the role
  • separate ordinary and administrator accounts
  • require multi-factor authentication where supported, especially for remote and privileged access
  • approve and log time-limited vendor access
  • review access when a person joins, changes role, goes on extended leave or leaves
  • revoke access promptly and recover practice devices at departure
  • retain logs and investigate unexpected access
  • review the access matrix on a risk-based schedule, with higher-risk and privileged access checked more often.

From 1 October 2026, organisations registered with My Health Record must comply with the My Health Records Rules 2026. Their security and access policy must be reviewed at least annually, as well as when material risks change or the System Operator requests it. The Australian Digital Health Agency provides the current security and access policy template, including user authorisation, deactivation, training and record-keeping requirements.

Set review dates by requirement and risk

A single annual review date for the whole manual creates a rushed audit and allows high-risk procedures to drift. Use rolling reviews and event triggers.

Document or controlBaseline cadenceReview earlier when
Policies, procedures and operational documents in a general practice applying RACGP sixth edition F1.DAt least every two yearsLaw, standards, services, systems, staffing or risk changes
My Health Record security and access policyAt least annually for registered organisationsA material risk changes or the System Operator requests review
High-risk clinical workflows, access permissions and incident plansPractice-defined, commonly every 6 to 12 months as a risk controlAn incident, near miss, failed audit, complaint, system change or staff change occurs
Emergency, downtime, restore and breach response proceduresTest on a practice-defined schedule, commonly annuallyA test or real event shows a gap, contacts change or dependencies change
Work instructions tied to softwareAt release or process changeScreens, permissions, integrations or vendors change

The six-to-twelve-month and annual testing cadences above are operational recommendations. Set them through the practice's risk assessment rather than presenting them as universal legal requirements.

For every scheduled review, record the source changes checked, staff consulted, incidents considered, decision made and approver. A “reviewed, no change” decision still needs a dated record.

Put digital tools inside the procedure

Software can make a controlled process easier to run, but its status indicators and audit logs need defined meaning. The practice must decide which system is the source of truth, who reviews exceptions and what evidence shows completion.

In Lyrebird, shared templates and centralised user management can support consistent documentation and access administration. Document Sorter extracts and matches incoming documents, keeps a human review step before filing and records each send. That log can evidence routing, but it does not prove that a clinician reviewed or acted on the clinical content. The results procedure still needs clinical review, follow-up and closure in the patient record.

The same boundary applies to clinical artificial intelligence (AI). Lyrebird creates draft clinical notes for clinician review and editing. Your policy should cover approved uses, patient communication or consent where required for the workflow, access, quality checks, incident reporting and clinician sign-off. Our Australian healthcare AI policy template gives this newer control area a separate, detailed starting point.

Use current Australian templates as starting points

Practices searching for a medical practice policies and procedures free download should start with the organisation that owns the relevant standard or rule. Download the current source and adapt it. Do not reproduce an old manual or adopt placeholders without checking the workflow on the floor.

Official resourceUse it forAdaptation still required
RACGP policy and procedure templatesPrivacy, confidentiality, internet and email, eHealth, patient feedback, infection-control competency and selected prescribing topicsPractice scope, state or territory duties, current sixth edition changes, owners, systems and escalation
RACGP privacy policy templatePatient-facing privacy policy under the Australian Privacy PrinciplesActual collection, storage, access, disclosure, complaints and overseas handling processes; keep the collection notice distinct
My Health Record policy templateSecurity and access policy for registered healthcare provider organisationsYour access method, responsible roles, user lifecycle, training, controls and linked policies
OAIC data breach response guideResponse roles, escalation, assessment, notification, records and post-incident reviewPractice contacts, decision authority, suppliers, insurer and other reporting obligations. The OAIC says this guide is being updated to reflect changes to the Privacy Act 1988 made by the Privacy and Other Legislation Amendment Act 2024, including Division 5 of Part IIIC, which commenced on 11 December 2024. Current legislation and OAIC updates govern legal assessment and notification.
National vaccine storage resourcesCold-chain procedures, breach actions, checks and temperature recordsEquipment, staff roles, local health department contacts and service-specific logistics

Check every downloaded document against the sixth edition Standards and mapping. The RACGP's general template page still refers to fifth edition accreditation, so its files are inputs to your controlled set rather than finished sixth edition policies.

Put the operating system in place over 30 days

Days 1 to 5: inventory. List controlled documents and unofficial workarounds. Identify duplicates, missing owners, broken links and procedures that no longer match practice.

Days 6 to 10: prioritise. Rank documents by patient harm, privacy exposure, legal or accreditation requirement, and frequency of use. Assign owners, clinical reviewers, backups and approvers.

Days 11 to 20: repair the highest-risk loops. Start with results and recalls, urgent task escalation, information access and incident response, adjusted for the practice's own risk profile. Write the normal route and the failure route.

Days 21 to 25: test and train. Run realistic scenarios with the people who do the work. Confirm that they can find the current version, use the systems, recognise their limits and escalate without delay.

Days 26 to 30: approve and control. Publish read-only current versions, withdraw superseded copies, record training, schedule rolling reviews and add unresolved risks to the practice's improvement plan.

A useful manual is visible in daily work: tasks have owners, results close safely, access follows roles and changes trigger review. Lyrebird can support controlled documentation and document handling while clinicians retain review and sign-off.

Contact us

Keep reading

All posts
Questions about compliance?