Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Healthcare

    Secure Microsoft 365 for Australian healthcare providers

    Secure, manage and monitor clinical Microsoft 365 environments under one governance model — without disrupting patient care.

    Pressures on healthcare technology

    Protect patient information without slowing clinical work.

    Clinicians need systems that are available and simple. Patients need their information kept private.

    Patient information exposuresensitive records reachable by too many people
    Clinical uptimesystems that must be available during care delivery
    Distributed workforcesmultiple sites, home visits and shared workstations
    Workforce turnoverconstant onboarding and offboarding of staff
    Device securityshared clinical devices and personal phones
    Jurisdictional requirementsdiffering obligations across regions

    Technology controls support your obligations; they do not by themselves create legal compliance.

    What success looks like

    Secure, available technology that supports care rather than interrupting it

    • Patient information access controlled and auditable
    • Reliable systems during clinical hours
    • Fast onboarding and clean offboarding of staff
    • Shared and mobile devices managed securely
    • Security evidence ready for accreditation reviews
    • Support that understands clinical priorities

    The plan

    A simple plan to get there

    1. 1

      Understand

      We assess your environment, risks and business priorities.

    2. 2

      Fix

      We resolve the underlying problems and establish a secure, modern foundation.

    3. 3

      Improve

      We manage, monitor and continuously improve your technology environment.

    On-the-ground resources across Australia
    Security by design
    Microsoft 365 specialists
    Managed cybersecurity and SOC services
    Healthcare-focused governance
    Compliance-supporting controls
    Multi-clinic support
    Clear security and service reporting

    How healthcare providers use Microsoft 365

    Australian general practices, specialist and allied health providers, dental, psychology, radiology, pathology, day hospitals, Aboriginal Community Controlled Health Organisations, disability and care providers, medical groups and franchise networks all rely on Microsoft 365 for Outlook and Exchange Online, Microsoft Teams, SharePoint, OneDrive, Microsoft Entra ID and Microsoft Intune. Shared mailboxes, referral communication, rostering, internal collaboration, document storage, mobile access, telehealth administration, finance, payroll and clinical-system integrations all sit on or connect to Microsoft 365.

    Microsoft 365 may contain patient-related, employee, financial, referral and operational information even when the organisation's primary clinical records live in a separate practice-management or clinical system.

    Having Microsoft 365 licences does not mean the environment is securely configured, monitored, properly governed or aligned with the organisation's privacy obligations. A Microsoft 365 environment can appear functional while still containing serious security, permission and information-governance gaps.

    Healthcare technology risks

    Healthcare providers face a distinctive combination of clinical, operational and information-security risks. Common Microsoft 365 exposures include:

    Phishing and credential theft
    Business email compromise
    Patient information sent to the wrong recipient
    Compromised shared mailboxes
    Unauthorised access to patient-related documents
    Former staff retaining access
    Excessive administrator privileges
    Personal devices accessing sensitive information
    Weak mobile-device controls
    Inconsistent onboarding and offboarding
    Uncontrolled external sharing and overshared SharePoint sites
    Unprotected email attachments and ransomware
    Accidental deletion and inadequate backups
    Unapproved cloud and AI applications
    Poor incident-response preparation
    Limited audit evidence and inconsistent controls between clinics

    Understanding Australian Healthcare Privacy and Security Obligations

    The obligations that apply to any specific healthcare provider depend on the services delivered, the location, contracts, systems in use and participation in government health programs. The following is general information and is not legal advice.

    Privacy Act 1988

    Organisations providing a health service and holding health information are generally covered by the Privacy Act, including qualifying small healthcare businesses. Health information is treated as sensitive information and requires privacy governance, appropriate collection practices, purpose-limited use, access controls, information accuracy, secure handling, patient access and correction processes, appropriate retention, secure destruction, privacy policies, staff awareness and third-party oversight.

    Australian Privacy Principles

    • APP 1 — Open and transparent management: Privacy governance, documented security responsibilities, Microsoft 365 governance documentation, policy management and clear accountability.
    • APP 6 — Use and disclosure: Role-based access, external-sharing restrictions, guest-user governance, DLP, sensitivity labels, mail-flow controls, audit logs and access reviews.
    • APP 8 — Cross-border disclosure: Review of where information is stored and accessed, third-party assessments, overseas guest control, Conditional Access, geographic access policies and vendor reviews. Data location requirements only apply where a specific obligation establishes them.
    • APP 11 — Security of personal information: Reasonable steps mapped to MFA, Conditional Access, PIM, device compliance, encryption, anti-phishing, Defender, logging, monitoring, backup, incident response, vulnerability management, secure offboarding and retention. What is reasonable depends on the organisation's size, risks and circumstances.
    • APP 12 and APP 13 — Access and correction: Information classification, search, retention and access controls support access and correction requests, but do not replace the provider's formal privacy request process.

    Notifiable Data Breaches scheme

    An eligible data breach may require notification to affected individuals and the Office of the Australian Information Commissioner. Mycelium 365 supports breach readiness through security monitoring, centralised audit logging, alert investigation, incident triage, preservation of technical evidence, compromised-account containment, device isolation, session revocation, credential resets, impact investigation, documentation and coordination with your legal, privacy and executive teams. Mycelium 365 does not make the legal determination about whether a breach is notifiable.

    My Health Records Act and Rules

    Providers participating in My Health Record have additional obligations, including a written security and access policy, defined roles, authorised-user management, staff policy communication and enforcement, access control, user identity management, records of enforcement, security measures protecting health information, access review as staff roles change, prompt removal of access, incident management and appropriate training. Mycelium 365 supports the Microsoft 365 and identity components; the healthcare organisation remains responsible for its My Health Record registration, clinical-system configuration, policies, training and compliance decisions.

    Healthcare Identifiers framework

    Participating providers may also have responsibilities relating to healthcare identifiers and the systems that use them. Microsoft 365 is not itself a Healthcare Identifiers Service or a clinical identity platform.

    State and territory requirements

    State and territory health-records, privacy, public-sector and records-management laws may also apply — for example additional obligations for Victorian and New South Wales providers, public health services, government-contracted providers, providers handling state health records, and providers operating across multiple jurisdictions. A single national Microsoft 365 configuration cannot be presented as satisfying every state or territory law. Each provider should confirm its applicable requirements with qualified privacy and legal advisers.

    Essential Eight and other security frameworks

    The Australian Cyber Security Centre's Essential Eight is a cybersecurity baseline rather than a healthcare privacy law. Mycelium 365 uses it as a practical reference for application control, patch management, Microsoft Office macro controls, user application hardening, administrative privilege restrictions, operating-system patching, multi-factor authentication and regular backups. Essential Eight maturity does not automatically establish Privacy Act or healthcare compliance.

    Disclaimer: This content provides general information about technology controls that may support healthcare privacy and cybersecurity obligations. It is not legal, regulatory or clinical advice. Healthcare providers should obtain advice appropriate to their organisation, jurisdiction and circumstances.

    How Mycelium 365 supports compliance

    A summary of how Microsoft 365 controls and Mycelium 365 services align with common healthcare requirements. This mapping is illustrative — each provider's obligations should be confirmed with qualified advisers.

    Requirement or riskFrameworkMicrosoft 365 controlMycelium 365 serviceCustomer responsibilityEvidence
    Privacy governance (APP 1)Privacy Act / APPsGovernance documentation, policy templates, security responsibility matrixMicrosoft 365 governance review, policy templates, scheduled security reviewsLegal interpretation, privacy policy approval, executive risk acceptanceConfiguration documentation, review records, risk and remediation register
    Identity and access (APP 6, APP 11)Privacy Act / My Health Records RulesMFA, Conditional Access, RBAC, PIM, access reviewsIdentity design, access reviews, guest-user reviews, privileged access managementApproving roles, staff conduct, authorised-user decisionsAccess-review reports, sign-in logs, Conditional Access configuration, remediation records
    Onboarding and offboardingMy Health Records Rules / APP 11Standardised account lifecycle, session revocation, device recoveryTicketed onboarding and offboarding, mailbox retention, licence changesHR notifications, approval workflows, contractor managementService tickets, approval records, offboarding and account-status reports
    Device security (APP 11)Privacy Act / Essential EightIntune, encryption, compliance policies, endpoint protection, MAMIntune administration, patching, endpoint protection, BYOD controls, remote wipeDevice procurement decisions, workforce mobility policyDevice compliance and encryption reports, patch status, endpoint alerts
    Information protection (APP 6, APP 11)Privacy ActSensitivity labels, DLP, retention, sharing controls, auditLabel rollout, DLP tuning, permission reviews, SharePoint remediationInformation classification decisions, records retention approvalDLP alerts, sharing and label usage reports, permission reviews
    Email securityEssential Eight / APP 11Anti-phishing, Safe Links, Safe Attachments, domain authenticationDefender for Office configuration, mail-flow monitoring, forwarding detectionApproving mail-flow rules, communicating with staffThreat and quarantine reports, mail-flow configuration, investigation records
    Backup and recoveryAPP 11 / Business continuityIndependent Microsoft 365 backup and recovery testingBackup for Exchange Online, SharePoint, OneDrive and Teams-related dataApproving retention periods and restoration decisionsBackup status, failed-job alerts, recovery-test and restoration records
    Security monitoring and incident responseNotifiable Data Breaches / APP 11Defender, identity risk, endpoint alerts, SOC monitoringManaged SOC, alert triage, containment, evidence preservation, reportingLegal determination of notifiability, patient communication, regulator engagementAlert records, incident timelines, investigation and remediation reports
    Retention and secure disposal (APP 11)Privacy Act / State health records lawsRetention policies, secure decommissioning, device wipeRetention configuration, account decommissioning, redundant-data identificationLawful retention periods, destruction approval, clinical-record retentionRetention configuration records, decommissioning tickets
    Business continuityAPP 11 / Clinical governanceBackup, identity recovery, service continuity proceduresDocumented recovery playbooks, administrative-access recovery, incident communicationClinical downtime procedures, patient-safety planningContinuity documentation, incident post-reviews

    What our managed Microsoft 365 service includes

    An ongoing management, security, cybersecurity and continuous-improvement program for healthcare — not one-off technical support.

    Microsoft 365 administration

    • Users, licences, Exchange Online and Teams
    • SharePoint, OneDrive and Entra ID
    • Intune and security configuration
    • Administrator governance and service health
    • Change management

    Identity and access management

    • Multi-factor authentication and Conditional Access
    • Privileged access and risk-based controls
    • Guest access and access reviews
    • Geographic restrictions
    • Passwordless authentication readiness

    User onboarding and offboarding

    • Standardised account creation and role-based licensing
    • Device setup and secure access configuration
    • Timely account disablement and session revocation
    • Mailbox retention and file ownership transfer
    • Device recovery procedures

    Device management

    • Microsoft Intune for Windows, macOS, iOS and Android
    • Compliance, encryption and screen-lock controls
    • Patching and endpoint protection
    • Mobile application protection and BYOD controls
    • Remote wipe and lost-device response

    Information protection

    • Sensitivity labels and data loss prevention
    • Retention policies and external-sharing restrictions
    • SharePoint and OneDrive permission reviews
    • Audit logging and secure email controls
    • Download restrictions where appropriate

    Email and collaboration security

    • Anti-phishing, Safe Links and Safe Attachments
    • Impersonation protection and domain authentication
    • Mail-flow monitoring and suspicious forwarding detection
    • Shared-mailbox governance
    • Referral and inter-provider communication protection

    Cybersecurity monitoring and SOC

    • Microsoft Defender and identity-risk monitoring
    • Endpoint alert monitoring
    • Managed SOC options and incident triage
    • Containment and evidence preservation
    • Incident documentation and reporting

    Backup and recovery

    • Independent Microsoft 365 backup
    • Exchange Online, SharePoint, OneDrive and Teams protection
    • Recovery testing and restoration procedures
    • Long-term retention options
    • Protection against ransomware and accidental deletion

    Reporting and governance

    • Monthly service and security posture reporting
    • Access and device-compliance reviews
    • Risk register and remediation tracking
    • Licence optimisation and technology roadmap
    • Executive reporting

    Healthcare-specific use cases

    Secure communication between clinics and locations
    Protection of referral information
    Securing shared reception and triage mailboxes
    Restricting access to sensitive patient-related documents
    Protecting mobile devices used by clinicians
    Onboarding locums and temporary staff
    Removing access when practitioners leave
    Supporting multiple clinic locations and franchise networks
    Protecting finance, payroll and Medicare-related administration
    Secure collaboration with external specialists, hospitals and pathology
    Reducing email-based fraud and impersonation
    Recovering accidentally deleted files and mailboxes
    Reviewing third-party clinical-system integrations
    Preparing for cyber incidents and notifiable data breaches
    Supporting practice acquisitions
    Establishing common controls across a healthcare group

    Microsoft Copilot and AI governance

    Copilot and other AI tools can expose overshared or poorly governed information. Mycelium 365 helps healthcare providers prepare responsibly by:

    SharePoint and OneDrive permission reviews and oversharing remediation
    Data classification and sensitivity labelling
    Acceptable-use policy for AI tools
    Privacy impact considerations and human oversight
    Third-party AI application controls
    Licence governance and pilot groups
    Staff training and adoption monitoring
    Restrictions on sensitive-information use with AI

    General-purpose Microsoft 365 Copilot should not be used to make clinical diagnoses or independently determine patient treatment.

    Why Mycelium 365

    Mycelium 365 helps Australian healthcare providers translate privacy, cybersecurity and operational requirements into practical Microsoft 365 controls. We manage the technology, monitor its security and provide evidence and reporting, while your organisation retains responsibility for clinical governance, legal interpretation and regulatory accountability.

    • Australian on-the-ground resources
    • Security by design
    • Managed services rather than reactive support
    • Microsoft 365 and managed cybersecurity expertise
    • Managed SOC capability
    • Compliance-supporting technical controls
    • Clear evidence and reporting
    • Multi-clinic delivery
    • Business and operational understanding
    • Continuous improvement and practical risk management

    Our service approach

    A repeatable five-step model that scales from a single practice to a multi-clinic healthcare group.

    1

    Discover

    • Microsoft 365 environment, users, devices and administrators
    • Licences, sharing, security controls and backups
    • Clinical integrations and My Health Record participation
    • Regulatory, contractual and policy context
    2

    Assess

    • Risk findings and control-gap analysis
    • Priority remediation plan
    • Responsibility matrix
    • Compliance-support mapping and roadmap
    3

    Secure

    • Identity, device, email and information controls
    • Backup, logging and monitoring
    • Administrative governance
    • Documented configurations and evidence
    4

    Manage

    • Administration, support and onboarding/offboarding
    • Monitoring, incident response and backup oversight
    • Reporting and policy-control reviews
    • Multi-clinic coordination
    5

    Improve

    • Security and compliance-support reviews
    • Trend analysis and remediation tracking
    • Licence optimisation and user feedback
    • Technology roadmap and continuous improvement

    Is your Microsoft 365 environment protecting patient information?

    A Microsoft 365 environment can operate normally while still containing serious gaps in identity security, device management, external sharing, backup, monitoring and governance.

    Mycelium 365 can review your healthcare environment, map relevant controls to your operational and regulatory requirements and provide a prioritised improvement roadmap.

    Frequently asked questions

    Does the Privacy Act apply to small medical practices?+

    Organisations that provide a health service and hold health information are generally covered by the Privacy Act 1988, including many small healthcare businesses that would otherwise be exempt. Health information is treated as sensitive information and attracts stronger handling obligations. Providers should confirm their specific position with qualified privacy or legal advisers.

    What are the Australian Privacy Principles?+

    The Australian Privacy Principles (APPs) are the thirteen principles in the Privacy Act that govern how organisations handle personal information — including how it is collected, used, disclosed, stored, secured, accessed and corrected. For healthcare providers, APPs 1, 6, 8, 11, 12 and 13 are particularly relevant to Microsoft 365 configuration and governance.

    How does APP 11 apply to Microsoft 365?+

    APP 11 requires organisations to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. In Microsoft 365 this typically maps to multi-factor authentication, Conditional Access, privileged access management, device compliance, encryption, anti-phishing protection, Defender, logging, monitoring, backup, incident response, vulnerability management, secure offboarding and retention. What is reasonable depends on the organisation's size, risks, systems and circumstances.

    What is the Notifiable Data Breaches scheme?+

    The Notifiable Data Breaches (NDB) scheme requires organisations covered by the Privacy Act to notify affected individuals and the Office of the Australian Information Commissioner when an eligible data breach occurs. Mycelium 365 supports NDB readiness through monitoring, alert investigation, incident triage, evidence preservation, account containment and coordination with your legal, privacy and executive teams — while the legal determination of whether a breach is notifiable rests with the provider and its advisers.

    What Microsoft 365 controls support healthcare privacy?+

    Key controls include identity security (MFA and Conditional Access), device compliance through Microsoft Intune, sensitivity labelling and data loss prevention, external sharing controls, anti-phishing and impersonation protection in Exchange Online, audit logging, security monitoring through Microsoft Defender, and independent backup of Microsoft 365 data.

    Can Mycelium 365 guarantee Privacy Act compliance?+

    No technology provider can independently guarantee an organisation's legal compliance. Compliance depends on the healthcare provider's policies, staff practices, clinical systems, contracts, information handling and governance. Mycelium 365 implements and operates Microsoft 365 controls that support applicable requirements and provides evidence to assist with governance, audits and ongoing reviews.

    What are the My Health Record security requirements?+

    Providers participating in My Health Record must maintain a written security and access policy, define roles and responsibilities, manage authorised users, control access, keep records of enforcement, review access when roles change, promptly remove access, manage incidents and provide appropriate training. Mycelium 365 supports the Microsoft 365 and identity components of these obligations while the provider retains responsibility for its My Health Record participation, clinical-system configuration and policies.

    Do medical practices need independent Microsoft 365 backups?+

    Microsoft provides service availability and short-term retention, but this is not a substitute for independent backup. A dedicated Microsoft 365 backup service protects Exchange Online, SharePoint, OneDrive and Teams-related data against accidental deletion, ransomware, malicious activity and long-term recovery needs.

    How should healthcare providers manage staff access?+

    Access should be role-based, granted only for as long as needed, protected by multi-factor authentication and Conditional Access, and reviewed regularly. Onboarding and offboarding should be standardised, with timely disablement, session revocation and evidence of the change. This supports both APP 11 and My Health Record participation requirements.

    Can Microsoft Intune protect clinician devices?+

    Microsoft Intune can enforce encryption, screen-lock, compliance and update policies on Windows, macOS, iOS and Android devices, deploy applications, protect data in mobile apps for both corporate and personal devices, and support remote wipe of lost or stolen devices used by clinicians.

    Can you support multiple clinics?+

    Yes. Mycelium 365 can standardise Microsoft 365 administration, device management, identity, security and support across multiple clinics and franchise networks — with consistent policies, common reporting and coordinated response, while recognising legitimate differences between locations.

    Can you help with Microsoft Copilot governance?+

    Yes. Mycelium 365 reviews SharePoint and OneDrive permissions, remediates oversharing, applies data classification, helps develop AI acceptable-use policies, addresses privacy impact considerations, manages licences and monitors adoption so Copilot can be introduced without exposing poorly governed information. General-purpose Copilot should not be used to make clinical diagnoses or independently determine patient treatment.

    Can you work with our clinical software provider?+

    Microsoft 365 can be managed alongside practice-management and clinical systems. Mycelium 365 reviews integrations for identity, security, access and data-protection risks so those systems remain safely connected, while the clinical vendor remains responsible for its own software and configuration.

    What evidence can you provide for audits and reviews?+

    Depending on the services engaged, Mycelium 365 can provide access-review reports, sign-in and audit logs, Conditional Access configuration, device compliance and patch status, DLP and sharing reports, backup and recovery-test records, incident timelines, remediation records and monthly service reporting.

    Does Essential Eight equal healthcare compliance?+

    No. The Australian Cyber Security Centre's Essential Eight is a cybersecurity baseline, not a healthcare privacy law. It is a useful reference for controls such as MFA, patching, macro settings, application control, administrative privilege restrictions and backups, but Essential Eight maturity does not automatically establish Privacy Act or healthcare compliance.

    Do state privacy laws also apply?+

    Yes, potentially. State and territory health-records, privacy, public-sector and records-management laws can apply in addition to the Privacy Act — for example in Victoria, New South Wales and the ACT, and for public health services or government-contracted providers. Each provider should confirm applicable requirements with qualified privacy and legal advisers.