Pressures on healthcare technology
Protect patient information without slowing clinical work.
Clinicians need systems that are available and simple. Patients need their information kept private.
Technology controls support your obligations; they do not by themselves create legal compliance.
What success looks like
Secure, available technology that supports care rather than interrupting it
- Patient information access controlled and auditable
- Reliable systems during clinical hours
- Fast onboarding and clean offboarding of staff
- Shared and mobile devices managed securely
- Security evidence ready for accreditation reviews
- Support that understands clinical priorities
The plan
A simple plan to get there
- 1
Understand
We assess your environment, risks and business priorities.
- 2
Fix
We resolve the underlying problems and establish a secure, modern foundation.
- 3
Improve
We manage, monitor and continuously improve your technology environment.
How healthcare providers use Microsoft 365
Australian general practices, specialist and allied health providers, dental, psychology, radiology, pathology, day hospitals, Aboriginal Community Controlled Health Organisations, disability and care providers, medical groups and franchise networks all rely on Microsoft 365 for Outlook and Exchange Online, Microsoft Teams, SharePoint, OneDrive, Microsoft Entra ID and Microsoft Intune. Shared mailboxes, referral communication, rostering, internal collaboration, document storage, mobile access, telehealth administration, finance, payroll and clinical-system integrations all sit on or connect to Microsoft 365.
Microsoft 365 may contain patient-related, employee, financial, referral and operational information even when the organisation's primary clinical records live in a separate practice-management or clinical system.
Having Microsoft 365 licences does not mean the environment is securely configured, monitored, properly governed or aligned with the organisation's privacy obligations. A Microsoft 365 environment can appear functional while still containing serious security, permission and information-governance gaps.
Healthcare technology risks
Healthcare providers face a distinctive combination of clinical, operational and information-security risks. Common Microsoft 365 exposures include:
Understanding Australian Healthcare Privacy and Security Obligations
The obligations that apply to any specific healthcare provider depend on the services delivered, the location, contracts, systems in use and participation in government health programs. The following is general information and is not legal advice.
Privacy Act 1988
Organisations providing a health service and holding health information are generally covered by the Privacy Act, including qualifying small healthcare businesses. Health information is treated as sensitive information and requires privacy governance, appropriate collection practices, purpose-limited use, access controls, information accuracy, secure handling, patient access and correction processes, appropriate retention, secure destruction, privacy policies, staff awareness and third-party oversight.
Australian Privacy Principles
- APP 1 — Open and transparent management: Privacy governance, documented security responsibilities, Microsoft 365 governance documentation, policy management and clear accountability.
- APP 6 — Use and disclosure: Role-based access, external-sharing restrictions, guest-user governance, DLP, sensitivity labels, mail-flow controls, audit logs and access reviews.
- APP 8 — Cross-border disclosure: Review of where information is stored and accessed, third-party assessments, overseas guest control, Conditional Access, geographic access policies and vendor reviews. Data location requirements only apply where a specific obligation establishes them.
- APP 11 — Security of personal information: Reasonable steps mapped to MFA, Conditional Access, PIM, device compliance, encryption, anti-phishing, Defender, logging, monitoring, backup, incident response, vulnerability management, secure offboarding and retention. What is reasonable depends on the organisation's size, risks and circumstances.
- APP 12 and APP 13 — Access and correction: Information classification, search, retention and access controls support access and correction requests, but do not replace the provider's formal privacy request process.
Notifiable Data Breaches scheme
An eligible data breach may require notification to affected individuals and the Office of the Australian Information Commissioner. Mycelium 365 supports breach readiness through security monitoring, centralised audit logging, alert investigation, incident triage, preservation of technical evidence, compromised-account containment, device isolation, session revocation, credential resets, impact investigation, documentation and coordination with your legal, privacy and executive teams. Mycelium 365 does not make the legal determination about whether a breach is notifiable.
My Health Records Act and Rules
Providers participating in My Health Record have additional obligations, including a written security and access policy, defined roles, authorised-user management, staff policy communication and enforcement, access control, user identity management, records of enforcement, security measures protecting health information, access review as staff roles change, prompt removal of access, incident management and appropriate training. Mycelium 365 supports the Microsoft 365 and identity components; the healthcare organisation remains responsible for its My Health Record registration, clinical-system configuration, policies, training and compliance decisions.
Healthcare Identifiers framework
Participating providers may also have responsibilities relating to healthcare identifiers and the systems that use them. Microsoft 365 is not itself a Healthcare Identifiers Service or a clinical identity platform.
State and territory requirements
State and territory health-records, privacy, public-sector and records-management laws may also apply — for example additional obligations for Victorian and New South Wales providers, public health services, government-contracted providers, providers handling state health records, and providers operating across multiple jurisdictions. A single national Microsoft 365 configuration cannot be presented as satisfying every state or territory law. Each provider should confirm its applicable requirements with qualified privacy and legal advisers.
Essential Eight and other security frameworks
The Australian Cyber Security Centre's Essential Eight is a cybersecurity baseline rather than a healthcare privacy law. Mycelium 365 uses it as a practical reference for application control, patch management, Microsoft Office macro controls, user application hardening, administrative privilege restrictions, operating-system patching, multi-factor authentication and regular backups. Essential Eight maturity does not automatically establish Privacy Act or healthcare compliance.
How Mycelium 365 supports compliance
A summary of how Microsoft 365 controls and Mycelium 365 services align with common healthcare requirements. This mapping is illustrative — each provider's obligations should be confirmed with qualified advisers.
| Requirement or risk | Framework | Microsoft 365 control | Mycelium 365 service | Customer responsibility | Evidence |
|---|---|---|---|---|---|
| Privacy governance (APP 1) | Privacy Act / APPs | Governance documentation, policy templates, security responsibility matrix | Microsoft 365 governance review, policy templates, scheduled security reviews | Legal interpretation, privacy policy approval, executive risk acceptance | Configuration documentation, review records, risk and remediation register |
| Identity and access (APP 6, APP 11) | Privacy Act / My Health Records Rules | MFA, Conditional Access, RBAC, PIM, access reviews | Identity design, access reviews, guest-user reviews, privileged access management | Approving roles, staff conduct, authorised-user decisions | Access-review reports, sign-in logs, Conditional Access configuration, remediation records |
| Onboarding and offboarding | My Health Records Rules / APP 11 | Standardised account lifecycle, session revocation, device recovery | Ticketed onboarding and offboarding, mailbox retention, licence changes | HR notifications, approval workflows, contractor management | Service tickets, approval records, offboarding and account-status reports |
| Device security (APP 11) | Privacy Act / Essential Eight | Intune, encryption, compliance policies, endpoint protection, MAM | Intune administration, patching, endpoint protection, BYOD controls, remote wipe | Device procurement decisions, workforce mobility policy | Device compliance and encryption reports, patch status, endpoint alerts |
| Information protection (APP 6, APP 11) | Privacy Act | Sensitivity labels, DLP, retention, sharing controls, audit | Label rollout, DLP tuning, permission reviews, SharePoint remediation | Information classification decisions, records retention approval | DLP alerts, sharing and label usage reports, permission reviews |
| Email security | Essential Eight / APP 11 | Anti-phishing, Safe Links, Safe Attachments, domain authentication | Defender for Office configuration, mail-flow monitoring, forwarding detection | Approving mail-flow rules, communicating with staff | Threat and quarantine reports, mail-flow configuration, investigation records |
| Backup and recovery | APP 11 / Business continuity | Independent Microsoft 365 backup and recovery testing | Backup for Exchange Online, SharePoint, OneDrive and Teams-related data | Approving retention periods and restoration decisions | Backup status, failed-job alerts, recovery-test and restoration records |
| Security monitoring and incident response | Notifiable Data Breaches / APP 11 | Defender, identity risk, endpoint alerts, SOC monitoring | Managed SOC, alert triage, containment, evidence preservation, reporting | Legal determination of notifiability, patient communication, regulator engagement | Alert records, incident timelines, investigation and remediation reports |
| Retention and secure disposal (APP 11) | Privacy Act / State health records laws | Retention policies, secure decommissioning, device wipe | Retention configuration, account decommissioning, redundant-data identification | Lawful retention periods, destruction approval, clinical-record retention | Retention configuration records, decommissioning tickets |
| Business continuity | APP 11 / Clinical governance | Backup, identity recovery, service continuity procedures | Documented recovery playbooks, administrative-access recovery, incident communication | Clinical downtime procedures, patient-safety planning | Continuity documentation, incident post-reviews |
What our managed Microsoft 365 service includes
An ongoing management, security, cybersecurity and continuous-improvement program for healthcare — not one-off technical support.
Microsoft 365 administration
- Users, licences, Exchange Online and Teams
- SharePoint, OneDrive and Entra ID
- Intune and security configuration
- Administrator governance and service health
- Change management
Identity and access management
- Multi-factor authentication and Conditional Access
- Privileged access and risk-based controls
- Guest access and access reviews
- Geographic restrictions
- Passwordless authentication readiness
User onboarding and offboarding
- Standardised account creation and role-based licensing
- Device setup and secure access configuration
- Timely account disablement and session revocation
- Mailbox retention and file ownership transfer
- Device recovery procedures
Device management
- Microsoft Intune for Windows, macOS, iOS and Android
- Compliance, encryption and screen-lock controls
- Patching and endpoint protection
- Mobile application protection and BYOD controls
- Remote wipe and lost-device response
Information protection
- Sensitivity labels and data loss prevention
- Retention policies and external-sharing restrictions
- SharePoint and OneDrive permission reviews
- Audit logging and secure email controls
- Download restrictions where appropriate
Email and collaboration security
- Anti-phishing, Safe Links and Safe Attachments
- Impersonation protection and domain authentication
- Mail-flow monitoring and suspicious forwarding detection
- Shared-mailbox governance
- Referral and inter-provider communication protection
Cybersecurity monitoring and SOC
- Microsoft Defender and identity-risk monitoring
- Endpoint alert monitoring
- Managed SOC options and incident triage
- Containment and evidence preservation
- Incident documentation and reporting
Backup and recovery
- Independent Microsoft 365 backup
- Exchange Online, SharePoint, OneDrive and Teams protection
- Recovery testing and restoration procedures
- Long-term retention options
- Protection against ransomware and accidental deletion
Reporting and governance
- Monthly service and security posture reporting
- Access and device-compliance reviews
- Risk register and remediation tracking
- Licence optimisation and technology roadmap
- Executive reporting
Healthcare-specific use cases
Microsoft Copilot and AI governance
Copilot and other AI tools can expose overshared or poorly governed information. Mycelium 365 helps healthcare providers prepare responsibly by:
General-purpose Microsoft 365 Copilot should not be used to make clinical diagnoses or independently determine patient treatment.
Why Mycelium 365
Mycelium 365 helps Australian healthcare providers translate privacy, cybersecurity and operational requirements into practical Microsoft 365 controls. We manage the technology, monitor its security and provide evidence and reporting, while your organisation retains responsibility for clinical governance, legal interpretation and regulatory accountability.
- Australian on-the-ground resources
- Security by design
- Managed services rather than reactive support
- Microsoft 365 and managed cybersecurity expertise
- Managed SOC capability
- Compliance-supporting technical controls
- Clear evidence and reporting
- Multi-clinic delivery
- Business and operational understanding
- Continuous improvement and practical risk management
Our service approach
A repeatable five-step model that scales from a single practice to a multi-clinic healthcare group.
Discover
- •Microsoft 365 environment, users, devices and administrators
- •Licences, sharing, security controls and backups
- •Clinical integrations and My Health Record participation
- •Regulatory, contractual and policy context
Assess
- •Risk findings and control-gap analysis
- •Priority remediation plan
- •Responsibility matrix
- •Compliance-support mapping and roadmap
Secure
- •Identity, device, email and information controls
- •Backup, logging and monitoring
- •Administrative governance
- •Documented configurations and evidence
Manage
- •Administration, support and onboarding/offboarding
- •Monitoring, incident response and backup oversight
- •Reporting and policy-control reviews
- •Multi-clinic coordination
Improve
- •Security and compliance-support reviews
- •Trend analysis and remediation tracking
- •Licence optimisation and user feedback
- •Technology roadmap and continuous improvement
Is your Microsoft 365 environment protecting patient information?
A Microsoft 365 environment can operate normally while still containing serious gaps in identity security, device management, external sharing, backup, monitoring and governance.
Mycelium 365 can review your healthcare environment, map relevant controls to your operational and regulatory requirements and provide a prioritised improvement roadmap.
Frequently asked questions
Does the Privacy Act apply to small medical practices?+
Organisations that provide a health service and hold health information are generally covered by the Privacy Act 1988, including many small healthcare businesses that would otherwise be exempt. Health information is treated as sensitive information and attracts stronger handling obligations. Providers should confirm their specific position with qualified privacy or legal advisers.
What are the Australian Privacy Principles?+
The Australian Privacy Principles (APPs) are the thirteen principles in the Privacy Act that govern how organisations handle personal information — including how it is collected, used, disclosed, stored, secured, accessed and corrected. For healthcare providers, APPs 1, 6, 8, 11, 12 and 13 are particularly relevant to Microsoft 365 configuration and governance.
How does APP 11 apply to Microsoft 365?+
APP 11 requires organisations to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. In Microsoft 365 this typically maps to multi-factor authentication, Conditional Access, privileged access management, device compliance, encryption, anti-phishing protection, Defender, logging, monitoring, backup, incident response, vulnerability management, secure offboarding and retention. What is reasonable depends on the organisation's size, risks, systems and circumstances.
What is the Notifiable Data Breaches scheme?+
The Notifiable Data Breaches (NDB) scheme requires organisations covered by the Privacy Act to notify affected individuals and the Office of the Australian Information Commissioner when an eligible data breach occurs. Mycelium 365 supports NDB readiness through monitoring, alert investigation, incident triage, evidence preservation, account containment and coordination with your legal, privacy and executive teams — while the legal determination of whether a breach is notifiable rests with the provider and its advisers.
What Microsoft 365 controls support healthcare privacy?+
Key controls include identity security (MFA and Conditional Access), device compliance through Microsoft Intune, sensitivity labelling and data loss prevention, external sharing controls, anti-phishing and impersonation protection in Exchange Online, audit logging, security monitoring through Microsoft Defender, and independent backup of Microsoft 365 data.
Can Mycelium 365 guarantee Privacy Act compliance?+
No technology provider can independently guarantee an organisation's legal compliance. Compliance depends on the healthcare provider's policies, staff practices, clinical systems, contracts, information handling and governance. Mycelium 365 implements and operates Microsoft 365 controls that support applicable requirements and provides evidence to assist with governance, audits and ongoing reviews.
What are the My Health Record security requirements?+
Providers participating in My Health Record must maintain a written security and access policy, define roles and responsibilities, manage authorised users, control access, keep records of enforcement, review access when roles change, promptly remove access, manage incidents and provide appropriate training. Mycelium 365 supports the Microsoft 365 and identity components of these obligations while the provider retains responsibility for its My Health Record participation, clinical-system configuration and policies.
Do medical practices need independent Microsoft 365 backups?+
Microsoft provides service availability and short-term retention, but this is not a substitute for independent backup. A dedicated Microsoft 365 backup service protects Exchange Online, SharePoint, OneDrive and Teams-related data against accidental deletion, ransomware, malicious activity and long-term recovery needs.
How should healthcare providers manage staff access?+
Access should be role-based, granted only for as long as needed, protected by multi-factor authentication and Conditional Access, and reviewed regularly. Onboarding and offboarding should be standardised, with timely disablement, session revocation and evidence of the change. This supports both APP 11 and My Health Record participation requirements.
Can Microsoft Intune protect clinician devices?+
Microsoft Intune can enforce encryption, screen-lock, compliance and update policies on Windows, macOS, iOS and Android devices, deploy applications, protect data in mobile apps for both corporate and personal devices, and support remote wipe of lost or stolen devices used by clinicians.
Can you support multiple clinics?+
Yes. Mycelium 365 can standardise Microsoft 365 administration, device management, identity, security and support across multiple clinics and franchise networks — with consistent policies, common reporting and coordinated response, while recognising legitimate differences between locations.
Can you help with Microsoft Copilot governance?+
Yes. Mycelium 365 reviews SharePoint and OneDrive permissions, remediates oversharing, applies data classification, helps develop AI acceptable-use policies, addresses privacy impact considerations, manages licences and monitors adoption so Copilot can be introduced without exposing poorly governed information. General-purpose Copilot should not be used to make clinical diagnoses or independently determine patient treatment.
Can you work with our clinical software provider?+
Microsoft 365 can be managed alongside practice-management and clinical systems. Mycelium 365 reviews integrations for identity, security, access and data-protection risks so those systems remain safely connected, while the clinical vendor remains responsible for its own software and configuration.
What evidence can you provide for audits and reviews?+
Depending on the services engaged, Mycelium 365 can provide access-review reports, sign-in and audit logs, Conditional Access configuration, device compliance and patch status, DLP and sharing reports, backup and recovery-test records, incident timelines, remediation records and monthly service reporting.
Does Essential Eight equal healthcare compliance?+
No. The Australian Cyber Security Centre's Essential Eight is a cybersecurity baseline, not a healthcare privacy law. It is a useful reference for controls such as MFA, patching, macro settings, application control, administrative privilege restrictions and backups, but Essential Eight maturity does not automatically establish Privacy Act or healthcare compliance.
Do state privacy laws also apply?+
Yes, potentially. State and territory health-records, privacy, public-sector and records-management laws can apply in addition to the Privacy Act — for example in Victoria, New South Wales and the ACT, and for public health services or government-contracted providers. Each provider should confirm applicable requirements with qualified privacy and legal advisers.
