Accreditation practice pointer: business continuity and information recovery
C6.4 D Our practice has a business continuity and information recovery plan.
RACGP Standards for general practice, 5th edition.
General practice needs to prepare for power outages, computer system crashes or other adverse events. This can be achieved by maintaining a business and continuity plan, which includes:
processes by which all critical information relating to the practice’s operations (such as appointments, billing and patient health information) will be frequently backed up
a schedule of regular tests so that backups are being correctly created and can be accessed and read as expected
details of the secure offsite location where backup information is stored
standard letters of agreement that external IT providers sign to indicate their commitment.
Practices might also keep a policy for the management of patient health information and undertake regular privacy training.
To meet the criterion, practices must:
operate a server backup log
maintain up-to-date antivirus protection and hardware/software firewalls
maintain a privacy policy.