fbpx

IT Foundations For The Future Of Digital Health

In today’s rapidly evolving healthcare landscape, cybersecurity is no longer optional, it’s essential. At our recent webinar, Rob Dawson, Myrtec’s Head of Business Development, unpacked the critical IT foundations that healthcare practices must adopt to stay secure, compliant, and future-ready.

Why Cybersecurity in Healthcare Matters More Than Ever

Healthcare practices are prime targets for cyber threats due to the sensitive nature of patient data. With increasing legal and financial risks, including potential personal liability for directors, robust cybersecurity is a business imperative. Rob highlighted how compliance with cybersecurity frameworks not only protects data but also ensures eligibility for cyber insurance, an increasingly vital safety net.

Comparing Cybersecurity Frameworks: DHA vs. Essential 8 vs. Myrtec Standards

1. Digital Health Agency (DHA) Cybersecurity Fundamentals

 

A solid starting point, DHA’s recommendations include:

  • Regular software updates
  • Strong passwords and multi-factor authentication (MFA)
  • Off-site data backups
  • Phishing awareness
  • Avoiding ransom payments

 

While foundational, these steps alone may not be sufficient for today’s threat landscape.

 
2. Essential 8 Framework by the Australian Cybersecurity Centre

 

Designed for broader business environments, the Essential 8 includes:

  • Application and OS patching
  • MFA enforcement
  • Admin privilege restrictions
  • Application control
  • Office macro restrictions
  • User application hardening
  • Regular backups

 

This framework operates on a maturity model, with Level 1 targeting large-scale attacks and Level 3 designed for government and enterprise environments.

 

3. Myrtec’s Minimum Standards

 

Tailored for small to medium healthcare practices, Myrtec’s standards bridge the gap between DHA and Essential 8. They include:

  • Business-grade antivirus and anti-malware
  • Device encryption
  • DMARC and SPF email security
  • Admin access restrictions
  • Up-to-date software
  • Australian data storage
  • Remote desktop disabling
  • Password managers
  • Ongoing compliance monitoring
     

These standards are dynamic, scalable, and designed to work with your existing tech stack.

Beyond Frameworks: Best Practices for Cyber Resilience

Rob also shared advanced strategies to further strengthen your cybersecurity posture:

 

  • Staff Training: Equip your team to spot phishing attempts and respond to incidents.
  • Mobile Device Management: Secure data on the go.
  • Data Loss Prevention: Monitor and restrict sensitive data movement.
  • Advanced Email Security: Protect against sophisticated email threats.
  • Conditional Access and Network Hardening: Use firewalls, VPNs, and access controls to safeguard your environment.

Actionable Steps for Healthcare Practices

 

To build a resilient cybersecurity foundation:

 

  • Request a cyber health audit from your IT provider
  • Ensure compliance with Myrtec’s minimum standards
  • Apply for cyber insurance
  • Provide regular staff training
  • Establish clear cybersecurity policies and procedures

Choosing The Right Framework

 

While DHA’s fundamentals are a good starting point, they’re not comprehensive enough for 2025. The Essential 8 offers depth but may be costly and complex. Myrtec’s minimum standards strike a practical balance: cost-effective, dynamic, and tailored to healthcare needs. Layering Essential 8 on top of Myrtec’s standards can further enhance your security posture.

Contact our team to discuss how the FLEX Managed Service Agreement can help you get your technical foundations right so that you have the cyber security tools in place to secure and grow your practice.