A lot has been said publicly and written about over the past 12 months that has put the risk and effects of cyberattacks into the spotlight – and rightly so. In Australia alone, several large-scale attacks were a part of a 26% increase in total notifiable breaches to the Office of the Australian Information Commissioner (OAIC). Of those, healthcare service providers made up the largest industry sector of notifiable breaches which has consistently been the case for the past 5 years.
Image: Notifiable data breaches report July to December 2022, Office of the Australian Information Commissioner (OAIC)
Despite this significance, we are still consistently seeing pharmacy small businesses not taking the adequate steps to protect themselves and their patients’ data.
But to give most pharmacy owner’s some credit, this often isn’t out of negligence or spite. Because if there’s one good outcome to come from the widely publicised data breaches that have occurred here in Australia, it is that people are now more vigilant, and businesses are finally reaching out for advice.
So rather than me going on about the impacts I think it’s important to share some simple steps you can take now to ensure your pharmacy is as protected as possible from potential cyber attacks.
1. Develop awareness in your team and understand the risks
Make awareness and training a part of your staff onboarding requirements. This includes understanding of phishing and scams. The Australian Digital Health Agency has some great eLearning materials that all staff should undertake
2. Ensure all hardware, operating systems and devices are up-to-date
This is by far the easiest step to implement – but often the one that gets most overlooked. As the old saying goes – ‘you’re only as strong as your weakest link’ so ensure this is done on all your workstations, especially the server as well as portable devices such as tablets and laptops.
3. Use multi-factor authentication to protect your accounts
It can be frustrating at times, but a necessary step to ensuring security of key accounts. It may also be important to consider what staff need access to what accounts and creating multiple options (e.g. App, email & SMS) to avoid significant inconveniences.
4. Ensure all networks both local or cloud are secured
Your pharmacy should be running on its own private and secure network with limited access. Therefore, be careful when sharing or setting up guest/staff wifi access, your IT provider can assist with separating this.
5. Ensure multiple secure & accessible back up options are available
Don’t wait until it’s too late! This is also extremely important to be protected from natural disasters. Ensure you have set up regular, secure and Australian based offsite cloud back-ups. Keep in mind that most Dropbox, Google or Microsoft cloud drives are stored off-shore. Contact the Scrypt team if you are looking for competitive options.
6. If you fall victim to ransomware, seek legal advice
Paying a ransom is not recommended and does not guarantee your affected files will be recovered or avoid a data breach. If you’re considering the ransom necessary, seek legal advice.
On a final note, it is also important to encourage a positive security culture and to have a plan in place in case of emergency. If you’re yet to build your QCPP Data Recovery Plan and need assistance with certain cloud and back up options, reach out to the team at Scrypt to see if any of our cloud products are suitable for your business.

