Clinic Policy Center
Our commitment to transparency, privacy, security, and accessibility.
Information Security Policy
Last Updated: June 14, 2026
Your Spine & Your Wellness is committed to protecting patient healthcare data, clinical applications, and physical IT assets from digital threats. Our information security management practices are aligned with the Australian Cyber Security Centre (ACSC) Essential Eight Framework.
1. Scope & Security Objectives
This policy establishes security baselines for all staff, clinical workstations, web applications, and database storage servers handling patient details.
2. Essential Eight Security Implementation
We target and implement security strategies within the Essential Eight maturity model:
- Application Control: Only pre-approved, digitally signed clinical applications and browsers are permitted to run on workstations holding patient data. Executables outside administrative clearance are blocked.
- Patch Applications: Clinical software, server operating systems, and website frameworks (Laravel, PHP runtimes) are kept up to date. Security updates are applied within 48 hours for critical vulnerabilities.
- Configure Microsoft Office/Document Settings: Macro execution in spreadsheets and document attachments is disabled across all clinic computers.
- User Application Hardening: Flash, Java, and other legacy web browser components are blocked. Browsers are configured to block ad networks and malicious scripts.
- Restrict Administrative Privileges: Administrative accounts are restricted to system configurations only. Routine tasks (billing, booking, clinical input) must be executed from standard user accounts. We enforce Role-Based Access Control (RBAC).
- Patch Operating Systems: Workstation and server OS security patches are applied systematically.
- Multi-Factor Authentication (MFA): MFA is enforced for all administrative and user logins to the clinic dashboard, email portals, and databases.
- Regular Backups: Automated backups of database tables and patient records are executed daily, encrypted in transit and at rest, and stored offline to ensure complete resilience against ransomware.
3. Physical IT Security
Workstations are locked automatically when inactive. Server hubs and hardware backups are stored inside locked cabinets accessible only by authorized practitioners.
4. Security Incident Reporting
All suspected data leaks, weak credentials, or security incidents must be reported immediately to the Information Security Representative:
Security Officer
Your Spine & Your Wellness
Email: urspineurwellness@gmail.com
Phone: +61 430 665 005