CertIQ
Cyber risk for healthcare providers

Health records are the most valuable stolen data there is — and the hardest to make right.

You cannot reissue someone's medical history. Health data sells for more than card data and the harm from disclosure is permanent, which is why the notification regime is strictest here and why insurers look closely at how patient systems are exposed.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways healthcare providers get hit.

01
Patient record exposure
Practice management and imaging systems reachable from the internet, frequently through a remote-support tool left switched on after an install.
02
Permanent, unremediable harm
A leaked diagnosis cannot be cancelled or reissued. Regulatory and reputational consequences run far longer than a card breach.
03
Connected device sprawl
Imaging and monitoring equipment running unsupported operating systems, attached to the same network as clinical records.
What we check first

The three that matter most for healthcare providers.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Exposed services
Open ports and remote access visible from the internet.
Forgotten systems
Subdomains and old hosts still attached to your domain.
Leaked passwords
Staff addresses appearing in public breach databases.
Where you stand

The obligations that apply to you.

My Health Records Act penalties apply on top of the Privacy Act, and health service providers are covered regardless of turnover — the small-business exemption does not apply.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

No exemption
Health providers are covered by the Privacy Act at any size

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.