Services › Service Packages

Service Packages

Assessment, policies, and vendor risk reviews bundled into a single fixed-fee engagement — with meaningful savings compared to purchasing individually.

Both packages are coordinated end-to-end, so findings from the Health Check directly inform the policy customisation and the vendor prioritisation. You get a more complete picture — and a clear roadmap — rather than three separate engagements running in isolation.

Why bundle?

The services in each package are designed to build on each other — so you get more value from them together than you would running them separately.

Coordinated findings

The Security Health Check identifies gaps; the policies address them. The vendor assessment targets the providers flagged in the health check — not just any three.

One scoping call

We gather what we need to know about your practice once, upfront — not three separate discovery conversations.

Clear savings

The Starter saves $300–$500 and the Complete saves $1,000–$1,400 compared to purchasing the same services individually.

Choose your package

Two options designed for different practice sizes and coverage needs.

Practice Security Starter

Everything a small practice needs to get the fundamentals right.

From $2,000 ex GST

Saves $300–$500 vs. purchasing separately

What's included

Security Health Check
  • Pre-assessment questionnaire
  • 60–90 minute assessment session
  • Detailed report covering 9 security domains
  • Prioritised recommendations
  • Delivery walkthrough call
Core Policy Pack (5 policies)
  • Acceptable Use Policy
  • Password & Authentication Policy
  • Data Breach Response Plan
  • Privacy Policy (patient-facing)
  • Staff Offboarding Security Checklist

Best for: Solo GPs, small practices (1–4 practitioners), allied health practices.

Typical timeline: 3–4 weeks from scoping call to completion.

Comprehensive

Practice Security Complete

Comprehensive coverage for practices that want to address security, compliance, and vendor risk in one engagement.

From $4,200 ex GST

Saves $1,000–$1,400 vs. purchasing separately

What's included

Security Health Check
  • Pre-assessment questionnaire
  • 60–90 minute assessment session
  • Detailed report covering 9 security domains
  • Prioritised recommendations
  • Delivery walkthrough call
Extended Policy Pack (13 policies)
  • Acceptable Use Policy
  • Password & Authentication Policy
  • Data Breach Response Plan
  • Privacy Policy (patient-facing)
  • Staff Offboarding Security Checklist
  • Access Control Policy
  • Backup & Recovery Policy
  • Remote Access & Telehealth Security Policy
  • Vendor & Third-Party Management Policy
  • Physical Security Policy
  • Incident Response Plan
  • BYOD (Bring Your Own Device) Policy
  • Records Retention & Disposal Policy
Vendor Risk Assessment (3 vendors)
  • Full 7-dimension assessment per vendor
  • Individual vendor reports with risk ratings
  • Cross-vendor risk summary
  • Findings review call
Priority Recommendations Roadmap
  • Consolidated action plan across all three engagements
  • Ranked by priority and estimated effort
  • Identifies your highest-impact next steps across security, policy, and vendor risk

Best for: Medium practices (5–10+ practitioners), specialist practices, practices preparing for RACGP accreditation.

Typical timeline: 4–6 weeks from scoping call to completion.

All prices are fixed-fee and exclusive of GST. Final pricing is confirmed after a short scoping call based on practice size and complexity.

Not sure which package is right for your practice? Our free 15-minute scoping call will help you decide — no obligation.

What happens after the package

Both packages leave you with clear documentation, a prioritised roadmap, and — where relevant — implemented policies your team can use immediately. We don't disappear after delivery.

Annual policy reviews

Policies should be reviewed at least annually. We offer ongoing reviews to keep your documentation current as regulations and your practice evolve.

Staff security awareness

Once you have your policies in place, the next step is making sure your team actually understands them. We offer practical staff awareness sessions tailored to clinical and administrative roles.

Incident response support

If something goes wrong after your package is complete, we can provide hands-on breach response support — including OAIC notification assistance.

Additional vendor assessments

Assess more vendors as you onboard new software or as your existing contracts come up for renewal. Per-vendor pricing applies.

Not sure which package fits?

A free 15-minute scoping call is the best place to start. We'll understand your practice, recommend the right option, and give you a fixed quote — no obligation.

Or send us a message if you have questions before booking.

Frequently asked questions

Can I customise what's in a package?

Yes — these are starting configurations. If you'd like to swap the Core Policy Pack for the Extended, add more vendors, or adjust scope in another way, we can quote accordingly. Get in touch or mention it on the scoping call.

Do all the services run at the same time?

Typically sequentially, not simultaneously. The Health Check usually runs first — its findings inform which policies to prioritise and which vendors to assess. This adds a few weeks to the overall timeline but significantly improves the value of each deliverable.

Is there a payment schedule?

Yes. For bundled packages we typically invoice in two stages — 50% on commencement and 50% on delivery. We can discuss payment terms on the scoping call.

What if my practice is in a different city?

All services can be delivered remotely via video call. Onsite visits are available in the Adelaide metropolitan area. Travel to other locations can be arranged for an additional fee — ask on the scoping call.

Can I start with just one service and add more later?

Absolutely. Many practices start with the Security Health Check to understand where they stand, then engage us for policies or vendor assessments as follow-on work. The bundle pricing applies when services are engaged together at the outset.

Have a question not answered here?

Get in touch