BERRY GOVERNANCE & ADVISORY
info@berryadvisory.com.au

Privacy, security and AI obligations, in plain English.

I work with independent Canberra health practices to meet the obligations they already have — starting with a baseline assessment and a short list of what to fix first.

The small business exemption has never applied to health providers.

Most practices under $3 million in turnover assume the Privacy Act isn’t their problem. Health service providers are a specific exception: if you hold health information, all 13 Australian Privacy Principles apply to you, whatever your size. The ACT Health Records Act sits on top of that, with its own privacy principles and access requirements.

That means a privacy policy that meets APP 1, a process for responding to a data breach, security controls that stand up under APP 11, and — if you’re registered for My Health Record — a written security and access policy that addresses every matter the rules prescribe.

Most practices I speak to have some of this. Very few have all of it, and almost none have the records to show it.

There is now a date on it. The RACGP released the 6th edition of the Standards for general practice in August 2026, with significantly strengthened cyber security requirements — a named digital governance role, a cyber incident plan, broader ICT governance, and a criterion covering the safe use of AI tools. Accreditation is still assessed against the 5th edition while transition arrangements are settled, which makes the next twelve months the cheapest time to close the gap.

Where to start

A baseline assessment tells you where you actually stand. From there, we fix the gaps that matter and keep the position current — the same way you’d use an accountant, a quarter at a time.

Privacy & Security Baseline Assessment

$1,250 + GST

One 90-minute session at your practice, then a plain-English report within ten business days: every gap rated by risk and effort, a prioritised twelve-month plan, and a clear statement of what you’re already doing right.

Policy & Records Pack

from $3,500 + GST

The documents you’re required to hold, written for your practice rather than pulled off a shelf — privacy policy, collection notice, breach response plan, information security policy, records retention, My Health Record security and access policy, plus the training and offboarding records that prove they operate.

Governance Retainer

$1,750 + GST per quarter

A 60-minute review each quarter, your compliance register kept current, one policy refreshed, a short briefing on what’s changed in privacy and AI regulation, and priority triage if you ever have a suspected breach.

Fixed prices, quoted before work starts. No retainer minimum beyond the first year, and no charge for the first conversation.

Also available

AI governance for practices using scribes or other AI tools, ISO 27001 and ISO 42001 alignment, Essential Eight assessment, threat and risk assessments, staff awareness training, security questionnaire and tender support, and virtual CISO engagements for larger organisations.

Who you’d be working with

I’m Matt Berry. I work as a virtual CISO for private companies — the security and governance function for organisations that need the decisions made properly but can’t justify a full-time hire. Before that I spent more than a decade in cybersecurity, including Defence and national security, as a penetration tester and a governance and risk consultant.

That mix is the useful part here. I’ve tested systems, so I know which risks are real; I’ve written the governance, so I know what an auditor or a regulator will actually ask for; and I’ve sat in the chair making the call, so I won’t hand you a list and leave.

Practices your size get handed forty-page reports by firms that don’t service contracts under $15,000. I’d rather give you three things to do before we next speak, and tell you plainly which of them actually matters.

Start with a conversation

Tell me what your practice uses and what’s worrying you. The first conversation is free and takes about twenty minutes — if there’s nothing worth doing, I’ll say so.

info@berryadvisory.com.au
0400 199 546
Canberra, ACT