Cyber Security Checklist for Pharmacies

Cyber security is no longer something only large organisations need to worry about.

Pharmacies hold sensitive patient information, process financial transactions and rely heavily on technology to deliver patient care. Ongoing cyber incidents affecting Australian pharmacies demonstrate that cybercriminals are increasingly targeting healthcare organisations through phishing attacks and compromised email accounts.

Use this checklist to help reduce cyber risk within your pharmacy.

Protect Your Email Accounts

Protect Your Email Accounts

Email remains the most common entry point for cyber attacks.

  • Enable Multi-Factor Authentication (MFA) on all email accounts.
  • Use strong, unique passwords.
  • Disable shared email logins wherever possible.
  • Be suspicious of unexpected links, invoices, attachments and QR codes.
  • Verify unusual requests by phone before taking action.
  • Never enter passwords after following a link in an email.
  • Regularly review mailbox rules and account settings.

Train Your Team

Train Your Team

People remain one of the most important cyber security controls.

  • Train staff to identify phishing emails and scams.
  • Discuss recent cyber incidents during team meetings.
  • Encourage staff to pause and question anything unusual.
  • Create a culture where reporting suspected scams is encouraged.
  • Ensure all team members know who to contact if they are concerned.

Remember: cybercriminals increasingly use legitimate compromised business email accounts, making attacks much harder to identify.

Secure Your Computers and Devices

Secure Your Computers and Devices


  • Keep Windows, servers and software up to date.
  • Replace unsupported operating systems.
  • Use reputable anti-virus and endpoint protection.
  • Restrict administrator privileges.
  • Remove software that is no longer required.
  • Secure tablets, mobile devices and laptops.
  • Review who has access to critical systems.

Review Remote Access

Review Remote Access

Remote access tools are frequently targeted by cybercriminals.

  • Enable MFA on all remote access systems.
  • Use complex passwords.
  • Disable unused remote access software.
  • Review who has remote access permissions.
  • Remove access for departed staff.
  • Regularly audit remote access activity.

Protect Your Data

Protect Your Data

Maintain secure backups.

  • Keep backups in at least three locations:
    • Live data
    • Local backup
    • Offsite/cloud backup
  • Regularly test backup recovery procedures.
  • Ensure backup data is encrypted.
  • Know how quickly systems could be restored following an incident.

Monitor for Threats

Monitor for Threats

Prevention is important. Detection is equally important.

  • Implement cyber security monitoring.
  • Review security reports and alerts.
  • Monitor for unusual login activity.
  • Investigate suspicious behaviour quickly.
  • Ensure critical systems are monitored outside business hours.

Recent pharmacy incidents have shown that early detection can be the difference between a minor incident and a major disruption.

Have an Incident Response Plan

Have an Incident Response Plan

If an incident occurs, speed matters.

  • Know who to call.
  • Document emergency contact details.
  • Ensure staff understand escalation procedures.
  • Immediately disconnect compromised devices if instructed.
  • Change passwords where compromise is suspected.
  • Preserve information that may assist investigation.
  • Understand your reporting obligations.

Consider Privacy Obligations

Consider Privacy Obligations

Pharmacies are custodians of highly sensitive health information.

  • Understand the Notifiable Data Breaches Scheme.
  • Assess whether patient information may have been accessed.
  • Seek professional advice following a cyber incident.
  • Be aware that reportable data breaches may need to be reported to affected individuals and the OAIC.

Threats to Watch For

Signs your email account may be compromised:

  • Email forwarding rules you did not create.
  • Rules automatically deleting or hiding emails.
  • Messages in Sent Items you do not recognise.
  • Password reset notifications you did not request.
  • Complaints from people receiving emails you did not send.
  • Unexpected login alerts.

If you notice any of these signs, change your password immediately and contact your IT provider.

Be alert to these emerging cyber threats:

  • Phishing emails from legitimate healthcare businesses whose accounts have been compromised.
  • Fake CAPTCHA or verification screens requesting unusual actions.
  • QR code phishing attacks.
  • SMS phishing ("smishing").
  • Requests to install software via email links.
  • Unexpected remote support requests.
  • Business email compromise, including payment redirection scams.

Does your pharmacy need help with cyber security?

Cyber threats are constantly evolving, with many attacks now starting from trusted healthcare email accounts that have already been compromised. Staff awareness, strong security controls and proactive monitoring work together to provide the strongest protection against modern cyber threats.

Ask yourself these five questions. If you answer "No" to any of these, you may have gaps that need attention.

  1. Is MFA enabled on every email account?
  2. Would you know if a device was compromised today?
  3. Could you restore your business from backup?
  4. Have all staff received cyber security awareness training?
  5. Do you know exactly who to call if a breach occurs?

If this checklist has raised any concerns for your pharmacy please Contact us to request a Fred team member to call you to discuss cyber security in your pharmacy.

Fred offers a cyber security service designed specifically for pharmacy and healthcare environments with 24x7 Security Operations Centre monitoring, threat detection and incident response.