Industry Insights

Practice Management Software in Australia: Pricing and IT Setup

Josh Blunden·Technical Integrations Manager
24 August 20267 min read

Cloud practice management software is the cheapest line item in most clinics' IT budgets. Entry-level plans for Australian allied health start around $19 per practitioner per month ex GST, and even a full-suite system for a six-person physio practice lands in the low thousands per year. What sits around that software - where the data lives, who can get into it, what happens when a laptop goes missing, whether you can reconstruct who opened which record - costs more, takes longer, and is where clinics either quietly save money or end up writing to their patient list. This is what the software costs in 2026, and what the environment around it has to do.

What cloud practice management costs per practitioner

For allied health, a June 2026 comparison of the main Australian platforms puts entry-level pricing (ex GST) as follows.

PlatformEntry-level price
Zandaaround $19 per practitioner/month
Splose$27 per practitioner/month
coreplusfrom around $35 per practitioner/month
Cliniko$45/month for one practitioner
Nookal$55 per practitioner/month for solo practitioners
PracSuite$84/month for the first practitioner, scaled after that

Those figures come from a June 2026 comparison of practice management systems for Australian allied health, which also lists PracSuite AI as an optional $48 per practitioner/month add-on. A separate May 2026 review of booking and practice management software for Australian clinics puts solo-practitioner systems at $40 to $60 per month, full-suite systems with booking, billing, Medicare integration and clinical notes at $150 to $300 per month per practitioner, and cites Halaxy with a free core tier and paid tiers around $30/month, and Power Diary from $99/month for small clinics.

Two things matter more than the headline rate. The first is what is bundled: SMS reminders, telehealth minutes, Medicare claiming via Tyro or HICAPS, and AI scribing are frequently separate line items, and a $27 base plan with three add-ons is not a $27 plan. The second is the multiplier. Per-practitioner pricing is fine at four practitioners and starts to hurt at fourteen, particularly where you have part-timers, students and contractors each consuming a seat. Before you sign, model three years at your expected headcount, with add-ons, and compare that against a practice-wide licence if the vendor offers one.

Bp Premier's licence change from 1 July 2026

General practice runs on a different pricing model. Best Practice Software's published Bp Premier annual licence fees, effective 1 July 2026, are $1,489.41 ex GST per year for a full-time doctor working more than 25 hours a week, $893.65 for a part-time doctor at 25 hours or less, and $521.29 for allied health.

The structural change is in the part-time tier. As The Medical Republic reported on 24 June 2026, the full-time licence rose about 5 per cent from $1,418.49, an increase of roughly $71, while the part-time licence moved from 50 per cent of full-time to 60 per cent - taking it from about $709.24 to $893.65, an increase of $184.41 year on year. For a practice with three full-timers and five part-timers, that is roughly $1,135 a year in additional licence cost, most of it from the part-time reweighting.

Worth noting that vendor pricing in this segment is often quoted rather than published, and modules, support tiers and server arrangements change the total. Confirm your own numbers with the vendor before you budget from a web page, including anyone else's summary of one.

Telehealth: the free option and its edges

Healthdirect Video Call is provided at no cost to general practices, Aboriginal Medical Services and Aboriginal Community Controlled Health Organisations. That covers a lot of Australian primary care. For everyone else, a July 2026 Primary Health Network guide to telehealth puts comparable health-specific video systems at roughly $19.95 per month for allied health up to $45 per month for GP users, and expects Healthdirect's commercial pricing to sit in a similar range if it is ever charged.

The practical question is not free versus paid, it is whether consultations conducted over a general-purpose meeting tool sit inside your clinical record and your audit trail, or outside them. If the consultation happens in Teams or Zoom and the note is typed into the PMS afterwards, that is workable - provided the meeting platform is configured under your tenancy, recordings are governed, and the link between consult and record is not a staff member's memory.

The work that sits around the licence

Vendor due diligence, specifically data residency

Ask every cloud PMS vendor where the primary data is stored, where backups are stored, which subprocessors touch the data, and whether any support access originates offshore. Ask for evidence, not assurances: certification scope, penetration test summaries, breach notification commitments in the contract, and the recovery time and recovery point they will actually commit to. The My Health Record system security controls, updated 1 July 2026, describe firewalls, audit logging, anti-virus scanning of uploaded documents and continuous monitoring across connected provider software - the clinical system you connect is part of that picture, not exempt from it.

Get the answers in writing during procurement. Extracting them from a vendor after you have migrated three years of clinical records is a much weaker negotiating position.

Identity, across the people who are not on your payroll

Unauthorised access is a recurring theme in health sector breach reporting, and the fix is unglamorous. Every clinician, locum, visiting specialist, casual receptionist and student needs a named account with multi-factor authentication, tied to a joiner-mover-leaver process that actually deprovisions on the last day rather than the day someone remembers. Shared "reception" logins have to go, because an audit log that says "reception" answers nothing.

The evidence that this works is in the numbers. The OAIC's digital health annual report for 2024-25, published 8 October 2025, records 18 data breach notifications relating to the My Health Record system, down from 39 the year before - a drop reported as associated with stronger authentication including passkeys. Access control is also where individual liability sits: the RACGP's guidance on criminal and civil penalties for My Health Record misuse sets out that deliberate unauthorised access, use or disclosure can attract imprisonment and substantial fines.

Patching, and the server in the comms cupboard

Server-based clinical systems have not disappeared, and they tend to carry dependencies on older Windows builds, an on-premises database, and remote access that was set up years ago by someone no longer involved. The ACSC's advisory on APT actors targeting the Australian health sector recommends timely patching, hardened remote access and monitoring, and none of that is optional because a clinic is small.

The frameworks are shifting underneath this. The Australian Signals Directorate announced in June 2026 that the Essential Eight will be retired within two years and replaced by a new Essentials series, with national consultation on "Essentials for enterprise IT" running to 12 July 2026. If your clinic has an Essential Eight uplift underway, keep going - patching, multi-factor authentication, application control and tested backups carry through any renaming, and the Essential Eight guidance remains the current published baseline.

Logs you can hand to a regulator

One incident can trigger three separate reporting obligations. Under the Notifiable Data Breaches scheme, an entity must assess a suspected eligible breach within 30 days and notify the Commissioner and affected individuals where serious harm is likely. Where My Health Record data is involved, the provider organisation must notify the System Operator and the OAIC as soon as practicable. And a 2026 guide to Australian healthcare breach obligations sets out the Cyber Security Act 2024 rule requiring notification within 72 hours of a ransomware payment.

None of that turnaround is achievable if the logs are incomplete or scattered across the PMS, the mail tenancy and a file server. Centralised, retained, searchable logging is what turns a two-week forensic scramble into a defensible answer. That is the substance of the security and compliance work behind clinical systems in Australian healthcare practices - retention, alerting, and a runbook naming who leads, who calls the regulators and who drafts the patient letter.

Also worth knowing: private health service providers are covered by the Privacy Act regardless of annual turnover. The small business exemption does not apply, and the OAIC publishes a data breach action plan specifically for health service providers that is a sensible starting template.

Start here

Pull two lists this week. First, every account with access to your practice management system, matched against your current payroll and contractor register - the gap between those two lists is usually the fastest risk to close. Second, your actual annual software spend per practitioner, add-ons included, projected against next year's headcount and the 1 July 2026 Bp Premier structure if you are a GP practice.

If you want that assessed rather than guessed at, Precision IT will review your practice management platform, tenancy and identity configuration against Essential Eight-aligned controls and your My Health Record and NDB evidence obligations, and come back with a scoped remediation plan, a fixed number, and a straight answer on what is worth doing now versus at your next platform renewal. We are ISO 27001 certified, cloud-first, and work with Australian data residency requirements as a default rather than an exception - book a consultation and we will tell you where your environment actually stands.

healthcarepractice-managementcloudprivacy-actmy-health-record

Ready to Transform Your IT?

Our team of cloud and security experts is ready to help your business thrive. Get a free consultation today.

Get in Touch

Ready to simplify your IT?

Talk to our team about managed IT, cloud and cybersecurity for your business.