Healthcare databases have two properties that change how they must be run. They are read at three in the morning by someone making a clinical decision, and they hold health information — which Australian privacy law treats as a special category, with a higher bar and a mandatory breach notification regime behind it.
That combination rules out a lot of ordinary database practice. A maintenance window that suits a retailer does not suit an emergency department. A backup you have never restored is not a backup when the system holding a medication chart is unavailable. And an access model you cannot describe in writing is a problem the first time a privacy officer asks who can see what.

