This article discusses the planning and formulation of security policies for Royal Melbourne Hospital to ensure the safety of patients' data. It highlights potential threats and vulnerabilities and suggests ways to mitigate them. The policies are designed for doctors, nurses, and system administrators, and the management of the policies is also discussed. The article emphasizes the importance of compliance with the policies and the need for regular revisiting and monitoring. The article also stresses the need for training and awareness among employees to prevent insider security threats.