As more aged care providers embrace digital platforms, automation and AI, we’re hearing the same question more than ever:
“Where is our data stored?”
Understanding where you data is stored is an important question. But it’s only one piece of a much bigger picture.
With the introduction of the Aged Care Act 2024 and the Strengthened Aged Care Quality Standards, providers are expected to demonstrate stronger governance over the information they collect, use, store and share. In particular, Strengthened Standard 2 – The Organisation, including Outcome 2.7 (Information Management), reinforces the expectation that providers have effective systems in place to protect information, manage privacy and ensure appropriate governance of data.
While engaging a technology partner doesn’t remove these obligations, it does mean providers should understand how their vendors manage and protect information on their behalf. In other words, asking questions about data security is no longer just good practice: it’s part of good governance and form a part of your requirements under the Act.
A vendor may proudly tell you that your data never leaves Australia. That’s a great start – but it doesn’t necessarily tell you how well your data is protected, who can access it, or what happens to it over time.
If you’re trusting a technology partner with resident, workforce or financial information, here are some of the questions worth asking.
Is the vendor independently certified?
The Strengthened Aged Care Quality Standards place greater emphasis on organisational governance and effective information management. Choosing a vendor that is independently certified to standards such as ISO 27001 and ISO 9001 provides assurance that their information security and quality management systems have been externally audited and are subject to ongoing review, not simply self-assessed. Certification provides independent assurance that the organisation’s security and quality management systems have been externally audited against internationally recognised standards.
Who can actually access your data?
Outcome 2.7 – Information Management requires providers to appropriately manage the information they collect, use and disclose. Ask:
- Is access limited to only those who genuinely need it?
- Is every user individually authenticated?
- Is Multi-Factor Authentication (MFA) enforced?
- Are privileged accounts managed separately?
Good security is about ensuring nobody has more access than they need, not just based on trust.
Is access monitored and every action recorded?
Protecting information isn’t just about preventing unauthorised access, it’s also about being able to demonstrate accountability. Ask whether the vendor maintains:
- Audit logs
- Access monitoring
- Security event logging
- Regular reviews of user access
If someone accesses your data, there should always be a record.
What happens when staff or contractors leave?
A strong security program has formal processes to ensure accounts are disabled promptly, access is removed, devices are recovered and permissions are reviewed. This applies equally to employees, contractors and third-party suppliers.
How does the vendor manage security incidents and data breaches?
No organisation can guarantee a security incident will never occur. What matters is how quickly and effectively it is detected, contained and managed.
Ask your technology partner:
- Do you have a documented Incident Response Plan?
- How are customers notified if a security incident occurs?
- What are your breach reporting obligations and timeframes?
- How are incidents investigated, reviewed and prevented from happening again?
- How often are incident response processes tested?
- A mature security program doesn’t just focus on prevention – it also plans for rapid response and continuous improvement should an incident occur.
How is infrastructure secured?
Ask questions such as:
- Is the environment hosted in a secure private cloud?
- Are IP restrictions or whitelisting used where appropriate?
- Who has physical access to the infrastructure?
- How are backups protected?
How are third-party suppliers managed?
The new regulatory environment expects providers to understand risks that extend beyond their own organisation. If your technology vendor relies on subcontractors, cloud providers or AI platforms, ask:
- Which third parties can access our data?
- How are they assessed?
- Are they contractually bound by security obligations?
- Are they reviewed regularly?
Many technology vendors rely on additional suppliers. Your vendor’s security is only as strong as the organisations they trust.
Can your data be deleted?
Ask about:
- Data retention periods
- Secure deletion processes
- Whether data can be permanently removed upon request
- How backups are managed after deletion
Understanding what happens when your relationship ends is just as important as understanding how it begins.
What happens if ownership changes or the Vendor ceases training?
If the vendor is acquired, changes ownership, or enters administration or liquidation:
- Who owns your data?
- What happens to your data if the business is sold or ceases trading?
- Can another organisation access or inherit your data?
- Does your contract protect your data in these circumstances?
- Can you retrieve your data easily, and in what format?
- How long will your data remain accessible if the vendor can no longer provide the service?
- What rights do you retain to have your data transferred or securely deleted?
These are conversations worth having before they’re ever needed.
How is AI being used?
As AI becomes embedded into more technology platforms, providers should understand how resident and organisational information interacts with these tools.
Ask:
- Is customer data used to train AI models?
- Is data used within Retrieval-Augmented Generation (RAG) systems?
- Is information retained by the AI provider?
- Which countries or jurisdictions process AI requests?
- Can AI features be disabled if required?
- Are AI-generated outputs reviewed by a person before influencing care or business decisions?
Knowing where your data lives is no longer enough – you also need to know where it may travel.
Security is much bigger than location.
Data sovereignty is important, of course! Some of the factors that determine whether your information truly remains secure are governance, access control, monitoring, supplier management, retention policies and AI governance. Under the Aged Care Act 2024 and the Strengthened Quality Standards, providers remain accountable for how resident and organisational information is managed, even when that information is held or processed by a third-party technology provider.
Asking these questions helps demonstrate that you’ve considered privacy, security, accountability, information management and organisational risk – not just where your data is stored. Technology environments change constantly with the introduction of new system, evolving integrations, staff changes and AI capabilities continue to emerge. That’s why regularly auditing your digital environment is just as important as reviewing your financial or clinical governance. If you’re unsure how your current technology landscape measures up, as a part of our Digital Systems Health Check we can help assess your digital ecosystem from a governance, security, data and operational perspective. A Digital Health Checks helps providers understand not only whether their technology is secure, but whether it’s working as effectively as it should.
The right technology partner shouldn’t just help you innovate. They should help you meet your governance obligations with confidence.
You can always reach out to chat to us about all things data and data security.
Aaron Tabone
Chief Information Officer - Provider Assist
