Patient and Participant Data Protection

"Prevention is cheaper than a breach"

Project Overview

An NDIS registered provider delivering supports across 15 sites engaged TERU Solutions to rebuild its network security. The organisation held participant records including care plans, incident reports and health information about vulnerable people on a flat network with no segmentation, protected by a consumer-grade router supplied by its internet provider.

Staff workstations, the guest Wi-Fi in the waiting area, door access controllers and support workers’ personal phones all shared the same network. There was no visibility of what traffic left the site, no control over which applications staff installed, and no way to prevent participant records being copied to a USB drive or forwarded to a personal email address.

Under the NDIS Practice Standards, the provider was required to demonstrate that participant information was stored and transmitted securely. It had documentation asserting this. The network did not support the claim.

Challenges

1
Limited visibility into network traffic and potential unauthorized access attempts.
2
Participant records shared a flat network with guest Wi-Fi, staff personal devices and building access systems.
3
Support workers accessing systems from participant homes over unmanaged connections using shared credentials.
4
No control over installed applications, with participant documents moving through unsanctioned file-sharing tools.
5
NDIS Practice Standards documentation asserted secure information handling that the network could not evidence.

Solutions

1
Deployed next-generation firewalls with deep packet inspection and AI threat analysis.
2
Network segmented so participant data is isolated from guest, personal and building device traffic.
3
Authenticated, encrypted remote access with device posture checks, replacing shared credentials for field staff.
4
Application control enforced on managed devices, with DLP policies blocking participant records leaving via personal email, cloud storage or USB.
5
Centralised logging with 12 months' retention, and a documented control set mapped directly to NDIS Practice Standards information management requirements.
Scroll to top