An NDIS registered provider delivering supports across 15 sites engaged TERU Solutions to rebuild its network security. The organisation held participant records including care plans, incident reports and health information about vulnerable people on a flat network with no segmentation, protected by a consumer-grade router supplied by its internet provider.
Staff workstations, the guest Wi-Fi in the waiting area, door access controllers and support workers’ personal phones all shared the same network. There was no visibility of what traffic left the site, no control over which applications staff installed, and no way to prevent participant records being copied to a USB drive or forwarded to a personal email address.
Under the NDIS Practice Standards, the provider was required to demonstrate that participant information was stored and transmitted securely. It had documentation asserting this. The network did not support the claim.
Challenges
Limited visibility into network traffic and potential unauthorized access attempts.
Participant records shared a flat network with guest Wi-Fi, staff personal devices and building access systems.
Support workers accessing systems from participant homes over unmanaged connections using shared credentials.
No control over installed applications, with participant documents moving through unsanctioned file-sharing tools.
NDIS Practice Standards documentation asserted secure information handling that the network could not evidence.
Solutions
