Data Security Services
Where does your patient data actually live?
Health information is the most protected category of personal data in Australian law. In most practices it is also the least contained copies sitting in email attachments, on a USB stick in a drawer, in a personal Dropbox someone set up so they could work from home, in photos on a phone, and in a folder of scanned referrals nobody has opened in three years.
You cannot protect data you can’t locate, and you cannot tell patients what was exposed in a breach if you don’t know where their records were in the first place.
Key Features
Encryption
Patient information encrypted at rest and in transit, including on laptops and mobile devices that leave the building.
Data loss prevention
Policies that stop patient records leaving through personal email, unsanctioned cloud storage or removable media with alerting when someone tries.
Secure sharing
A proper channel for sending referrals, reports and imaging to other providers, replacing unencrypted email attachments.
Departure controls
Alerting on bulk downloads and exports. When a practitioner leaves to set up their own practice, the patient list is the thing most likely to go with them and once it's gone, it's both a commercial loss and a notifiable breach.
Retention and disposal
Records kept as long as the law requires and disposed of securely afterwards. Over-retention is its own risk: data you no longer need is data that can still be stolen.
Shadow IT cleanup
Identifying and removing the file-sharing tools and personal accounts staff adopted because the official way was too slow and fixing the reason they did.
Not sure if your practice is compliant?
