7 min read · Published
Start with the framework
Australian health information is regulated under the Privacy Act 1988, the Australian Privacy Principles and, depending on jurisdiction, state health records legislation. A vendor's security position should be expressed against that framework.
A vendor citing HIPAA — United States legislation with no application here — has not assessed the Australian framework. That is worth noting not because the platform is necessarily insecure, but because it indicates the compliance position has not been examined.
Ask for specifics, not adjectives
Phrases like 'bank-level' or 'military-grade' encryption describe nothing. Encryption is specified by algorithm and key length, and any vendor able to answer will do so immediately.
- Which algorithm and key length, at rest and in transit
- In which country production data and backups are stored
- Whether multi-factor authentication is available and whether it can be enforced
- What is captured in audit logs, how long logs are retained, and whether customers can access them
- Which sub-processors handle hosting, payments and messaging
Certification is evidence, not a substitute
ISO 27001 or SOC 2 indicates an assessed control environment. Absence of certification is not disqualifying for a smaller vendor, but the absence should be stated rather than obscured.
A vendor that says plainly which certifications it holds, which it does not, and what compensating controls exist is giving you more usable information than one that implies certification through careful wording.
Ask what happens when something goes wrong
Incident response, breach notification and recovery objectives matter more than most preventive controls, because they determine the outcome in the situation you are actually worried about.
Under the Notifiable Data Breaches scheme, an eligible breach must be notified to affected individuals and the OAIC. Establish who makes that assessment and within what timeframe before you need to know.
On exit
Ask how data is extracted if the relationship ends, in what format, and how long the vendor retains it afterwards. A vendor that has not considered this has not thought about your position, only their own.