Skip to main content

Security and privacy

Assessing a billing platform's security: questions that get real answers

What a practice manager or privacy officer should ask a health technology vendor, and which answers should prompt further questions.

7 min read · Published

Start with the framework

Australian health information is regulated under the Privacy Act 1988, the Australian Privacy Principles and, depending on jurisdiction, state health records legislation. A vendor's security position should be expressed against that framework.

A vendor citing HIPAA — United States legislation with no application here — has not assessed the Australian framework. That is worth noting not because the platform is necessarily insecure, but because it indicates the compliance position has not been examined.

Ask for specifics, not adjectives

Phrases like 'bank-level' or 'military-grade' encryption describe nothing. Encryption is specified by algorithm and key length, and any vendor able to answer will do so immediately.

  • Which algorithm and key length, at rest and in transit
  • In which country production data and backups are stored
  • Whether multi-factor authentication is available and whether it can be enforced
  • What is captured in audit logs, how long logs are retained, and whether customers can access them
  • Which sub-processors handle hosting, payments and messaging

Certification is evidence, not a substitute

ISO 27001 or SOC 2 indicates an assessed control environment. Absence of certification is not disqualifying for a smaller vendor, but the absence should be stated rather than obscured.

A vendor that says plainly which certifications it holds, which it does not, and what compensating controls exist is giving you more usable information than one that implies certification through careful wording.

Ask what happens when something goes wrong

Incident response, breach notification and recovery objectives matter more than most preventive controls, because they determine the outcome in the situation you are actually worried about.

Under the Notifiable Data Breaches scheme, an eligible breach must be notified to affected individuals and the OAIC. Establish who makes that assessment and within what timeframe before you need to know.

On exit

Ask how data is extracted if the relationship ends, in what format, and how long the vendor retains it afterwards. A vendor that has not considered this has not thought about your position, only their own.

Next step

Talk through how your practice bills today

A consultation covers how cases are captured, how quotes and consent are handled, where accounts are being lost, and what moving to Anaemate would involve for your practice or group.