Cyber Security and Digital Trust in Australian Aged Care: Protecting Connected Care Systems
Cyber security is no longer a specialist technology issue operating at the edge of Australian aged care. It is becoming a central part of care safety, service continuity, privacy, governance and public confidence.
Providers increasingly rely on digital care records, mobile workforce applications, medication systems, telehealth, remote monitoring, electronic referrals, cloud platforms, connected devices, rostering systems and online communication with older people and families.
These technologies can improve coordination, visibility and responsiveness. They can also create new points of vulnerability.
A cyber incident may prevent workers from accessing care plans, disrupt visit schedules, expose sensitive personal information, interfere with medication support, disable communication systems or weaken confidence in a provider’s ability to keep people safe.
The wider Australia Social Care and Community Services Knowledge Hub explores how technology, governance and innovation can strengthen community-based support while protecting dignity, accessibility and human relationships.
In aged care, cyber security should be treated as part of operational care assurance. A system does not need to cause physical injury directly to create harm. It may create the conditions in which support is delayed, information becomes unreliable or staff are unable to respond safely.
Why Cyber Security Matters in Aged Care
Aged care organisations hold large volumes of sensitive information.
This may include:
- identity and contact information;
- medical history;
- medication records;
- care plans;
- financial details;
- family contacts;
- staff records;
- behavioural and safeguarding information;
- mobility and equipment needs;
- advance-care information;
- home-access arrangements;
- incident records;
- photographs and identity documents;
- location data; and
- information about daily routines.
This information is valuable because it can be used for fraud, identity theft, extortion, targeted scams or unauthorised access to other systems.
It is also highly personal. A breach may affect dignity, safety, trust and relationships even where no financial loss occurs.
Cyber Security and Care Safety Are Connected
Cyber risk is sometimes framed primarily around confidentiality. Confidentiality is essential, but availability and integrity are equally important.
Confidentiality
Confidentiality means information is accessible only to authorised people.
A breach may expose health conditions, addresses, financial information or personal circumstances.
Integrity
Integrity means information remains accurate, complete and protected from unauthorised alteration.
If medication, allergy or risk information is changed or corrupted, staff may make unsafe decisions even though the system appears to be functioning.
Availability
Availability means systems and information can be accessed when needed.
A secure system that becomes unavailable during a critical period may still place older people at risk.
Providers therefore need to protect:
- privacy;
- accuracy;
- continuity;
- accessibility;
- traceability;
- recovery capability; and
- public confidence.
The Expanding Digital Aged Care Environment
Australian aged care increasingly operates through interconnected technologies.
These may include:
- electronic care-management systems;
- mobile worker devices;
- electronic medication systems;
- telehealth platforms;
- wearable monitoring devices;
- smart-home sensors;
- digital access-control systems;
- cloud-based document storage;
- payroll and rostering platforms;
- customer portals;
- online payment systems;
- video communication;
- workforce-learning platforms;
- electronic referral systems;
- business-intelligence dashboards;
- artificial intelligence tools; and
- third-party integration platforms.
Each system may be secure in isolation while the overall environment remains vulnerable because of weak passwords, excessive access, poor supplier controls, unmanaged devices or insecure data exchange.
Understanding the Threat Landscape
Cyber threats are not limited to highly sophisticated attacks.
Many incidents begin with routine weaknesses such as:
- phishing emails;
- stolen passwords;
- reused login details;
- lost mobile devices;
- unpatched software;
- misdirected emails;
- incorrect access permissions;
- former staff accounts remaining active;
- weak supplier security;
- insecure remote access;
- shared user accounts;
- unprotected spreadsheets;
- publicly visible cloud folders;
- malicious attachments;
- fraudulent payment requests; and
- staff disclosing information during social-engineering calls.
Strong security therefore depends on everyday operational discipline as much as specialist technical controls.
Older People May Face Additional Digital Risks
Older people can experience increased exposure to scams, impersonation and financial exploitation.
Factors may include:
- social isolation;
- limited digital confidence;
- cognitive impairment;
- sensory loss;
- dependency on others for technology support;
- difficulty distinguishing genuine communications from fraudulent messages;
- shared devices;
- unfamiliarity with digital payment systems;
- high trust in apparently official communication; and
- limited understanding of how personal information may be used.
Cyber security in aged care should therefore include practical protection for older people, not only protection of organisational networks.
Digital Trust
Digital trust exists when older people, families, staff and partners have reasonable confidence that technology is:
- safe;
- reliable;
- proportionate;
- transparent;
- accessible;
- used for a clear purpose;
- subject to meaningful oversight;
- capable of correction;
- resilient during disruption; and
- consistent with the person’s rights and preferences.
Trust cannot be created through privacy notices alone.
It is built when providers explain how systems work, respond honestly when something goes wrong and demonstrate that digital innovation remains subordinate to care quality and human judgement.
Operational Scenario One: A Phishing Email Targets the Finance Team
Context: A staff member receives an email that appears to come from a senior executive requesting urgent payment to a new supplier account.
Step 1 – Recognising indicators: The worker notices unusual urgency, a slightly altered email address and a request to bypass normal approval.
Step 2 – Independent verification: The worker contacts the executive through a known telephone number rather than replying to the email.
Step 3 – Immediate containment: The message is reported to the internal security lead, related emails are identified and malicious links are blocked.
Step 4 – Organisational learning: Staff receive a short alert explaining the method used without blaming the person who received the message.
Step 5 – Control improvement: The provider reviews payment-authorisation processes, email protections and supplier-account verification.
This scenario demonstrates how workforce awareness and clear financial controls can prevent a routine phishing attempt from becoming a significant operational loss.
Human Behaviour Is Part of the Security System
Staff are sometimes described as the weakest link in cyber security. This framing can be counterproductive.
People are more likely to report concerns quickly when the organisational culture is supportive rather than punitive.
A strong security culture encourages workers to:
- question unusual requests;
- report mistakes immediately;
- avoid sharing passwords;
- lock unattended devices;
- verify identity before disclosing information;
- use approved systems;
- challenge inappropriate access;
- report lost devices;
- recognise phishing and social engineering; and
- ask for help when uncertain.
Training should connect security to real aged care work rather than relying on generic annual e-learning.
Role-Based Access
Not every worker requires access to every record or function.
Role-based access should reflect:
- the person’s responsibilities;
- the services they deliver;
- the information required for safe work;
- the locations they support;
- their level of authority;
- whether access is permanent or temporary;
- whether they can view, edit, export or delete information; and
- whether additional approval is needed for highly sensitive records.
Excessive access increases the potential impact of mistakes, misuse or account compromise.
Access should be reviewed when staff:
- change roles;
- move between services;
- take extended leave;
- work temporarily on another programme;
- become subject to investigation; or
- leave the organisation.
Multi-Factor Authentication
Passwords alone provide limited protection, particularly where staff reuse credentials or respond to convincing phishing messages.
Multi-factor authentication adds an additional verification step.
This may involve:
- an authentication application;
- a security key;
- a device confirmation;
- a one-time code;
- biometric verification; or
- another approved identity check.
Implementation should consider accessibility, device availability, rural connectivity and workforce practicality.
Security controls that workers cannot use reliably may lead to unsafe workarounds.
Mobile Device Security
Home-support workers often access records through mobile phones or tablets while travelling between people’s homes.
Mobile-device controls may include:
- device encryption;
- strong screen locking;
- automatic timeout;
- remote wipe capability;
- approved application installation;
- secure software updates;
- restricted local storage;
- separation of personal and work information;
- lost-device reporting;
- protection against copying sensitive information into personal applications; and
- secure connection requirements.
Workers also need guidance on practical risks such as leaving devices in vehicles, discussing information in public places or allowing family members to use work equipment.
Bring Your Own Device Arrangements
Some organisations permit staff to use personal devices for work.
This may improve flexibility but creates governance questions.
Providers should define:
- which devices are permitted;
- minimum security standards;
- approved applications;
- management and monitoring arrangements;
- what data may be stored locally;
- how access is removed;
- what happens if the device is lost;
- how personal privacy is protected;
- who pays for replacement or data use; and
- whether the organisation can remotely remove work information.
Where these controls cannot be applied consistently, organisation-managed devices may provide stronger assurance.
Password and Account Management
Password controls should reduce predictable weaknesses without making systems unusable.
Providers should avoid:
- shared accounts;
- default passwords;
- passwords written beside workstations;
- unchanged supplier credentials;
- weak recovery questions;
- accounts without named owners;
- unnecessary administrator privileges;
- delayed account closure; and
- using the same credentials across multiple systems.
Password managers and single sign-on may improve security where implemented carefully and supported by multi-factor authentication.
Secure Communication
Aged care teams frequently exchange information through email, messaging, telephone and video systems.
Providers should establish clear rules for:
- which communication platforms are approved;
- what information may be sent through each channel;
- how recipient identity is checked;
- when encryption is required;
- how urgent information is escalated;
- how messages become part of the formal record;
- how group chats are governed;
- how screenshots are controlled;
- how personal email accounts are prohibited or restricted; and
- how misdirected communication is reported.
Convenience should not override privacy, but security controls should reflect the urgency and realities of frontline care.
Protecting Electronic Care Records
Electronic care records sit at the centre of many aged care services. They may contain information required for daily visits, medication support, incident response, family communication, workforce coordination and clinical escalation.
Controls should protect records throughout their life cycle, including:
- creation;
- review;
- access;
- editing;
- sharing;
- export;
- archiving;
- retention; and
- secure deletion.
Providers should be able to identify:
- who created an entry;
- who changed it;
- what was changed;
- when the change occurred;
- which version is current;
- whether information was exported;
- whether access was unusual; and
- how incorrect information was corrected.
Audit trails are essential, but they should be actively reviewed rather than retained only for retrospective investigation.
Protecting Medication Systems
Electronic medication-management systems may reduce transcription error and improve visibility, but disruption or manipulation can create serious consequences.
Providers should consider:
- authorised prescribing and administration roles;
- identity verification;
- medication-change alerts;
- protection against unauthorised editing;
- clear audit trails;
- pharmacy integration;
- downtime procedures;
- access to current medication lists during outages;
- reconciliation after system restoration;
- device security;
- staff competency; and
- escalation where electronic information conflicts with other evidence.
Continuity plans should ensure that medication support remains safe when the primary system cannot be accessed.
Connected Devices and the Internet of Things
Connected devices are becoming more common in aged care and home-support environments.
Examples include:
- wearable alarms;
- falls sensors;
- door sensors;
- bed and chair sensors;
- smart medication dispensers;
- environmental monitors;
- remote vital-sign equipment;
- smart speakers;
- digital locks;
- video communication devices;
- location technology; and
- power-dependent assistive equipment.
These technologies may improve independence and early intervention, but they may also introduce risks through weak passwords, unsupported software, insecure wireless connections, excessive data collection or unclear supplier access.
Before deployment, providers should establish:
- the purpose of the device;
- what information it collects;
- where information is stored;
- who can access it;
- how long information is retained;
- how software is updated;
- what happens if the supplier ceases trading;
- how the device is monitored;
- how false alerts are managed;
- what happens during loss of power or connectivity;
- how consent is recorded; and
- how the device is removed securely.
Operational Scenario Two: A Compromised Remote-Monitoring Device
Context: A provider identifies unusual activity involving a remote-monitoring platform used in several people’s homes. The supplier confirms that unauthorised access may have occurred.
Step 1 – Immediate risk assessment: The provider identifies which people, devices and information may be affected and whether any current care decisions depend on the platform.
Step 2 – Containment: Remote access is restricted, affected credentials are changed and alternative monitoring arrangements are introduced.
Step 3 – Continuity of care: Additional welfare calls or visits are arranged for people who rely on the devices for risk monitoring.
Step 4 – Communication and investigation: Older people, representatives and relevant authorities are informed in a clear and proportionate manner while technical evidence is preserved.
Step 5 – Recovery and learning: Devices are checked, security updates are completed, supplier controls are reviewed and future procurement requirements are strengthened.
This scenario shows why device security, supplier assurance and care-continuity planning must operate together.
Cloud Services
Cloud platforms can improve accessibility, resilience and scalability. However, moving information to the cloud does not transfer accountability away from the provider.
Organisations should understand:
- where data is stored;
- which legal jurisdictions may apply;
- how information is encrypted;
- how access is controlled;
- which subcontractors are involved;
- how backups are managed;
- how quickly services can be restored;
- how incidents are reported;
- how logs are made available;
- how data can be exported;
- what happens when the contract ends; and
- how information is securely deleted.
Provider leaders should avoid assuming that a widely used platform is automatically suitable for aged care information.
Supplier Assurance
Aged care providers may depend on dozens of technology suppliers. A weakness in one supplier can affect multiple services.
Supplier due diligence should consider:
- security governance;
- privacy arrangements;
- independent assurance or certification;
- previous incidents;
- penetration testing;
- vulnerability management;
- software-update processes;
- staff vetting;
- subcontractor controls;
- data location;
- business continuity;
- incident-notification timescales;
- support availability;
- financial sustainability;
- data portability; and
- exit arrangements.
Assurance should continue after contract award. Supplier risk can change because of acquisitions, staffing changes, new subcontractors, software updates or emerging vulnerabilities.
Security Requirements in Contracts
Technology contracts should translate security expectations into enforceable obligations.
Relevant clauses may address:
- minimum security standards;
- compliance with applicable privacy obligations;
- access restrictions;
- encryption;
- breach notification;
- cooperation during investigations;
- availability targets;
- backup and recovery;
- vulnerability remediation;
- subcontracting;
- audit rights;
- data ownership;
- secondary use;
- artificial intelligence training;
- record retention;
- secure deletion;
- data export; and
- termination support.
Providers should understand whether contractual promises are matched by practical evidence.
Software Updates and Vulnerability Management
Software vulnerabilities are identified continually. Delayed updates can leave systems exposed to known risks.
Providers need a process for:
- maintaining an inventory of systems and devices;
- identifying software versions;
- receiving supplier security notices;
- assessing vulnerability severity;
- prioritising critical updates;
- testing updates where necessary;
- scheduling implementation;
- recording exceptions;
- applying temporary safeguards;
- verifying successful installation; and
- retiring unsupported technology.
Unsupported systems may continue to appear functional while no longer receiving security fixes.
Asset and System Inventories
Organisations cannot protect technology they do not know they operate.
An effective inventory should include:
- system or device name;
- business purpose;
- service owner;
- technical owner;
- supplier;
- information held;
- user groups;
- integration points;
- software version;
- support status;
- backup arrangements;
- recovery priority;
- contract end date;
- known risks; and
- planned replacement date.
Inventories should cover informal systems such as locally created spreadsheets, shared drives and messaging groups, not only major corporate platforms.
Shadow IT
Shadow IT refers to systems, applications or workarounds used without formal organisational approval.
Examples may include:
- personal messaging applications;
- unapproved cloud storage;
- private email accounts;
- locally purchased software;
- personal spreadsheets;
- shared online documents;
- consumer video platforms;
- unapproved artificial intelligence tools; and
- personal devices storing care information.
Workers often create these workarounds because approved systems are slow, inaccessible or do not support operational needs.
Providers should therefore investigate the reason shadow IT exists rather than relying only on prohibition.
Artificial Intelligence and Cyber Risk
Artificial intelligence may support documentation, scheduling, risk analysis, communication and decision support. It may also introduce additional security and privacy risks.
These include:
- staff entering personal information into public tools;
- unclear storage and reuse of prompts;
- supplier access to sensitive information;
- incorrect or fabricated outputs;
- automated decisions without sufficient review;
- model manipulation;
- exposure of confidential organisational information;
- embedded bias;
- weak auditability; and
- dependence on external platforms.
Providers should define which artificial intelligence tools are approved, what information may be entered, how outputs must be checked and where human accountability remains.
Email Security
Email remains one of the most common routes for phishing, malware, fraud and accidental disclosure.
Controls may include:
- multi-factor authentication;
- spam and malware filtering;
- domain protection;
- warning banners for external messages;
- blocking dangerous file types;
- link scanning;
- automatic encryption where appropriate;
- recipient confirmation for sensitive messages;
- restrictions on automatic forwarding;
- monitoring unusual login activity;
- report-phishing functions; and
- regular simulated exercises.
Training should help staff recognise urgency, impersonation, altered payment details, unexpected attachments and requests for passwords or codes.
Social Engineering
Social engineering relies on manipulating people rather than breaking technical controls directly.
An attacker may pretend to be:
- a senior manager;
- a family member;
- a general practitioner;
- a pharmacy representative;
- a technology supplier;
- a bank;
- a regulator;
- a payroll officer;
- a maintenance contractor; or
- another care provider.
Staff should verify identity through independent contact details before disclosing information, changing payment arrangements, resetting accounts or granting access.
Protecting Older People From Scams
Providers can strengthen digital safety through practical education and early identification.
Support may include:
- discussing common scams in accessible language;
- encouraging people not to share security codes;
- helping individuals verify unexpected requests;
- identifying sudden financial or communication changes;
- supporting trusted-contact arrangements;
- explaining how caller identity can be falsified;
- helping secure devices and online accounts;
- recording consent regarding family involvement;
- responding to suspected financial abuse; and
- referring concerns through safeguarding and financial channels.
Digital protection should respect autonomy. It should not be used to remove control solely because a person is older or requires support.
Cyber Security and Safeguarding
Some cyber incidents may also be safeguarding concerns.
Examples include:
- financial exploitation;
- coercion to disclose passwords;
- unauthorised surveillance;
- technology-facilitated abuse;
- impersonation;
- access to personal records by someone known to the person;
- misuse of location data;
- harassment through digital channels;
- fraudulent changes to contact information; and
- control of the person’s communications or finances.
Cyber response and safeguarding processes should connect so that technical evidence, personal risk and protective action are considered together.
Network Segmentation
Network segmentation limits how far an attacker or technical failure can spread.
Providers may separate:
- care systems;
- corporate administration;
- finance;
- guest wireless access;
- connected care devices;
- building-management systems;
- staff personal devices;
- development or testing environments; and
- supplier remote access.
Segmentation should be proportionate to organisational scale and risk, but small providers should not assume it is relevant only to large organisations.
Backup and Recovery
Backups are essential for recovering from ransomware, accidental deletion, system failure and data corruption.
Providers should know:
- which information is backed up;
- how frequently backups occur;
- where copies are stored;
- whether backups are encrypted;
- whether they are separated from the main network;
- how long they are retained;
- who can access them;
- how restoration is authorised;
- how often recovery is tested; and
- how much data could be lost between backups.
A backup strategy is not reliable until restoration has been tested successfully.
Business Continuity During System Failure
Providers should plan for periods when essential systems are unavailable.
Continuity arrangements may require access to:
- current visit schedules;
- essential care-plan summaries;
- medication information;
- allergies;
- critical risks;
- emergency contacts;
- staff contact information;
- priority service lists;
- manual recording forms;
- escalation routes;
- supplier support details; and
- procedures for reconciling records after restoration.
Paper or offline alternatives must be current, secure and accessible to the people who need them.
Ransomware
Ransomware may encrypt systems, steal information or threaten publication unless payment is made.
A response plan should address:
- immediate isolation of affected systems;
- activation of incident command;
- care-continuity arrangements;
- engagement of technical specialists;
- preservation of evidence;
- assessment of information exposure;
- regulatory and contractual notification;
- communication with older people and families;
- restoration from trusted backups;
- monitoring for continued compromise; and
- post-incident review.
Decisions about ransom demands involve legal, ethical, financial and operational considerations and should not be made informally under pressure.
Incident Detection and Reporting
Providers need mechanisms to detect unusual activity before a major incident becomes obvious.
Indicators may include:
- repeated failed logins;
- access from unusual locations;
- large data downloads;
- unexpected administrator activity;
- new forwarding rules;
- disabled security tools;
- unusual system slowness;
- files becoming inaccessible;
- unexpected account creation;
- multiple password resets;
- unexplained record changes; and
- reports of suspicious messages.
Staff should know how to report concerns quickly and what information to preserve.
Cyber Incident Command
A significant cyber incident requires coordinated leadership.
Roles may include:
- incident lead;
- technical response lead;
- care-continuity lead;
- privacy and legal lead;
- communications lead;
- workforce lead;
- supplier liaison;
- executive decision-maker;
- board liaison; and
- record keeper.
The incident structure should distinguish between technical recovery and continuity of support. Both are essential and may require different expertise.
Communication During a Cyber Incident
Poor communication can increase fear, speculation and loss of trust.
Communications should be:
- accurate;
- timely;
- clear about what is known;
- honest about uncertainty;
- accessible;
- consistent across channels;
- proportionate to risk;
- protective of ongoing investigation; and
- updated as circumstances change.
Older people and families may need practical information about whether visits, medication support, payments, appointments or personal information are affected.
Learning Without Blame
Cyber incidents often involve human actions, but focusing only on individual error may conceal wider weaknesses.
Reviews should consider:
- whether systems were usable;
- whether staff had realistic workloads;
- whether warnings were understandable;
- whether procedures were accessible;
- whether reporting was encouraged;
- whether technical controls were proportionate;
- whether supplier obligations were clear;
- whether similar incidents had occurred previously; and
- whether leadership acted on known risks.
A learning culture supports earlier reporting and stronger prevention.
Cyber Security Governance
Cyber security governance should connect technical controls with care quality, operational risk, privacy, safeguarding, workforce practice and business continuity.
Governance arrangements should define:
- board and executive accountability;
- named operational ownership;
- information-security responsibilities;
- privacy and data-protection oversight;
- supplier governance;
- incident escalation thresholds;
- business-continuity responsibilities;
- risk acceptance authority;
- reporting arrangements;
- audit requirements;
- policy review cycles; and
- evidence required for assurance.
Security should not be delegated entirely to an internal technology team or external supplier. Those functions may manage technical activity, but organisational leaders remain accountable for whether risks are understood and controlled.
Board and Executive Assurance
Boards and executive teams should receive information that explains both technical exposure and potential consequences for older people.
Useful assurance questions include:
- Which systems are critical to safe care delivery?
- How long could services operate without them?
- Which systems or devices are unsupported?
- How quickly are critical vulnerabilities addressed?
- Are access permissions reviewed regularly?
- How many former staff accounts remain active?
- Which suppliers create the highest dependency?
- When were restoration arrangements last tested?
- What cyber incidents or near misses have occurred?
- How quickly were concerns detected and contained?
- What evidence shows staff understand current threats?
- Are older people informed clearly about digital risks?
- Which risks have been accepted, by whom and why?
- How would a prolonged outage affect medication, visits and emergency response?
- What improvements remain overdue?
The Governance Maturity Assessment can help organisations review whether leadership accountability, risk ownership, assurance and oversight are sufficiently mature to govern an increasingly digital care environment.
Building a Cyber Risk Register
Cyber risks should be integrated into the organisation’s wider risk-management system rather than held in an isolated technical document.
Each significant risk should record:
- the system, device or process affected;
- the threat or vulnerability;
- the potential consequence for people and services;
- existing controls;
- control weaknesses;
- current risk rating;
- required action;
- named owner;
- target date;
- residual risk;
- assurance evidence;
- dependencies; and
- escalation status.
Risk descriptions should be specific.
“Cyber attack” is too broad to support meaningful action. A stronger entry might identify that unsupported remote-access software could allow unauthorised entry into the care-record system, disrupting visit coordination and exposing personal information.
Cyber Security Metrics and Dashboards
Leaders need visibility of whether key controls are working.
Possible measures include:
- percentage of users protected by multi-factor authentication;
- number of dormant or inactive accounts;
- time taken to close accounts after staff departure;
- percentage of critical updates completed within target;
- number of unsupported systems;
- phishing-reporting rates;
- click rates during simulated exercises;
- number of lost or stolen devices;
- unusual-access investigations;
- supplier assurance reviews completed;
- backup success rates;
- restoration tests completed;
- system downtime;
- incident-detection time;
- containment time;
- outstanding high-risk actions;
- privacy breaches;
- repeat incident themes; and
- percentage of critical services with tested continuity plans.
The Quality Dashboard Builder can support the development of a balanced assurance view combining cyber indicators, care-continuity measures, incident learning, supplier risk and overdue actions.
Dashboards should avoid creating false reassurance. High training completion does not prove that staff can respond effectively, and successful backups do not prove that information can be restored within the required timescale.
Cyber Security Audits
Audit activity should test whether controls operate in practice.
Audit topics may include:
- user-access permissions;
- account closure;
- administrator privileges;
- mobile-device compliance;
- supplier assurance;
- software-update status;
- backup restoration;
- incident-response readiness;
- business-continuity arrangements;
- care-record audit trails;
- email security;
- connected-device governance;
- shadow IT;
- artificial intelligence use;
- privacy notices;
- consent processes; and
- workforce understanding.
Audits should include evidence sampling, practical testing and frontline discussion rather than relying only on policy review.
Penetration Testing and Technical Assurance
Independent technical testing can help identify weaknesses before they are exploited.
Depending on scale and risk, this may include:
- external vulnerability scanning;
- penetration testing;
- cloud-configuration review;
- wireless-network testing;
- application-security assessment;
- mobile-device testing;
- phishing simulations;
- supplier evidence review;
- identity and access testing;
- incident-response exercises; and
- backup-recovery testing.
Testing should be carefully planned so that critical care systems are not disrupted.
Findings should be prioritised according to likely harm, exploitability and service dependency rather than technical severity alone.
Operational Scenario Three: A Ransomware Attack Disrupts Care Records
Context: Staff arrive for an early shift and cannot access the electronic care-record and rostering systems. Several devices display a ransom message.
Step 1 – Activating incident command: The provider isolates affected devices, activates the cyber incident plan and appoints separate technical and care-continuity leads.
Step 2 – Protecting essential support: Teams use secure offline schedules and essential care summaries to prioritise medication visits, people living alone and those with high clinical or safeguarding risk.
Step 3 – Preserving communication: Approved alternative channels are established so workers can report completed visits, deterioration and urgent concerns without using compromised systems.
Step 4 – Investigation and recovery: Technical specialists assess the breach, preserve evidence, identify affected information and restore systems from verified backups.
Step 5 – Reconciliation and learning: Temporary records are entered into restored systems, missed actions are reviewed, affected people are informed appropriately and weaknesses are added to an accountable improvement plan.
The immediate success of the response depends not only on removing malicious software, but on maintaining safe support while digital systems are unavailable.
Cyber Security Exercises
Incident plans should be rehearsed before a real event.
Exercises may test scenarios such as:
- loss of the care-record system;
- ransomware affecting multiple services;
- compromise of a major supplier;
- loss of mobile devices;
- exposure of personal information;
- failure of electronic medication systems;
- fraudulent changes to payment details;
- remote-monitoring disruption;
- cloud-service outage;
- misuse of an administrator account;
- loss of connectivity during extreme weather; and
- simultaneous cyber and safeguarding concerns.
Exercises should involve operational managers, care teams, technology specialists, privacy leads, communications, executive leaders and relevant suppliers.
Post-exercise reviews should identify:
- what worked;
- where decisions were delayed;
- which information was missing;
- whether roles were understood;
- whether alternative systems were usable;
- which people or services were most vulnerable;
- what communications were required;
- which dependencies had been overlooked; and
- which actions require investment.
Workforce Training and Competence
Cyber awareness should be tailored to role and exposure.
Frontline workers may need practical learning on:
- secure mobile working;
- identity verification;
- phishing and suspicious messages;
- lost-device reporting;
- safe use of care applications;
- confidential conversations;
- approved communication channels;
- recognising scams affecting older people;
- system-outage procedures; and
- reporting mistakes quickly.
Managers may require additional competence in:
- incident escalation;
- access approval;
- continuity planning;
- supplier risk;
- information-sharing decisions;
- investigation;
- staff support after incidents; and
- implementation of corrective action.
Executives and board members should understand:
- organisational exposure;
- critical service dependencies;
- risk appetite;
- investment priorities;
- incident leadership;
- legal and contractual obligations;
- public communication; and
- how to challenge assurance evidence.
Inclusive and Accessible Security
Security controls must be usable by the people expected to follow them.
Poorly designed controls may disadvantage workers or older people who experience:
- visual impairment;
- hearing loss;
- limited dexterity;
- cognitive impairment;
- language barriers;
- low digital confidence;
- limited access to smartphones;
- unreliable connectivity;
- memory difficulties; or
- difficulty interpreting complex instructions.
Inclusive approaches may involve:
- accessible authentication methods;
- clear language;
- large-text options;
- screen-reader compatibility;
- alternative verification routes;
- supported decision-making;
- translated guidance;
- face-to-face assistance;
- careful use of trusted representatives; and
- testing with people who have different accessibility needs.
Security that excludes people may push them towards unsafe workarounds or remove their ability to participate independently.
Balancing Security and Person-Centred Care
Security should not become an excuse for inflexible or impersonal practice.
Examples of poor balance include:
- denying a person access to their own information without clear justification;
- preventing appropriate family involvement despite valid consent;
- using surveillance technology without meaningful discussion;
- requiring inaccessible authentication methods;
- withholding essential information from frontline workers;
- imposing controls that delay urgent support;
- collecting excessive information for possible future use; and
- assuming every older person lacks digital capacity.
Strong security enables safe participation. It should protect autonomy, not replace it.
Privacy and Transparency After an Incident
Where personal information may have been exposed, communication should explain:
- what happened;
- when it occurred;
- which information may be affected;
- what the provider has done;
- whether care delivery is affected;
- what action the person should take;
- where support is available;
- how further updates will be provided;
- how concerns or complaints can be raised; and
- what improvements will follow.
Providers should avoid both unnecessary alarm and minimisation.
People should receive information that allows them to make informed decisions about passwords, financial accounts, identity protection and future communication.
Cyber Security in Commissioning and Partnership Working
Commissioners, funders and system partners can strengthen digital trust by making security expectations clear and proportionate.
Procurement and contract-management arrangements may examine:
- information-security governance;
- critical system resilience;
- business-continuity testing;
- supplier and subcontractor controls;
- incident-notification arrangements;
- data location;
- access management;
- workforce competence;
- connected-device security;
- privacy-by-design;
- data portability;
- artificial intelligence governance; and
- evidence of improvement after incidents.
Requirements should reflect provider scale and risk while maintaining minimum protections for personal information and essential care systems.
A Phased Cyber Security Improvement Roadmap
Phase One – Identify Critical Services and Information
Map the systems, devices, suppliers and information required to deliver safe support.
Prioritise:
- medication systems;
- care records;
- visit schedules;
- emergency contacts;
- remote monitoring;
- financial systems;
- workforce communication;
- building access; and
- high-risk personal information.
Phase Two – Establish Basic Controls
Implement proportionate protections such as:
- multi-factor authentication;
- named user accounts;
- timely account closure;
- device encryption;
- software updates;
- secure backups;
- approved communication systems;
- phishing reporting; and
- clear incident escalation.
Phase Three – Strengthen Supplier Assurance
Review major suppliers, contract terms, subcontractors, data location, recovery arrangements and exit plans.
Phase Four – Test Continuity and Recovery
Rehearse how essential services will continue during loss of records, rostering, medication or communication systems.
Phase Five – Improve Monitoring
Introduce meaningful metrics, access reviews, audit trails, vulnerability tracking and board reporting.
Phase Six – Embed Workforce Learning
Use real scenarios, short updates, simulated exercises and supportive reporting rather than relying only on annual training.
Phase Seven – Mature Governance
Integrate cyber risk with quality, safeguarding, privacy, procurement, resilience and organisational strategy.
Common Pitfalls
Common weaknesses include:
- treating cyber security as solely an IT responsibility;
- focusing only on confidentiality and ignoring availability;
- failing to identify critical system dependencies;
- allowing former staff accounts to remain active;
- using shared logins;
- delaying security updates;
- retaining unsupported technology;
- relying on suppliers without evidence of assurance;
- failing to test backup restoration;
- having continuity plans that staff cannot access;
- using generic training unrelated to aged care;
- blaming staff for reporting mistakes;
- ignoring connected-device risks;
- failing to control artificial intelligence use;
- poor visibility of shadow IT;
- security arrangements that exclude people;
- weak communication after incidents;
- measuring activity rather than control effectiveness; and
- failing to connect cyber incidents with safeguarding and care safety.
The Future of Digital Trust in Australian Aged Care
Australian aged care will become more digitally connected through interoperable records, remote monitoring, artificial intelligence, smart homes, mobile working and integrated health and community systems.
This development could support:
- earlier identification of deterioration;
- more reliable care coordination;
- safer medication support;
- better rural access;
- stronger emergency response;
- reduced administrative duplication;
- more responsive home support;
- greater independence; and
- better use of system intelligence.
These benefits will depend on trust.
Older people and families need confidence that information will not be collected carelessly, accessed without reason, reused without transparency or lost when suppliers and systems change.
Workers need secure systems that support rather than obstruct frontline practice.
Leaders need reliable assurance that critical services can continue during disruption.
The most digitally advanced aged care organisations will not be those that deploy the greatest number of technologies. They will be those that combine innovation with strong governance, accessible security, tested resilience, transparent use of information and unwavering attention to the safety and rights of older people.
Latest from the knowledge hub
- Interoperable Aged Care Data in Australia: Connecting Health, Home Support and Community Intelligence
- Digital Twins in Australian Aged Care: Building Intelligent, Predictive and Connected Care Systems
- Artificial Intelligence in Australian Aged Care: Governing Automation, Risk and Human Decision-Making
- Predictive Aged Care in Australia: Using Data to Identify Deterioration Before Crisis