An Aged Care Provider's Guide to the Aged Care Act 2024 IT Obligations in 2026
The Aged Care Act 2024 has been in force since 1 November 2025. Six months on, the seven Strengthened Standards ask more of a provider's IT than most expected.
Jump to section
- 01 What the Aged Care Act 2024 changed for your IT
- 02 Information management under the Strengthened Standards
- 03 Records you have to keep, and for how long
- 04 Cybersecurity expectations under the new Act
- 05 Systems most providers run, and where they are weak
- 06 Shortlisting software for an aged-care provider
- 07 Annual cost of compliance for a mid-size provider
- 08 What the CEO and the governance committee need
- 09 How we work with an aged-care provider
- 10 Primary sources
We write this as IT operators. It covers the systems and software Australian aged-care providers use under the Aged Care Act 2024 and the Strengthened Aged Care Quality Standards. It isn’t legal advice, a clinical-governance opinion, or an Aged Care Quality and Safety Commission compliance ruling. Whether any particular control satisfies your obligations is your governance lead’s, your aged-care lawyer’s, or the Commission’s call. We implement the technical stack. They decide whether it is enough.
The Aged Care Act 2024 has been in force since 1 November 2025, and seven Strengthened Aged Care Quality Standards commenced alongside it. Six months on, the registered providers we work with are seeing what those Standards mean day to day. The IT side is heavier than most expected at commencement. Information management is now a standard of its own, and the Commission has published a practice guide for it. Cyber resilience expectations have firmed up significantly. The Commission’s audit posture has shifted from “do you have a policy” to “show me how the policy operates”.
Aged care has been the most-attacked sub-sector of healthcare in Australia for several years now. The attackers have not slowed down since the new Act commenced. Small and mid-size providers are where the new Act’s expectations and the available staffing budget are hardest to reconcile. That means residential providers running one to five facilities, and home-care providers with 50 to 250 staff. A default IT setup no longer meets the Strengthened Standards at that size. The work is real.
What the Aged Care Act 2024 changed for your IT
The Aged Care Act 2024 replaced the Aged Care Act 1997. It brought residential, home and flexible aged care under a single rights-based statute. Three changes matter most for IT. Information management became an explicit standard within the Strengthened Quality Standards. The governance expectation around cybersecurity sharpened. And the link between information integrity and quality of care tightened.
The Act and the Standards are rights-based and outcomes-focused, so they do not prescribe technology. But the outcomes they require are hard to deliver without modern identity controls, retention discipline and properly tested resilience.
The move from the 1997 framework to the 2024 one was material in clinical and governance terms. For IT, the practical effect is that “we have a system” is no longer enough. You have to show the system operates the way the standards describe, and produce audit-grade evidence that it does. The Commission’s emerging audit posture matches that shift.
Information management under the Strengthened Standards
The standard requires you to run an information management system. Four things have to be true of it:
- Records are managed.
- Workers get access to the right information at the right time.
- Older people and their supporters can access the information they need.
- Stored information is accurate and complete.
The Commission’s practice guide expands on each element. It describes what compliance looks like in operation across a provider’s clinical, financial, workforce and quality records.
The key word is “system”. A clinical-records platform on its own does not satisfy the standard. You have to operate a coherent environment across clinical records, care planning, incident management, complaints, workforce credentialling and financial management. That includes the records each of those produce.
Information has to move between those systems where it needs to. Access controls have to be right at each step. And the audit trail has to demonstrate information integrity.
This is the standard that exposes a patchwork of legacy systems with staff moving data between them by hand. Say you run one system for clinical care, a second for incidents and complaints, a third for workforce and a fourth for finance. Microsoft 365 handles documents and email. That can satisfy the standard. But only if the integrations are documented, the access controls agree with each other, and the audit trail can be reconstructed end-to-end. Most providers we onboard cannot do that out of the box.
Records you have to keep, and for how long
Retention obligations apply to clinical records, care plans, incident reports, complaints records and medication administration records. They also apply to the financial records tied to a resident’s or recipient’s care. The minimums vary by record type and by the state legislation that applies.
Seven years from the date of the last entry is a common minimum for the clinical records of an adult. Records of a person who was a minor at the time of care are kept longer. Records subject to an active complaint, investigation or coronial proceeding have to be kept indefinitely, until those processes conclude.
For most providers these obligations overlap. Several sets of rules apply to the same record at once:
- Aged Care Act obligations.
- State health-records legislation.
- Privacy Act obligations for personal information.
- Professional registration obligations for clinical staff.
Whatever system holds the record has to honour the longest rule that applies to it. One retention setting for the whole system will not do that. Retention labelling record by record is the only answer that lasts.
Cybersecurity expectations under the new Act
The Strengthened Quality Standards do not prescribe specific cybersecurity controls. But the Governance and Information Management standards together expect you to manage the cyber risks to the information you hold. The Commission has been clear, in published guidance and in how it runs audits, that cybersecurity is not optional.
A breach affecting personal information triggers Notifiable Data Breach obligations under the Privacy Act on its own. A breach that happened because baseline controls were missing also draws Commission attention, through the governance standard.
Audit conversations across our aged-care clients have produced a practical baseline. It is closer to the Essential Eight, the Australian Signals Directorate’s eight baseline security controls, than to anything more specialist.
- Multi-factor authentication (MFA) on all administrative and clinical-system access. MFA is the second step after the password: a code typed, or a prompt approved on a phone.
- Application control, or restricted application installation.
- Patching of operating systems and applications on a defined cadence.
- User application hardening.
- Restricted use of administrative privileges.
- Backup of critical data with tested restore.
- Daily backups of critical data.
The Commission does not name the Essential Eight. But a provider that can demonstrate those controls in operation is much better positioned in an audit conversation than one that cannot.
Why aged care is a ransomware target
Aged care is the most-attacked sub-sector of Australian healthcare, and the targeting is opportunistic rather than sophisticated. The dominant pattern is a phishing email that ends in ransomware, aimed at an under-resourced IT environment. The easiest targets in the sector are providers with no MFA on email, no application control on staff devices and no tested backup.
A meaningful number of the ransomware events we have responded to in this sector started the same way. A clinical or rostering staff member opened an email attachment from a familiar-looking sender, on a device with no application control.
The risk is real and the controls that reduce it are well understood. The Commission’s audit posture under the new Act gives providers an explicit accountability framework for managing it. Running care services through a ransomware event is hard on its own. Doing it while meeting Privacy Act notification obligations and Commission compliance expectations is harsh on a provider without baseline controls.
Systems most providers run, and where they are weak
A typical mid-size residential or home-care provider runs five kinds of system:
- Clinical care. AutumnCare, Manad Plus, Leecare, iCareHealth, Person Centred Software and similar.
- Workforce and rostering.
- Finance.
- Microsoft 365, for general productivity.
- Point tools for medication administration, incident management, family communication and clinical assessment.
The weak points are in three places.
First, the integrations between the clinical platform and everything else. The clinical platform usually has its own access controls and audit trail, which the provider has invested time in configuring. The other systems are often set to a default that does not match. A workforce system that lets the human resources team see clinical records they do not need is a finding waiting to happen.
Second, the Microsoft 365 environment. Most providers have it because it came with the email subscription, not because anyone configured it for aged-care information management. Retention labels are usually absent. Conditional access, the rules deciding who can sign in and from which device, is usually permissive. Audit logging is usually unconfigured, and data loss prevention is usually off.
Third, the device estate. Clinical staff use shared devices in care areas. Administrative staff use personal devices in some setups. In many providers the device estate has not been brought under modern device management. A device that is not enrolled cannot be patched, controlled or wiped if it is lost.
Home-care versus residential exposure
Home-care providers have a different IT risk profile to residential providers. The workforce is mobile, the devices travel, and the office network controls nothing once a staff member is in a recipient’s home.
The information-management obligations are the same. The way you meet them has to be built around the device, not the network. That means managed devices, conditional access, encryption at rest, and MFA enforced wherever the person is. Home-care providers running a “trusted office network” with personal devices outside it usually need larger catch-up projects than residential providers of the same size.
Shortlisting software for an aged-care provider
There is no single shortlist. The choice depends on which clinical platform you are committed to, and on what your existing Microsoft 365 environment supports. Four patterns have worked in our engagements over the past six months.
- A clinical platform with mature audit logging and role-based access at the field level. Some Australian aged-care platforms have invested heavily in this. Others lag.
- A Microsoft 365 environment configured properly for aged-care information management. That means retention labels by record type, conditional access by user role, and audit logging on. It also means data loss prevention on clinical and financial document libraries.
- Modern device management. Microsoft Intune, for the typical Microsoft-aligned provider.
- A backup and recovery approach tested against the clinical platform, not just promised by the vendor.
The clinical platform is the biggest decision here. If you are due a platform refresh, evaluate against the Strengthened Standards’ Information Management criteria directly, not against an older procurement framework. Three things are non-negotiable. Audit logging at field level. Role-based access where nobody starts with more than their job needs. And an audit trail you can export if you change vendors.
Off-the-shelf versus custom build
There is no case for a custom-built clinical platform at the size of provider we typically work with. The off-the-shelf market is mature and competitive. Custom development in a regulated clinical environment adds a risk that a few extra features cannot justify.
The realistic work is integration. Wiring the clinical platform, the workforce platform, the finance system and Microsoft 365 together, so the Strengthened Standards can be operated against coherently. Most of the real implementation effort is there.
Microsoft 365 licensing for aged-care providers
Most providers rely on Microsoft 365 for retention labelling, audit logging, conditional access and data loss prevention. If yours does, the licence tier matters. Microsoft 365 Business Premium covers the basic features. E3 with the E5 Security add-on, or full E5, adds advanced auditing, identity protection, and eDiscovery for answering a legal or regulatory request. Audits and serious incident responses both rely on those. E3 and E5 are the tiers above Business Premium.
Providers on Business Standard cannot produce the evidence the Strengthened Standards imply. The licence step-up is a real cost line. For a provider of 100 staff, the difference between Business Premium and E3 plus E5 Security across all named users is meaningful annually. Put it in the IT budget conversation alongside the clinical platform fees.
Annual cost of compliance for a mid-size provider
For a 50-to-200-seat Australian aged-care provider, the typical IT-side cost of running compliantly with the Strengthened Standards is 30,000 to 90,000 Australian dollars a year. That covers software licensing, integration support, device management, and backup-and-recovery discipline.
One-off catch-up projects can be a multiple of that. They usually arrive in the year a provider deals with an end-of-life clinical platform or an unmanaged device estate. Or a Microsoft 365 environment that needs configuring from the ground up.
The cost varies most with the maturity of what is already there. A provider with a current clinical platform, a tidy Microsoft 365 environment and a managed device estate is at the lower end. A provider that has deferred IT investment across the board is at the higher end. That provider usually needs a one-off catch-up project before the operating cost settles.
What the CEO and the governance committee need
Cybersecurity and information management are now governance-level concerns, with a specific accountability framework attached. The chief executive needs to be confident that a Commission audit will not surface a material finding on the IT side. The governance committee needs to see the controls protecting resident and recipient information. Ransomware incidents across the sub-sector over the past two years have made that unavoidable.
In practice, governance attention is two things. The first is a documented assessment of the IT environment against the Strengthened Standards, refreshed annually, with the gaps tracked and fixed against a budget. The second is a standing reporting line:
- Monthly cyber-risk position to the executive.
- Quarterly governance-committee briefing on information management.
- A documented incident-response plan the committee has signed off on.
How we work with an aged-care provider
We do not interpret the Quality Standards. We set up the IT systems you need to operate compliantly against them, and we keep those systems audit-ready and resilient.
The work usually breaks into three streams.
Microsoft 365. Identity, retention labels, conditional access, audit logging, data loss prevention, and the licence uplift where the current tier cannot support the audit evidence.
Devices and integration. Modern device management for shared care-area devices and mobile home-care devices. The integration discipline that makes the clinical platform, the workforce platform and the finance system work as one information environment, not four silos.
Resilience. Backup, tested recovery, and an incident-response capability for the kind of ransomware event that hits this sector regularly. Plus the cyber-controls baseline, Essential Eight or close to it, that reduces the chance of an incident in the first place.
The interpretation of the Standards stays with the provider’s clinical and governance leadership. So does the design of the clinical-governance framework, and the call on whether any particular control satisfies any particular Standard. Our boundary is explicit. We handle the machinery. They handle the interpretation.
Providers that did the IT catch-up work before 1 November 2025 are now in a steady rhythm. Providers that deferred it are working through the catch-up against the active audit cycle, which is harder. The Commission’s audit cadence does not pause for IT catch-up projects, and the attackers do not pause for governance frameworks. Better to be ahead of both.
Primary sources
- Strengthened Aged Care Quality Standards, Department of Health, Disability and Ageing. Accessed 5 May 2026.
- Information management practice guide, Aged Care Quality and Safety Commission. Accessed 5 May 2026.
- Aged Care Act 2024 (Cth), available via Federal Register of Legislation.
- Privacy Act 1988 (Cth), in particular the Notifiable Data Breaches scheme provisions, available via Federal Register of Legislation.