Anand Technologies Bot

The NDIS Provider’s Guide to IT Compliance and Participant Data Security

Essential Eight Maturity Level 2 cybersecurity compliance for Australian SMBs

The NDIS Practice Standards say very little about servers, laptops or cloud platforms. They say a great deal about participant information — how it is collected, stored, accessed, corrected and disposed of. That makes your IT systems the mechanism by which you either meet those standards or fail an audit.

Most registered providers discover this the hard way, during a mid-term audit, when an auditor asks who can access participant records and nobody can produce an answer backed by evidence. This guide covers what the standards actually require of your systems, what auditors ask for, and the practical controls that make an NDIS provider audit-ready.

Why IT sits inside the Practice Standards

Registered NDIS providers are regulated by the NDIS Quality and Safeguards Commission and assessed against the NDIS Practice Standards. Several modules bear directly on information systems:

  • Privacy and dignity — participants control who sees their information, and providers must protect it
  • Information management — records must be accurate, current, secure, retrievable and disposed of appropriately
  • Incident management — incidents must be recorded, escalated and retained in a form that withstands scrutiny
  • Governance and operational management — including risk management, which now unavoidably includes cyber risk

On top of the Practice Standards, providers handling health information fall under the Privacy Act and the Notifiable Data Breach scheme. If participant data is compromised in a way likely to cause serious harm, you must notify both the Office of the Australian Information Commissioner and the affected participants.

The stakes have risen sharply. As of April 2026, civil penalties for serious non-compliance can exceed $15 million where a participant is harmed, alongside new criminal offences carrying custodial sentences for the most serious breaches.

What auditors actually ask about your systems

Auditors rarely ask technical questions. They ask operational ones and expect your systems to answer them:

  • Who can access participant records, and how do you know?
  • What happens to a support worker’s access the day they leave?
  • Can you show me the incident record for this date, unaltered?
  • Where is participant data physically stored?
  • How would you know if records had been accessed inappropriately?
  • What is your process if participant data is exposed?

Each of these is an IT control problem dressed as a governance question. If your answer relies on someone remembering, you will struggle.

The seven controls that matter most

1. Role-based access, not shared logins

Shared accounts are the most common serious finding in NDIS provider assessments. If three coordinators use one login, you cannot demonstrate who accessed a participant’s record, which defeats both the privacy standard and any meaningful incident investigation.

Every staff member needs their own account, with access scoped to the participants and functions their role requires. A support worker on one participant’s plan does not need access to every plan in the organisation.

2. Offboarding that actually revokes access

Disability support has genuine staff turnover. Every departure needs a documented process that disables accounts, revokes mobile device access, removes the person from shared drives, and reclaims any devices — on the day they finish, not at the end of the month.

Auditors frequently test this by asking for a list of active accounts and comparing it to your current staff roster. Mismatches are hard to explain.

3. Australian data residency, verified

The Practice Standards do not mandate onshore storage in every case, but participants and auditors reasonably expect to know where records live. Many providers assume their software stores data in Australia without ever confirming it.

Ask each vendor in writing where participant data is stored, where backups are held, and which jurisdictions support staff access it from. Keep the answers. Microsoft 365 and Google Workspace both offer Australian data residency, but it depends on how your tenant was provisioned.

4. Immutable incident records

Incident data must be retained in a form that cannot be quietly altered after the fact. A shared spreadsheet fails this test — it has no reliable version history and no meaningful audit trail.

Use a system that timestamps entries, records who made each change, retains previous versions, and prevents deletion by ordinary users. If you record incidents in documents, they need to sit in a platform with version history and retention policies enabled.

5. Backups that have been restored

Participant records are the operational core of your organisation. Losing them is both a service failure and a reportable problem. Backups need to run automatically, be retained in line with NDIS record-keeping requirements, and — critically — be tested by actually restoring data.

Backups must also be protected from deletion by ordinary administrator accounts. Ransomware attackers delete backups first, and a provider without recoverable participant records is in a genuinely serious position.

6. MFA on everything holding participant data

Multi-factor authentication on email, your client management system and any remote access is now a baseline expectation rather than a refinement. Most participant data exposure begins with a compromised staff mailbox, not a sophisticated intrusion.

7. A breach response plan you have rehearsed

The Notifiable Data Breach scheme gives you 30 days to assess a suspected eligible breach, and requires prompt notification where serious harm is likely. Thirty days sounds generous until you are trying to establish what was accessed with no logging in place.

Your plan needs named responsibilities, a containment process, an assessment method, and pre-drafted notification templates for the OAIC and for participants.

Choosing NDIS software without regret

Purpose-built NDIS platforms handle plan management, rostering, claiming, incident capture and worker credential tracking. Good ones automatically track police checks, NDIS Worker Screening clearances and training expiry, alerting you before they lapse.

Before committing, get written answers to these:

  • Where is participant data stored and backed up, by jurisdiction?
  • Does it maintain a tamper-evident audit trail of record access and changes?
  • Can access be scoped per participant, not just per role?
  • Does it export your data in a usable format if you leave?
  • Does it integrate with your accounting and payroll, or will staff double-enter?
  • What happens to your data at the end of the contract?

That last question matters more than most providers realise. Data portability is the difference between changing platforms and being trapped in one.

Common compliance gaps in Australian NDIS providers

Gap Why it fails an audit Fix
Shared logins Cannot attribute record access to an individual Individual accounts, role-scoped access
Participant data in personal email Outside organisational control and retention Move to managed platform, block forwarding
Ex-staff accounts still active Unauthorised access risk, no access control evidence Documented same-day offboarding
Untested backups Cannot demonstrate records are recoverable Quarterly restore test, documented
Incidents in a spreadsheet No tamper evidence or reliable version history Platform with audit trail and retention
Unknown data location Cannot answer a basic privacy question Written vendor confirmation, retained

Building an audit-ready environment

The providers who handle audits comfortably are not the ones with the most expensive systems. They are the ones who can produce evidence quickly — an access list, an offboarding record, a restore test log, a vendor data residency letter.

That evidence comes from consistent operation, which is where an experienced managed provider earns its keep. The Anand Technologies supports NDIS and disability services providers with managed IT services built around access control, monitored backups and documented offboarding, backed by advanced endpoint and email protection. For providers outgrowing spreadsheets, our business IT solutions team helps select and implement systems that hold up under Commission scrutiny.

Frequently asked questions

Does the NDIS require participant data to be stored in Australia?

The Practice Standards require secure management of participant information but do not universally mandate onshore storage. In practice, participants and auditors expect you to know exactly where data is held, and Australian data residency is the simplest defensible position. Confirm it in writing with every vendor and retain the confirmation.

How long must NDIS providers keep participant records?

Record retention obligations vary by record type and by the state or territory legislation that applies alongside NDIS requirements — records relating to children and to incidents typically attract longer periods. Confirm your specific obligations with the NDIS Commission and your legal adviser, then configure retention in your systems to match rather than deleting on an ad hoc basis.

What happens if participant data is breached?

If the breach is likely to result in serious harm, it is an eligible data breach under the Notifiable Data Breach scheme. You must assess it promptly, and where the threshold is met, notify the OAIC and the affected participants. Depending on the circumstances, reporting obligations to the NDIS Commission may also apply.

Do we need specialised NDIS software, or is Microsoft 365 enough?

Microsoft 365 can provide secure storage, access control, retention and audit logging, and many smaller providers run compliantly on it. Purpose-built NDIS platforms add plan management, claiming, rostering and worker credential tracking. Most providers end up using both — the productivity platform for documents and email, the NDIS platform for participant and claiming workflows.

What is the most common IT finding in NDIS audits?

Access control. Specifically shared logins, former staff whose accounts remain active, and an inability to demonstrate who has accessed a participant’s record. All three are fixable with individual accounts, role-based permissions and a documented offboarding process.

Where to start

If you do nothing else this quarter, do three things: give every staff member their own login, run an access review against your current roster, and restore a backup to prove you can. Those three steps close the gaps auditors find most often and cost very little.

For a review of how your current systems would hold up against the Practice Standards, talk to our team.

Comments are closed.