Skip to content
CVChecl logo
  • Products
    • Our Checks
      • National Police Checks
      • Employment Reference Checks
      • Employment and Qualification Checks
      • VEVO Visa and Work Entitlement
      • Credit, Financial and Business Checks
      • Traffic and Licence Checks
      • Predictive Psychometric Assessments
      • International Checks
    • ID Requirements
    • Verify a CVCheck Certificate
    • CVCheck Help
  • About Us
    • Who we are
      • Our History
      • Our Mission and Values
      • Our Board
    • Why CVCheck
    • Integration Partners
    • Investor Center
  • Blog
  • Contact Us
Menu
  • Products
    • Our Checks
      • National Police Checks
      • Employment Reference Checks
      • Employment and Qualification Checks
      • VEVO Visa and Work Entitlement
      • Credit, Financial and Business Checks
      • Traffic and Licence Checks
      • Predictive Psychometric Assessments
      • International Checks
    • ID Requirements
    • Verify a CVCheck Certificate
    • CVCheck Help
  • About Us
    • Who we are
      • Our History
      • Our Mission and Values
      • Our Board
    • Why CVCheck
    • Integration Partners
    • Investor Center
  • Blog
  • Contact Us
CVCheck Checkpoint logo
Search
Close this search box.
  • Categories
    • HR
    • Recruitment
    • Talent Acquisition
    • Jobseekers
    • CVCheck News
    • Product News
    • News Affairs
    • SOCI Act
  • Product News
    • National Police Checks
    • Employment Reference Checks
    • Employment and Qualifications Checks
    • VEVO Visa and Work Entitlement Checks
    • Credit, Financial and Business Checks
    • Traffic and License Checks
    • Predictive Psychometric Assessments
    • Working with Children
  • Resources
    • Articles
    • Announcements
    • Case Studies
    • eBooks
    • Infographics
    • Testimonials
    • Videos
    • White Papers
Menu
  • Categories
    • HR
    • Recruitment
    • Talent Acquisition
    • Jobseekers
    • CVCheck News
    • Product News
    • News Affairs
    • SOCI Act
  • Product News
    • National Police Checks
    • Employment Reference Checks
    • Employment and Qualifications Checks
    • VEVO Visa and Work Entitlement Checks
    • Credit, Financial and Business Checks
    • Traffic and License Checks
    • Predictive Psychometric Assessments
    • Working with Children
  • Resources
    • Articles
    • Announcements
    • Case Studies
    • eBooks
    • Infographics
    • Testimonials
    • Videos
    • White Papers

How disability providers are affected by changes to the SOCI Act

  • CVCheck By CVCheck
  • June 9, 2023
soci disability featured image cz

If your company is part of the disability sector, then safety and security have always been a priority – there is no room for error when people’s lives are at stake. However, there have been recent updates to compliance laws, and as part of the healthcare and medical sector, disability providers are considered ‘critical infrastructure’ and will be affected by these changes.

The Security of Critical Infrastructure Act (the SOCI Act) is the most recent bill to go through amendments – a move influenced by widespread data security breaches across Australia – and every company in a ‘critical’ sector must now achieve compliance.

What are the changes to the SOCI Act?

Although the Security of Critical Infrastructure Act (SOCI Act) was first created in 2018, it has now been updated and expanded, and suddenly affects a new swathe of companies. After the Security Legislation (Critical Infrastructure) Act 2021, the SOCI Act was amended to enhance the security and resilience of critical infrastructure, aiming to protect against potential cyber-attacks and other security breaches. There are now 11 sectors included as critical infrastructure providers, and companies within these sectors have a 6-month window, from February 17 to August 17, 2023, to organise a Risk Management Program (RMP) in compliance with the new regulations.

How disability providers are included in the SOCI Act

Disability providers are not directly mentioned in the list of critical infrastructure providers in the SOCI Act, but they are included under the healthcare and medical sector.

Your company will be considered part of the healthcare and medical sector if it involves:

  • The provision of healthcare
  • The production, distribution, or supply of medical supplies

And if you are affected, the general requirements for your company will be:

  • Create and maintain a critical infrastructure Risk Management Program (RMP)
  • Register critical assets and report any cybersecurity events

How can disability providers meet the requirements?

The Risk Management Program (RMP) is the most time-consuming aspect of these requirements and will be the part that looms overhead as the August 17 deadline moves closer. For disability providers in the healthcare and medical sector, developing your RMP involves determining which components and sites of your asset are critical, and then analysing how its operations may be harmed by threats and hazards.

Let’s strip away the legal jargon and use the example of a hospital to illustrate. In this case, the critical sites (physical locations that are required for it to function) could be the intensive care units or data centres for Information and Communication Technology (ICT) services. And the critical components could include air conditioning and ventilation systems, or the ICT systems in the data centres.

Your job is to do what is ‘reasonably practicable’ to minimise and mitigate any risks that could affect these aspects of your asset—just replace the hospital with your company’s critical asset. And the plan you devise based on the analysis of these risks, that is your RMP. (Risk Assessment Advisory for Critical Infrastructure Healthcare and Medical Sector, 2022)

Consequences of non-compliance, through the Medibank lens

Disability providers handle sensitive, personal information, and carry out work that has a direct effect on participants’ everyday lives and well-being, so the effects of a data or security breach can be deeply damaging.

“An outage affecting a critical asset in the healthcare and medical sector could result in significant economic or societal implications, with effects including loss of life, reduced patient care, reputational damage, and financial and productivity loss.”

Risk Assessment Advisory for Critical Infrastructure Healthcare and Medical Sector, 2022

We only need to look to Medibank to see the financial and societal implications of a healthcare data breach. In October 2022, Medibank was hacked by a Russian ransomware group that released data from millions of customers onto the dark web (Brown, 2023). Personal information like customers’ addresses, date of birth, and health claims data was exposed, the latter revealing their medical history (Bogle, 2022).

A law firm has now begun proceedings in the Federal Court to compensate people affected by this breach, they state that Medibank failed to take reasonable steps to protect their customers’ information and failed to comply with legal obligations (Brown, 2023).

What happens if you fail to meet requirements

Even without the potentially dramatic consequences of non-compliance, providers will be faced with a penalty if they fail to meet obligations. If you fail to meet the requirements for the Risk Management Program (RMP), then you will receive 1,000 penalty units ($275,000) per day until you meet the requirements. You will also be penalised if you fail to meet the annual reporting requirement for your RMP, in this circumstance you will have to pay 750 penalty units ($206,250) per day (Clyde & Co, 2023).

soci disability cta cz 1

References:

Bogle, A. (2022, Oct 28). Privacy fears for children caught up in Medibank data breach. ABC News. https://www.abc.net.au/news/science/2022-10-28/medibank-data-breach-children-caught-up-privacy-concerns/101584376

Brown, M. (2023, May 5). Law firm launches class action on behalf of millions of customers caught up in Medibank data hack. ABC News. https://www.abc.net.au/news/2023-05-05/medibank-data-breach-class-action-slater-gordon/102307106

“Critical Infrastructure Update: Risk management program obligations under the SOCI Act now ‘turned on’”. Clyde & Co. (2023, February 27). https://www.clydeco.com/en/insights/2023/02/critical-infrastructure-update-risk-management-pro)

Risk Assessment Advisory for Critical Infrastructure Healthcare and Medical Sector.(2022). Cyber and Infrastructure Security Centre. https://www.cisc.gov.au/critical-infrastructure-centre-subsite/Files/raa-healthcare-medical.pdf

Recent Articles

Happy teacher and schoolboy giving each other high-five on a class.

Top 5 Checks keeping Education Sector Screened and Compliant

why an ndis check isn't enough blog featured image

Why an NDIS check isn’t enough

npc vs afp blog featured image

Understanding the Differences: National Police Checks vs. Australian Federal Police Checks

school boards responding to child safety concerns

School boards responding to child safety concerns

Browse by

Category

  • HR
  • Recruitment
  • Talent Acquisition
  • Jobseekers
  • CVCheck News
  • Product News
  • News Affairs

Product

  • National Police Checks
  • Employment Reference Checks
  • Employment and Qualifications Checks
  • VEVO Visa and Work Entitlement Checks
  • Credit, Financial and Business Checks
  • Traffic and License Checks
  • Predictive Psychometric Assessments
  • Working with Children

Resource

  • Articles
  • Announcements
  • Case Studies
  • eBooks
  • Infographics
  • Testimonials
  • Videos
  • White Papers

You may also like

Loading...
Dealing With Workplace Breaches
HR professionals & personal liability: Know your obligations
Holcim
Safety and quality – Holcim’s recruitment in the construction industry
Finance Checks For Professionals
The top 5 most requested finance checks and who’s ordering them
inspector talking with female dock worker used laptop checking cargo freight
How Cited is saving the WA mining industry millions
CVCheck Checkpoint logo
Powered by
CVCheck logo white

Browse checks

  • National Police Checks
  • Employment Reference Checks
  • Employment and Qualification Checks
  • VEVO Visa and Work Entitlement
  • Credit, Financial and Business Checks
  • Traffic and Licence Checks
  • Predictive Psychometric Assessments
  • International Checks

Quick links

  • About Us
  • Resources
  • CVCheck Help
  • Contact Us

Checkpoint Newsletter

Subscribe now

Connect with us

Facebook-f Linkedin-in Twitter Youtube Instagram
  • Copyright 2022 - CV Check Ltd
  • Privacy Policy
  • Terms of Access

Get the latest news straight to your inbox

Checkpoint provides smart and creative insights in the form of useful tips, resources and relevant information. Each month we will send you the best updates so you stay informed.