This page is currently under construction. For orders, please visit https://shop.aushealth.com.au/
or return to Aushealth homepage.
AusHealth
Home / Healthcare Revenue Management / Quality Compliance And Data Security

Quality, Compliance and Data Security

AusHealth Hospitals meets all certifications and assurances – so you do, too

Quality, Compliance and Data Security

Outsourced revenue recovery rests on trust — the accuracy of the work, the legality of every patient contact and the security of the clinical and financial data moving through it.
AusHealth manages that foundation with independently certified systems, a credentialled compliance function and a modern, standards-aligned security environment, so the health services we work with can evidence quality, meet their obligations and protect their data without carrying the governance overhead.

AusHealth is independently certified to ISO 9001 (Quality) and ISO 45001 (Safety) and aligns its information-security controls to ISO/IEC 27001 and the ASD Essential Eight — the position our SOCI-classified clients rely on.

Our quality, compliance and data security framework includes

  • Certified quality management: An Integrated Quality Management System certified to ISO 9001:2015 and ISO 45001:2018 (TQCSI), with clinical coders assigning accurate diagnostic and procedure codes to ICD-10-AM/ACHI/ACS, state coding authorities and IHACPA conventions.
  • Quality assurance: Calls are recorded and a sample is reviewed each month against conduct, accuracy and hardship standards, with results fed into coaching to improve quality and compliance.
  • Australian data hosting: Client data, including data held in our Collect system, is stored and processed in Australia, and our key technology suppliers are assessed for security and privacy risk before and during engagement.
  • Staff screening and training: Staff undergo pre-employment screening, including National Police Checks, and are bound by annual confidentiality agreements and training.
  • Regulatory compliance: A documented Legislative Compliance Procedure and Register aligning AusHealth to the ACCC/ASIC Debt Collection Guidelines, Australian Consumer Law, and privacy, credit and anti-discrimination law – with no finding of non-compliance under any law relevant to debt collection.
  • Governed compliance and risk: A Compliance and Performance Policy consistent with AS 3806 and ISO 37301, enacted by a credentialled Quality and Compliance Manager with internal audit, and a risk system aligned to AS/NZS ISO 31000 with a Risk and Quality Plan for each implementation.
  • Layered information security: Controls aligned to the ASD Essential Eight – application hardening, timely patching and application control, least-privilege access, multi-factor authentication across every access point, and secure, immutable daily backups. Controls are tested through regular vulnerability scanning and independent penetration testing.
  • ISO/IEC 27001 controls and encryption: AusHealth is pursuing ISO/IEC 27001 accreditation under the Australian Government PSPF and ISM, with access-controlled sites, encryption at rest and in transit, endpoint protection and automated monitoring with full audit trails.
  • Secure transfer, payments and privacy: A modern SFTP architecture using each client’s own identity provider, conditional access for cloud resources and annually reviewed PCI-DSS attestations; data is handled under the Privacy Act, its Privacy Principles and ISO/IEC 29100, with staff bound by annual confidentiality agreements and training.  Client data is never entered into public AI tools.
  • Records, complaints and responsible business: Records managed to AS ISO 15489 and complaints to AS ISO 10002 and the NSQHS Clinical Governance Standard; full insurance cover; alignment to the Modern Slavery Act 2018; and, as a registered charity, profit returned to medical research – over $60 million since 1985.

Bottom line: every check and control is documented, mapped to a recognised standard and independently audited where applicable — so you can outsource revenue recovery knowing your patients’ data and your organisation’s obligations are protected, and compliance can be evidenced rather than asserted.

If quality, compliance and data security are currently assured through separate policies or ad-hoc controls, a focused review can confirm where obligations are met and where independent, standards-based assurance would strengthen your position.

 

Hit enter to search or ESC to close