What are the IT requirements under the Aged Care Quality Standards?

Stuart providing remote support

Search for this question and most of what comes back describes the old eight Aged Care Quality Standards. Those were replaced on 1 November 2025, when the strengthened Quality Standards commenced alongside the new Aged Care Act 2024. If your compliance folder still maps to Standard 8 Organisational Governance, it is mapped to a framework that no longer applies.

This guide covers what the strengthened Standards actually ask of your IT systems, which outcomes they sit under, and what an assessor is likely to want to see. It is written for facility managers and quality leads in Western Australia, not for IT people.

Everything below breaks down each part of C6.4, what it means day to day, and how a practice actually satisfies it.

Which parts of the Aged Care Quality Standards actually apply to our IT?

There is no IT standard. No outcome mentions firewalls, backup schedules or antivirus. What the Standards do instead is describe results your systems have to deliver, and leave the technology choices to you.

Three outcomes carry almost all of the IT weight, and all three sit inside Standard 2: The Organisation.

  • Outcome 2.7 — Information management. The core one. Records must be accurate, current, secure, accessible to the right people at the right time, and handled with informed consent.
  • Outcome 2.4 — Risk management. Where cyber security lives. There is no separate cyber outcome.
  • Outcome 2.10 — Emergency and disaster management. Where business continuity and recovery testing land.

One nuance that generic compliance checklists tend to miss: not every provider is assessed against every Standard. Under the regulatory model, providers in registration categories 4 to 6 must meet the strengthened Standards relevant to the services they deliver. Providers in category 4 must meet Standards 1, 2, 3 and 4 — which means Outcome 2.7 applies. Providers in categories 1 to 3 are not audited against the Standards at all and have different obligations under the Act. Confirm your registration category before you scope any of this work.

Did the strengthened Standards change what we need from our systems?

Yes, though less in substance than in how it is proven.

The headline changes: eight Standards became seven, and the framework now contains 33 outcomes supported by 154 actions. The outcome statements sit in the Aged Care Rules as subordinate legislation, so they are enforceable rather than advisory.

The change that matters most for IT is the assessment method. Providers are now graded at the level of each individual outcome, and those gradings feed the overall Standard rating and your Star Rating on the Find a Provider tool. Under the old model, a strong governance narrative could carry a weak area. Under outcome-level grading, information management is assessed on its own merits.

The practical consequence: a policy document describing how you manage records is no longer sufficient evidence that you manage records well. Assessors look for the system working, not the intention to have one.

What does Outcome 2.7 require, action by action?

Outcome 2.7 has three actions. The second has five sub-parts. Here is each one, what it means for your systems, and where we come in.

2.7.1 — Implement an information management system that securely manages records

What this means in practice. You need one identifiable system of record, and it has to be secure. “Secure” here is doing a lot of work: access controlled by role, protected against loss, and protected against unauthorised access. Two shared logins on a nurses station workstation will not survive scrutiny, because you cannot demonstrate who accessed what.

Note the phrasing is a system, singular, to manage records. Care records in Leecare, incident records in a spreadsheet on a desktop, and consent forms in a filing cabinet is three systems, and the gaps between them are where evidence goes missing.

How Bluebird IT helps. We support Leecare, Clinical Manager (formerly iCareHealth), e-Tools and Care Systems, and we work on the infrastructure underneath them: individual user accounts with role-based access, multi-factor authentication, encrypted storage, and audit logging that can actually answer the question of who opened a resident file and when.

2.7.2(a) — The right people can access the right information at the right time

What this means in practice. Access is a requirement, not just a risk to be minimised. Care staff, visiting GPs, allied health professionals, agency staff and the older person themselves all need appropriate access. Locking everything down until nobody can reach anything is as much a non-conformance as leaving it open.

The recurring failure here is the visiting practitioner. A locum or a visiting physiotherapist arrives, cannot get an account, and ends up working from a printout or a colleague’s session. That is a 2.7.2(a) gap and an access-control gap simultaneously.

How Bluebird IT helps. We configure role-based access within your care platform and build guest and temporary accounts that can be issued quickly and expire on their own, so the fast path for a visiting practitioner is the compliant path rather than a borrowed login.

2.7.2(b) — Information collected and stored stays accurate and complete

What this means in practice. Accuracy is partly a clinical practice question and partly a systems question. The systems half is about preventing silent data loss: records that fail to sync from a mobile device on the floor, documents saved to a local drive that is not backed up, and entries lost when a session times out mid-note.

Integration between services counts here too, including telehealth. If a telehealth consultation produces notes that live only in the telehealth platform, the resident record is incomplete.

How Bluebird IT helps. Reliable device sync across the facility, wireless coverage that holds up in the areas where staff actually chart, storage that is backed up by default rather than by staff remembering to save in the right place, and enough capacity that nothing is being deleted to make room.

2.7.2(c) — Informed consent is obtained to collect, use, store and disclose information

What this means in practice. This is primarily a process obligation, but it has a systems tail. Consent has to be recorded, findable, and current — and when consent is withdrawn, that has to be recorded and communicated too.

The technical question is whether your system can tell you, for any given resident, what they have consented to share and with whom. If answering that requires opening a paper file, disclosure decisions are being made without the record in front of the person making them.

How Bluebird IT helps. We make sure consent records are stored where they are visible alongside the resident record in your care platform and included in backup and retention, rather than sitting in a separate document store nobody thinks to check.

Bluebird IT Team Photo

2.7.2(d) — People understand their right to access, correct, or withdraw consent

What this means in practice. Residents and their supporters can ask to see their information, ask for corrections, and withdraw consent. Your system needs to make it possible to actually fulfil those requests within a reasonable time.

Extracting one resident’s complete record is harder than most facilities expect, particularly where information is spread across a care platform, an email archive and scanned documents.

How Bluebird IT helps. We help you find out, before someone asks, how long it takes to assemble a complete record for one resident — and reduce that time where the answer is uncomfortable.

2.7.2(e) — Information from different sources is integrated

What this means in practice. Hospital discharge summaries, GP correspondence, allied health reports and pathology results need to reach the resident record rather than accumulating in an inbox. Where information arrives by fax or email, someone has to move it, and that step is where things go missing.

How Bluebird IT helps. We reduce the number of manual handling steps between an inbound document and the resident record, including secure messaging and digital fax where it replaces a paper process, and we handle the integration points between your care platform and the rest of your systems.

2.7.3 — Regularly review and improve the effectiveness of the system

What this means in practice. Review is itself an action you are assessed against, and the guidance is explicit that it includes current technologies and data practices. A system chosen in 2018 and never revisited is a finding waiting to happen even if it works.

Evidence of review can be drawn from care plan audits, complaints and feedback, incident data, and how well staff are actually using the system.

How Bluebird IT helps. We provide a scheduled review of the technical side — access rights that have drifted, accounts belonging to departed staff, storage nearing capacity, care platform versions approaching end of support — written up so it can go straight into your continuous improvement record.

Does our information management system have to be digital?

What this means in practice. Review is itself an action you are assessed against, and the guidance is explicit that it includes current technologies and data practices. A system chosen in 2018 and never revisited is a finding waiting to happen even if it works.

Evidence of review can be drawn from care plan audits, complaints and feedback, incident data, and how well staff are actually using the system.

How Bluebird IT helps. We provide a scheduled review of the technical side — access rights that have drifted, accounts belonging to departed staff, storage nearing capacity, care platform versions approaching end of support — written up so it can go straight into your continuous improvement record.

Where does cyber security sit in the strengthened Standards?

Under risk management, not under information management. The guidance for Outcome 2.7 directs providers to manage cyber security risks under Outcome 2.4.

This matters more than it sounds. It means cyber security is not a technical matter that lives with your IT provider — it belongs in your organisation-wide risk register, with named owners, mitigations and review dates, alongside falls and medication risks. If your risk register has no cyber entries, that is visible at audit under 2.4 regardless of how good your actual defences are.

It also means your IT provider needs to give you information in a form you can put into a risk register, rather than a technical report you cannot translate.

What happens to our records when the internet or the power goes down?

You need a documented way to keep delivering care, and the guidance names two approaches directly: processes that make information available offline, and processes to record clinical information on paper during internet or power outages.

This is sharper for regional and remote providers, where a connectivity outage can last longer and there is no option to drive to another site. A workable downtime plan usually needs four things:

  1. A current offline copy of the information needed to run a shift safely — who is here, what they take, what they must not have.
  2. Paper forms that already exist, printed, in a known location, rather than forms someone has to find and print during the outage.
  3. A defined trigger for switching to downtime mode, so it is a decision rather than a drift.
  4. A back-loading process for entering paper records once systems return, because information sitting on paper after the fact is a 2.7.2(b) completeness gap.

Point four is the one most often missing. The outage gets handled; the records never fully catch up.

What does Outcome 2.10 mean for our backups and recovery?

Outcome 2.10 requires emergency and disaster management plans, strategies to prepare and respond, engagement with residents and staff about those plans, and regular testing and review of the plans in partnership with residents, staff and response partners.

For IT, the demanding word is testing. Backups that have never been restored are not evidence of recovery capability, they are evidence of intent. The question an assessor can reasonably ask is when you last proved you could restore, and what the result was.

If you are reviewing your recovery position, the two figures worth establishing first are how much data you would lose and how long you would be down — both measured, not estimated.

How will an assessor check this at audit?

Expect evidence rather than documents. Under outcome-level grading, each outcome is rated on what can be demonstrated.

Likely lines of enquiry for the outcomes covered here:

  • Asking a care worker to retrieve a specific piece of information and watching how long it takes and whether they can.
  • Checking that access levels match roles, and that departed staff no longer have accounts.
  • Looking for consent records and withdrawal records that are current and findable.
  • Asking when the information management system was last reviewed, and what changed as a result.
  • Asking when the emergency and disaster plan was last tested, and who took part.

None of these are answered by a policy document alone.

Where to start before your next audit

If you take one thing from this guide, make it the review evidence. Outcomes 2.7.3 and 2.10.4 both require regular review and testing, and both are straightforward to fail simply because nobody wrote down that it happened.

Bluebird IT works exclusively with healthcare organisations across Western Australia, and aged care is a core part of that work. We support providers including Bedingfeld Park and East Pilbara Independence Support, from the Peel region to remote northern communities. Our clients reach us with a typical response time of under 5 minutes during business hours.

If you would like your information management systems reviewed against Outcomes 2.7, 2.4 and 2.10 before your next audit, we can walk through it with you and give you the technical evidence in a form your quality team can use. You can read more about our specialist IT support for WA aged care facilities, including Leecare, Clinical Manager (formerly iCareHealth), e-Tools and Care Systems.

If your facility is outside the metropolitan area, we ship pre-configured equipment and resolve most issues remotely — see how we support aged care providers in remote and northern WA.

Your phone system carries family contact and clinical coordination, and it belongs in the same conversation — 3CX phone systems for aged care facilities run on the same agreement as the rest of your IT.

Your next steps

1
2
3
Bluebird IT healthcare IT specialist meeting with client

Let's talk

We'll learn about your organisation, your clinical systems, and what's keeping you up at night.

Bluebird IT technician providing managed IT support for WA healthcare providers

Choose your plan

If we're the right fit, you'll select the IT service agreement that best suits your organisation.

Bluebird IT providing managed IT support for WA healthcare providers

Focus on resident care

With Bluebird IT managing your technology, your team can do what they do best — delivering outstanding care to your residents.