Skip to content
Paperbark NDIS
Open menu

Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.

Documentation

How To Write an NDIS Information Management Policy

by Penny Halpin |

Information Management is one of nine standards under Provider Governance and Operational Management in the NDIS Core Module. The outcome requires that each participant's information is identifiable, accurately recorded, current and confidential, easily accessible to the participant and appropriately utilised by relevant workers. Specifically, you need to have processes in place to ensure the following:

  • Each participant's consent is obtained to collect, use and retain their information or to disclose their information to other parties, including details of the purpose of collection, use and disclosure. Each participant is informed in what circumstances the information could be disclosed without their consent if required or authorised by law
  • Each participant is informed of how their information is stored and used, and when and how they can access or correct their information, and withdraw or amend their prior consent
  • An information management system is maintained that is relevant and proportionate to the size and scale of the organisation and records each participant's information in an accurate and timely manner
  • Documents are stored with appropriate use, access, transfer, storage, security, retrieval, retention, destruction and disposal processes relevant and proportionate to the scope and complexity of supports delivered

This article looks at what to consider when writing your information management policy and procedure.

Consent to collect, use and disclose

You need to gain consent for collecting, using, retaining and disclosing a participant's information, and also make sure you clearly explain the purpose of each.

In your policy, include:

  • What personal information you collect, and why
  • How you use that information in the course of delivering supports
  • Who you might share it with, and for what purpose (for example, other providers, health practitioners, plan managers, the NDIA, the Commission)
  • That consent is specific to each purpose, and agreeing to one doesn't mean agreeing to all
  • How consent is recorded
  • That consent can be withdrawn or amended (covered further below)

Consent should be informed, which means the participant understands what they're agreeing to before they agree. If you use a consent form, make sure someone has explained it, in a form the person can understand, and that there's a record of that conversation occurring (not just a consent signature).

Where you collect information or reports from other providers or health practitioners, the participant's consent should cover receiving and retaining that information as well.

Disclosure without consent

The first indicator also requires you to tell each participant about the circumstances in which their information could be disclosed without their consent, where this is required or authorised by law.

This can include mandatory reporting obligations (such as reporting to child protection authorities), disclosure to the NDIS Commission during an investigation or in relation to a reportable incident, and disclosure required by a court or tribunal. Your policy should name the specific circumstances that apply to your service and the types of supports you provide, rather than using a general statement.

Make sure you discuss this with participants at intake, and that it's explained in a way they can understand.

Access, correction, and withdrawal of consent

The second indicator covers three separate rights:

  • Each participant can access their own information and is told how they can do this
  • Each participant can request corrections to their information
  • Each participant can withdraw or amend their prior consent

Your policy should set out how a participant can request and gain access to their records, how quickly you'll respond, and what format the information will be provided in. If there are circumstances where access might be limited (e.g. information about a third party contained in the record), include how you'd manage this.

For corrections, consider what happens when a participant says something in their record is wrong, and document how a correction can be made, whether the original entry is retained, and how corrected information is communicated to anyone it was previously shared with.

For withdrawal of consent, set out what happens when a participant withdraws consent to collect or disclose their information, including what you can and can't continue to do with information you've already collected, and any obligations you have to retain records regardless of consent (e.g. under your reportable incidents obligations).

Information Management and Privacy and Dignity

Information Management and Privacy and Dignity are separate standards with different focuses. Privacy and Dignity is about respecting privacy and dignity in the way you deliver supports, while Information Management is about the mechanics of how participant information is collected, stored, used, secured and disposed of.

Consider cross-referencing your policies here if suitable.

Your information management system

The third indicator requires an information management system that records each participant's information accurately and in a timely manner, and is proportionate to the size and scale of your organisation.

For smaller providers, a consistent approach to recording and storing information meets this requirement. Your policy should cover:

  • Where participant records are kept (digital, paper or both)
  • Who can access them, and how access is controlled
  • How records are kept accurate and up to date
  • How you ensure information is recorded in a timely way, particularly shift notes, incident records and changes to a participant's circumstances or support needs

If workers use their own devices to access or record participant information, your policy should cover this, including what information can be stored/accessed on a personal device and what can't.

Storage, retention and destruction

The fourth indicator lists requirements for information use, access, transfer, storage, security, retrieval, retention, destruction and disposal. Your policy should address each of these.

For storage and security:

  • How records are secured, including digital (passwords, encryption, access controls) and physical (locked storage, restricted access)
  • How information is transferred between workers, locations or systems, and how it's kept secure during transfer
  • How you handle a data breach or loss of records

For retention:

  • How long you retain participant records after services end
  • How long you retain other records such as incident reports, complaints and worker records
  • Any legislative requirements that set a minimum retention period (these vary by record type and jurisdiction)

For destruction:

  • How records are destroyed when the retention period ends (secure deletion for digital records, shredding for paper)
  • Who authorises destruction
  • Whether a record of destruction is kept

What to put in place

This seems like a lot to cover, but it is required by the standards and it's also important to document these processes to strengthen your business's approach to information management. Your documentation should include:

  • An information management policy covering consent, disclosure, access, correction and withdrawal
  • A consent process that explains purpose and is recorded, not just signed
  • Guidance for workers on what information to record, where, and how quickly
  • Access controls appropriate to the size of your service
  • Retention periods for different types of records
  • A process for secure destruction when records are no longer required
  • A cross-reference to your privacy and dignity policy if suitable

Paperbark's Certification Toolkit helps you build your information management policy and procedure directly from your answers about how your service actually operates.

About the author

Penny Halpin

Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.

More about Penny →