Important upgrades to improve security of your clinical information systems

Australian Medical Association

Services Australia (the agency) is upgrading its digital health and aged care channels to web services technology. The agency is also strengthening its authentication process between health provider organisations and the agency for online claiming.

From 13 March 2022, you will need to upgrade your clinical software to web services to access any of the following channels:

  • Medicare Online

  • Australian Immunisation Register

  • Department of Veterans’ Affairs

  • ECLIPSE

  • PBS Online

  • Aged Care Online

If you use a Medicare Public Key Infrastructure (PKI) site certificate to authenticate to any of the channels above, you may need to register your organisation in Provider Digital Access (PRODA). PRODA will help you do your electronic business with the agency securely.

What healthcare providers need to do

These upgrades may affect health provider businesses differently. To find out how you will be impacted, take the following steps.

Step one: Contact your software provider to find out:

  1. How they are managing your transition to upgrade clinical software to web services (Services Australia have been communicating with software providers since 2018 to prepare for this change).

  1. When your clinical software will be upgraded to web services.

The software upgrade may vary according to your version of the clinical software used.

Step two: While your software provider continues to upgrade your clinical software to web services, you may need to register your healthcare business as an organisation in PRODA.

Contact your software developer now to confirm if you need to register your organisation in PRODA. You can set up your organisation to best reflect your business structure. Once a PRODA organisation is set up, you can link your PRODA to the digital health channels you need to access.

What if a healthcare provider purchased a clinical information system off the shelf and doesn’t have an ongoing relationship with their software provider?

In this situation, the agency recommends healthcare organisations should contact the software provider that developed the clinical software, or select a new software provider who provides clinical software that has been upgraded to web services and PRODA.

You can find developers who provide web services clinical software on the Services Australia’s website. Go to servicesaustralia.gov.au/hpwebservices and select How to find a software developer.

What if a healthcare provider does not use online claiming?

If healthcare providers use an alternative channel for claiming or don’t use clinical software, they don’t need to do anything. These upgrades won’t affect them.

You can continue accessing Health Professional Online Services (HPOS) for Medicare Online claiming or the Age Care Provider Portal for Aged Care Online claiming in the absence of a web services solution.

Why are healthcare providers required to switch to PRODA for online claiming and access to the agency’s digital health and aged care channels?

These changes will ensure Services Australia’s digital health and aged care channels are stable and using up-to-date industry standard technology.

The switch from PKI to PRODA offers higher levels of security to patient and provider information.

Do healthcare providers need to maintain their Public Key Infrastructure (PKI) site certificate?

Yes.

Medicare/PBS PKI certificates can continue to be used for purposes other than digital claiming or transmitting data to the agency. Some of these uses include:

  • Access to the HI Service

  • Prescription Exchange

  • Secure Messaging

The agency is renewing all Medicare and PBS PKI site certificates to make sure there is business continuity post 13 March 2022.

Where possible, some PKI site certificates will be auto renewed. These sites will not receive any correspondence notifying them of the renewal.

Some PKI site certificates can’t be auto-renewed and will need to be renewed manually. For these sites, a CD with their renewed Medicare SHA-1 PKI site certificate will be mailed to the last known contact at the healthcare site. These sites must install the new PKI certificate, even if:

  • their current certificate is yet to expire; or

  • they have transitioned to PRODA to authenticate for their new web services clinical software.

/AMA/AusMed News. This material from the originating organization/author(s) may be of a point-in-time nature, edited for clarity, style and length. The views and opinions expressed are those of the author(s).