ISO 27001 Certified aged care software Badge

ISO 27001:2022 Certified

Independently audited information security you can rely on.

VCare operates under a certified ISO/IEC 27001:2022 information security management system (ISMS), ensuring structured controls are in place to manage risk and protect sensitive clinical and operational data.

93

Controls Implemented

ISO/IEC 27001:2022

Standard

Independently Certified

Accredited Certification Body

4

Control Categories

Our Approach To Security

At VCare, information security is more than a certification — it is a core part of how we develop our software, manage risk and protect the information entrusted to us. Our approach is guided by three principles that underpin everything we do.

01

Security by Design

Built securely from the ground up.

02

Certification & Accountability

Certified to international standards.

03

Continuous Improvement

Continuously improving security measures.

These principles work together to create a proactive and resilient approach to information security. By embedding security throughout the development of our platform, maintaining an ISO/IEC 27001:2022 certified Information Security Management System and continually strengthening our security practices, we help protect the sensitive information entrusted to us while giving our clients confidence in the security of the VCare platform.

VCare Security Capabilities

Our proactive approach to information security is supported by security measures built into every aspect of VCare. From secure access and data protection to business continuity and ongoing platform maintenance, these measures help protect sensitive information while ensuring the platform remains secure, reliable and resilient.

👤 Identity & Access

Secure access is fundamental to protecting sensitive information. VCare supports Multi-Factor Authentication (MFA), Single Sign-On (SSO) and role-based user permissions to help ensure only authorised users can access the information relevant to their role.

🔐 Data Protection

Sensitive information is protected through secure cloud hosting in New Zealand, secure data storage and industry best practices. These measures help safeguard information while supporting the confidentiality, integrity and availability of data.

🔄 Business Continuity

Business continuity is supported through regular backups and disaster recovery planning designed to minimise disruption in the event of an incident. These measures help ensure critical data can be recovered and the platform can continue to support our clients when it matters most.

📊 Monitoring & Governance

Comprehensive audit trails and document activity logs provide greater visibility into user actions and system activity. This supports governance, strengthens accountability and assists organisations with internal auditing and compliance requirements.

⚙️ Platform Resilience

The VCare platform is proactively maintained through regular updates and ongoing security monitoring. These measures help maintain a secure, reliable and resilient environment while supporting the protection and availability of the information entrusted to us.

Why ISO 27001 Matters in Aged Care

Organisations delivering aged care manage highly sensitive clinical, personal and operational information every day. Protecting this information is essential to maintaining trust, safeguarding privacy and supporting high-quality care.

 

As an ISO 27001 certified organisation, VCare has implemented an independently assessed Information Security Management System (ISMS) that supports the secure development, operation and continual improvement of our platform. This provides our clients with confidence that information security is embedded throughout our organisation.

What is ISO 27001?

ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). It defines how organisations identify risks, implement controls, and continuously improve their approach to protecting information.

Certification requires independent third-party audit and ongoing compliance review.

What ISO 27001 Means for VCare Customers

ISO/IEC 27001 certification provides assurance that your data is protected through defined controls, governance, and risk management practices.

This includes structured policies, access controls, monitoring processes, and ongoing risk assessment, supporting stringent standards for personally identifiable information, strong security awareness, and a focus on minimising risk across clinical, resident, and organisational data.

Independent Certification

Certification is issued by an accredited certification body and maintained through regular surveillance audits and periodic recertification.

This ensures that security controls are independently verified and remain effective over time.

Maintaining Certification

Maintaining ISO/IEC 27001 certification requires regular risk assessments, internal audits, surveillance audits and management review. These ongoing activities help ensure our Information Security Management System remains effective and continues to evolve alongside changing risks.

Security Resources

Information security is continually evolving, and staying informed is an important part of protecting sensitive information. We regularly publish practical security insights, industry updates and educational resources to help aged care and retirement living providers understand emerging cyber risks, strengthen their security practices and make informed decisions about protecting sensitive information. Explore our latest security insights below.

Featured Articles

ISO 27001:2022 Control List

All 93 ISO/IEC 27001:2022 Annex A controls are implemented and independently verified as part of our certified information security management system. If you would like to view the entire list of implemented controls, you can view our control summary page below.

View the JASANZ Register to search for our certification. VCare is registered under Concept Engineering.

You can find the register here:

Request Compliance Documents

Security Documentation

Get in contact with us to get a copy of our security documents.

Available on request:

ISO/IEC 27001 Certificate

Privacy Policy

Summary of Information Security Policy

Risk Management Approach

Data Protection and Privacy Overview

Statement of Applicability