Careview Hosting and NDIA Cyber Security Compliance

Careview Hosting and NDIA Cyber Security Compliance

Version 2025

This article explains how Careview meets NDIA cyber-security and data-residency requirements for NDIS plan managers. It may be provided directly to NDIA auditors or compliance assessors.


1. Hosting Location and Data Residency

Careview is hosted on Microsoft Azure in Australian datacentres only.

1.1 Australian hosting regions

Careview infrastructure and customer data are hosted exclusively in:

  1. Australia East (Sydney)    
  2. Australia Southeast (Melbourne)

These Azure regions are IRAP-assessed for Australian Government workloads.

1.2 Backups and redundancy

All backups, replicas and disaster-recovery systems remain within Australian Azure regions.

1.3 What stays on-shore

The following data always remains fully on-shore:

  1. NDIS participant information
  2. Customer operational data
  3. Documents and attachments
  4. Database records
  5. Audit logs
  6. Backups and archival data

Careview does not store or process NDIS participant data outside Australia.

1.4 About offshore telemetry (non-PII)

As with all modern cloud platforms, some non-identifying operational telemetry handled by Microsoft Azure (such as system health signals, routing metadata, or global performance metrics) may be processed offshore.

This telemetry never includes:

  1. NDIS participant information
  2. Any personally identifiable information
  3. Any NDIA-related data
  4. Any customer documents or content stored in Careview

This is normal and accepted under NDIA, NDIS Practice Standards, and Australian Government Information Security Manual expectations.


2. Encryption and Protection of Data

2.1 Encryption in transit

All connections to Careview use:

  1. HTTPS
  2. TLS 1.2 or TLS 1.3
  3. ​AES-256-GCM or AES-128-GCM cipher suites
  4. ​Ephemeral ECDHE/DHE key exchange
  5. SHA-256 or SHA-384 hashing
Legacy protocols (SSL, TLS 1.0, TLS 1.1) are disabled.

2.2 Encryption at rest

Careview data is encrypted at rest using:

  1. AES-256 for databases
  2. AES-256 for file storage
  3. AES-256 for backups and managed disks

2.3 Certificates

Careview uses RSA-SHA256 TLS certificates issued by a recognised Certificate Authority. Azure Front Door and App Service enforce modern cipher suites and perfect-forward secrecy.


3. Access Control, Logging, and Monitoring

3.1 Least-privilege operational model

Careview enforces strict least-privilege access:

  1. Role-based access control
  2. Segregated environments (production vs non-production)
  3. Operational access restricted to authorised personnel
  4. No access to customer data unless explicitly authorised and logged

3.2 Network isolation

Careview infrastructure operates inside private Azure virtual networks. Internal services communicate over Microsoft’s secure internal backbone rather than the public internet.

3.3 Logging and auditing

Careview logs:

  1. User logins and access
  2. Changes to participant records
  3. Administrative actions
  4. System-level events

Logs are stored securely within Australia.

3.4 Monitoring and incident response

Careview uses Azure-native monitoring and alerting and maintains incident-response procedures aligned with NDIA expectations.


4. Statement for NDIA Audits

Your organisation may provide the following statement to auditors:

Careview, our CRM provider, hosts all NDIS participant and customer data exclusively within Australian Microsoft Azure datacentres (Australia East and Australia Southeast). All backups and redundancy systems also remain within Australia. No NDIS participant information or personally identifiable data is stored or processed offshore.

Careview enforces encryption in transit using TLS 1.2 or TLS 1.3 with modern AES-GCM cipher suites and forward-secret key exchange. All data stored within Careview is encrypted at rest using AES-256.

Careview applies a least-privilege operational model, private network isolation, secure Microsoft Azure service-to-service routing, and audit logging of user activity. Careview’s Azure platform is IRAP-assessed for government workloads and meets NDIA data-residency and cyber-security expectations.


5. Summary

Careview satisfies NDIA expectations for:

  1. Australian-only storage of NDIS participant data
  2. Encryption at rest (AES-256)
  3. Encryption in transit (TLS 1.2/1.3)
  4. Modern ISM-aligned cryptography
  5. Network isolation and platform segmentation
  6. Least-privilege operational access
  7. Audit logging and monitoring
  8. Secure Microsoft Azure infrastructure

This KB article may be provided to auditors, the NDIA, or internal compliance teams.
    • Related Articles

    • Security Overview

      The Careview Software Platform (Careview) uses Microsoft Azure as its Cloud Service Provider. The five major reasons we selected Microsoft Azure were: Microsoft invests over 1 billion USD annually on cyber security research and development Microsoft ...
    • Change your Organisation's 'Authorised Data Sharing Contact Information' Details

      Use the following steps to change your organisation's Authorised Data Sharing Contact Information in Careview; 1. Click on the Settings icon. 2. Under Security, click on Authorised Data Sharing Contact Information. 3. Make the required changes to the ...
    • Careview Release 1 - 2nd March 2023

      Careview Release 1 - 2nd March 2023 Release notes attached.
    • Careview Release 4 - 29 March 2022

      Careview Release 4 - 29 March 2022 Release notes attached.
    • 2FA Access Code Generation Frequency Security Setting

      Use this Setting to control how often a Careview User Account will be prompted to enter an Access Code, when they login to the Careview Web Application. We strongly encourage you to consider changing the frequency from every 30 days to every 24 ...