Skip to main content

Case Study: Outcome Health

Project at a glance

Dedicated to building a more intelligent health ecosystem, Outcome Health has been at the forefront of data intelligence and clinical services across Australia for over 25 years.

A not-for-profit based in Melbourne, Outcome Health provides tailored clinical programs to improve patient outcomes, support general practices and serve the broader community. Their programs include POLAR, a platform that provides data and analysis to GPs and government peak bodies known as Primary Health Networks for their population health and analysis reporting.

Outcome Health also delivers a range of mental health programs and maintains a data platform, that enables more than 1,500 GP practices to intuitively use their data to optimise patient care.

Outcome Health was recently certified to ISO 27001 with the help of de.iterate.

outcome-health-case-study

Impact

innovation

3 months worth of manhours in work saved

integrity-sm

Up to $30K in staff resourcing  saved

collaboration

A certification and audit process that could not have been easier

insuran-1

Certified to ISO 27001 in just 12 weeks time

PROJECT GOALS

  • Achieve ISO 27001 certification within a defined 12-week timeframe to meet business, customer and market expectations around security compliance.
  • Strengthen the protection of sensitive health information by implementing a structured, defensible information security management system.
  • Reduce internal resource burden and certification costs by using a streamlined platform and expert support to make the accreditation process more efficient.
  • Embed ongoing compliance into business-as-usual operations so certification could be maintained sustainably, without last-minute audit panic.

Protecting senstive information

Given the sensitivity of personal health information and the stringent regulatory requirements surrounding it, achieving ISO 27001 certification not only helps in safeguarding patient data against breaches but also builds trust with patients and partners by showcasing a proactive approach to data protection.

According to Outcome Health’s Chief Information Officer, Jason Ferriggi, ISO 27001 certification is a must-have to manage and mitigate security risks, and protect data in an increasingly unsafe cyber world.

“Our customers are increasingly pursuing ISO accreditation and, therefore, want their suppliers to have the same level of compliance. It was becoming more and more of a requirement of doing business that we have ISO 27001.”

“We have been working with the NIST cybersecurity framework controls for the last five years. This made our transition to ISO a little more manageable. However, we were worried about the resource commitment, given we are a small team,” said Jason.


admin-mock-up

The de.iterate difference

ISO certification may seem daunting, with a range of hoops to jump through, making the process seem slow and expensive.

For Jason though, the certification process was made easier by having a sound partner along for the ride.

“We decided to partner with de.iterate because of their knowledge, customer service and the look and feel of the platform. The de.iterate platform seemed to be a one-stop shop of everything we needed to consider as part of our ISO journey.”

“The phone app made reading the policies a breeze. We achieved 100 per cent policy reading compliance with no complaints before our first audit, which was a real bonus,” said Jason.

“I cannot recommend Andrew, his team and the de.iterate platform more highly. He took the pain out of what could have been a very daunting process. I’m now looking forward to the next audit review, as I know we have the right partner on board.”

“I’m a living and breathing ISO convert due to de.iterate making the process easy."

deiterate-platform

Save time and reduce costs

With de.iterate’s help, Outcome Health saved time, resources, and met their 12 week certification timeline.

“I know that we saved time and resources due to de.iterate’s expertise. We had a February 2024 goal and hit that with de.iterate’s support and help.”

“de.iterate saved us 3 months and—conservatively—up to $30K in resourcing,” said Jason.

Data security becomes business as usual

“The de.iterate platform will keep us on track and ensure—now that we are accredited—we remain so. It does this through scheduling yearly compliance tasks that, if maintained, take the last-minute panic out of our audit process,” said Jason.

“It’s not just a tick box exercise; it’s an organic process that grows with the organisation and gives you a degree of comfort that you are taking care of your customers through the implementation of good processes.”

“de.iterate has helped enforce the importance of certification and demonstrate how it improves your organisation,” said Jason.

policy-calendar

A painless process

“Every time we had a question, the de.iterate team was there with answers. Having de.iterate on your side during accreditation was like having countless lifelines available to help you through what can be an anxiety-provoking process, especially having never led an accreditation process before.”

“I cannot recommend Andrew, his team and the de.iterate platform more highly. He took the pain out of what could have been a very daunting process. I’m now looking forward to the next audit review, as I know we have the right partner on board.”

“I’m a living and breathing ISO convert due to de.iterate making the process easy,” said Jason.

Ready for simple, stress-free compliance? Want help from real GRC experts?