Your vulnerability report has more findings in it than your team could clear in a decade, and a meaningful share of your estate can't be patched at all because the vendor won't support it or a restart is a clinical event rather than an IT one. This guide sets out why patch-everything was never achievable, what you're actually obliged to do across hospitals, community care and aged care, and how to build a decision framework your audit and risk committee can defend.
Full guide delivered to your inbox
Covers why published vulnerabilities have outpaced remediation capacity, how fabricated AI-generated CVEs are entering the same feeds as genuine ones, and why Australian regulation gives health services no binding standard for the part of the clinical estate that can't be patched. Sets out the Stakeholder-Specific Vulnerability Categorization framework CISA now mandates in place of severity scoring, and the four practical capabilities, a reconciled asset picture, a written decision rule, a compensating-control pathway and procurement that prices unpatchability upfront, that let a health service answer 'is this exposure urgent' in hours.
The four-question exposure decision tree, a table mapping which Australian obligations (Privacy Act, SOCI Act, Essential Eight, My Health Records Act, Aged Care Quality Standards) actually bind which type of provider, and the funnel diagram showing what a health service should be resourcing against instead of the raw CVE count.
No noise. Unsubscribe anytime. Your details are used only to deliver this guide and occasional Lumaris insights on the same topic.
Read enough? The guide is one form away.
Get the guideGenerally no. The Therapeutic Goods Administration's guidance for large-scale service providers instructs health services to avoid installing unvalidated patches or changing device configuration without explicit manufacturer instructions. Obligations under the therapeutic goods framework sit with the manufacturer, not the hospital, and modifying a device without authorisation risks the hospital being treated as a manufacturer itself under the Act.
Only narrowly. The Security of Critical Infrastructure Act's register and incident reporting obligations apply solely to a 'critical hospital', meaning one with a general intensive care unit. The Critical Infrastructure Risk Management Program obligation applies only to the roughly 91 hospitals named in Schedule 1 of the CIRMP Rules. Most community care and aged care providers sit outside the regime entirely.
SSVC is a decision-tree framework, published by CISA in 2022 and developed at Carnegie Mellon's Software Engineering Institute, that replaces severity scoring with decision points including exploitation status, technical impact, automatability, mission prevalence and public well-being impact. CISA formally adopted it over patch-by-severity in June 2026 through Binding Operational Directive 26-04.
Aged care isn't captured by the SOCI Act. Under the strengthened Quality Standards in force since 1 November 2025, the only express information security obligation is Outcome 2.7, Action 2.7.1, which requires an information management system to securely manage records. It's outcome-based, with no maturity level or patching timeframe specified in the Standard itself.
Most conversations begin simply. Someone wants to know whether we are the right fit for what they are navigating. That is a perfectly good starting point.