
Expanding privacy and security regulations, and an increasingly hostile online environment, have made information privacy and cyber security an increasing concern. The digitisation of services and increasing use of data for decision-making are key drivers in the health care industry’s transformation.
Ramsay recognises the significant importance of information privacy, data governance, cyber security and responsible AI use to our business, particularly in an environment of expanding information privacy and security regulations, and an increasingly hostile online landscape.
Ramsay engages third parties and utilises internal information systems to perform key functions essential to our ability to operate, provide care and manage patient information.
Each Ramsay regional business monitors cyber risks and data and privacy concerns. Each region has its own accountability framework to reduce risk, protect all data held, meet regulatory requirements and undertake training and awareness which forms part of continual improvement processes.
Each region has a Privacy Policy which complies with jurisdictional requirements regarding information collection, use, disclosure, retention and raising concerns:
Measures include:
Ramsay has implemented a global cyber security control framework aligned to the NIST Cyber Security Framework v2.0 including increasing annual maturity targets for all regions. The NIST Framework defines a set of controls across six categories (Govern, Identify, Protect, Detect, Respond, and Recovery) and is designed to provide both protection and resilience against the broad range of cyber security risks.
Measures include:
Artificial Intelligence (AI) tools provide the opportunity to improve clinical outcomes and ease frontline workload. To support safe implementation, Ramsay has introduced additional governance, including an AI Governance Framework and Committee. Our AI Governance Framework is designed to ensure that approved AI initiatives are safe, ethical, and aligned with our values. The Framework provides oversight across the full lifecycle of AI use - from pilot to deployment - ensuring transparency, accountability, and responsible innovation.
Regular reporting on AI use is provided to the Group Executive and Risk Management Committee.
Our measures are provided in our annual reporting suite and Funding Group Data Book (Voluntary disclosures) Quality Scorecard and include notifiable breaches of patient privacy.