← Back to blogCompliance

Cloud Services — What to Check Before You Sign

24 July 2026 · 5 min read

Cloud-based practice management software isn't a future consideration for Australian clinics anymore — it's the default direction most PMS vendors are already moving in. Genie, Zedmed, and others all now offer or are transitioning to cloud-hosted versions. That makes "should we move to the cloud" the wrong question. The right one is: what should we actually check before signing?

The Australian Digital Health Agency put together a solid framework for this. Here's the condensed, clinic-relevant version.

The core idea: shared responsibility isn't shared accountability

Moving to a cloud service provider doesn't transfer your legal obligations — it splits the technical work while your practice keeps the accountability. If a cloud provider mishandles patient data, your practice can still be found in breach of the Privacy Act for not taking reasonable steps to ensure they were doing the right thing. This has actually happened in Australia: a cloud provider exposed 550,000 people's details by misconfiguring a backup, and the healthcare organisation using that provider was found in breach alongside them — for not verifying the provider's security and for keeping data longer than necessary.

The lesson isn't "don't use cloud services." It's "don't assume the provider automatically has it covered."

Where is your data actually stored?

This is called data sovereignty, and it matters more than it sounds. Data stored overseas is subject to that country's laws, not Australia's — which can undercut your ability to meet Australian privacy obligations, and complicates things if something goes wrong and you need local legal recourse. Ask directly where a prospective cloud provider stores and processes your data, and treat "Australia" as the answer you're looking for.

What happens when the contract ends?

Before signing anything, check:

  • Who owns the data — and does the contract confirm the provider can't use it for their own purposes?
  • What happens to your data when the contract ends? You should get a full, usable copy back, and the provider should be contractually required to permanently delete their copies afterward.
  • Does the contract include service level agreements covering uptime, quality of service, and your ownership rights — or is it silent on all of that?

Understand what kind of cloud service you're actually buying

Not all "cloud" is the same:

  • Public cloud — shared infrastructure, usually cheapest, but carries slightly higher risk since your data sits alongside other tenants'.
  • Private cloud — dedicated to your organisation, more control, usually more expensive.
  • Community cloud — shared among organisations with common needs (research consortiums, for example).
  • Hybrid cloud — a mix, often used to avoid putting all your eggs in one provider's basket.

Most clinic-facing software (booking systems, cloud PMS, billing platforms) is delivered as Software as a Service (SaaS) on a public or private cloud — you're not managing infrastructure, just using the application. That's fine, provided the other checks in this post are covered.

Back up your own copy anyway

Whatever backup arrangement your cloud provider has, keep your own copy too. If the provider suffers an outage, a breach, or simply goes out of business, "the cloud has it" isn't a recovery plan if you can't get to it. This is the same principle behind our stance on Synology-based local backups even for practices running cloud PMS — redundancy shouldn't rely on a single party.

A short checklist before you sign

  • Does the provider meet your business needs, security requirements, and legal obligations — all three, not just the first one?
  • Where is the data stored, and does that meet Australian privacy requirements?
  • Does the contract cover data ownership, portability, and deletion on termination?
  • Is the provider's security posture verifiable — any certifications, any published security practices?
  • Do you understand your supply chain — does this provider rely on other subcontracted cloud services you'd also need to vet?
  • Do you have your own independent backup, separate from the provider's?

None of this is a reason to avoid cloud services — most Australian clinics are heading there regardless, and there are real efficiency gains to be had. It's a reason to ask the right questions before the contract is signed, while you still have leverage to negotiate the answers you don't like.

This article draws on guidance published by the Australian Digital Health Agency.

Not sure where your practice stands?

A Compliance Gap Assessment covers backup and DR posture, access controls, and compliance documentation — a written report with a prioritised roadmap.