MedTalk AI Logo
VENDOR RISK

Third-party security

Security requirements for vendors, contractors and service providers that access, process or store MedTalk information.

Purpose

This policy establishes the requirements for managing security risks associated with third-party service providers that access, process or store MedTalk information or support its services, ensuring external providers maintain appropriate controls to protect sensitive information, including healthcare-related data, and do not introduce unacceptable risk to MedTalk systems or operations.
  • Identify and assess risks associated with third-party engagements
  • Ensure third parties implement appropriate security controls
  • Protect sensitive information from unauthorised access or disclosure
  • Maintain compliance with legal and regulatory obligations
  • Reduce the likelihood of supply chain-related security incidents
  • Maintain visibility and oversight of third-party risk

Scope

Third-party relationships

  • Vendors and suppliers
  • Cloud and SaaS providers
  • Managed service providers
  • Contractors and consultants
  • Technology partners
  • Subcontractors engaged by third parties

Information types

  • Personal and healthcare-related information
  • Customer and partner data
  • Corporate confidential information
  • Intellectual property

Governance and regulatory alignment

  • Chief Information Security Officer: owns third-party security requirements, oversees the risk management framework, approves high-risk vendor engagements and exceptions, and reports third-party risks to executive stakeholders.
  • Business owners: justify the use of third-party services, identify the type of data shared, and manage vendor performance and risk throughout the lifecycle.
  • Procurement and vendor management: embed security requirements in procurement processes, coordinate due diligence and contract management, and maintain vendor records and risk classifications.
This policy aligns with the Australian Privacy Act 1988, the Notifiable Data Breaches (NDB) Scheme, the ACSC Essential Eight, and ISO/IEC 27001 Information Security Management. Where MedTalk operates across jurisdictions, additional regulatory obligations may apply.

Third-party risk management lifecycle

  • Engagement and risk assessment: every engagement is assessed against the nature of the service, sensitivity of data involved, level of system access required, and criticality to business operations, with higher-risk engagements requiring more detailed security assessment.
  • Due diligence: prior to onboarding, third parties must demonstrate appropriate security capabilities, including review of security policies and controls, compliance certifications, data protection practices, and incident response and business continuity capabilities.
  • Contractual controls: agreements include data protection obligations, confidentiality requirements, incident notification obligations, right-to-audit clauses, and data retention and disposal requirements.
  • Onboarding: access controls are established and security configurations validated before access is granted, data sharing is minimised, and monitoring mechanisms are put in place.
  • Ongoing monitoring: periodic security reviews, assessment of updated certifications or attestations, review of incidents or control failures, and tracking of remediation actions.
  • Change management: material changes, including ownership or location changes, changes in services or data handling, new subcontractors, or security incidents, trigger reassessment.
  • Offboarding: access to systems is revoked, data is returned or securely destroyed, and residual risk is assessed and managed.

Minimum security requirements

Third parties must implement appropriate security controls proportionate to the level of risk. Additional requirements may apply for high-risk vendors.
  • Protection of sensitive data through encryption
  • Secure access controls and authentication mechanisms
  • Ongoing vulnerability management and patching
  • Logging and monitoring of system activity
  • Incident response capability
  • Business continuity and disaster recovery arrangements
Where third parties host MedTalk workloads in cloud infrastructure, they must use automated patch management tooling to ensure uniform application of security updates across all instances, and enable automated configuration auditing for real-time visibility into the security posture of the hosted environment, aligned with MedTalk security standards.

Data protection and incident management

Third parties must protect personal and sensitive information in accordance with applicable laws, limit data collection and usage to agreed purposes, ensure secure storage and transmission of data, and comply with data retention and disposal requirements. Where personal information is involved, obligations under the Notifiable Data Breaches (NDB) scheme are considered.
Third parties must notify MedTalk of any security incident that may impact MedTalk systems, MedTalk data, or service availability, in a timely manner to support incident response and regulatory obligations, and are expected to cooperate fully with investigations and remediation activities.

Subcontractor management

Third parties must not engage subcontractors that access MedTalk data or systems without appropriate oversight. Vendors remain responsible for ensuring subcontractors meet equivalent security requirements and for managing risks associated with subcontractor access.

Exceptions, monitoring and enforcement

Third-party risk is monitored and reported to governance stakeholders, including risk ratings of key vendors, outstanding security issues, incident trends involving third parties, and compliance status.
Compliance with this policy is mandatory. Failure by third parties to meet requirements may result in restricted access, remediation requirements, contractual penalties, or termination of services. Exceptions must be formally documented with business justification, a risk assessment, compensating controls and a defined expiry date, and approved by the Chief Information Security Officer.
This policy is reviewed at least annually, following major incidents, and after regulatory or business changes.

Contact

Security & Compliance: support@medtalk.co

Legal / compliance: legal@medtalk.co

Get Started

Streamline your clinical notes with MedTalk AI

Intelligent medical scribe

Get A Free Trial