A registered provider must protect the personal information of individuals it serves: use it only for delivering their funded aged care services or the purpose for which it was given; without consent, disclose it only for their care by it, an associated provider or another registered provider, for the purpose it was given, or to comply with the Act; and protect it with reasonable security safeguards against loss or misuse. Courts, tribunals and bodies with compulsory powers may still obtain it.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.