We are publishing this alert in response to a recent case where an unauthorised aged care worker was able to access a residential care provider’s electronic National Residential Medication Chart (eNRMC), prescribe medications and adjust medication charts, within a residential care home. Over an extended period, the worker:
- created a false prescriber profile
- prescribed and changed medications without valid prescribing authority
- changed medication charts.
An external nurse practitioner raised the issue when they noticed an unfamiliar prescriber name.
Although the incident caused no significant harm to older people, it shows the considerable risks to older people’s safety when there are inadequate privacy controls in electronic prescribing systems.
Provider obligations
Registered providers have obligations under the Aged Care Act 2024 to make sure there are appropriate security safeguards in place to protect against misuse of personal information.
Providers are required to protect personal information relating to an individual they deliver funded aged care services to, by implementing appropriate safeguards to prevent misuse, loss, and unauthorised access (Section 168, Aged Care Act 2024).
They also have obligations to make sure aged care workers and responsible persons comply with the Aged Care Code of Conduct (Code) and act with integrity, honesty and transparency (section 14-5, Aged Care Rules 2025).
Providers should have effective governance arrangements for eNRMC systems, including regular monitoring of prescriber identities to identify, respond to and report security breaches, including unauthorised and fraudulent (dishonest) activity.
Responding to prescribing concerns
If providers suspect or identify unauthorised or fraudulent prescribing activity, they should:
- immediately make sure older people are safe
- arrange an urgent review by a medical practitioner of all older people who are or may have been affected
- investigate the incident and assess any risk or harm
- notify the police
- notify the Australian Health Practitioner Regulation Agency (Ahpra), where appropriate
- notify the Aged Care Quality and Safety Commission (Commission).
Reporting concerns to the Commission
Depending on the circumstances, providers may need to report the matter to the Commission. They can do this through one or both of the following pathways:
- If there are concerns about an aged care worker not meeting their obligations under the Aged Care Act, including the Code of Conduct, providers can lodge their concerns as feedback about the worker with the Commission.
- If the incident has resulted in or could have resulted in harm to an older person and meets the requirements for reportable incidents, providers should report the incident through the Serious Incident Reporting Scheme portal in accordance with their reporting obligations.
Providers also need to record and respond to the matter in line with their incident management obligations. This would include open disclosure when the incident has resulted in harm or could have resulted in harm.
Risks with eNRMC prescribing
While electronic prescribing platforms are considered safer than paper-based prescribing, they’re not without risk. These systems remain vulnerable if providers don’t have the appropriate governance and safeguards in place.
Unauthorised access to, or activity within, an electronic prescribing platform can put older people’s safety at risk. It can cause harm by:
- prescribing the wrong medication
- unauthorised medication changes
- medication omissions
- inappropriate changes to medication doses and timing
- making it harder to assess clinical deterioration
- increased risk of medication-related adverse effects.
Indicators of possible unauthorised access
Providers should monitor their eNRMC system for indicators of unauthorised access including:
- new or unfamiliar prescriber profiles
- prescriber credentials (username and password) that can't be verified
- medication changes without supporting documentation
- prescribing activity that’s not consistent with usual practice
- prescribing activity that happens at unusual times
- a high volume of prescribing activity by a new prescriber.
There are reported cases of prescribers sharing their log-in details and passwords with other staff. This weakens system security and accountability and increases the risk of unauthorised prescribing.
Providers should support a positive speak-up culture to make sure they quickly identify and address these behaviours.
Reviewing security safeguards
To meet their obligations to protect personal information and support safe medication management, providers should review how effective their system and organisation safeguards are.
Prescriber registration and verification controls
Safeguards may include:
- verifying a prescriber’s identity before giving them access to the system
- cross-checking verified prescriber identities with their:
- prescriber numbers
- individual Ahpra Healthcare Provider Identifier (HPI-I) numbers
- individual Healthcare Identifier (IHI-I) numbers
- independent approval or a second sign-off before activating new prescriber accounts
- only registering authorised prescribers in the eNRMC system.
System security measures
Providers should consider:
- using eNMRC software that meets government requirements (this will be required from 31 December 2026)
- using strong passwords and authentication practices to reduce the risk of unauthorised access to the system
- regularly monitoring the system to make sure user accounts of people who are no longer authorised to access eNRMC systems are deactivated, disabled or suspended promptly
- letting older people and their supporters see changes to medications and to prescribers, in line with privacy requirements.
Organisational security measures
Providers should consider:
- regular clinical reviews of medication plans and non-primary prescriber changes, by qualified registered health practitioners
- monitoring prescribing activity, including new prescriber registrations and prescribing patterns, to identify unusual or potentially inappropriate activity
- reporting prescribing activity to provider governance committees to support oversight and risk management
- strengthening psychological safety to encourage staff to raise concerns about prescribing practices and security concerns
- educating and training staff to recognise unauthorised access and learn how to escalate incidents
- maintaining good working relationships with the eNRMC software provider to help identify and fix security concerns.
Dr. Mandy Callary
Chief Clinical Advisor
More information
Electronic Prescriptions Security and Access Policy, Department of Health, Disability and Ageing.