Compliance Guides

Whistleblower Protections Under the Aged Care Act 2024

Published Updated 4 min readStatura Care

A disclosure process needs to work for two people: the person raising a concern and the person responsible for responding. The first needs a clear way to speak up and follow up. The second needs confidential handling arrangements, a response process and a record of the action taken.

This guide explains the distinction between statutory protection and the software that supports disclosure handling. Guidance checked 25 September 2026.

When a disclosure qualifies for protection

The Commission’s provider guidance explains that a disclosure must reach an eligible recipient and the person must have reasonable grounds to suspect an aged care law contravention. Disclosures can be oral or written, including anonymous disclosures. The person does not need to establish the alleged breach before raising the concern.

Eligible recipients are broader than the people your organisation gives access to its case software. They include the Commission, relevant Department staff, registered providers, responsible persons, aged care workers, police officers and independent aged care advocates. Check the full statutory scope when establishing your receiving arrangements. A software permission cannot decide whether a recipient is legally eligible.

The Department’s guidance explains confidentiality and protection from retaliation. Identity information is protected, with specified exceptions such as the discloser’s consent and circumstances involving a serious threat. Do not describe confidentiality as an absolute promise that identifying information can never be shared.

In practice, limit access to the people who need to handle the matter, consider whether the report’s narrative could identify someone, and review what information is included in any wider action. Record decisions about disclosure and protection measures through your approved process. Get appropriate advice where the legal position is uncertain.

Make the provider process usable

Section 165 of the Aged Care Act 2024 addresses provider systems and policy. The qualifying disclosures and protections are set out in the Act’s whistleblower provisions, beginning at section 547. Avoid treating the policy’s existence as proof that the process works.

A practical review can ask:

  • Can a person find the reporting channel and understand how to follow up?
  • Do receiving staff know how to handle information confidentially?
  • Is there a clear process for assessing risk and responding?
  • Who takes and reviews measures to protect the discloser?
  • How are findings and resulting actions recorded?

Keep the policy current and review the system regularly. The Aged Care Rules 2025, rules 165-45 to 165-55, set specific duties: training at least annually and at relevant commencement or role/system changes, and communication at least monthly that qualifying disclosures are welcome. Schedule these recurring activities separately from policy updates.

Keep case handling and incident reporting distinct

A disclosure may raise an immediate safety issue or describe an incident that needs separate reporting. Assess those responsibilities promptly through your incident process. Opening a disclosure case does not submit an incident notification or restart its reporting period.

Plan investigation responsibilities, confidentiality, fair handling and follow-up. Record findings and the action taken, then review whether the response addressed the concern. Protection measures need active oversight by people; a case status alone cannot prevent retaliation.

What the Statura Care workflow supports

The whistleblower workspace provides a provider-linked public reporting form without requiring an account. An anonymous reporter receives a reference token for later status checks and follow-up messages. The token must be saved securely; information written in a report may itself reveal someone’s identity.

Configured recipients review cases within their provider scope. When no active recipient is configured, a limited administrator fallback applies to default-routed reports; it does not open earlier reports sent through configured recipients. Review the receiving configuration when responsibilities change.

The team can record an internal or external investigator, protection status and notes, remediation work and a closure outcome. A neutral improvement task can carry wider action without putting protected report details in shared task content. This workflow does not promise automatic detection of retaliation or logging of every viewing event.

Test both sides of the process

In a tailored demonstration, use a fictional disclosure. Follow submission, the reference token and a later message, then inspect the receiving team’s case and access arrangements.

Ask how your organisation will assign responsibility, record protection measures and follow remediation through to review. Confirm what happens when a recipient leaves and how confidential information is kept out of shared work. Use the module overview alongside your policy to decide whether the process fits your organisation.

Bring the work you need to improve.

Show us where your team spends time today. We’ll walk through the relevant care, workforce or finance workflows and discuss what a move to Statura would involve.