Governance Built for Healthcare
OneCredential provides a structured governance framework for healthcare industry representative credentialing and access.
Designed specifically for Australian healthcare, the platform combines defined credential requirements, risk-based access controls, facility oversight and traceable decision records within a secure Australian-hosted environment.
Built to adapt as requirements change.
OneCredential's governance framework and operating system are kept informed by healthcare facilities, peak industry bodies, industry employers, representatives and governance stakeholders.
Changes in recognised standards, regulatory expectations, operational experience and emerging risks are incorporated into the continuing development of the platform.
Security and Assurance Standards
OneCredential operates within recognised information security and cloud governance frameworks.
- ISO/IEC 27001:2022 certified
- CSA STAR Level 1 registered
- SMB1001 compliant
- Australian-hosted AWS infrastructure
Our CSA STAR Level 1 security self-assessment is published through the Cloud Security Alliance STAR Registry, providing transparency into the cloud security controls applied by OneCredential.
Aligned to AS 5182
OneCredential is the only Australian platform to formally align its credential governance framework with AS 5182, the Australian Standard for healthcare industry representative credentialing and access.
- Consistent credential requirements
- Risk-based access controls
- Defined review and escalation pathways
- Traceable credential and access decisions
- Facility-specific governance settings
AS 5182 provides guidance rather than mandatory requirements. Each facility retains authority over the credential requirements and access rules applied within its own environment.
OneCredential provides the structure to apply those requirements consistently and demonstrate how decisions were made.
Governance That Can Be Explained
Important credential and access decisions should be capable of being understood and evidenced after the event. OneCredential creates a traceable record of:
- The requirement being assessed
- Credential status at the relevant time
- Approvals, exceptions and rejections
- User and system actions
- Check-in and access activity
- Date and time of relevant events
- Historical changes in status
This creates a defensible digital history that authorised users can search, review and export when required.
Evidence When It Matters
Whether responding to an audit, reviewing an incident or examining historical access, OneCredential maintains evidence of what occurred and the governance conditions that applied at the time.
Records can show:
- Who attended a facility
- When and where they checked in
- The purpose of the visit
- Credential status at the time
- Access approvals or rejections
- Exceptions and governance actions
- Relevant historical status changes
Facilities can demonstrate not simply that a governance process exists, but how it operated in practice.
Facility Control by Design
OneCredential provides the governance infrastructure while each healthcare facility retains control of its own environment.
Facilities can define requirements and access rules according to location, activity and risk. The platform operates independently of clinical and patient systems:
- No access to patient records
- No integration with clinical workflows required
- No dependency on hospital identity systems
- No requirement for facilities to maintain duplicate credential documents
- Role-based access to OneCredential information
- Configurable facility and location-level access rules
Privacy and Security by Design
OneCredential is designed to minimise unnecessary collection, access and duplication of personal information. Platform controls include:
- Australian-hosted cloud infrastructure
- Encryption in transit and at rest
- Role-based access controls
- Controlled access to credential information
- Secure, time-limited document access
- Comprehensive audit logging
- Encrypted backups and recovery controls
- Defined information security and access management processes
Facilities receive the information required to make and oversee access decisions without needing to maintain separate copies of representative credential records.
Our Governance Principles
Consistency
Requirements and decisions are applied through defined processes.
Proportionality
Controls are matched to the risk associated with the location and activity.
Privacy by Design
Personal information is limited to what is required for the relevant purpose.
Accountability
Important decisions and actions are recorded and capable of review.
Facility Autonomy
Each facility determines the requirements and access rules appropriate to its environment.
Australian Built. Australian Hosted.
OneCredential is an Australian-founded platform designed for Australian healthcare facilities, healthcare industry employers and representatives.
Platform data is hosted within Australian AWS infrastructure, supporting Australian data residency while reducing reliance on duplicated documents, paper records and fragmented local credentialing processes.
Explore the OneCredential Governance Framework
Learn more about OneCredential's security, privacy, credential governance and access controls.