A Play For Not-For-Profit Care Providers

Your Microsoft renewal is a security decision, not just a cost one.

Three things are true at once for most care providers: Microsoft costs are rising, they are paying third parties for security tools their Microsoft entitlement already includes, and they are not using the security capability they are entitled to. Fixing the three together is the reset, funded by the spend you recover, not new budget.

Figure — Illustrative Worked Example

$50,500$21,500BEFOREAFTER

Composite of a ~120-seat Victorian care provider: about $29,000 recovered a year while raising the security posture. Illustrative, not a quote.

Why This Is A Security Decision, Not A Licensing Chore

The stakes are higher for a care provider

  1. 01

    The Privacy Act applies to you at any size

    The small-business exemption does not apply to health service providers. A provider holding health information carries the full Australian Privacy Principles obligations regardless of turnover, the same core obligations as a hospital.

  2. 02

    Your data is as sensitive as data gets

    Clinical notes, care plans, family circumstances, financial hardship: the records of people at their most vulnerable. The reputational consequence of a breach is existential for an organisation that runs on community trust and government funding.

  3. 03

    Ransomware reporting is now law

    Organisations with $3 million or more in annual turnover that make a ransomware payment must report it within 72 hours under the Cyber Security Act 2024. A question your board should be able to answer before an incident, not during one.

  4. 04

    Your board carries the duty

    ACNC Governance Standard 5 places duties of care and diligence on responsible persons. Information and cyber risk sit inside that duty, and volunteer directors are rarely briefed on it until something goes wrong.

The Good News

The security stack you already own

None of this requires new spending to address in most providers. The capability usually already exists inside the licensing you hold or are about to pay for. What is missing is architecture: deciding who needs what, switching the controls on, and retiring the duplicates.

  1. 01

    Entra ID — MFA & conditional access

    Multi-factor authentication for every account, and rules like “clinical records only from managed devices”. The single highest-value control against account takeover.

  2. 02

    Microsoft Defender

    Endpoint and email protection: antivirus, phishing and malicious-link defence, attack detection. The category most providers also buy separately from a third party.

  3. 03

    Intune

    Device management. Requires a PIN, encryption and up-to-date protection before a laptop or phone can touch client data; remotely wipes lost devices.

  4. 04

    Purview & privileged access

    Data-loss prevention and retention: rules that stop client health information leaving by email or Teams, plus time-limited administrator rights so a compromised IT account isn't the keys to everything.

The Guide

A fifteen-minute self-check, with your IT manager or MSP

The full guide includes what changed and when it hits you, the three-tier licensing model that funds the reset, the overlap list of what you may be paying for twice, and a twelve-question self-check your board can act on.

Download the guide →

The reset works the same way everywhere it lands: recovered spend, not new budget.

Vyfority does not resell Microsoft licences and earns nothing from your licensing decisions. Sometimes the right answer is the cheaper licence. That independence is the point.