Sovereign Technology

Veteran Medical Files Are Not Ordinary Records

ADF medical and claim files carry protected identifiers that expose service history, health and location. Here is the standard of care they deserve, how Valour Keystone meets it, and what every veteran should ask an advocate.

Shaune IrvingShaune IrvingTechnical Founder & CTO·Published 21 Aug 2026· 11 min·Intermediate

A veteran medical file is not ordinary health data. It is a service record wearing a clinical jacket. Open one and you will find a service number, a PMKeyS identifier, unit postings, deployment locations and dates, injury mechanisms, psychological assessments, discharge medical boards, DVA claim numbers, and often the names of family members listed as dependants or contacts. Any one of those fields is sensitive. Assembled into a single claim bundle, which is exactly how claims are prepared, they become a complete profile of where a person served, what happened to them, what they struggle with now, and how to find them.

That is why the standard of care applied to this data cannot be average. Average is a shared inbox. Average is a claim bundle sitting in a consumer cloud drive with link sharing switched on. Average is a laptop in a car boot. For a veteran with a suppressed address, a special operations background, or an active mental health condition, average is a risk to safety, not a paperwork problem.

Why these files carry protected identifiers

Australian privacy law already treats health information as sensitive information under the Privacy Act 1988 and the Australian Privacy Principles, which the Office of the Australian Information Commissioner administers. Veteran files raise the stakes further because they combine health information with service history. Service history can reveal capability, posting patterns and operational association. It is the kind of detail that fraudsters, foreign collectors and stalkers all value for different reasons.

There is a second layer that most people miss. Claim documents frequently contain third party information. A statement from a former colleague. A specialist report describing others present at a shared incident. A partner writing about the effect of a condition on the household. When a file leaks, it does not only expose the veteran. It exposes everyone written into the story.

The threat sits at the handover, not the fortress

Most breaches in the Australian health sector have not been dramatic assaults on a hardened data centre. They have been failures at the boundary between organisations. A supplier with weak access control. A migration that copied production data into a test environment. A staff account without multi factor authentication. Notifiable Data Breaches reporting published by the OAIC has consistently placed health service providers among the most affected sectors, with human error and third party involvement appearing again and again.

Now count the hops a single claim makes. The veteran to the advocate. The advocate to a general practitioner. The GP to a specialist. The specialist back to the advocate. The advocate to DVA. Somewhere in that chain, copies land in email, in a phone scanning app, in a case management platform, and in a backup nobody has looked at for three years. Every hop is a new copy, and every copy has its own worst day waiting for it.

What proper handling of veteran data actually looks like

Data residency in Australia. The file should live on Australian owned and Australian operated infrastructure, with no silent replication to overseas regions for redundancy or analytics. Residency is not patriotism. It decides which legal system can compel disclosure of the record.

Encryption in transit and at rest, with keys held under Australian control and rotated on a schedule someone can actually name.

Least privilege and just in time access. An advocate should see the files of the clients they are actively representing, not the whole repository. Administrators should hold elevated rights only for the window in which they are performing a task, and every elevation should be logged.

Immutable audit logging. Every view, download, share and export of a document recorded in a log the operator cannot quietly edit. If nobody can tell you who opened your file last Tuesday, they are not protecting it. They are storing it.

Data minimisation and retention limits. Collect the documents required for the claim, not the entire medical history since enlistment. Dispose or archive on a defined schedule tied to the claim lifecycle rather than keeping everything forever because storage is cheap.

Production data never used for testing. Real veteran records have no place in a development environment, a demonstration account or a vendor sandbox.

Breach notification readiness. Under the Notifiable Data Breaches scheme an eligible breach must be assessed and reported to the OAIC and to the people affected. An organisation that cannot describe its notification process has not rehearsed it.

How Valour Keystone meets that standard

Valour Keystone was built by Keytech Intelligence for this exact problem, and the design choices follow from the threat model above rather than from a compliance checklist.

Sovereign custody first. The platform runs on Australian owned infrastructure through the Keytech partnership with Macquarie Cloud Services, which keeps the data path, the support path and the legal jurisdiction inside Australia. The people who can touch the underlying platform are onshore and accountable here.

Classification at intake, not after the fact. Keytech ingestion intelligence reads documents as they arrive, identifies protected identifiers such as service numbers, PMKeyS references, dates of birth and clinical codes, and routes those records into the protected data zone rather than letting them scatter across general storage. Classification happens before a human ever opens the file.

Tiered zones with hard boundaries. Presentation, application, protected data, management and audit are separated so that a compromise in one tier does not hand over the record store. The protected zone has no direct path from the public internet.

Consent scoped access. An advocate is granted access to a specific client matter for a specific purpose, and that grant expires. Access is tied to a recorded authority from the veteran rather than to a general staff role.

Chain of custody on every document. Every open, export and share is written to an append only audit trail that the veteran can be shown. That is the difference between a promise and evidence.

Retention aligned to the claim, not to convenience. Documents carry a lifecycle. When a matter closes the retention clock starts, and disposal is a scheduled action with a record, not an afterthought.

None of this is exotic. It is the standard applied to critical infrastructure, applied to a class of data that earns it just as much.

What every veteran should ask their advocate

Ask in plain language and expect answers in plain language. Vagueness is the finding.

One. Where is my file physically stored, and is that storage in Australia?

Two. Who inside your organisation can open my file, and what stops everyone else from opening it?

Three. Do you send my documents by email, and if so are they encrypted or password protected?

Four. Do you use personal devices, consumer cloud drives or phone scanning apps to handle my documents?

Five. Can you show me a record of who has accessed my file?

Six. How long do you keep my file after my claim finishes, and how is it destroyed?

Seven. What happens to my records if your organisation closes, merges or changes systems?

Eight. If you have a data breach, how and when will you tell me?

Nine. What exactly have I authorised you to share, and with whom? Ask for the authority in writing, and ask for it to be limited.

Ten. Do you use external providers to store or process my file, and who are they?

An advocate who takes your welfare seriously will not be offended by these questions. Most will be relieved that someone finally asked.

How to read a privacy policy without a law degree

A privacy policy is a promise you can hold someone to, so read it as a contract rather than as furniture. Look for six things.

What is collected and why. The policy should name categories of information and the purpose. If the purpose reads like it covers everything, it protects nothing.

Disclosure. Who else receives the data. Named categories of third parties are a good sign. Silence is not.

Cross border disclosure. The Australian Privacy Principles require an organisation to tell you if information may go overseas and, where practicable, which countries. If a policy mentions overseas service providers with no detail, ask directly.

Secondary use. Watch for language allowing data to be used for service improvement, research, marketing or analytics. Health data should not quietly become training material or a marketing list.

Retention and destruction. A policy that never mentions how long records are kept is telling you they are kept indefinitely.

Access, correction and complaints. There should be a named contact, a process, and a pathway to the OAIC if you are not satisfied.

Comparing the policies you are likely to meet

Treat this as a framework for your own reading rather than a scorecard. Policies change, so verify each one at its source before relying on it.

Department of Veterans Affairs. DVA is a Commonwealth agency, so it is bound by the Privacy Act and the Australian Privacy Principles, it operates under the Protective Security Policy Framework, and its systems sit within Australian Government security expectations for cloud and information handling. Its privacy notices sit on dva.gov.au. Verify for yourself what DVA discloses to contracted service providers, how long claim records are retained under the Archives Act, and how to request access to your own records.

RSL and the larger ex service organisations. RSL Australia and the state branches are private organisations covered by the Privacy Act where the threshold tests are met, and they publish privacy policies on their websites. Their advocacy services generally use nationally recognised advocacy training and shared case systems. Verify whether the policy names the systems used to store claim documents, whether files are held by the state branch or by a local sub branch, what happens to documents held locally, and whether volunteers handling files are bound by written confidentiality and security obligations.

Local advocates and small practices. This is where the variation is widest. Many are dedicated people doing important work with little technical support. Some operate as sole traders below the small business threshold in the Privacy Act, although organisations providing a health service are generally covered regardless of turnover. Verify whether a written privacy policy exists at all, where documents are stored, whether personal email and consumer cloud accounts are in use, and who takes custody of your file if the advocate retires or becomes unwell.

The pattern is simple. The larger and more regulated the body, the more likely a formal policy exists. That does not automatically mean the handling is better in practice, and a small advocate with disciplined habits can outperform a large body with sloppy ones. What matters is evidence, not size.

Other assessments worth asking about

Essential Eight maturity. The Australian Signals Directorate Essential Eight is the national baseline. Ask which maturity level the organisation targets and who assessed it.

IRAP assessment or ISO 27001 certification. For any platform holding veteran records at scale, ask whether an independent assessor has reviewed it and when.

Penetration testing. Ask for the date of the most recent test and whether findings were remediated. A test from four years ago is a museum piece.

Supplier register. Ask for the list of third parties that touch the data, including case management platforms, storage providers, transcription services and IT support.

Staff and volunteer vetting. Ask whether people with access hold current police checks and, where relevant, security clearances, and whether access is removed the day someone leaves.

Incident response. Ask whether there is a written response plan, whether it has been exercised, and who makes the call to notify.

Where to go for authoritative information

The Office of the Australian Information Commissioner publishes the Australian Privacy Principles, health information guidance and the Notifiable Data Breaches scheme at oaic.gov.au. The Australian Cyber Security Centre publishes the Essential Eight at cyber.gov.au. The Department of Veterans Affairs publishes privacy and claims information at dva.gov.au. Open Arms provides free and confidential counselling for veterans and families at openarms.gov.au. RSL Australia publishes advocacy and privacy information at rslaustralia.org.

The duty of care underneath all of it

I spent twelve years in the Royal Australian Air Force, then years as a paramedic and a tradesman, before building technology for a living. In every one of those roles the same principle applied. You do not test the load path after the load is on it. You test it before, because someone is standing underneath.

Veteran data is the same. The time to ask where your file lives is before you hand it over, not after a notification email lands. And for those of us building the systems, the standard is not what we can defend to an auditor. It is what we could defend to the person whose worst days are written in that file.

Ask the questions. Expect the answers. Anything less is not good enough for the people who served.

Veteran DataData SovereigntyPrivacyValour KeystoneDVAGovernance
Shaune Irving

Written by

Shaune Irving

Technical Founder & CTO · Keytech Intelligence

Shaune Irving is Chief Technology Officer of Keytech Intelligence, a role born out of a deep and long standing interest in the development of sovereign technology capability within Australia. He is a 12-year Royal Australian Air Force veteran, a qualified Queensland Ambulance paramedic, a qualified mechanical fitter, and founder and owner of ARC Industrial Rope Access. He founded CrossFit Ipswich in 2008 and sold his shareholdings in 2014 to learn a trade, and owned BodyFit Aspley from 2020 to 2022. Shaune writes authoritatively on sovereign AI, cyber security, governed decision systems and enterprise architecture. He will compete in Nice this year as an Australian qualified age group athlete at the IRONMAN 70.3 World Championship. Relevant commercial or professional relationships are disclosed on individual articles where applicable.

View profile

Related reading

The Deep Tech Briefing · Weekly

Australian deep technology intelligence, delivered every Tuesday.

One thoughtful email a week — original analysis, curated links and the research we are reading on AI, cyber security and sovereign technology. No spam. No pop-ups. Unsubscribe in one click.

By subscribing you agree to receive editorial email from Deep Tech Australia. We never share your address.