Mail handling for NDIS providers: privacy, audit trails and a workforce that is never in one place

August 1, 2026

Michael Tippett

Mail handling for NDIS providers in Australia

Mail handling for NDIS providers is an unglamorous problem with a sharp edge on it. The correspondence is sensitive by definition — participant plans, plan review outcomes, allied health reports, guardianship and nominee paperwork, complaints, invoices tied to named individuals — and the workforce that needs it is typically distributed across participants' homes, community settings and vehicles rather than sitting in one office. A registered provider is also operating inside a compliance framework where "we think it was posted to the coordinator" is not a satisfactory answer during an audit. The following is general information about mail logistics, not compliance advice; your registered plan and the NDIS Quality and Safeguards Commission's current guidance govern your actual obligations.

What arrives on paper for an NDIS provider

Even providers who run everything else digitally still receive a steady paper stream:

  • NDIA correspondence about participant plans, plan reviews and funding changes.
  • Service agreements and consent forms returned by post, often signed by a participant's nominee or guardian.
  • Allied health assessments, functional capacity reports and specialist letters supplied in hard copy.
  • Correspondence from the NDIS Quality and Safeguards Commission, including anything relating to reportable incidents or complaints.
  • Worker screening and clearance documentation.
  • Insurance, audit scheduling, ATO and general business mail.

Almost every item in that list contains personal information, and several contain sensitive information within the meaning of the Privacy Act 1988 — health information in particular attracts a higher standard of protection than ordinary personal information.

Why the usual arrangements break down

Small and mid-sized providers usually start with one of three arrangements, and each fails in a predictable way:

  1. Mail to the director's home address. Fast to set up, and it puts participant health information in a residential letterbox that other household members can access. It also publishes a home address on business registers and participant-facing documents.
  2. A PO Box collected by whoever is nearby. Better physically, but there is no record of who collected what or when, and collection depends on somebody driving to a specific post office. When that person is on leave, mail sits uncollected.
  3. An office address with an empty office. Common after providers moved to community-based delivery. Mail accumulates, occasionally for weeks, and time-limited correspondence expires unopened.

All three share the same defect: there is no reliable record of what arrived, when it arrived, and who saw it. That record is exactly what an auditor, or a complaint investigation, asks for.

What a scanned, logged mail stream changes

Routing business mail through a monitored address that scans and timestamps everything changes the failure modes rather than just moving the letterbox:

  • Date-stamped receipt. Every item is logged on arrival, so "when did we receive the Commission's letter" has an answer that does not depend on memory.
  • Same-day visibility for a distributed team. A support coordinator working out of their car sees a scanned plan review the day it lands, not the next time somebody visits the office.
  • Nothing sensitive sitting in a residential letterbox. Participant health information does not pass through anyone's home.
  • A searchable archive. Digital copies can be filed into your client management system against the right participant record immediately, rather than being scanned in a batch weeks later — or not at all.
  • Controlled physical handling. Originals that must stay physical, such as wet-signed agreements, can be forwarded to a nominated person, while everything else stays digital.

Record keeping and retention

NDIS providers are subject to record-keeping obligations under the NDIS legislation and practice standards, and separately to ATO record-keeping rules for the business side. Retention periods for participant records are longer than the general business default, and are commonly cited as seven years — confirm the period that applies to your registration groups against the current NDIS Quality and Safeguards Commission guidance rather than relying on a rule of thumb.

Two practical points follow. First, digital copies are generally acceptable where they are a true and clear reproduction of the original and cannot be altered — the same principle that applies to digital mail for business tax records. Second, a retention obligation is only as good as your ability to actually find the document, which is an argument for scanning at the point of receipt rather than at the point somebody asks for it.

Privacy considerations when a third party handles the mail

Bringing any external provider into the handling of personal information is a decision that deserves the same scrutiny you would apply to a software vendor. Sensible questions to ask, of us or of anyone else:

  • Where is scanned material stored, and who within the provider can access it?
  • What is the destruction process for physical items after scanning, and is it logged?
  • Can you restrict which of your own staff can view which items?
  • What happens to your archive if you close the account?
  • Is the arrangement documented well enough to describe in your own privacy policy and participant-facing consent material?

You remain accountable for participant information regardless of who physically opens the envelope. The right arrangement is one you can describe accurately to a participant who asks.

A practical setup for a small provider

A workable configuration for a provider with a handful of coordinators and no permanent office:

  1. Use the mail address as the business correspondence address on your registers, invoices and participant documents, keeping directors' home addresses off public records.
  2. Set the default action to open-and-scan, so nothing waits on a decision.
  3. Nominate one person responsible for triaging the day's scans into the client management system against participant records.
  4. Flag categories that must be physically forwarded — original signed agreements, certified copies, anything with a seal.
  5. Keep a documented retention and destruction rule, and apply it consistently to both digital and physical copies.

Providers with a similar shape — mobile staff, sensitive correspondence, no fixed office — face much the same problem; see our pages on locum healthcare workers and small business owners for adjacent versions of it.

The goal is not to digitise for its own sake. It is to be able to answer, quickly and with evidence, what arrived and what was done about it — which is the question that actually gets asked.

Set up a secure, scanned business mail address with HotSnail
NDIS providersMail scanningPrivacy & recordsAudit trail