The Privacy Act 2020 and the Health Information Privacy Code. The standard the platform is designed against from the start, not retro-fitted to once someone asks.
Security & privacy
Patient data deserves a straight answer.
Health information is the most sensitive data most practices hold. Here is our position, stated plainly, before anyone has to ask for it.
What we build to.
Role-based access. People see what their role requires and no more, and you control the roles.
A complete audit trail. Who viewed what, who changed what, and when. Available to you, not only to us.
Encryption in transit and at rest. A baseline, not a feature to be sold back to you.
Where your data lives.
Where patient data physically sits matters to New Zealand practices, and it should be a stated decision rather than a buried one. We will publish our position on region, provider and sub-processors before the first practice goes live.
Who can see your records.
Your patient records are yours. We access them when you ask us to, for support, and the access is logged and visible to you.
We do not sell data. We do not use identifiable patient information to train models.
We do not sell data. We do not use identifiable patient information to train models.
What we’ll publish before launch.
- A security overview, written to be read by a practice owner rather than by a lawyer.
- Our sub-processor list, and how you will be told when it changes.
- Our incident response and notification commitments.
- Backup and recovery objectives, in hours rather than adjectives.
- Our data processing terms.