01
Written in the same transaction
The audit entry is committed with the change it describes, not afterwards and not best-effort. There is no window in which a change exists and its record does not.
Security and privacy
Katina holds health information, which is sensitive information under the Privacy Act 1988 (Cth). This page is the detail your procurement checklist asks for, and the notice a patient is sent to from the consent step on a clinic's enquiry form. Everything on it is true of the product today.
Encryption
Per-record keys
Every patient record is encrypted with its own key. That key is wrapped by one customer-managed key held in the same region, and the ciphertext is bound to its own table, column and row — so a record lifted somewhere it does not belong cannot be read there.
Server-side only
Fields are decrypted for a single request, by a role holding the permission. No key, no ciphertext and no decryption path is ever sent to a browser.
Residency
Patient data is held in ap-southeast-2, the AWS Asia Pacific (Sydney) region. It is not replicated offshore.
Access
Five roles, twenty permissions, enforced on the server. document:verify and booking:book are deliberately separate from referral:write: reading a referral, approving its documents and committing an appointment are three different authorities.
The audit chain
Each practice has its own chain, and every entry carries the hash of the entry before it. Remove a row or edit one and the chain stops agreeing with itself, visibly.
01
The audit entry is committed with the change it describes, not afterwards and not best-effort. There is no window in which a change exists and its record does not.
02
Opening a practitioner's clinical profile, or the text read off a fax, writes an entry. Looking is an event, not a silence.
03
The log records which record and which field, never the content of it. An audit trail that quoted the information it was protecting would be a second copy of it.
04
A member holding audit:read can read your chain. Nobody can quietly rewrite it.
Consent
Nothing is disclosed to a third party until a specific purpose has been consented to. Consent is append-only: withdrawing it writes a new record saying so, rather than deleting the old one, so the history of what was agreed and when remains readable.
The enquiry form says what is collected, who will see it, and where it is held, at the point it is asked for.
What a patient submits is never read back to them in a confirmation. They get an acknowledgement, not a copy.
Any disclosure that would leave Australia is a separate, named consent. It is not bundled into the first one.
Documents
Versioned and dated, and linked from the consent step on every clinic's enquiry form.
The agreement a practice signs, and the one a practitioner using it is bound by.
Who else touches the data, for what, and in which region.
An export of your referrals, documents and audit chain. Deletion is confirmed in writing, with a date.
Breach notification follows the Notifiable Data Breaches scheme. If an eligible data breach affects your practice we tell you and the OAIC, and we tell you what we know as we know it rather than once at the end.
Next
It is written to be forwarded. If your practice owner, your insurer or your legal adviser needs something that is not here, ask and we will either answer it or tell you we cannot yet.