Security and privacy

What happens to a patient's information

Katina holds health information, which is sensitive information under the Privacy Act 1988 (Cth). This page is the detail your procurement checklist asks for, and the notice a patient is sent to from the consent step on a clinic's enquiry form. Everything on it is true of the product today.

Encryption

Record by record, and never in the browser

Per-record keys

Every patient record is encrypted with its own key. That key is wrapped by one customer-managed key held in the same region, and the ciphertext is bound to its own table, column and row — so a record lifted somewhere it does not belong cannot be read there.

Server-side only

Fields are decrypted for a single request, by a role holding the permission. No key, no ciphertext and no decryption path is ever sent to a browser.

Residency

Patient data is held in ap-southeast-2, the AWS Asia Pacific (Sydney) region. It is not replicated offshore.

Access

Five roles, twenty permissions, enforced on the server. document:verify and booking:book are deliberately separate from referral:write: reading a referral, approving its documents and committing an appointment are three different authorities.

The audit chain

Tamper-evident, not merely append-only

Each practice has its own chain, and every entry carries the hash of the entry before it. Remove a row or edit one and the chain stops agreeing with itself, visibly.

01

Written in the same transaction

The audit entry is committed with the change it describes, not afterwards and not best-effort. There is no window in which a change exists and its record does not.

02

Deliberate disclosures are recorded

Opening a practitioner's clinical profile, or the text read off a fax, writes an entry. Looking is an event, not a silence.

03

Identifiers, never values

The log records which record and which field, never the content of it. An audit trail that quoted the information it was protecting would be a second copy of it.

04

Readable by your own practice

A member holding audit:read can read your chain. Nobody can quietly rewrite it.

Consent

Default-deny, and a revocation is a new record

Nothing is disclosed to a third party until a specific purpose has been consented to. Consent is append-only: withdrawing it writes a new record saying so, rather than deleting the old one, so the history of what was agreed and when remains readable.

At collection

The enquiry form says what is collected, who will see it, and where it is held, at the point it is asked for.

Never an echo

What a patient submits is never read back to them in a confirmation. They get an acknowledgement, not a copy.

Cross-border

Any disclosure that would leave Australia is a separate, named consent. It is not bundled into the first one.

Documents

The things you can ask us for

Privacy notice

Versioned and dated, and linked from the consent step on every clinic's enquiry form.

Practice and practitioner terms

The agreement a practice signs, and the one a practitioner using it is bound by.

Sub-processor list

Who else touches the data, for what, and in which region.

Your data on request

An export of your referrals, documents and audit chain. Deletion is confirmed in writing, with a date.

Breach notification follows the Notifiable Data Breaches scheme. If an eligible data breach affects your practice we tell you and the OAIC, and we tell you what we know as we know it rather than once at the end.

Next

Send this page to whoever asks the security questions.

It is written to be forwarded. If your practice owner, your insurer or your legal adviser needs something that is not here, ask and we will either answer it or tell you we cannot yet.