4 min read · Published
In short
- Production data is hosted in Australia, in the Sydney region.
- Traffic is encrypted with TLS, and sensitive stored data with AES.
- Multi-factor authentication and single sign-on are available, and activity is logged across the platform.
Where is our data?
In Australia. Anaemate’s cloud services run in the Sydney region, and the platform operates on Australian time.
How is it protected?
All traffic between the apps, the dashboard and Anaemate’s services travels over TLS, and sensitive stored data is encrypted using AES. Outbound connections are limited to an approved list of destinations.
Who can see what?
Roles and permissions decide who can see financial information, change billing settings or administer the account. Financial visibility can be scoped separately from access to cases.
How do people sign in?
Multi-factor authentication is available, and single sign-on is supported. Sessions use short-lived access tokens that expire after 30 minutes, with refresh tokens limited to five days.
How do patients get in?
Patients have no account or password. Each link they receive does one thing, such as consenting to an estimate or downloading a receipt, and opens only after they confirm their surname and date of birth.
What is recorded?
Activity is logged across the platform, including sign-ins, unauthorised access attempts, claim transactions and record-level changes. Encounter activity logs show the user, action, date and time, and administrators can see them.
Who else handles our data?
A small number of service providers: Australian cloud hosting, a payment provider, email and SMS delivery, an accredited open banking provider for bank feeds, and document-reading services. A current list naming each one is available on request. Card payments are processed by a specialist payment provider, and Anaemate does not store full card numbers.
How is the software kept safe?
Every change is built, tested and scanned for exposed credentials and vulnerable packages, and static analysis runs across the code every week.
Which rules apply?
Health information is sensitive information under the Privacy Act 1988, and Anaemate handles it under the Australian Privacy Principles and the Notifiable Data Breaches scheme. Security enquiries go to legal@tcihealth.com.au.
In the platform
Security and privacy