Your data, your cloud, onshore always
Health data stays private, auditable and in your control. Deployment is sovereign, secrets are encrypted with a key held in your own key vault, and compliance frameworks were designed in from the start.
A standards-based data model (FHIR R4) with an audit trail.
Records are de-identified before they reach the LLM.
De-identification and ethics-ready exports.
What a security review will find
Single-tenant and onshore
HealthOS runs single-tenant, inside a cloud account you control, onshore in Australia. There is no shared infrastructure and no co-tenancy, and data never leaves the country.
Encrypted at rest and in transit
Data is encrypted with AES-256 at rest and TLS 1.3 in transit. Secrets are encrypted with a key stored in your own key vault, and sensitive fields carry authenticated encryption (AES-256-GCM) on top.
Your identity provider, your roles
Staff sign in once through your existing identity provider, with role-based access control. Multi-factor authentication is enforced for admin accounts, and idle sessions time out automatically.
Enforced at the database
Row-level security at the database means staff see only the records their organisation, facility and role permit. It is enforced on every query as well as in the interface. Several organisations can share one deployment, with each one's data logically walled off.
Every change kept for seven years
Every record change is captured with the user, the timestamp and the before and after values. The log is append-only, queryable and kept for seven years. Nothing is ever hard-deleted.
Built against the Australian Privacy Principles
Consent management and data minimisation are part of the platform itself, beyond a policy document. Daily automated backups come with point-in-time recovery, restricted administrative privileges and network segmentation, following the ACSC Essential 8 maturity model.
Working towards ISO 27001
HealthOS is being built to support ISO 27001 certification. The target artefacts of that work are an information security management system, a risk register, an Annex A control mapping and evidence packs. Ask us for the detailed security pack and we will walk your team through each control.
The short version
Related
See the security model first-hand
A 45-minute walkthrough covering deployment architecture, encryption, access controls and compliance evidence.



