Australian data boundary
Identifiable health information, audio, transcripts, derived data and operational logs are intended to be hosted and processed in Australia using approved services. Before a pilot, every model, telephony, transcription, messaging and support dependency must be checked against that boundary and documented contractually.
Consent and voice recording
The proposed service records healthcare conversations. Recording will require clear notice and recorded, informed consent, including why the recording is made, how it is used, who may hear it and how long it is retained. Caregiver authority and the person's capacity must also be represented in the workflow.
Access and accountability
- Organisation-aligned single sign-on and multi-factor authentication.
- Role-based access and least-privilege permissions.
- Encryption in transit and at rest.
- Audit logs for access, data changes, agent actions and human decisions.
- Protected logs, security monitoring and incident response.
- Access, correction, export, deletion and de-identification workflows.
Retention follows record purpose
Patient-generated observations, recordings, transcripts and formal clinical records may have different legal and operational purposes. Each pilot will define which organisation is the record holder, what becomes part of the clinical record, the applicable retention schedule, and what is securely deleted or de-identified when no longer required.
NSW starting point
Initial pilots are intended for New South Wales. Project governance will be designed around the NSW Health Privacy Principles, relevant NSW Health policies, the Australian Privacy Principles and the participating organisation's own security and record-management requirements.