Security, privacy and governance
Written for the people who assess it
This page is structured for a practice manager, a privacy officer or an enterprise security reviewer. It states each control area, and says plainly whether the detail behind it has been confirmed.
Review status
5/28
control areas confirmed. 23 require verification before this page is published.
Why this page is incomplete on purpose
A security page that asserts more than it can evidence fails at exactly the moment it matters — during review, when someone asks which standard, which region, which certification, and the answer is not available.
Anaemate handles health information regulated under the Privacy Act 1988 and the Australian Privacy Principles. Where a control is confirmed, it is stated. Where it is not, it is marked as requiring confirmation rather than filled with language that sounds reassuring and means nothing.
Note for review: the current Anaemate website refers to HIPAA compliance and military-grade encryption. HIPAA is United States legislation and does not apply to Australian health data; “military-grade” is not a standard. Both statements should be corrected at the source, and neither is reproduced here.
01
Australian regulatory context
Anaemate processes health information and financial information relating to Australian patients. That places it within a specific regulatory framework, and the framework — not an overseas equivalent — is what governs the obligations.
| Control area | Position | Status |
|---|---|---|
| Privacy Act 1988 (Cth) | Health information is sensitive information under the Act, attracting a higher standard of handling and consent than ordinary personal information. | Confirmed |
| Australian Privacy Principles | APPs govern collection, use, disclosure, quality, security, access and correction of personal information. | Confirmed |
| Notifiable Data Breaches scheme | Eligible data breaches likely to result in serious harm must be notified to affected individuals and to the OAIC. | Confirmed |
| State health records legislation | Applicability of state-based health records legislation to Anaemate's operations requires confirmation. | Requires confirmation |
| Privacy policy and collection notice | Published policy requires legal review against current operations before this site goes live. | Requires confirmation |
02
Data protection
The questions a security reviewer asks are specific: which algorithm, what key length, where the data physically sits, and who holds the keys.
| Control area | Position | Status |
|---|---|---|
| Encryption in transit | TLS version, cipher suites and certificate management require confirmation. A named standard is required — a general assurance is not sufficient for review. | Requires confirmation |
| Encryption at rest | Algorithm, key length and key management approach require confirmation. | Requires confirmation |
| Data location | Hosting region for production data and backups requires confirmation. Australian data residency is commonly a procurement requirement for health data. | Requires confirmation |
| Data retention | Retention periods for patient, procedure and financial records, and the deletion process on account closure, require confirmation. | Requires confirmation |
| Data export on exit | Format and process for extracting practice data on termination requires confirmation. | Requires confirmation |
03
Access and authentication
Anaemate holds financial data alongside clinical identifiers, so who can see what is a control question rather than a convenience question.
| Control area | Position | Status |
|---|---|---|
| Role-based permissions | User roles and permissions determine access to financial data, billing configuration and administration. | Confirmed |
| Separation of clinical and financial access | Permissions allow financial visibility to be scoped separately from case access. | Confirmed |
| Multi-factor authentication | Availability, enforcement options and supported factors require confirmation. | Requires confirmation |
| Session management | Session timeout, concurrent session handling and revocation require confirmation. | Requires confirmation |
| Device controls | Mobile device authentication, device registration and remote revocation require confirmation. | Requires confirmation |
| Single sign-on | Support for enterprise identity providers requires confirmation. | Requires confirmation |
04
Assurance and testing
Enterprise procurement generally requires evidence rather than assertion. Where evidence exists it should be named; where it does not, saying so is more credible than implying otherwise.
| Control area | Position | Status |
|---|---|---|
| Independent certification | No certification is claimed. Any ISO 27001, SOC 2 or equivalent certification — held or in progress — requires confirmation before it is stated. | Requires confirmation |
| Penetration testing | Cadence, scope and whether summary reports can be shared under NDA require confirmation. | Requires confirmation |
| Vulnerability management | Scanning, triage and remediation timeframes require confirmation. | Requires confirmation |
| Audit logging | Administrative changes are retained as history. Log scope, retention period and availability to customers require confirmation. | Requires confirmation |
05
Resilience and incident management
A billing platform holding accounts receivable is an availability-sensitive system. Downtime is not only inconvenient, it delays income.
| Control area | Position | Status |
|---|---|---|
| Backups | Frequency, retention, encryption and restoration testing require confirmation. | Requires confirmation |
| Business continuity | Recovery time and recovery point objectives require confirmation. | Requires confirmation |
| Incident response | Incident classification, customer notification commitments and post-incident reporting require confirmation. | Requires confirmation |
| Service status | A public service-status page is not currently published. | Requires confirmation |
06
Vendor and organisational governance
Anaemate depends on third parties for hosting, payments, banking and communications. A reviewer will assess that chain, not only the platform.
| Control area | Position | Status |
|---|---|---|
| Sub-processors | A list of sub-processors covering hosting, payment processing, SMS and email delivery requires confirmation. | Requires confirmation |
| Payment security | Card payments are processed through a payments provider. PCI DSS responsibility split and the provider's certification require confirmation. | Requires confirmation |
| Personnel controls | Background checks, security training and access provisioning require confirmation. | Requires confirmation |
| Security contact | A dedicated address for security enquiries and vulnerability disclosure requires confirmation. | Requires confirmation |
Security enquiries
Reviewing Anaemate for your organisation
Security questionnaires, privacy assessments and requests for evidence are handled directly. If you are conducting a review, the fastest path is to send the questionnaire you need completed.