Skip to main content

Security, privacy and governance

Written for the people who assess it

This page is structured for a practice manager, a privacy officer or an enterprise security reviewer. It states each control area, and says plainly whether the detail behind it has been confirmed.

Review status

5/28

control areas confirmed. 23 require verification before this page is published.

Why this page is incomplete on purpose

A security page that asserts more than it can evidence fails at exactly the moment it matters — during review, when someone asks which standard, which region, which certification, and the answer is not available.

Anaemate handles health information regulated under the Privacy Act 1988 and the Australian Privacy Principles. Where a control is confirmed, it is stated. Where it is not, it is marked as requiring confirmation rather than filled with language that sounds reassuring and means nothing.

Note for review: the current Anaemate website refers to HIPAA compliance and military-grade encryption. HIPAA is United States legislation and does not apply to Australian health data; “military-grade” is not a standard. Both statements should be corrected at the source, and neither is reproduced here.

01

Australian regulatory context

Anaemate processes health information and financial information relating to Australian patients. That places it within a specific regulatory framework, and the framework — not an overseas equivalent — is what governs the obligations.

Australian regulatory context — control areas and confirmation status
Control areaPositionStatus
Privacy Act 1988 (Cth)Health information is sensitive information under the Act, attracting a higher standard of handling and consent than ordinary personal information.Confirmed
Australian Privacy PrinciplesAPPs govern collection, use, disclosure, quality, security, access and correction of personal information.Confirmed
Notifiable Data Breaches schemeEligible data breaches likely to result in serious harm must be notified to affected individuals and to the OAIC.Confirmed
State health records legislationApplicability of state-based health records legislation to Anaemate's operations requires confirmation.Requires confirmation
Privacy policy and collection noticePublished policy requires legal review against current operations before this site goes live.Requires confirmation

02

Data protection

The questions a security reviewer asks are specific: which algorithm, what key length, where the data physically sits, and who holds the keys.

Data protection — control areas and confirmation status
Control areaPositionStatus
Encryption in transitTLS version, cipher suites and certificate management require confirmation. A named standard is required — a general assurance is not sufficient for review.Requires confirmation
Encryption at restAlgorithm, key length and key management approach require confirmation.Requires confirmation
Data locationHosting region for production data and backups requires confirmation. Australian data residency is commonly a procurement requirement for health data.Requires confirmation
Data retentionRetention periods for patient, procedure and financial records, and the deletion process on account closure, require confirmation.Requires confirmation
Data export on exitFormat and process for extracting practice data on termination requires confirmation.Requires confirmation

03

Access and authentication

Anaemate holds financial data alongside clinical identifiers, so who can see what is a control question rather than a convenience question.

Access and authentication — control areas and confirmation status
Control areaPositionStatus
Role-based permissionsUser roles and permissions determine access to financial data, billing configuration and administration.Confirmed
Separation of clinical and financial accessPermissions allow financial visibility to be scoped separately from case access.Confirmed
Multi-factor authenticationAvailability, enforcement options and supported factors require confirmation.Requires confirmation
Session managementSession timeout, concurrent session handling and revocation require confirmation.Requires confirmation
Device controlsMobile device authentication, device registration and remote revocation require confirmation.Requires confirmation
Single sign-onSupport for enterprise identity providers requires confirmation.Requires confirmation

04

Assurance and testing

Enterprise procurement generally requires evidence rather than assertion. Where evidence exists it should be named; where it does not, saying so is more credible than implying otherwise.

Assurance and testing — control areas and confirmation status
Control areaPositionStatus
Independent certificationNo certification is claimed. Any ISO 27001, SOC 2 or equivalent certification — held or in progress — requires confirmation before it is stated.Requires confirmation
Penetration testingCadence, scope and whether summary reports can be shared under NDA require confirmation.Requires confirmation
Vulnerability managementScanning, triage and remediation timeframes require confirmation.Requires confirmation
Audit loggingAdministrative changes are retained as history. Log scope, retention period and availability to customers require confirmation.Requires confirmation

05

Resilience and incident management

A billing platform holding accounts receivable is an availability-sensitive system. Downtime is not only inconvenient, it delays income.

Resilience and incident management — control areas and confirmation status
Control areaPositionStatus
BackupsFrequency, retention, encryption and restoration testing require confirmation.Requires confirmation
Business continuityRecovery time and recovery point objectives require confirmation.Requires confirmation
Incident responseIncident classification, customer notification commitments and post-incident reporting require confirmation.Requires confirmation
Service statusA public service-status page is not currently published.Requires confirmation

06

Vendor and organisational governance

Anaemate depends on third parties for hosting, payments, banking and communications. A reviewer will assess that chain, not only the platform.

Vendor and organisational governance — control areas and confirmation status
Control areaPositionStatus
Sub-processorsA list of sub-processors covering hosting, payment processing, SMS and email delivery requires confirmation.Requires confirmation
Payment securityCard payments are processed through a payments provider. PCI DSS responsibility split and the provider's certification require confirmation.Requires confirmation
Personnel controlsBackground checks, security training and access provisioning require confirmation.Requires confirmation
Security contactA dedicated address for security enquiries and vulnerability disclosure requires confirmation.Requires confirmation

Security enquiries

Reviewing Anaemate for your organisation

Security questionnaires, privacy assessments and requests for evidence are handled directly. If you are conducting a review, the fastest path is to send the questionnaire you need completed.