Security & Data Controls

Security and data controls,set out in full.

Medspec is an AI clinical scribe and documentation platform used by Australian medical, dental and allied health practices. This page explains how Medspec handles clinical data: where it is stored and processed, who can access it, how long it is retained, how its AI functions operate and which third parties are involved. It is intended to support procurement, privacy and compliance assessments.

Security at a glance

  • Clinical data stored and processed in Australia
  • Consultation audio not retained
  • Encryption in transit and at rest
  • Clinic-scoped access controls
  • Configurable retention and deletion
  • AI-generated content requires approval
  • Customer data not used for cross-customer model training
  • Independent penetration testing
  • A published subprocessor list
Processing lifecycle

How a consultation is processed.

This lifecycle shows each stage within Medspec, the controls applied and when consultation audio ceases to be processed.

  1. Consultation begins

    Capture starts and speech is streamed for real-time transcription.

  2. Transcription in progress

    Text is produced continuously over an encrypted connection. Raw consultation audio is streamed for transcription.

  3. No retrievable consultation audio file is retained

    Audio processing ends

    Raw consultation audio is not written to persistent storage. Temporary in-memory audio buffers are discarded when transcription ends. No retrievable consultation audio recording is created or retained.

  4. Transcript stored

    The transcript is encrypted at rest in Australia and scoped to the originating clinic.

  5. Draft produced

    The draft is created within the clinician’s workspace. It is not approved, exported or securely distributed until an authorised user reviews it.

  6. Review and approval

    An authorised clinician reviews, edits, approves or discards the draft. Nothing is exported or distributed before approval.

  7. Export or secure distribution

    The approved document can be copied or exported for filing in the practice’s clinical system, or securely distributed to an authorised recipient using a link protected by a one-time passcode.

  8. Retention period applies

    The retention rule configured for the relevant record type is applied automatically.

  9. Deletion

    The record is removed from production systems when its retention period expires and remains only within existing backup sets until those backups expire under the backup schedule.

01 · Data residency

All clinical data is stored and processed in Australia.

Data residency is often answered only in part, with storage in one jurisdiction and processing, backups or key management in another. This section describes the location of each component that handles Medspec clinical data.

Medspec operates its clinical platform in the Amazon Web Services Asia Pacific region. Clinical data, backups and encryption keys are stored and processed within that region.

Static application files are delivered through a global content delivery network. That service processes file-delivery metadata but does not process Medspec clinical data. The arrangement is described under Application delivery below.

Region and scope

Components that store or process clinical data operate in AWS Australian environment.

This includes databases holding patient records, object storage holding documents, processing services and backups. Clinical data is not replicated outside Australia for disaster recovery. Redundancy is provided within the other Australian regions.

Tenant isolation

Each clinic operates within a separately scoped and encrypted data boundary.

Isolation is enforced through storage-level scoping, encryption controls and application permissions rather than application filtering alone. Requests outside a clinic’s authorised boundary cannot access that clinic’s records.

Encryption and key management

Encryption keys are managed in Australia.

Encryption keys are generated and managed within a Key Management Service. Key material is not embedded in application code or stored alongside the data it protects.

Data is encrypted at rest using AWS-managed encryption controls using AES-256 at rest and in transit using TLS 1.2 or above, including traffic between Medspec services.

Availability and redundancy

Medspec is designed to operate across multiple availability zones within the Australian region.

Operating across multiple availability zones reduces the risk that a hardware or facility failure in one zone will cause data loss or prolonged service disruption. All redundancy remains within Australia.

Application delivery

Static application files are delivered through a content delivery network. Clinical data is sent directly to Medspec’s Australian APIs and is not processed by the delivery network.

The Medspec application runs in the browser, and its static code, stylesheets and images are delivered by Vercel.

Static files may be served from global edge locations and contain no customer clinical data. Vercel receives request metadata required to deliver those files, such as IP address, timestamp and browser type. After loading, the application communicates directly with Medspec’s Australian APIs.

02 · Retention and deletion

Raw consultation audio recordings are not retained.

Medspec streams consultation audio for real-time transcription and does not write it to persistent storage. No retrievable audio file is retained, so no customer-configured audio-retention period applies.

Medspec retains the transcript, approved documents and other authorised platform records. Retention settings for those records are configured by the user, subject to the customer agreement and applicable legal obligations.

Consultation audio

Audio is streamed for transcription and is not retained as a retrievable recording.

Audio is not written by Medspec to persistent storage or retained for quality review. Because no retrievable audio file is retained, there is no consultation audio file available for later retrieval or account-closure export.

Records retained

Transcripts, approved documents and authorised platform records.

Medspec may also hold patient, appointment, task, template and personalisation records. Each record type is subject to the retention controls described below.

Retention configuration

Retention periods can be configured separately for supported record types.

Users can configure retention separately for supported categories such as patient records, appointments and tasks rather than applying one period to all data. The customer remains responsible for selecting periods that meet its legal and clinical-record obligations.

Cascading deletion

Related records follow the retention and deletion rule of their governing record.

When a governing record is deleted, linked notes and documents are also removed according to the configured relationship and retention rule.

Records are removed from active production systems when deletion is executed. A deleted record may remain within immutable or existing backup sets until those backups expire under the backup-retention schedule.

03 · Access control

Access is granted explicitly.

Access to customer data is granted rather than assumed. This applies to the clinic’s workforce and to Medspec personnel. Support access is described separately below.

Roles and scoping

Permissions follow role and are scoped to the relevant organisation, clinic and location.

Clinicians, support staff and administrators hold distinct roles. Permissions can be scoped to the relevant organisation, clinic or location so users see only the information and functions required for their work.

Audit logging

Access and changes to clinical records are logged where supported.

Audit logs record supported access and modification events and are retained under the applicable log within Medspec.

Medspec support access

User-authorised, limited in scope and time-bound.

When hands-on template is required, the customer can grant Medspec temporary access to the support area. Access is limited to the approved scope (personalise section) and duration, can be withdrawn by the customer and is logged.

Medspec does not maintain standing support access to customer workspaces.

04 · AI governance

The model drafts; the clinician decides.

Medspec’s AI functions produce draft documentation for review. Generated content cannot be approved, exported or securely distributed without explicit action by the user. The clinician remains in charge of content and review process.

Model training

Clinician and patient data is not used to train models that serve other customers.

This applies to transcripts, generated documents and clinician corrections. Customer content is processed to produce that customer’s output and is not aggregated to train models serving other customers.

Review and approval

Approval is enforced by the product workflow rather than relying only on policy.

Generated notes, letters, reports and suggested tasks are presented as drafts. The authorised user finalises it. The clinician remains in control of the content.

Generated suggestions

Follow-up tasks are proposed and require acceptance.

Medspec proposes follow-up tasks from the consultation content, and each suggestion must be accepted or rejected by an authorised clinician. Medspec structures and drafts documentation; it does not replace clinical judgement or make autonomous clinical decisions.

Dynamic summary reconciliation

Proposed differences from the existing record are presented for review rather than applied automatically.

Where the Dynamic Clinical Summary is enabled, Medspec compares consultation content with the existing patient record and presents proposed differences for review. This includes highlighting new diagnosis, medication changes or investigations. Nothing is applied automatically.

Processing environment

AI processing is performed through services configured within the AWS Australia region.

Any third party involved in processing clinical content is identified in the subprocessor list in section 06.

05 · Assurance and testing

Controls are independently tested and regularly monitored.

The controls described on this page are subject to independent testing and ongoing monitoring. This section explains the testing approach, the handling of findings and the incident-response process.

Independent testing

Conducted by an independent external security-testing partner on a defined schedule.

An external testing partner (OWASP, CREST) performs independent authorised security assessments against Medspec systems using controlled test access and data. Assessments are supplemented by automated vulnerability scanning between scheduled tests.

Handling of findings

Findings are assessed, prioritised and tracked to an appropriate resolution.

Findings are assessed according to severity and tracked through remediation, mitigation or formal risk acceptance.

Monitoring

Infrastructure and application activity is continuously monitored.

Activity is logged and monitored for defined anomalous conditions, with alerting configured for events that require investigation.

Incident response

Suspected incidents are managed under an incident-response process.

Suspected security events are escalated and managed under a documented response process. Where an incident affects customer data, Medspec will notify affected customers in accordance with contractual and legal obligations and provide information reasonably required for their own response. Medspec retains an active cyber liability insurance policy.

Australian Privacy Principles

Medspec is designed to align with the Australian Privacy Principles.

Clinical data is stored and processed in Australia. The controls supporting privacy obligations — including residency, tenant isolation, access control, retention and deletion — are described in sections 01 to 03. The healthcare organisation remains responsible for its clinical records and determines how Medspec is used. Medspec processes customer data in accordance with the customer agreement, its own privacy obligations and the controls described on this page.

06 · Subprocessors

Third parties involved in processing or operating Medspec services.

Medspec publishes the third parties involved in operating the platform and identifies whether they process clinical data, account data, billing data or website information. The list is maintained as service providers change.

The list separates platform providers from marketing-website providers because the categories of data they process differ materially.

Medspec platform

Third parties involved in operating the platform. What each one can see is set out per row.

WhoWhat they doWhereWhat they see
Amazon Web ServicesProvides compute, databases, object storage, backups and key management.Sydney (ap-southeast-2)AWS processes the clinical data required to operate the platform. Data is encrypted in transit and at rest.
VercelDelivers static application files through a global edge network.Global edge networkVercel receives request metadata required for file delivery, such as IP address, timestamp and browser type. Clinical data is sent directly to Medspec’s Australian APIs and is not processed by Vercel.
StripeProcesses subscriptions and billing.GlobalStripe receives billing contact and payment information. Card details are handled by Stripe and are not stored by Medspec. Stripe does not receive clinical data.
BlacklockPerforms independent security testing and vulnerability assessment.New ZealandTesting is performed from New Zealand using authorised test systems, accounts and data. Blacklock does not receive routine access to customer clinical data.

medspec.com.au

Marketing and enquiry tooling operating on this website. None of these services processes clinical data or has access to the Medspec platform.

WhoWhat they doWhereWhat they see
Amazon SESDelivers website enquiry and contact-form email through the Sydney region.Sydney (ap-southeast-2)It processes the name, email address and message submitted by the visitor.
Google AnalyticsMeasures public website traffic.GlobalMay process pageview, device, browser, approximate location and cookie or identifier data, depending on configuration. It does not receive Medspec clinical data.
3CXProvides the public website chat facility.AustraliaProcesses information entered into the chat widget and related connection metadata. Visitors should not submit patient or clinical information through public website chat.

Your documents, in your words, ready to action.

14-day free trial
No credit card required
Support-staff accounts included