Medspec is an AI clinical scribe and documentation platform used by Australian medical, dental and allied health practices. This page explains how Medspec handles clinical data: where it is stored and processed, who can access it, how long it is retained, how its AI functions operate and which third parties are involved. It is intended to support procurement, privacy and compliance assessments.
Security at a glance
Clinical data stored and processed in Australia
Consultation audio not retained
Encryption in transit and at rest
Clinic-scoped access controls
Configurable retention and deletion
AI-generated content requires approval
Customer data not used for cross-customer model training
Independent penetration testing
A published subprocessor list
Processing lifecycle
How a consultation is processed.
This lifecycle shows each stage within Medspec, the controls applied and when consultation audio ceases to be processed.
Consultation begins
Capture starts and speech is streamed for real-time transcription.
Transcription in progress
Text is produced continuously over an encrypted connection. Raw consultation audio is streamed for transcription.
No retrievable consultation audio file is retained
Audio processing ends
Raw consultation audio is not written to persistent storage. Temporary in-memory audio buffers are discarded when transcription ends. No retrievable consultation audio recording is created or retained.
Transcript stored
The transcript is encrypted at rest in Australia and scoped to the originating clinic.
Draft produced
The draft is created within the clinician’s workspace. It is not approved, exported or securely distributed until an authorised user reviews it.
Review and approval
An authorised clinician reviews, edits, approves or discards the draft. Nothing is exported or distributed before approval.
Export or secure distribution
The approved document can be copied or exported for filing in the practice’s clinical system, or securely distributed to an authorised recipient using a link protected by a one-time passcode.
Retention period applies
The retention rule configured for the relevant record type is applied automatically.
Deletion
The record is removed from production systems when its retention period expires and remains only within existing backup sets until those backups expire under the backup schedule.
01 · Data residency
All clinical data is stored and processed in Australia.
Data residency is often answered only in part, with storage in one jurisdiction and processing, backups or key management in another. This section describes the location of each component that handles Medspec clinical data.
Medspec operates its clinical platform in the Amazon Web Services Asia Pacific region. Clinical data, backups and encryption keys are stored and processed within that region.
Static application files are delivered through a global content delivery network. That service processes file-delivery metadata but does not process Medspec clinical data. The arrangement is described under Application delivery below.
Region and scope
Components that store or process clinical data operate in AWS Australian environment.
This includes databases holding patient records, object storage holding documents, processing services and backups. Clinical data is not replicated outside Australia for disaster recovery. Redundancy is provided within the other Australian regions.
Tenant isolation
Each clinic operates within a separately scoped and encrypted data boundary.
Isolation is enforced through storage-level scoping, encryption controls and application permissions rather than application filtering alone. Requests outside a clinic’s authorised boundary cannot access that clinic’s records.
Encryption and key management
Encryption keys are managed in Australia.
Encryption keys are generated and managed within a Key Management Service. Key material is not embedded in application code or stored alongside the data it protects.
Data is encrypted at rest using AWS-managed encryption controls using AES-256 at rest and in transit using TLS 1.2 or above, including traffic between Medspec services.
Availability and redundancy
Medspec is designed to operate across multiple availability zones within the Australian region.
Operating across multiple availability zones reduces the risk that a hardware or facility failure in one zone will cause data loss or prolonged service disruption. All redundancy remains within Australia.
Application delivery
Static application files are delivered through a content delivery network. Clinical data is sent directly to Medspec’s Australian APIs and is not processed by the delivery network.
The Medspec application runs in the browser, and its static code, stylesheets and images are delivered by Vercel.
Static files may be served from global edge locations and contain no customer clinical data. Vercel receives request metadata required to deliver those files, such as IP address, timestamp and browser type. After loading, the application communicates directly with Medspec’s Australian APIs.
02 · Retention and deletion
Raw consultation audio recordings are not retained.
Medspec streams consultation audio for real-time transcription and does not write it to persistent storage. No retrievable audio file is retained, so no customer-configured audio-retention period applies.
Medspec retains the transcript, approved documents and other authorised platform records. Retention settings for those records are configured by the user, subject to the customer agreement and applicable legal obligations.
Consultation audio
Audio is streamed for transcription and is not retained as a retrievable recording.
Audio is not written by Medspec to persistent storage or retained for quality review. Because no retrievable audio file is retained, there is no consultation audio file available for later retrieval or account-closure export.
Records retained
Transcripts, approved documents and authorised platform records.
Medspec may also hold patient, appointment, task, template and personalisation records. Each record type is subject to the retention controls described below.
Retention configuration
Retention periods can be configured separately for supported record types.
Users can configure retention separately for supported categories such as patient records, appointments and tasks rather than applying one period to all data. The customer remains responsible for selecting periods that meet its legal and clinical-record obligations.
Cascading deletion
Related records follow the retention and deletion rule of their governing record.
When a governing record is deleted, linked notes and documents are also removed according to the configured relationship and retention rule.
Records are removed from active production systems when deletion is executed. A deleted record may remain within immutable or existing backup sets until those backups expire under the backup-retention schedule.
03 · Access control
Access is granted explicitly.
Access to customer data is granted rather than assumed. This applies to the clinic’s workforce and to Medspec personnel. Support access is described separately below.
Roles and scoping
Permissions follow role and are scoped to the relevant organisation, clinic and location.
Clinicians, support staff and administrators hold distinct roles. Permissions can be scoped to the relevant organisation, clinic or location so users see only the information and functions required for their work.
Audit logging
Access and changes to clinical records are logged where supported.
Audit logs record supported access and modification events and are retained under the applicable log within Medspec.
Medspec support access
User-authorised, limited in scope and time-bound.
When hands-on template is required, the customer can grant Medspec temporary access to the support area. Access is limited to the approved scope (personalise section) and duration, can be withdrawn by the customer and is logged.
Medspec does not maintain standing support access to customer workspaces.
04 · AI governance
The model drafts; the clinician decides.
Medspec’s AI functions produce draft documentation for review. Generated content cannot be approved, exported or securely distributed without explicit action by the user. The clinician remains in charge of content and review process.
Model training
Clinician and patient data is not used to train models that serve other customers.
This applies to transcripts, generated documents and clinician corrections. Customer content is processed to produce that customer’s output and is not aggregated to train models serving other customers.
Review and approval
Approval is enforced by the product workflow rather than relying only on policy.
Generated notes, letters, reports and suggested tasks are presented as drafts. The authorised user finalises it. The clinician remains in control of the content.
Generated suggestions
Follow-up tasks are proposed and require acceptance.
Medspec proposes follow-up tasks from the consultation content, and each suggestion must be accepted or rejected by an authorised clinician. Medspec structures and drafts documentation; it does not replace clinical judgement or make autonomous clinical decisions.
Dynamic summary reconciliation
Proposed differences from the existing record are presented for review rather than applied automatically.
Where the Dynamic Clinical Summary is enabled, Medspec compares consultation content with the existing patient record and presents proposed differences for review. This includes highlighting new diagnosis, medication changes or investigations. Nothing is applied automatically.
Processing environment
AI processing is performed through services configured within the AWS Australia region.
Any third party involved in processing clinical content is identified in the subprocessor list in section 06.
Patient notification and consent
Managed by the clinician and organisation under their governance framework.
The clinician and operating organisation are responsible for determining and following the appropriate patient-notification or consent process under their clinical governance, privacy and professional obligations.
05 · Assurance and testing
Controls are independently tested and regularly monitored.
The controls described on this page are subject to independent testing and ongoing monitoring. This section explains the testing approach, the handling of findings and the incident-response process.
Independent testing
Conducted by an independent external security-testing partner on a defined schedule.
An external testing partner (OWASP, CREST) performs independent authorised security assessments against Medspec systems using controlled test access and data. Assessments are supplemented by automated vulnerability scanning between scheduled tests.
Handling of findings
Findings are assessed, prioritised and tracked to an appropriate resolution.
Findings are assessed according to severity and tracked through remediation, mitigation or formal risk acceptance.
Monitoring
Infrastructure and application activity is continuously monitored.
Activity is logged and monitored for defined anomalous conditions, with alerting configured for events that require investigation.
Incident response
Suspected incidents are managed under an incident-response process.
Suspected security events are escalated and managed under a documented response process. Where an incident affects customer data, Medspec will notify affected customers in accordance with contractual and legal obligations and provide information reasonably required for their own response. Medspec retains an active cyber liability insurance policy.
Australian Privacy Principles
Medspec is designed to align with the Australian Privacy Principles.
Clinical data is stored and processed in Australia. The controls supporting privacy obligations — including residency, tenant isolation, access control, retention and deletion — are described in sections 01 to 03. The healthcare organisation remains responsible for its clinical records and determines how Medspec is used. Medspec processes customer data in accordance with the customer agreement, its own privacy obligations and the controls described on this page.
06 · Subprocessors
Third parties involved in processing or operating Medspec services.
Medspec publishes the third parties involved in operating the platform and identifies whether they process clinical data, account data, billing data or website information. The list is maintained as service providers change.
The list separates platform providers from marketing-website providers because the categories of data they process differ materially.
Medspec platform
Third parties involved in operating the platform. What each one can see is set out per row.
Who
What they do
Where
What they see
Amazon Web Services
Provides compute, databases, object storage, backups and key management.
Sydney (ap-southeast-2)
AWS processes the clinical data required to operate the platform. Data is encrypted in transit and at rest.
Vercel
Delivers static application files through a global edge network.
Global edge network
Vercel receives request metadata required for file delivery, such as IP address, timestamp and browser type. Clinical data is sent directly to Medspec’s Australian APIs and is not processed by Vercel.
Stripe
Processes subscriptions and billing.
Global
Stripe receives billing contact and payment information. Card details are handled by Stripe and are not stored by Medspec. Stripe does not receive clinical data.
Blacklock
Performs independent security testing and vulnerability assessment.
New Zealand
Testing is performed from New Zealand using authorised test systems, accounts and data. Blacklock does not receive routine access to customer clinical data.
medspec.com.au
Marketing and enquiry tooling operating on this website. None of these services processes clinical data or has access to the Medspec platform.
Who
What they do
Where
What they see
Amazon SES
Delivers website enquiry and contact-form email through the Sydney region.
Sydney (ap-southeast-2)
It processes the name, email address and message submitted by the visitor.
Google Analytics
Measures public website traffic.
Global
May process pageview, device, browser, approximate location and cookie or identifier data, depending on configuration. It does not receive Medspec clinical data.
3CX
Provides the public website chat facility.
Australia
Processes information entered into the chat widget and related connection metadata. Visitors should not submit patient or clinical information through public website chat.