Protecting practice and patient privacy is our priority
We’ve made privacy and security our top priority, to protect practice and patient personal information, so you have trust in how we achieve that, and to be transparent in everything we do.
Our focus is to provide the highest standards of care and confidentiality.
We’re upfront about the information we collect and how it is used. And most importantly, we keep your information secure. To further demonstrate this commitment, Healthengine earned ISO 27001 Certification for Information Security Management Systems in October 2022. This is the global standard for information security and recognises the world class processes and procedures we have in place to protect and safeguard practice and patient information.
Data security
Healthengine is serious about maintaining the confidentiality, integrity and availability of data.
We prevent the compromise of personal information of both our users and staff by implementing business-tailored, industry-standard security controls and following best practice security advice. We maximise security by minimising the amount of data transmitted between our servers and your PMS. Data is always transmitted securely over an encrypted channel (TLS encryption in transit), with sensitive data always encrypted at rest, within the database.
Healthengine websites and mobile application are subject to penetration testing and regular security reviews, adhering to stringent Australian Digital Health Agency operating standards and our software packages are digitally signed to prevent tampering.
HealthEngine Practice FAQ
How does Healthengine interact with our practice management software?
The Healthengine appointment connector, which is deployed alongside your PMS, facilitates the exchange of information between you and Healthengine, and complies with Healthengine’s obligations owed under the Privacy Act and as an Australian Privacy Principle entity, and adheres to ADHA operating standards.
How do you ensure data is transferred securely?
Healthengine takes its responsibility for handling personal information seriously, and we have put measures in place to maintain the integrity of personal information and provide full transparency on our conduct. Healthengine is bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and is committed to ensuring compliance with those requirements.
Healthengine minimises the amount of data transmitted between our servers and your practice management software (PMS). Data is always transmitted using Transport Level Security (TLS) standards on an as-needed basis. Sensitive data is encrypted at rest, within the database.
Are you collecting data from the PMS regarding non-Healthengine registered patients?
Healthengine will only access personal information of non-registered individuals where it has been directed to by the practice customer. In these circumstances, Healthengine is effectively acting as a messaging gateway. The information enabling the communication to be sent on behalf of the practice customer remains at all times under the effective control of the practice customer. Accordingly, there is no “disclosure” of personal information by the practice customer to Healthengine.
How does Healthengine store my patients' data?
Healthengine takes its responsibility for handling personal information seriously, and we have put measures in place to maintain the integrity of personal information and provide full transparency on our conduct. Healthengine is bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth), and is committed to ensuring compliance with those requirements.
When providing its services, Healthengine minimises the amount of data transmitted between our servers and your practice management software (PMS). Data is always transmitted using Transport Level Security on an as-needed basis. Sensitive data is encrypted at rest, within the database.
How does Healthengine use patient data?
We use the patients’ personal information for the primary purpose for which it was collected, to provide the services the patient elected to receive.
We may also use the patients personal information for secondary purposes, such as where:
The patient has provided express consent for us to do so.
It might reasonably expected for us to do so, for example, auditing or using de-identified and aggregated personal information to identify insights into the Australian health care sector.
It is required by law or court order.
Does Healthengine sell my patients' data to third parties?
Healthengine does not sell user databases to third parties, refer to “How does Healthengine use patient data” for more information
How safe is my patients' data from a breach?
Healthengine prevents the compromise of personal information of both our users and staff by implementing business-tailored, industry-standard security controls and following best practice security advice. We also maximise security by minimising the amount of data transmitted between our servers and your PMS.
Data is always transmitted securely over an encrypted channel (TLS encryption in transit), with sensitive data always encrypted at rest, within the database. We conduct regular penetration testing and security reviews and adhere to Australian Digital Health Agency operating standards.