Encrypted information
Protected when stored and sent.
Privacy and security
Your health information is personal. MedStory helps protect it. Here’s who can access it and the choices you have.
Protected when stored and sent.
Sign-in and profile permissions help protect your records.
Uploaded files aren’t public.
We don’t sell your health information.
Product safeguards
MedStory uses HTTPS/TLS when information is sent. Our hosting providers encrypt stored database records and uploaded files.
You sign in to access MedStory. Role-based access control (RBAC) checks your profile role. Database row-level security (RLS) helps keep each person’s records separate.
MedStory checks who you are and which profiles you’re allowed to use.
Documents are stored privately. MedStory checks your access before opening or downloading a file.
Your documents aren’t placed in a public document library.

We don’t sell health information or use it for third-party advertising.
We use service providers for hosting, storage and account services. Some information may be stored or processed outside Australia.
Current systems may store information in Japan. Information may pass through the United States. It may also be processed there. Authorised MedStory staff and providers may need access. This may be for support, security, service operations or legal duties.
When document processing is available, suggested health details must be reviewed before they’re saved. These suggestions can be wrong or incomplete.
Read our Privacy PolicyWe aim to handle personal information in line with the Privacy Act 1988 and the Australian Privacy Principles. We also follow other laws that apply to MedStory.
We assess suspected data breaches. We make notifications when required under Australia’s Notifiable Data Breaches scheme.
We’re here to help you understand how MedStory handles your information.
Contact usPlease don’t email health documents, passwords or private medical notes.
Verified 11 October 2026.