Privacy and security

Your health information deserves care.

Your health information is personal. MedStory helps protect it. Here’s who can access it and the choices you have.

Encrypted information

Protected when stored and sent.

Controlled access

Sign-in and profile permissions help protect your records.

Private documents

Uploaded files aren’t public.

No data sales

We don’t sell your health information.

Product safeguards

Protection built into MedStory.

Encryption at rest and in transit

MedStory uses HTTPS/TLS when information is sent. Our hosting providers encrypt stored database records and uploaded files.

Role-based access controls

You sign in to access MedStory. Role-based access control (RBAC) checks your profile role. Database row-level security (RLS) helps keep each person’s records separate.

MedStory checks who you are and which profiles you’re allowed to use.

Private document storage

Documents are stored privately. MedStory checks your access before opening or downloading a file.

Your documents aren’t placed in a public document library.

A person reviewing health information on a tablet with a trusted supporter.

Your information is not for sale.

We don’t sell health information or use it for third-party advertising.

We use service providers for hosting, storage and account services. Some information may be stored or processed outside Australia.

Current systems may store information in Japan. Information may pass through the United States. It may also be processed there. Authorised MedStory staff and providers may need access. This may be for support, security, service operations or legal duties.

When document processing is available, suggested health details must be reviewed before they’re saved. These suggestions can be wrong or incomplete.

Read our Privacy Policy

Our approach to privacy obligations.

We aim to handle personal information in line with the Privacy Act 1988 and the Australian Privacy Principles. We also follow other laws that apply to MedStory.

We assess suspected data breaches. We make notifications when required under Australia’s Notifiable Data Breaches scheme.