Skip to main content
Australian Healthcare Compliance

Purpose-Built for Australian Healthcare

Briefly. is designed to align with Australian privacy legislation. Patient records are stored in Australia, and our controls are mapped to the Privacy Act 1988 and Australian Privacy Principles.

Privacy Act 1988
Australian Privacy Principles
Health Records Act 2001
AHPRA-Aligned

Comprehensive Australian Compliance

Supporting requirements across federal and state legislation

Aligned

Privacy Act 1988

Controls are mapped to the federal Privacy Act 1988. Your health information is protected with lawful collection, purpose limitation, and strict security safeguards.

Aligned

Australian Privacy Principles

Controls are mapped to all 13 Australian Privacy Principles (APPs) governing collection, use, disclosure, and security of personal information.

Aligned

Health Records Act 2001 (Vic)

Additional safeguards for Victorian healthcare providers and patients under the Health Records Act 2001 and Health Privacy Principles.

Aligned

AHPRA Guidelines

Controls are mapped to Australian Health Practitioner Regulation Agency guidance for health technology, supporting safe clinical documentation practices.

All 13 Australian Privacy Principles

Controls mapped to the APPs that govern personal information handling

1
Open and transparent management of personal information
2
Anonymity and pseudonymity
3
Collection of solicited personal information
4
Dealing with unsolicited personal information
5
Notification of the collection of personal information
6
Use or disclosure of personal information
7
Direct marketing
8
Cross-border disclosure of personal information
9
Adoption, use or disclosure of government related identifiers
10
Quality of personal information
11
Security of personal information
12
Access to personal information
13
Correction of personal information

Australian Data Sovereignty

Patient records and application data are stored in Australia. Some processing services use secure US-based providers under data protection agreements.

Application Data
Sydney, Australia
AWS ap-southeast-2
Database
Sydney, Australia
AWS ap-southeast-2
Backups
Sydney, Australia
AWS ap-southeast-2
Audio Processing
Secure third-party provider
Data protection agreements in place

Australian-First Data Storage

Patient records are stored in Australia. Transcription and letter generation use secure third-party providers under data protection agreements. Your data is never used for model training.

Enterprise Encryption

Industry-leading encryption protects your data at every stage

Data at Rest

  • AES-256-GCM encryption
  • Hardware Security Modules (HSM)
  • Encrypted database backups

Data in Transit

  • TLS 1.3 encryption
  • Certificate pinning
  • Perfect forward secrecy

Notifiable Data Breaches Scheme

We comply with the Notifiable Data Breaches (NDB) scheme with comprehensive incident response procedures.

24/7
Security Monitoring
72hr
OAIC Notification
Immediate
Provider Alert
Full
Incident Report

Frequently Asked Questions

Is my patient data stored in Australia?

Patient records and application data are stored in AWS Sydney (ap-southeast-2). Some processing services use secure third-party providers under data protection agreements. Briefly. does not retain patient data beyond 30 days — we encourage you to export letters and recordings to your own devices or secure cloud storage.

Does Briefly. comply with the Privacy Act 1988?

Briefly. is designed to align with the Privacy Act 1988 and all 13 Australian Privacy Principles. We continuously review and improve controls as independent assurance work progresses.

What about the Health Records Act 2001 for Victorian practices?

We provide additional safeguards for Victorian healthcare providers to ensure compliance with the Health Records Act 2001 and all Health Privacy Principles.

Is my data used for model training?

No. Your patient data is never used for model training. This is a core commitment of our platform.

How quickly are breaches reported?

We comply with the Notifiable Data Breaches (NDB) scheme with OAIC notification within 72 hours for eligible breaches. Affected healthcare providers are notified immediately.

Compliance Inquiries

Need detailed compliance documentation or have questions about our Australian regulatory adherence?