Security and privacy
papersGP is a custodian of clinical data. Every architectural decision — from data residency to encryption to access control — exists to make that custodianship trustworthy.
How we protect your data
Data stays in Australia
Clinical and health data is stored in Australia — AWS ap-southeast-2 (Sydney) for hosting and compute, and MongoDB Atlas in the Australian region for clinical data.
Encryption at rest and in transit
AES-256 encryption at rest for stored clinical data. TLS encrypts data in transit between your browser and papersGP.
Healthcare data standards
Clinical data is stored as FHIR R4 resources with Australian profiles (AU Base / AU Core).
Authentication and access control
Role-based access control (practitioner, patient, admin) with least privilege.
Audit logging
Access to clinical data is recorded with a who / what / when / outcome audit entry.
No PHI sent to external AI
AI runs server-side on Australian-resident infrastructure on AWS. No patient-identifiable data is sent to third-party AI providers, and AI is not used to interpret, diagnose, or recommend.
Regulatory alignment
Full security posture documentation is available for enterprise and PHN procurement review on request.
Policies
Privacy Policy
How we collect, use, store, and protect personal and health information.
End User Licence Agreement
Terms of use for the papersGP platform, including AI and automated processing.
Security enquiries
For security questions or to request our full security posture documentation.
