ENCRYPTION
Encryption policy
Mandatory requirements for encryption across MedTalk systems, applications and data environments.
Purpose
This policy establishes the mandatory requirements for the use of encryption across MedTalk systems, applications and data environments, protecting the confidentiality, integrity and security of organisational and personal information, particularly healthcare-related information, during storage, transmission and processing.
- Protect sensitive and regulated information from unauthorised access
- Ensure secure transmission of information across networks
- Support compliance with applicable regulatory obligations
- Reduce the likelihood and impact of data breaches
- Establish consistent encryption practices across all technology platforms
- Define governance and accountability for cryptographic controls
Scope
Technology environments
- Cloud infrastructure and hosted services
- Corporate networks and infrastructure
- Endpoints and mobile devices
- Applications and databases
- Development and testing environments
- Backup and disaster recovery systems
Information assets
- Personal and sensitive healthcare information
- Customer and partner data
- Corporate confidential information
- Authentication credentials and secrets
- Intellectual property
Encryption principles and regulatory alignment
- Protection of sensitive data: encrypted when stored, transmitted, or processed in environments with elevated risk
- Secure by default: systems handling sensitive data implement encryption controls by default unless formally approved otherwise through the risk management process
- Centralised key management: cryptographic keys are managed using approved enterprise key management solutions
- Least privilege access: access to encryption keys and cryptographic services is restricted to authorised personnel with a legitimate operational requirement
This policy supports compliance with the Australian Privacy Act 1988, the Notifiable Data Breaches (NDB) Scheme, the ACSC Essential Eight, and ISO/IEC 27001 Information Security Management. Where MedTalk operates across multiple jurisdictions, additional regulatory obligations may apply.
Encryption in transit and at rest
Data in transit
Sensitive data transmitted across external or untrusted networks, including web communications, API communications, remote administrative access and system integrations, is encrypted using secure communication protocols such as Transport Layer Security (TLS). Unencrypted protocols such as Telnet or standard FTP are not used in production environments.
Data at rest
Sensitive information stored across databases, file systems, backup repositories, cloud storage environments and portable storage devices is protected using encryption technologies appropriate to the platform, alongside access control, monitoring and logging.
Endpoints, mobile devices and removable media
All corporate laptops and mobile devices implement full-disk encryption. Devices that do not support encryption must not be used to store or access sensitive MedTalk data, and lost or stolen devices are reported immediately and may be remotely disabled or wiped where supported.
Use of removable storage devices to store sensitive information is avoided wherever possible. Where business requirements necessitate their use, hardware encryption and access controls must be applied, and the device must be approved by IT security.
Backups and key management
Backup data containing sensitive information is encrypted to prevent unauthorised access, with encryption keys stored separately from the backup data itself and protected by secure access controls and monitoring. MedTalk uses AWS-native backup and Key Management Service (KMS) platforms to enforce enterprise-grade encryption for all data at rest, with cryptographic keys used for backup protection stored and managed in a logically separate environment from the source data.
- Cryptographic keys are generated using secure methods and stored within approved key management systems
- Access to keys is restricted to authorised personnel
- Key rotation occurs at defined intervals or when risk conditions change
- Keys are revoked or replaced if compromise is suspected
Cryptographic standards
MedTalk maintains approved cryptographic standards aligned with recognised best practice, including the Advanced Encryption Standard (AES) for symmetric encryption, RSA or elliptic-curve cryptography for asymmetric encryption, and secure hashing algorithms for integrity verification. Deprecated or insecure cryptographic algorithms are not used.
Secrets management and third parties
Application secrets and credentials are stored within approved secrets management platforms rather than embedded in application code, with access tokens protected and rotated where appropriate, and development teams using approved security libraries and frameworks.
Where third-party vendors or cloud service providers process MedTalk information, they must demonstrate encryption of data in transit and at rest, secure key management practices, and appropriate independent security certifications, reviewed as part of MedTalk's vendor risk management process.
Monitoring, exceptions and review
Encryption controls are monitored through verification of encryption configurations, certificate lifecycle management, key management activity monitoring, vulnerability assessments and penetration testing. Non-compliant systems are remediated in accordance with MedTalk's risk management processes.
Any deviation from this policy must be formally documented with business justification, a risk assessment and compensating controls, and approved by the Chief Information Security Officer. This policy is reviewed at least annually, following significant technology or regulatory changes, and after major security incidents.
Contact
Security & Compliance: support@medtalk.co
Legal / compliance: legal@medtalk.co