MedTalk AI Logo
GOVERNANCE

Information security policy

The overarching governance framework for protecting MedTalk AI's information assets and technology systems.

Purpose

This policy establishes the overarching framework for protecting MedTalk AI's information assets and technology systems. MedTalk AI processes sensitive healthcare and personal information as part of its services, and effective information security controls are essential to ensure the confidentiality, integrity and availability of information, protect customers and patients, and maintain trust in MedTalk AI's services.
  • Protect sensitive information from unauthorised access, alteration or disclosure
  • Maintain the availability and reliability of business systems and services
  • Support compliance with applicable legal, regulatory and contractual obligations
  • Manage cyber security risks through appropriate controls and governance
  • Ensure security considerations are integrated into system design and operations
  • Promote a culture of security awareness across the organisation

Scope

Systems and technology

  • Cloud infrastructure and hosted services
  • Corporate networks and IT systems
  • Applications and databases
  • Endpoints and mobile devices
  • Development and testing environments
  • Backup and disaster recovery platforms

Information assets

  • Personal and healthcare-related information
  • Customer and partner data
  • Corporate confidential information
  • Credentials and authentication systems
  • Intellectual property

Governance, accountability and regulatory alignment

Executive leadership is responsible for ensuring appropriate resources and governance structures exist to manage information security risk, with performance reported through executive risk committees or security governance groups.
  • Chief Information Security Officer: owns the information security framework, develops and maintains security policies and standards, oversees security risk management, coordinates incident response, and reports on security monitoring.
  • Business and technology leaders: ensure security controls are implemented within their systems and processes, risks are identified and managed, and staff comply with security policies.
MedTalk AI's information security program aligns with the Australian Privacy Act 1988, the Notifiable Data Breaches (NDB) Scheme, the ACSC Essential Eight, and ISO/IEC 27001 Information Security Management. Where MedTalk AI operates internationally, additional regulatory obligations may apply.

Information security principles

  • Defence in depth: multiple layers of security controls across systems, networks and applications reduce the likelihood of successful cyber attacks
  • Least privilege: users are granted access only to the systems and information necessary to perform their authorised duties
  • Secure by design: security controls are incorporated into the design, development and deployment of systems and services
  • Risk-based security: security decisions are guided by formal risk assessments and aligned to business priorities

Access control

Access to MedTalk AI systems and information is controlled through formal identity and access management processes, with privileged system access tightly controlled and monitored.
  • Unique user accounts for all personnel
  • Role-based access control
  • Use of multi-factor authentication where appropriate
  • Periodic review of user access rights
  • Immediate revocation of access when employment or contractual relationships end

Data protection

Sensitive information is protected throughout its lifecycle, from classification through to secure storage, transmission and disposal.
  • Classification of information according to sensitivity
  • Secure storage and transmission of sensitive data
  • Encryption of sensitive information where appropriate
  • Secure handling of personal and healthcare-related data
  • Protection against unauthorised disclosure or data loss

Secure system management

Technology systems are securely configured and maintained. Systems that process sensitive information undergo appropriate security review prior to deployment.
  • Regular patching and vulnerability management
  • Secure configuration of systems and applications
  • Monitoring for suspicious activity
  • Endpoint protection controls
  • Logging and audit capabilities for critical systems

Incident management and third-party risk

MedTalk AI maintains an incident response capability to manage cyber security incidents, including unauthorised system access, malware or ransomware attacks, data breaches, and malicious service disruption. All personnel must report suspected security incidents promptly; incident response activities are managed under MedTalk AI's Incident Response Policy, and where incidents involve personal information, breach assessment and notification obligations are managed in accordance with regulatory requirements.
Vendors with access to MedTalk AI systems or information must meet defined security requirements, including security due diligence assessments, contractual security obligations, data protection requirements, and monitoring of vendor security posture. Third-party incidents affecting MedTalk AI information must be reported promptly.

Security awareness, compliance and review

MedTalk AI maintains a security awareness program covering cyber security awareness, privacy obligations, phishing and social engineering risks, and secure data handling practices, delivered at onboarding and periodically thereafter.
Compliance with this policy is mandatory. MedTalk AI may monitor systems and conduct security reviews to verify adherence, and non-compliance may result in disciplinary action, termination of contracts, or other appropriate measures. Exceptions must be formally documented with business justification, a risk assessment and compensating controls, and approved by the Chief Information Security Officer.
This policy is reviewed at least annually, following significant regulatory changes, after major security incidents, and when substantial changes occur to MedTalk AI's technology environments.

Contact

Security & Compliance: support@medtalk.co

Legal / compliance: legal@medtalk.co

Get Started

Streamline your clinical notes with MedTalk AI

Intelligent medical scribe

Get A Free Trial