Security

Security built around patient care.

Blue Merino works with sensitive patient and consultation information, so privacy and security are built into the way the platform processes, stores and controls access to that information.

Information stays within secure Australian infrastructure and is protected by encryption, access controls and multiple layers of security.

Follow your patient information

  1. Consultation
  2. Transcription in Sydney
  3. Patient background de-identified
  4. AI processing in AWS Bedrock in Sydney
  5. Completed documentation
  6. Practitioner review & Cliniko publishing

Encrypted in transit (TLS) and encrypted at rest (AES-256-GCM)

Consultation audio is transmitted over an encrypted connection, transcribed on Blue Merino’s own infrastructure in Sydney, and deleted automatically once the transcript has been produced unless the clinic has opted to retain it for up to seven days. AI note generation is performed through AWS Bedrock, also in Sydney. Audio is never used for advertising, profiling or AI-model training.

Australian by design

Blue Merino’s production environment operates within Australian infrastructure. Consultation transcription takes place on Blue Merino’s own infrastructure in Sydney, while AI note generation uses AWS Bedrock in Sydney.

  • All data storage and processing stays within Australia.
  • Patient and consultation information is not used to train AI models.
  • The AI provider does not retain consultation content for model training or ongoing processing retention under Blue Merino’s configured setup.
  • Patient records, clinical notes, consultation audio, transcripts, AI processing and patient-related email delivery remain within Australian infrastructure. A document emailed to a patient is never attached to the email itself — it is delivered through a private, date-of-birth-protected link.

Every clinic is isolated at the data layer

We use row-level security in the database to keep each clinic’s data completely separate.

Clinic content cannot be visible to any other clinic or service across the platform in Blue Merino’s environment.

Data access is scoped to the clinic and permissions control at the individual and role level.

Clinic A

Isolated database layer

Clinic B

Isolated database layer

Clinic C

Isolated database layer

Core technical safeguards

Encryption & sensitive credentials

Information is encrypted in transit using TLS and encrypted at rest using AES-256-GCM.

Cliniko API credentials are encrypted at rest and scoped to the relevant clinic or account.

Authentication & access control

Passwords are securely hashed and held to a strong minimum-length requirement.

Two-factor authentication and single-use backup codes are available for account protection. Access to sensitive features is restricted according to user role and permissions.

Auditability

Security-relevant actions are written to an append-only audit log that cannot be altered after the fact.

The log records who performed an action, what occurred, which record it related to and when. Audit logs are retained for seven years.

Defence in depth

Multiple layers of technical controls protect against common threats and reduce risk.

  • CSRF protection on state-changing requests
  • Rate limiting on authentication endpoints
  • Timing-safe comparison for sensitive secrets and tokens
  • Strict validation of external content
  • Session regeneration after two-factor authentication
  • Automated security tests designed to prevent controls quietly regressing

Retention & deletion

  • By default, consultation audio is deleted automatically once the transcript has been produced. A clinic owner can choose to retain it for up to seven days, so a consultation can be re-transcribed if something is wrong with the transcript. Audio is never used for advertising, profiling or AI-model training.
  • Transcripts and generated notes are retained separately as part of the clinical record while the clinic remains a Blue Merino customer.
  • Information can be deleted when it is no longer required, subject to applicable clinical and record-retention obligations.
  • If a Blue Merino subscription is cancelled, account data is retained for a 90-day recovery period before permanent deletion. During that period the clinic can sign back in to read and export its records.
  • Anything already published into Cliniko remains in Cliniko.
  • AI processing through AWS Bedrock in Sydney does not create a separate retained copy of consultation content with the AI provider under Blue Merino’s configured setup.

Australian privacy and record-keeping

Blue Merino is designed around Australia’s Privacy Act 1988 (Cth), the Australian Privacy Principles, and the privacy obligations relevant to health information.

We support your clinic’s responsibilities for the handling of health information and record-keeping under relevant Australian law.

Responsible disclosure

If you believe you’ve found a security vulnerability, please let us know privately so we can investigate and fix it before any details are made public.

Email security@bluemerino.com.au and give us a reasonable window to respond. We’ll work with you and acknowledge your help.

Have a security question?

We’re here to help. Talk to the Blue Merino team any time about our security, compliance or data protection.