On this page
Key points
- The clinic decides what patient information is entered into Miraa and remains responsible for clinical records and local compliance.
- Miraa processes clinic data to provide the product, secure the service, support users, and meet legal obligations.
- Security is shared: Miraa secures the platform, and clinics secure their people, devices, access decisions, and local workflows.
- This is a summary that forms part of the Terms of Service. Clinics needing a separately signed data processing agreement should contact legal@miraahealth.com.
Status of this Schedule
This Schedule describes Miraa's processing practices so a clinic can assess them without a negotiation. It forms part of the Terms of Service.
It does not replace a separately negotiated data processing agreement. Clinics that require an executed instrument, a security questionnaire response, or a procurement review should contact legal@miraahealth.com before production rollout so the required documents can be put in place.
Processing roles
For most workflows, the clinic is the responsible entity for patient information and determines the purpose for processing that information. Miraa acts as a hosted software provider and processor-style service provider, acting on the clinic's instructions as reflected in product use, configuration, and any written agreement.
Miraa acts as the responsible entity in its own right for account, billing, security, and product-operations data about clinic users.
Data handled by the service
Miraa may process account information, workspace information, patient demographics, consent status, appointment details, clinical notes, consultation audio, transcripts, AI prompts, generated drafts, approval state, tasks, prescriptions, referrals, billing context, audit logs, support data, and integration metadata.
Clinics should avoid entering information that is not needed for a legitimate clinical or administrative purpose.
Data movement and residency
Data may move between the browser or device, Miraa application servers, managed storage, authentication services, transcription providers, AI providers, billing providers, support tooling, and enabled integrations. Miraa limits transfers to what is needed to provide, secure, and support the requested feature.
Primary processing is Australian. Patient records, audio objects, and transcripts are stored in Australia; AI inference runs on Amazon Bedrock in ap-southeast-2 (Sydney) under an Australia-only inference configuration and zero data retention; authoritative transcription runs on Amazon Transcribe in ap-southeast-2.
Several paths process data outside Australia and a clinic should assess each one. Audio: the OpenAI Whisper transcription fallback, live telehealth audio chunks, cloud dictation clips, and the browser's built-in speech recognition used for the live preview, which on Chrome transmits audio to Google. Patient communication: outbound patient and next-of-kin email is delivered through Resend in the United States by default, SMS through Twilio, and AI receptionist calls through ElevenLabs. An Australian email path using Amazon SES in ap-southeast-2 is implemented and can be enabled per deployment, but it is not the default and should be confirmed rather than assumed.
Clinics that require an Australia-only configuration should raise this before rollout so the offshore paths can be disabled, avoided, or reflected in patient notice.
Where an overseas disclosure occurs, Miraa takes reasonable steps under Australian Privacy Principle 8 to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles.
Security controls
Miraa uses access-controlled workspaces, authentication with optional multi-factor enforcement, row-level database access controls, storage access policies, audit logs, API controls, rate limiting, managed infrastructure controls, and monitoring designed for sensitive clinical workflows.
Miraa reviews security risks when adding high-sensitivity features such as audio capture, transcription, note generation, prescriptions, referrals, evidence queries, exports, and integrations.
Subprocessor governance
The current subprocessors are listed in the Subprocessor List. Miraa imposes contractual data-protection obligations on subprocessors that handle clinic or patient information.
Miraa will give reasonable notice of a new subprocessor that will process clinical content, through the product, the website, or email.
Clinic responsibilities
Clinics must manage user access, promptly remove departing staff, maintain secure devices and networks, train staff on consent and recording workflows, verify AI outputs, retain final records according to professional obligations, and maintain internal incident response procedures.
Clinics should document their local operating procedure for when recording is allowed, how patient consent is captured, how generated notes are reviewed, and when a clinician must revert to manual documentation.
Incident response
Miraa will assess suspected security incidents affecting Miraa-managed data, take containment steps, investigate impact, and support legally required notifications, including under the Notifiable Data Breaches scheme. The clinic must promptly report suspected unauthorised workspace access, compromised credentials, incorrect disclosure, or patient data handling issues to security@miraahealth.com.
Where a suspected incident involves both Miraa systems and clinic systems, the parties should cooperate in good faith while limiting unnecessary disclosure of patient information.