On this page
Key points
- Miraa is built for Australian healthcare workflows and treats health information as sensitive information under the Privacy Act 1988 (Cth).
- Patient records, audio, transcripts, drafts, and workflow outputs are processed to provide clinician-reviewed documentation and related clinic workflow features.
- Miraa does not sell clinic or patient data, and never uses identifiable patient health information to train AI models.
- Privacy questions and access, correction, or complaint requests can be sent to privacy@miraahealth.com.
Scope and who this policy applies to
This Privacy Policy applies to Miraa, the clinical workflow platform used by healthcare organisations, clinicians, administrators, and authorised staff. It covers the Miraa web app, the Miraa iOS and desktop applications, the Miraa marketing website, related support channels, authentication flows, billing workflows, and connected features that process clinic or patient information.
Clinics remain responsible for the patient relationship and for deciding what information is entered into Miraa. Miraa provides hosted software and related processing services for the clinic and its authorised users.
Information Miraa collects
Miraa collects account and workspace information such as name, email address, authentication details, clinic name, role, subscription status, billing metadata, user preferences, support requests, referral metadata, and product activity.
Miraa processes clinical workflow information entered, uploaded, dictated, generated, or approved inside the product. This may include patient names, contact details, identifiers, consent status, appointment details, consultation audio, transcripts, notes, summaries, prescriptions, referral drafts, task lists, billing-related context, audit events, and generated documents.
Miraa also collects technical information needed to operate and secure the service, including device and browser details, IP address, log events, session metadata, usage limits, error reports, rate-limit events, and security audit records.
Miraa records which version of each legal document a user accepted, and when. That record is kept for the life of the account and is used to establish the terms that apply to that user.
Health information and sensitive information
Health information is sensitive information under Australian privacy law. Miraa handles patient health information only for clinic-authorised workflow purposes, such as transcription, note drafting, verification, closeout material, follow-up task generation, document preparation, auditability, and support requested by the clinic.
Clinics must ensure they have the consent, notice, lawful authority, and internal policy basis required to record, transcribe, upload, store, or otherwise process patient information through Miraa. Where a patient declines recording or transcription, the clinic must use an alternative workflow.
How Miraa uses information
Miraa uses information to authenticate users, manage clinic workspaces, provide transcription and AI-assisted drafting, display patient and consultation context, generate workflow outputs, support review and approval, maintain audit trails, process subscriptions, respond to support requests, improve reliability, prevent misuse, and comply with legal obligations.
Miraa may use de-identified, aggregated, or operational data to understand service performance, improve product quality, monitor safety, and prioritise development.
Miraa does not use identifiable patient health information to train AI models. This applies to Miraa's own models and to any third-party model provider, and it is not subject to a clinic opt-in.
AI and transcription processing
Miraa uses AI and transcription services to convert audio into text, structure consultation content, draft notes and documents, flag possible gaps, and support clinician review. AI output is assistive only and must be checked by a qualified human before it is filed, exported, prescribed from, sent, or otherwise relied on.
Prompts, transcripts, clinical context, and generated outputs are sent to the AI and transcription subprocessors listed in the Subprocessor List when required to provide a feature. Miraa limits those transfers to the data needed for the requested workflow and applies contractual, technical, and operational controls appropriate to the sensitivity of the data.
Miraa's primary AI and transcription processing runs in Amazon Web Services' Sydney region (ap-southeast-2) under zero-data-retention settings, meaning the provider does not retain request or response content. Some secondary paths still process audio outside Australia; these are identified in the Subprocessor List and in the Data Processing and Security Schedule.
Disclosure and overseas processing
Miraa discloses information to service providers and subprocessors that help host the app, authenticate users, store records, process transcription and AI workloads, manage billing, deliver email or support workflows, monitor reliability, and secure the service. The current providers are listed in the Subprocessor List.
Miraa does not sell clinic or patient data. Miraa may disclose information if required by law, court order, regulator request, security investigation, professional safety escalation, merger or business transfer, or where the clinic has authorised the disclosure.
Miraa is designed for Australian healthcare use. Primary clinical data storage, AI inference, and authoritative transcription are hosted in Australia. Some paths process information outside Australia, including outbound patient email, SMS, AI receptionist calls, the transcription fallback, and the browser's live speech preview. These are identified individually in the Subprocessor List so a clinic can assess them rather than having to assume. Where an overseas disclosure occurs, Miraa takes reasonable steps under Australian Privacy Principle 8 to ensure the recipient handles the information consistently with the Australian Privacy Principles. Clinics should review the Subprocessor List and any order form before production use.
Security safeguards
Miraa uses access-controlled clinic workspaces, authenticated sessions, role-aware workflows, row-level database access controls, managed cloud infrastructure, storage policies, audit logs, rate limiting, and operational monitoring to protect information. Security controls are reviewed as the product changes and as new clinical workflows are introduced.
No internet-connected service is risk-free. Clinics must maintain their own safeguards, including secure devices, staff training, credential hygiene, user offboarding, local backups where required, and internal incident response procedures.
Suspected vulnerabilities can be reported to security@miraahealth.com.
Retention, deletion, and export
Miraa retains information for as long as needed to provide the service, maintain auditability, comply with legal obligations, resolve disputes, enforce agreements, and support clinic-configured retention settings. Clinical record retention obligations remain the responsibility of the clinic.
Authorised clinic users may request export, deletion, or de-identification of clinic data where supported by the product and the clinic agreement. Miraa may retain limited information where required for security, fraud prevention, accounting, backup integrity, dispute resolution, legal compliance, or audit purposes.
Records of which legal document version a user accepted are retained after account closure, because they evidence the agreement that governed the account.
Access, correction, and complaints
Users can request access to, or correction of, account information by contacting privacy@miraahealth.com. Patient requests about clinical records should usually be directed to the treating clinic, because the clinic controls the patient relationship and medical record decisions.
Privacy complaints can be sent to privacy@miraahealth.com. Miraa will acknowledge the complaint, assess the request, respond within a reasonable period, and work with the clinic where the request concerns clinic-controlled patient information.
If a complainant is not satisfied with Miraa's response, they may refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
Data breaches
If Miraa becomes aware of unauthorised access, unauthorised disclosure, or loss of personal information, Miraa will assess the incident and take reasonable containment and remediation steps. Where the incident is likely to result in serious harm and the Notifiable Data Breaches scheme applies, Miraa will support required notifications to affected individuals, clinics, and the Office of the Australian Information Commissioner.
Clinics must promptly notify Miraa if they suspect compromised credentials, unauthorised workspace access, incorrect disclosure, or any incident involving Miraa-managed data.
Changes to this policy
Miraa may update this Privacy Policy to reflect product, legal, operational, or security changes. Each version carries a version identifier and an effective date. Material changes will be communicated through the app, website, email, or another reasonable channel before or when they take effect, and continued use after the effective date may require accepting the updated version.
Miraa keeps a record of the version each user accepted, so the terms that applied at any point in time can be established.
Contact
Miraa Health Pty Ltd (ABN 50 700 599 408, ACN 700 599 408), 3 Broadway, Ultimo NSW 2007, Australia. Privacy enquiries: privacy@miraahealth.com. General support: support@miraahealth.com. Security reports: security@miraahealth.com.