Privacy and security

Privacy and security for allied-health workflows that handle sensitive information every day

Opal is designed for Australian allied health organisations managing client, referral, intake, and appointment information. The product is structured to support privacy-aware operations, safer access boundaries, and clearer review steps.

Role-aware access
Audit-aware records
No clinical detail in reminders

We help teams reduce admin complexity while treating client information with the care it deserves.

Designed for Australian allied health organisations

Australian allied health providers handle sensitive personal and health information. Opal is designed to support privacy-conscious workflows for referrals, intake, bookings and team coordination.

Opal helps organisations manage client information responsibly by supporting structured data collection, secure access and clear operational workflows.

Important: Opal supports privacy-conscious operations, but each organisation remains responsible for meeting its own legal, professional and regulatory obligations.

What Opal supports

  • Referral and intake information captured in structured workflows
  • Reduced reliance on scattered emails, spreadsheets and paper forms
  • Team-based access to relevant client and booking information
  • Clearer visibility over referral progress and client communication
  • Operational workflows designed around allied health administration

Your organisation remains responsible for

  • Your own Privacy Policy and client consent processes
  • How your team collects, uses and discloses health information
  • Staff training and internal privacy procedures
  • Professional and clinical record-keeping obligations
  • Any legal advice specific to your organisation

Security measures

Opal is built with security and responsible information handling in mind. Here is what is available now and what we are working toward.

Available

Secure access

User accounts are protected through authenticated access, helping ensure only authorised users can access the platform.

Available

Role-based access

Admins, booking officers, therapists and viewers see only what their role permits. Therapists can access their own caseload via PIN-based login.

Available

Audit logging

Sensitive actions — creates, updates, deletes, exports and restores — are recorded with user, timestamp and change summary.

Available

Encrypted connections

The platform is accessed over secure HTTPS connections to protect information in transit.

Available

Privacy & consent records

Consent records, access requests and retention schedules are managed within the privacy module.

Available

Data breach register

A structured register tracks breach type, risk level, OAIC notification status and remediation.

Available

Admin-controlled data exports

Import and export tools are permission-protected and logged. Exports may contain sensitive information.

Available

Human review of AI suggestions

Scheduling suggestions are assistive. Every slot includes a fit rating and explanation, and users confirm each booking.

Available

Test/demo mode separation

Test mode generates sample data clearly marked as test data, separate from live practice records.

Planned

Backups and recovery

Automated backup monitoring and documented recovery procedures.

Planned

Incident response process

A documented process for responding to suspected privacy or security incidents.

Planned

Multi-factor authentication

Additional verification for admin accounts.

How Opal's scheduling suggestions work

Opal's scheduling suggestions are designed to assist appointment coordination. Suggestions may consider availability, appointment type, location, therapist capacity and other operational criteria. Users should review suggestions before confirming bookings. Opal does not replace professional judgement.

What suggestions consider

  • Therapist availability, working days and leave
  • Client preferred days, times and location
  • Therapist capacity and caseload pressure
  • Appointment type, duration and frequency
  • Funding-related notes (e.g. plan ending soon)

What Opal does not do

  • Make clinical decisions about client care
  • Automatically confirm bookings without human review
  • Replace professional judgement or clinical assessment
  • Claim to NDIS, Medicare or PRODA
  • Access My Health Record or external clinical systems

Every suggested slot includes a fit rating and a "Why this?" explanation. Users review and confirm each booking — Opal does not auto-schedule.

Test & demo mode

Test mode is for exploring Opal without using real client data. It generates sample clients, therapists and appointments so you can try scheduling, allocation and reporting workflows before setting up your practice.

What test mode does

  • Creates sample clients, therapists, schools and appointments
  • Enables all scheduling and allocation features for exploration
  • Clearly marks generated data so it can be removed
  • Can be switched off from Settings, which clears all test data

What to keep in mind

  • Do not enter real client information in demo or test workspaces
  • Test data is separate from live practice data
  • Test mode can be toggled by admins from Settings
  • Clearing test data does not affect real client records

Test mode is clearly indicated in the app interface. When test mode is active, a banner reminds users that they are working with sample data.

Our privacy commitments

We believe allied health software should make privacy easier to manage, not harder. Opal is being built around practical privacy principles that support responsible handling of client information.

Collect only what is needed

Opal workflows should be designed to collect the information needed to support referral, intake, booking and coordination processes.

Do not sell client health information

Opal should not sell client personal or health information.

Support clear access controls

Organisations should be able to manage who can access client and referral information within their team.

Support transparent workflows

Opal should help teams see where referrals, bookings and client communications are up to, reducing the risk of information being lost across disconnected systems.

Respect Australian privacy expectations

Opal is designed with Australian allied health privacy expectations in mind, including the responsible handling of sensitive health information.

What we are working toward

As Opal scales, we are building toward stronger independent security assurance and recognised security practices.

Independent security review

We intend to undertake external security review and penetration testing as the platform matures.

Essential Eight alignment

We are working toward alignment with the Australian Cyber Security Centre's Essential Eight mitigation strategies where relevant to our platform and operations.

ISO 27001 readiness

We are building our internal policies, controls and processes with future ISO 27001 readiness in mind.

SOC 2 readiness

As Opal grows, we may pursue SOC 2 readiness to provide further assurance for larger organisations and enterprise customers.

Frequently asked questions

Opal

Operational scheduling for Australian allied health teams who need clearer booking decisions, safer access boundaries, and audit-aware coordination.

Made by Blue Hair.

© 2026 Opal. Each organisation remains responsible for its own legal and professional obligations.