Privacy and security
Privacy and security for allied-health workflows that handle sensitive information every day
Opal is designed for Australian allied health organisations managing client, referral, intake, and appointment information. The product is structured to support privacy-aware operations, safer access boundaries, and clearer review steps.
We help teams reduce admin complexity while treating client information with the care it deserves.
Designed for Australian allied health organisations
Australian allied health providers handle sensitive personal and health information. Opal is designed to support privacy-conscious workflows for referrals, intake, bookings and team coordination.
Opal helps organisations manage client information responsibly by supporting structured data collection, secure access and clear operational workflows.
Important: Opal supports privacy-conscious operations, but each organisation remains responsible for meeting its own legal, professional and regulatory obligations.
What Opal supports
- Referral and intake information captured in structured workflows
- Reduced reliance on scattered emails, spreadsheets and paper forms
- Team-based access to relevant client and booking information
- Clearer visibility over referral progress and client communication
- Operational workflows designed around allied health administration
Your organisation remains responsible for
- Your own Privacy Policy and client consent processes
- How your team collects, uses and discloses health information
- Staff training and internal privacy procedures
- Professional and clinical record-keeping obligations
- Any legal advice specific to your organisation
Security measures
Opal is built with security and responsible information handling in mind. Here is what is available now and what we are working toward.
Secure access
User accounts are protected through authenticated access, helping ensure only authorised users can access the platform.
Role-based access
Admins, booking officers, therapists and viewers see only what their role permits. Therapists can access their own caseload via PIN-based login.
Audit logging
Sensitive actions — creates, updates, deletes, exports and restores — are recorded with user, timestamp and change summary.
Encrypted connections
The platform is accessed over secure HTTPS connections to protect information in transit.
Privacy & consent records
Consent records, access requests and retention schedules are managed within the privacy module.
Data breach register
A structured register tracks breach type, risk level, OAIC notification status and remediation.
Admin-controlled data exports
Import and export tools are permission-protected and logged. Exports may contain sensitive information.
Human review of AI suggestions
Scheduling suggestions are assistive. Every slot includes a fit rating and explanation, and users confirm each booking.
Test/demo mode separation
Test mode generates sample data clearly marked as test data, separate from live practice records.
Backups and recovery
Automated backup monitoring and documented recovery procedures.
Incident response process
A documented process for responding to suspected privacy or security incidents.
Multi-factor authentication
Additional verification for admin accounts.
How Opal's scheduling suggestions work
Opal's scheduling suggestions are designed to assist appointment coordination. Suggestions may consider availability, appointment type, location, therapist capacity and other operational criteria. Users should review suggestions before confirming bookings. Opal does not replace professional judgement.
What suggestions consider
- Therapist availability, working days and leave
- Client preferred days, times and location
- Therapist capacity and caseload pressure
- Appointment type, duration and frequency
- Funding-related notes (e.g. plan ending soon)
What Opal does not do
- Make clinical decisions about client care
- Automatically confirm bookings without human review
- Replace professional judgement or clinical assessment
- Claim to NDIS, Medicare or PRODA
- Access My Health Record or external clinical systems
Every suggested slot includes a fit rating and a "Why this?" explanation. Users review and confirm each booking — Opal does not auto-schedule.
Test & demo mode
Test mode is for exploring Opal without using real client data. It generates sample clients, therapists and appointments so you can try scheduling, allocation and reporting workflows before setting up your practice.
What test mode does
- Creates sample clients, therapists, schools and appointments
- Enables all scheduling and allocation features for exploration
- Clearly marks generated data so it can be removed
- Can be switched off from Settings, which clears all test data
What to keep in mind
- Do not enter real client information in demo or test workspaces
- Test data is separate from live practice data
- Test mode can be toggled by admins from Settings
- Clearing test data does not affect real client records
Test mode is clearly indicated in the app interface. When test mode is active, a banner reminds users that they are working with sample data.
Our privacy commitments
We believe allied health software should make privacy easier to manage, not harder. Opal is being built around practical privacy principles that support responsible handling of client information.
Collect only what is needed
Opal workflows should be designed to collect the information needed to support referral, intake, booking and coordination processes.
Do not sell client health information
Opal should not sell client personal or health information.
Support clear access controls
Organisations should be able to manage who can access client and referral information within their team.
Support transparent workflows
Opal should help teams see where referrals, bookings and client communications are up to, reducing the risk of information being lost across disconnected systems.
Respect Australian privacy expectations
Opal is designed with Australian allied health privacy expectations in mind, including the responsible handling of sensitive health information.
What we are working toward
As Opal scales, we are building toward stronger independent security assurance and recognised security practices.
Independent security review
We intend to undertake external security review and penetration testing as the platform matures.
Essential Eight alignment
We are working toward alignment with the Australian Cyber Security Centre's Essential Eight mitigation strategies where relevant to our platform and operations.
ISO 27001 readiness
We are building our internal policies, controls and processes with future ISO 27001 readiness in mind.
SOC 2 readiness
As Opal grows, we may pursue SOC 2 readiness to provide further assurance for larger organisations and enterprise customers.