On this page
Key points
- The clinic decides what patient information is entered into Miraa and remains responsible for clinical records and local compliance.
- Miraa processes clinic data to provide the product, secure the service, support users, and meet legal obligations.
- Security is shared: Miraa secures the platform, and clinics secure their people, devices, access decisions, and local workflows.
- This is a summary that forms part of the Terms of Service. Clinics needing a separately signed data processing agreement should contact legal@miraahealth.com.
Status of this Schedule
This Schedule describes Miraa's processing practices so a clinic can assess them without a negotiation. It forms part of the Terms of Service.
It does not replace a separately negotiated data processing agreement. Clinics that require an executed instrument, a security questionnaire response, or a procurement review should contact legal@miraahealth.com before production rollout so the required documents can be put in place.
Processing roles
For most workflows, the clinic is the responsible entity for patient information and determines the purpose for processing that information. Miraa acts as a hosted software provider and processor-style service provider, acting on the clinic's instructions as reflected in product use, configuration, and any written agreement.
Miraa acts as the responsible entity in its own right for account, billing, security, and product-operations data about clinic users.
Data handled by the service
Miraa may process account information, workspace information, patient demographics, consent status, appointment details, clinical notes, consultation audio, transcripts, AI prompts, generated drafts, approval state, tasks, prescriptions, referrals, billing context, audit logs, support data, and integration metadata.
Clinics should avoid entering information that is not needed for a legitimate clinical or administrative purpose.
Data movement and residency
Data may move between the browser or device, Miraa application servers, managed storage, authentication services, transcription providers, AI providers, billing providers, support tooling, and enabled integrations. Miraa limits transfers to what is needed to provide, secure, and support the requested feature.
Primary processing is Australian. Patient records, audio objects, and transcripts are stored in Australia; AI inference runs on Amazon Bedrock in ap-southeast-2 (Sydney) under an Australia-only inference configuration and zero data retention; and the server transcription batch runs on Amazon Transcribe in ap-southeast-2. That batch is not the transcript of record for every consult. Where the live in-consult transcript is usable, Miraa keeps it as the record and does not run the batch at all, so no consultation audio is sent to Amazon Transcribe for that consult. On most browsers the engine that produced it is Miraa's own model running in the browser, which sends the audio nowhere; the residency exception is Safari, described in the next paragraph.
Some paths still process data outside Australia and a clinic should assess each one. Audio: where Miraa's on-device dictation model is unavailable, the Ask Miraa composer microphone and the note-edit dictation island fall back to the browser's own speech recognition, which on Chrome and Edge sends the dictated audio to the browser vendor in the United States; cloud dictation clips are configured for a United States provider and are refused at Miraa's provider boundary, a refusal that is lifted only by a deliberate, reviewed compliance approval set in the deployment, so unless that approval has been made for your deployment no audio is sent on that path; and where Safari's built-in recognition supplies the in-consult transcript, Miraa can neither require nor observe whether Apple processes that audio on the device or on Apple's servers, so it records that transcript's residency as unknown rather than assuming it stayed local. Safari's recogniser is reached whenever Miraa's own in-browser model is unavailable, and the text it produces is then kept as the consult's transcript instead of the Amazon Transcribe batch, so it is the record the note is drafted from and not only a preview.
Three paths this Schedule previously listed as offshore audio legs no longer exist: the OpenAI transcription fallback for consultations, the live telehealth audio chunks, and the Chrome browser preview used as the live consult transcript were all removed from the product in August 2026. Patient communication: SMS is delivered through Twilio and AI receptionist calls through ElevenLabs, both in the United States, and a clinician who connects their own Google Workspace account discloses the connected mail, calendar, or contact data to Google. Clinical email to patients, next of kin, and referral recipients is delivered through Amazon SES in ap-southeast-2 (Sydney) and is no longer routed through a United States provider.
Clinics that require an Australia-only configuration should raise this before rollout so the offshore paths can be disabled, avoided, or reflected in patient notice.
Where an overseas disclosure occurs to a provider Miraa engages, Miraa takes reasonable steps under Australian Privacy Principle 8 to ensure that recipient handles the information consistently with the Australian Privacy Principles. The browser and Safari recognisers described above are not such providers: they are built into the clinician's own browser, Miraa has no agreement with either vendor and no way to observe what it does with the audio, so what Miraa can offer for those two paths is the disclosure and the avoidance described above rather than contractual assurance.
Security controls
Miraa uses access-controlled workspaces, authentication with optional multi-factor enforcement, row-level database access controls, storage access policies, audit logs, API controls, rate limiting, managed infrastructure controls, and monitoring designed for sensitive clinical workflows.
Miraa reviews security risks when adding high-sensitivity features such as audio capture, transcription, note generation, prescriptions, referrals, evidence queries, exports, and integrations.
Subprocessor governance
The current subprocessors are listed in the Subprocessor List. Miraa's position is that every subprocessor handling clinic or patient information should be under a data-protection agreement. That is executed for AI inference and for the server transcription batch, which run under Miraa's AWS Business Associate Addendum. For the other subprocessors the instrument is being put in place rather than already in place, and a clinic that needs the current status for a named provider before rollout should ask legal@miraahealth.com rather than assume it.
Miraa will give reasonable notice of a new subprocessor that will process clinical content, through the product, the website, or email.
Clinic responsibilities
Clinics must manage user access, promptly remove departing staff, maintain secure devices and networks, train staff on consent and recording workflows, verify AI outputs, retain final records according to professional obligations, and maintain internal incident response procedures.
Clinics should document their local operating procedure for when recording is allowed, how patient consent is captured, how generated notes are reviewed, and when a clinician must revert to manual documentation.
Incident response
Miraa will assess suspected security incidents affecting Miraa-managed data, take containment steps, investigate impact, and support legally required notifications, including under the Notifiable Data Breaches scheme. The clinic must promptly report suspected unauthorised workspace access, compromised credentials, incorrect disclosure, or patient data handling issues to security@miraahealth.com.
Where a suspected incident involves both Miraa systems and clinic systems, the parties should cooperate in good faith while limiting unnecessary disclosure of patient information.