On this page
Key points
- Miraa is built for Australian healthcare workflows and treats health information as sensitive information under the Privacy Act 1988 (Cth).
- Patient records, audio, transcripts, drafts, and workflow outputs are processed to provide clinician-reviewed documentation and related clinic workflow features.
- Miraa does not sell clinic or patient data, and does not use identifiable patient health information to train AI models of its own or supply it to anyone else for that purpose.
- Privacy questions and access, correction, or complaint requests can be sent to privacy@miraahealth.com.
Scope and who this policy applies to
This Privacy Policy applies to Miraa, the clinical workflow platform used by healthcare organisations, clinicians, administrators, and authorised staff. It covers the Miraa web app, the Miraa iOS and desktop applications, the Miraa marketing website, related support channels, authentication flows, billing workflows, and connected features that process clinic or patient information.
Clinics remain responsible for the patient relationship and for deciding what information is entered into Miraa. Miraa provides hosted software and related processing services for the clinic and its authorised users.
Information Miraa collects
Miraa collects account and workspace information such as name, email address, authentication details, clinic name, role, subscription status, billing metadata, user preferences, support requests, referral metadata, and product activity.
Miraa processes clinical workflow information entered, uploaded, dictated, generated, or approved inside the product. This may include patient names, contact details, identifiers, consent status, appointment details, consultation audio, transcripts, notes, summaries, prescriptions, referral drafts, task lists, billing-related context, audit events, and generated documents.
Miraa also collects technical information needed to operate and secure the service, including device and browser details, IP address, log events, session metadata, usage limits, error reports, rate-limit events, and security audit records.
Miraa records which version of each legal document a user accepted, and when. That record is kept for the life of the account and is used to establish the terms that apply to that user.
Health information and sensitive information
Health information is sensitive information under Australian privacy law. Miraa handles patient health information only for clinic-authorised workflow purposes, such as transcription, note drafting, verification, closeout material, follow-up task generation, document preparation, auditability, and support requested by the clinic.
Clinics must ensure they have the consent, notice, lawful authority, and internal policy basis required to record, transcribe, upload, store, or otherwise process patient information through Miraa. Where a patient declines recording or transcription, the clinic must use an alternative workflow.
How Miraa uses information
Miraa uses information to authenticate users, manage clinic workspaces, provide transcription and AI-assisted drafting, display patient and consultation context, generate workflow outputs, support review and approval, maintain audit trails, process subscriptions, respond to support requests, improve reliability, prevent misuse, and comply with legal obligations.
Miraa may use de-identified, aggregated, or operational data to understand service performance, improve product quality, monitor safety, and prioritise development.
Miraa does not use identifiable patient health information to train models of its own, and does not supply it to anyone else for model training. Miraa's primary AI and transcription path, Amazon Bedrock and Amazon Transcribe in Sydney, runs under an executed AWS Business Associate Addendum on an account configured for zero data retention, so content sent on that path is not retained by AWS or passed to a model provider. Some optional features, such as the AI receptionist, use providers that are not yet under equivalent retention and training terms; those providers are named in the Subprocessor List, and Miraa offers no clinic opt-in that would permit training on identifiable patient health information.
AI and transcription processing
Miraa uses AI and transcription services to convert audio into text, structure consultation content, draft notes and documents, flag possible gaps, and support clinician review. AI output is assistive only and must be checked by a qualified human before it is filed, exported, prescribed from, sent, or otherwise relied on.
Prompts, transcripts, clinical context, and generated outputs are sent to the AI and transcription subprocessors listed in the Subprocessor List when required to provide a feature. Miraa limits those transfers to the data needed for the requested workflow and applies contractual, technical, and operational controls appropriate to the sensitivity of the data.
Miraa's AI and transcription processing runs in Amazon Web Services' Sydney region (ap-southeast-2) under zero-data-retention settings, meaning the provider does not retain request or response content. Consultation transcription has no overseas fallback: if the Australian service cannot complete a job, the consultation is not transcribed and Miraa tells the clinician so, rather than sending the audio somewhere else.
The live transcript shown on screen while a consultation is recording is produced by a speech model that runs on the clinician's own device. Where that model cannot run, Miraa falls back to the speech recognition built into the browser or the device. On Chrome and Edge it starts only after the browser confirms it can recognise speech on the device. On an iPhone or iPad it is Apple's speech recognition, which stays on the device where the device supports that and is otherwise processed on Apple's servers, and Miraa records which of the two produced each transcript. In Safari it is also Apple's speech recognition; Apple describes that as running on the device, but the browser gives Miraa no way to require or confirm it.
A small number of other paths can still process audio outside Australia, namely cloud dictation and the browser or device speech recognition described above. These are named under 'Disclosure and overseas processing' below, in the Subprocessor List, and in the Data Processing and Security Schedule.
Disclosure and overseas processing
Miraa discloses information to service providers and subprocessors that help host the app, authenticate users, store records, process transcription and AI workloads, manage billing, deliver email or support workflows, monitor reliability, and secure the service. Each of those providers is named in the Miraa Subprocessor List, together with what it receives and the country it processes that information in. The Subprocessor List is published at miraahealth.com/subprocessors and inside the product at app.miraahealth.com/legal/subprocessors, and both can be read without an account.
Miraa does not sell clinic or patient data. Miraa may disclose information if required by law, court order, regulator request, security investigation, professional safety escalation, merger or business transfer, or where the clinic has authorised the disclosure.
Miraa is built for Australian healthcare use. Clinic and patient records, stored consultation audio, and transcripts are held in Australia, and the application itself is hosted in Sydney. AI note generation and drafting run on Amazon Bedrock in Sydney (ap-southeast-2) through Australia-only inference profiles configured for zero data retention. Authoritative transcription of a recorded consultation runs on Amazon Transcribe in Sydney and has no overseas fallback. Clinical email to patients, next of kin, and other practitioners is delivered through Amazon SES in Sydney; there is no second provider and no overseas fallback, so if that transport is not configured for a deployment the send fails and the clinician is told, rather than the letter being routed another way.
Some information is still disclosed to recipients outside Australia. The countries in which those recipients are likely to be located are the United States and New Zealand. The United States applies to SMS sent through Twilio; to AI receptionist calls handled by ElevenLabs where a clinic enables Miraa Connect; to Miraa's own non-clinical system email, such as invitations and referral-programme messages, which is delivered by Resend; and to a clinician's own Gmail, Calendar, Contacts or Google Tasks where that clinician chooses to connect a Google Workspace account. New Zealand applies to secure clinical messaging through HealthLink, which operates across Australia and New Zealand. Two further recipients are not fixed to a single country: a clinician's own Outlook mailbox, calendar, contacts, Teams chat or Microsoft To Do list, where that clinician connects a Microsoft 365 account, is reached through Microsoft Graph and processed wherever that clinician's own Microsoft 365 tenant is configured; and where a clinic connects Miraa to its own practice-management or hospital record system, information travels to wherever that clinic or health service hosts that system.
Two audio paths can also leave Australia. Cloud dictation would send a short dictated clip to OpenAI in the United States; Miraa's clinical-data register records OpenAI as not approved to receive clinical data and the upload is refused before any audio leaves, and a clinic should ask Miraa to confirm that setting for its own deployment rather than assume it. Separately, the speech recognition built into a browser or a device, used for the live preview where Miraa's own on-device model cannot run, is processed by that browser or device vendor: on an iPhone or iPad that vendor is Apple, which processes the audio on its own servers where the device cannot recognise speech locally, and in Safari it is also Apple, on terms Miraa cannot confirm from the browser.
Where an overseas disclosure occurs, Miraa takes reasonable steps under Australian Privacy Principle 8 to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles. A clinic that requires an Australia-only configuration should raise it before rollout so the overseas paths can be disabled, avoided, or reflected in the notice given to patients. The full current list of every provider, what it receives, and the country it processes in is published at miraahealth.com/subprocessors; clinics should review it, the Data Processing and Security Schedule, and any order form before production use.
Security safeguards
Miraa uses access-controlled clinic workspaces, authenticated sessions, role-aware workflows, row-level database access controls, managed cloud infrastructure, storage policies, audit logs, rate limiting, and operational monitoring to protect information. Security controls are reviewed as the product changes and as new clinical workflows are introduced.
No internet-connected service is risk-free. Clinics must maintain their own safeguards, including secure devices, staff training, credential hygiene, user offboarding, local backups where required, and internal incident response procedures.
Suspected vulnerabilities can be reported to security@miraahealth.com.
Retention, deletion, and export
Miraa retains information for as long as needed to provide the service, maintain auditability, comply with legal obligations, resolve disputes, enforce agreements, and support clinic-configured retention settings. Clinical record retention obligations remain the responsibility of the clinic.
Authorised clinic users may request export, deletion, or de-identification of clinic data where supported by the product and the clinic agreement. Miraa may retain limited information where required for security, fraud prevention, accounting, backup integrity, dispute resolution, legal compliance, or audit purposes.
Records of which legal document version a user accepted are retained after account closure, because they evidence the agreement that governed the account.
Access, correction, and complaints
Users can request access to, or correction of, account information by contacting privacy@miraahealth.com. Patient requests about clinical records should usually be directed to the treating clinic, because the clinic controls the patient relationship and medical record decisions.
Privacy complaints can be sent to privacy@miraahealth.com. Miraa will acknowledge the complaint, assess the request, respond within a reasonable period, and work with the clinic where the request concerns clinic-controlled patient information.
If a complainant is not satisfied with Miraa's response, they may refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
Data breaches
If Miraa becomes aware of unauthorised access, unauthorised disclosure, or loss of personal information, Miraa will assess the incident and take reasonable containment and remediation steps. Where the incident is likely to result in serious harm and the Notifiable Data Breaches scheme applies, Miraa will support required notifications to affected individuals, clinics, and the Office of the Australian Information Commissioner.
Clinics must promptly notify Miraa if they suspect compromised credentials, unauthorised workspace access, incorrect disclosure, or any incident involving Miraa-managed data.
Changes to this policy
Miraa may update this Privacy Policy to reflect product, legal, operational, or security changes. Each version carries a version identifier and an effective date. Material changes will be communicated through the app, website, email, or another reasonable channel before or when they take effect, and continued use after the effective date may require accepting the updated version.
Miraa keeps a record of the version each user accepted, so the terms that applied at any point in time can be established.
Contact
Miraa Health Pty Ltd (ABN 50 700 599 408, ACN 700 599 408), 3 Broadway, Ultimo NSW 2007, Australia. Privacy enquiries: privacy@miraahealth.com. General support: support@miraahealth.com. Security reports: security@miraahealth.com.