Handing a vendor your patients' consults is one of the more consequential decisions a practice makes, and it deserves more than a glance at a security page. The good news is that the questions that separate a serious vendor from a risky one are not technical, they are direct, and a vendor who cannot answer them plainly is telling you something.
Start from what you are handing over
A health AI vendor receives some of the most sensitive information a person has: the content of clinical consultations. Under the Australian Privacy Principles this is health information, at the sensitive end of the scale, and the obligations that attach to it are yours as much as the vendor's. So the evaluation starts by being clear about what is being shared, where it goes, and who can reach it, because everything else follows from that.
The aim of the questions below is not to become a security auditor. It is to establish whether the vendor has thought seriously about protecting the data, and whether their answers are specific and verifiable rather than reassuring and vague.
Encryption and data residency
Ask whether the data is encrypted in transit and at rest, and where it is physically stored and processed. For Australian health information, whether the data stays in Australia is a material question, both for the obligations that apply and for who can compel access to it. A vendor should be able to answer where the audio and the clinical text live without hedging.
Vague answers here are a signal. Encryption is table stakes, and a vendor who cannot state plainly where your patients' data is processed and stored has either not thought about it or does not want to say. Either is a reason to press.
Access, retention and deletion
Ask who can access the data inside the vendor, under what controls, and whether that access is logged. Ask how long the audio and the derived documents are retained, and what happens when you leave: can you get your data out, and is it actually deleted. A vendor that keeps audio indefinitely, or cannot describe its deletion process, is holding a risk on your behalf that you may not want.
Ask, too, whether your patients' content is ever used to train a general-purpose model. This is one of the sharpest questions, because the answer reveals how the vendor thinks about your data: as something to protect, or as something to mine. A clear no, in writing, is what you are looking for.
- Is the data encrypted in transit and at rest, and where is it stored and processed?
- Who can access it internally, under what controls, and is that access logged?
- How long are audio and documents retained, and how are they deleted?
- Can I export my data and have it deleted when I leave?
- Is my patients' content ever used to train a general-purpose model?
Independent assurance
Claims are easy; independent verification is harder to fake. Ask whether the vendor holds any independent security certification or has undergone external assessment, and what it actually covers. A recognised standard, or a certification that verifies on an issuer's registry, is worth more than a self-declared posture, because a third party has looked. It does not guarantee perfection, but it shows the vendor was willing to be examined.
Read what the certification covers rather than the badge alone. A certification scoped to a small part of the business tells you less than one that covers the service you are actually using.
Reading the answers
The pattern to watch for across all of this is specificity. A serious vendor answers these questions with concrete facts: this is where the data lives, this is who can reach it, this is how long we keep it, this is the assurance we hold. A weaker vendor answers with adjectives: enterprise-grade, bank-level, industry-leading. Adjectives are not answers, and the gap between the two is usually the whole story.
None of this requires you to be a security expert. It requires you to ask direct questions and to notice whether the replies are specific and verifiable. That alone will separate the vendors worth trusting from the ones worth avoiding.
How aurii answers these
This section is about our product. Everything above is not.
aurii is built so these questions have plain answers. Consults are captured, transcribed and stored in Australia, encrypted record by record, with access logged in a tamper-evident audit. Black Shard, behind aurii, holds SMB1001:2026 Gold certification, which verifies independently on the CyberCert registry. The detail sits on the security and compliance pages so you can check it rather than take it on faith.
The point of this guide is not to sell you aurii, it is to arm you to interrogate any vendor, including us. Ask the hard questions, expect specific answers, and treat vagueness as the answer it is.
Common questions
Where the data lives and who can reach it. Almost everything else follows from a clear answer to that, and a vendor who cannot answer it plainly is telling you something.
No, but an independent certification means a third party examined the vendor, which is worth more than a self-declared posture. Read what the certification actually covers, not just the badge.
Because the answer reveals how a vendor treats your data. Whether your patients' content is ever used to train a general-purpose model is a sharp, telling question, and a clear no in writing is what you want.
This is general information to help you evaluate vendors, not legal or security advice. More guides sit on the resources hub. If your practice needs a question answered before it adopts AI documentation, tell us and we will write it: hello@aurii.com.au.