Security at Doccy

Your health information, handled with the same care as a clinic visit.

Doccy is built by doctors and engineers who treat your privacy as part of clinical care. Your records are encrypted, access is limited to people involved in your care, and we do not sell your health information.

Compliance & standards

The regulation and clinical governance that apply to your care today, as an Australian telehealth provider.

Australian Privacy Act 1988

Applies today

As an Australian telehealth provider we operate under the Privacy Act and the Australian Privacy Principles (APPs) governing how health information is handled.

AHPRA clinical governance

Applies today

All consults are delivered by doctors registered with the Australian Health Practitioner Regulation Agency, under the same credentialing standards used across the Medlo network.

Security FAQ

Is my health data safe with Doccy?

Yes. As an Australian telehealth provider, Doccy operates under the Privacy Act 1988 and the Australian Privacy Principles (APPs).

For you, that means:

  • Your information is encrypted when sent and when stored
  • Only authorised clinicians and support staff involved in your care can access your records — not other patients, and not advertisers
  • We collect only what we need to provide safe care
  • We do not sell your health data to third parties

Your information should feel as confidential here as it would at a traditional clinic.

How does Doccy handle my payment details?

Card payments are processed by Stripe, which meets PCI DSS Level 1 — the highest standard for payment security.

Your full card number goes directly to Stripe and is never seen or stored by Doccy.

Who can see my medical records?

Your medical records are tied to your account — another patient cannot view your information.

Access is limited to the doctors and authorised staff delivering your care, and we maintain records of who accesses patient information.

Is Doccy SOC 2 or ISO 27001 certified?

We are actively pursuing SOC 2 Type II and aligning our information security practices to ISO 27001, supported by continuous compliance monitoring.

Today we already operate under Australian healthcare regulation — the Privacy Act 1988 and AHPRA clinical governance — and follow SOC 2-aligned controls across our stack.

How do I report a security vulnerability?

Please contact our team by email with clear steps to reproduce and the potential impact.

Please don't access, modify, or delete other users' data while researching, and give us reasonable time to remediate before any public disclosure. We acknowledge reports promptly and keep you updated throughout.

Does Doccy sell or share my data with advertisers?

No. We do not sell your health data, and we do not share it with advertisers.

We use a small number of trusted service providers to run Doccy — for example, payment processing and email — only for what's needed to deliver the service, and under strict privacy terms.

Working towards

We are actively investing in the leading international security frameworks, building the controls and evidence each one requires. Certification is in progress and not yet complete, and alongside this work your care is already protected by the Australian regulation and clinical governance above.

SOC 2 Type II

Not certified yet

We are working toward SOC 2 Type II — an independent audit of how we protect data. This is in progress; we are not certified yet.

ISO/IEC 27001

Not certified yet

We are aligning our security practices with the ISO 27001 framework. This is in progress; we are not certified yet.

Responsible disclosure

Security researchers keep everyone safer. If you believe you've found a vulnerability, please report it privately so we can investigate and fix it before any details are made public. We commit to acknowledging reports promptly and keeping you updated.

  • Share clear steps to reproduce and the potential impact.
  • Do not access, modify, or delete other users' data.
  • Give us reasonable time to remediate before disclosing.