How We Protect And Secure Your Health Data
Our security policy for the management of your personal client information
We are always conscious of the trust our clients place in us to protect their privacy and secure their personal information. As such, we’ve developed and refined our security practices and processes to help our clients understand and appreciate the steps we take to ensure all interactions with our practice remain private and confidential.
Our platforms
Practice Management System - Halaxy
At Karepsych, we use Halaxy (formely HealthKit) as our main patient administration system. This cloud based platform is where we store all client personal details, client files and session notes encompassing ongoing treatment.
Halaxy is recognised as one of the health industry’s leading global platforms and supports over 30,000 practitioners worldwide.
Beginning from a small office in Melbourne, Halaxy has grown to support thousands of practitioners and patients across more than 130 countries wanting to run better practices and improve health outcomes. Our mission remains the same today as it was when we began that first day in 2012 – to improve the standard of healthcare for all.
To ensure the privacy of our client records, Karepsych have implemented the following security controls within the Halaxy platform:
- All psychologists have their own unique Halaxy username and complex password.
- All Karepsych psychologist accounts are protected by 2 factor authentication (also commonly referred to as multi-factor authentication)
- Only psychologists can view client session notes. Front office staff are restricted to calendar bookings and financial management functions only.
- Psychologists (with the exception of our principle psychologist Kathy Matheson) are restricted to viewing their own session notes for clients they treat.
- All staff access to the Halaxy platform is protected by bank grade encryption.
- Access audits and reviews are conducted on a regular basis.
Video Consultation Platform - Coviu
Office Support Platform - Office365
As a predominantly location independent business, Karepsych leverages the Office365 platform allowing both security and mobility for our staff.
Of the complete package, Karepsych only use the Outlook and OneDrive components. Outlook for email communication with clients and external parties and OneDrive for document storage. The following security controls have been put in place to protect client information:
- All accounts have complex passwords
- Knowing clients often email psychologists directly, these accounts have been kept private. Front office staff do not have delegation access to these accounts.
- Psychologist accounts are further secured by two factor authentication
- OneDrive is only used for administrative document storage. Session notes are not stored in OneDrive.
Internal Messaging Platform - Slack
Karepsych uses the Slack communication platform for internal messaging between staff members. No personally identifiable information is passed using these channels, rather the system is used as a notification pathway for appointment cancellation or rescheduling operations.
Only active Karepsych employees have access to our Slack workspace.
Direct Marketing Platform - Mailchimp
Karepsych uses the Mailchimp direct marketing platform to send practice updates to our clientele. In doing so we store your email address and first name within the Mailchimp system.
Our Mailchimp account is protected by administrative and access controls, only allowing senior and approved staff members access.
In all instances where we send emails from Mailchimp, we will offer a means to remove yourself from the mail list.
We do not on-sell nor provide third party interests access to our client mailling list.