In safe hands

Your patients trust you with their information. Here's how we look after it.

Compliance

Protecting the trust you've earned

Every form holds something personal. Your patients share their details because they trust your practice. We make sure that trust is well placed.

wired-outline-457-shield-security-hover-pinch

Encrypted, sent and stored

Patient information is encrypted when it's sent and when it's stored, so no one who shouldn't see it can read it.

wired-outline-1189-kangaroo-hover-pinch

Stored in Australia

Patient answers and appointment details are stored in Sydney, on Amazon Web Services.

wired-outline-2536-no-bs-hover-pinch

Never sold, never used to train AI

Coviu never sells, commercialises, or uses your data to train AI, ever.

Certified, and independently audited

Coviu is ISO 27001 certified, the international standard for information security, and bound by the Privacy Act 1988 and the Australian Privacy Principles. The Privacy Act governs what we are allowed to do with your patients' information. ISO 27001 governs how well we protect it.

ISO 27001 Certified_col

Security and compliance FAQ's

Can your team see our patients’ information?

Our support team works with your settings and form templates, not patient answers. A small number of engineers can access the underlying systems to keep them running, under strict access controls that are independently audited as part of our ISO 27001 certification.

What happens to the information if we stop using Coviu?

Completed forms are already in back to your practice management system, so your records stay intact. For anything still held in Coviu, ask our team and we’ll export or delete it when you ask, and confirm in writing.

Which other companies handle our patients’ information?

Two providers. Amazon Web Services stores it in Sydney. Twilio sends the text message with the form link, and processes the patient’s mobile number and text message in the United States.

What if something goes wrong?

We'd act straight away to stop it and tell you directly. If patients or the privacy regulator need to be told, we'll work with you to make sure that happens, as the law requires.

Back to top

Need more detail?

We get it. Your patients' information is sensitive, and we're happy to talk through any questions you have.