Security and data protection at HosPortal

HosPortal holds rosters, leave, contact details and timesheets for hospital medical teams, and no patient data. It runs on Amazon Web Services in Sydney, complies with the Australian Privacy Act and the Australian Privacy Principles, is independently penetration-tested every two years, and supports SAML single sign-on and multi-factor authentication. This page sets out how the platform is hosted, protected, accessed and audited, in the order hospital IT and procurement teams usually ask. For anything not covered, email su*****@*******al.com and we will complete your security questionnaire.

What HosPortal stores, and what it does not

HosPortal stores staff names, roles, skills and credentials, contact details, rosters, on-call and leave, shift swaps, timesheets and each department’s rostering rules. It does not store patient records, clinical notes or Medicare data, and it has no connection to a hospital’s clinical systems. Administrators choose whether staff can see each other’s mobile numbers and email addresses.

Hosting and data residency

All customer data is hosted on Amazon Web Services in the Sydney region (ap-southeast-2) and stays in Australia. New Zealand customers’ data is hosted in Sydney alongside Australian customers’. AWS’s Australian infrastructure is assessed under the Australian Government’s Information Security Registered Assessors Program (IRAP). HosPortal is fully managed: nothing is installed on hospital infrastructure, and the platform is operated to a 99.9% uptime target.

Encryption

Data is encrypted in transit using TLS and encrypted at rest on AWS. Passwords are stored as salted hashes and cannot be recovered by HosPortal staff; a password policy is enforced and can be tightened per site.

Backups and recovery

Data is backed up daily and backups are retained for 30 days. Backups are encrypted and held within AWS in Australia.

Access control and authentication

  • Single sign-on. SAML 2.0, including Microsoft Entra ID (Azure AD) and other SAML identity providers, so hospital IT controls who can sign in and can revoke access centrally.
  • Multi-factor authentication. Available to every user, and can be made mandatory for a whole site.
  • Role-based permissions. Each site defines who can view, edit, approve and publish. Staff see their own roster and what the department chooses to share; administrators see the department.
  • Contact-detail masking. Mobile numbers and email addresses can be hidden site-wide or shown only to administrators.
  • Native apps. The iOS and Android apps use the same sign-in, SSO and MFA as the web application.

Audit trail

Every roster, leave, swap and settings change is recorded against the user who made it, with a timestamp, and is visible to site administrators. Audit records are retained for the life of the site rather than purged on a schedule. Changes made through the AI assistant are recorded against the person who confirmed them, exactly as if they had made the change themselves.

Penetration testing and vulnerability management

HosPortal commissions an independent web application penetration test every two years. The most recent was carried out by Gridware in March 2026 against the Penetration Testing Execution Standard (PTES), the Open Source Security Testing Methodology (OSSTMM) and the OWASP Top 10; all findings were remediated and confirmed on retest in April 2026. The previous test was in 2024. A customer summary letter from the tester is available to customers and prospective customers on request. Application errors and performance are monitored continuously with Sentry and New Relic, and dependencies are patched as part of the regular release cycle.

Privacy and compliance

HosPortal complies with the Australian Privacy Act 1988 and the Australian Privacy Principles, and with the New Zealand Privacy Act 2020 for New Zealand customers. HosPortal does not currently hold ISO 27001 or SOC 2 certification; we say so plainly because hospital procurement teams ask, and we complete security questionnaires and provide the penetration test summary instead. Our privacy policy sets out how personal information is handled.

Sub-processors

HosPortal uses a small number of third-party services to run the platform. Each processes only the data needed for its function.

  • Amazon Web Services (Sydney): hosting, storage, backups and, through Amazon Bedrock, the AI assistant.
  • Twilio: SMS delivery for roster alerts and shift-cover messages.
  • Postmark: transactional email delivery.
  • Intercom: in-app support chat and the Help Centre.
  • Sentry and New Relic: application error and performance monitoring.

AI and your data

HosPortal’s AI assistant lets your team ask questions about the roster in plain language: who is on call, what leave is pending, where the gaps are. Four things are worth knowing.

  • It does not see patient information. The assistant works with rostering and workforce data only. HosPortal holds no patient records, so the assistant has no route to them.
  • It does not store your conversations. Questions go in, answers come out, nothing is kept.
  • It does not learn from your data. Your information is never used to train or improve any AI model.
  • Nothing happens without a person. The assistant can help with tasks, such as drafting a leave approval, but it never acts on its own. It shows what it proposes, a person confirms, and the change is logged against that person. The assistant cannot do anything the person using it could not already do themselves.

The assistant runs on Amazon Bedrock, a service from Amazon Web Services, the same provider that already hosts HosPortal. AWS licenses models from companies such as Anthropic and runs them inside AWS’s own infrastructure, so your data goes to AWS, which already holds your HosPortal data, rather than to a separate AI company: no new supplier to assess, data stays within AWS, and nothing is shared with the company that made the model. Bedrock operates with zero operator access (AWS staff cannot see model inputs or outputs) and zero data retention (inputs and outputs are not stored).

Two different kinds of AI are used in HosPortal. The roster builder is a mathematical optimiser that scores candidate rosters against your rules; it uses no language model and sends no data outside HosPortal’s own AWS environment. The assistant is the language-model feature described above, and it is optional.

Support and incident response

Support operates 0600 to midnight AEST with a response time under ten minutes and typical close-out within two hours. Security incidents affecting a customer’s data are reported to that customer’s administrators, and HosPortal meets its obligations under the Notifiable Data Breaches scheme.

Offboarding and data return

When a department leaves HosPortal, its data is exported for it on request and then deleted on the timeline the customer specifies; HosPortal does not impose a fixed retention period of its own after a contract ends.

Frequently asked questions

Where is HosPortal data hosted?

On Amazon Web Services in the Sydney region (ap-southeast-2). Data stays in Australia, including for New Zealand customers, and is encrypted in transit and at rest.

Does HosPortal store patient data?

No. HosPortal stores rosters, leave, contact details, timesheets and department rules for medical staff. It holds no patient records and has no connection to clinical systems.

Does HosPortal support single sign-on and multi-factor authentication?

Yes. SAML 2.0 single sign-on including Microsoft Entra ID, and multi-factor authentication for every user, which a site can make mandatory.

How often is HosPortal penetration tested?

Every two years by an independent firm. The most recent test was by Gridware in March 2026, with all findings remediated and confirmed on retest in April 2026. A customer summary is available on request.

Is HosPortal ISO 27001 or SOC 2 certified?

Not currently. HosPortal completes hospital security questionnaires and provides its independent penetration test summary instead, and complies with the Australian Privacy Act and the Australian Privacy Principles.

Does HosPortal’s AI use our data for training?

No. The AI assistant runs on Amazon Bedrock within AWS with zero data retention and zero operator access. Conversations are not stored and your data is never used to train any model.

How long are backups kept?

Backups are taken daily and retained for 30 days, encrypted, within AWS in Australia.

© 2026 HosPortal Pty Ltd. All rights reserved. | Website Design by Wolf IQ