Security & Trust

Built for the demands of hospital pharmacy

Capsl is designed with security, privacy, and data sovereignty at its core — because the data we handle matters.

🔐

Encrypted at rest & in transit

All patient data is encrypted at rest using ALE encryption. All data in transit is protected by TLS.

🇦🇺

Australian data residency

All data is stored exclusively in Microsoft Azure Australian data centres. Your data never leaves Australia.

🛡️

Identity & access management

Authentication is managed via Okta with multi-factor authentication enforced for all users.

📋

Audit logging

All access to patient records and dispense actions is logged with a full, tamper-evident audit trail.

🇦🇺

100% Australian data residency

Capsl runs entirely on Microsoft Azure in Australian data centres (Australia East — Sydney, with Australia Southeast — Melbourne as the disaster recovery region). Patient data is never stored or processed offshore.

What data Capsl stores

Capsl stores the minimum patient information required to support prescription tracking and ward stock delivery workflows. At minimum, only patient initials, Medical Record Number (MRN), and admission and discharge dates are stored. Extended patient demographics are optional and only retained where explicitly enabled by the client organisation.

Capsl does not store clinical notes, diagnoses, or My Health Record data. Medication name, form and quantity are stored as part of prescription tracking records. Capsl operates as a data processor on behalf of your organisation, which retains data controller responsibility.


Who can access your data

Access to Capsl is controlled through Okta identity management with multi-factor authentication enforced for all users. Role-based access controls ensure staff only see the data relevant to their role.


Audit logging & data retention

Every access to patient records and every dispense or delivery action is recorded in a tamper-evident audit log, retained for seven years in line with Australian health records legislation.


Privacy Act compliance

Capsl operates in compliance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). As a data processor, Capsl handles patient information only for the purposes of delivering the contracted service.


Your data, always

If you end your Capsl subscription, your data remains yours. We provide a 30-day window to export all patient and operational data in a standard format, followed by secure deletion of all data from our systems. Written confirmation of deletion is available on request.

Security questions?

We're happy to discuss our security posture, provide documentation, or answer questions from your IT security team.

Get in touch