Healthcare (regulated)
AZ Therapy Hub
Compliant patient data with integrated telehealth
A HIPAA-compliant clinical CRM with built-in telehealth, where every access to patient data is immutably logged and the workflow still suits a working clinician.
This example comes from the technical delivery experience behind AussieSync. It does not necessarily represent a project contracted directly through AussieSync.
Have a process like this one? Tell us about it.
01 Problem
Patient data must be kept under legal compliance without making the system unusable for the clinicians who depend on it.
- Every access to a patient record has to be attributable and provable afterwards.
- Consultation video could not route through a general-purpose meeting tool.
- Security controls bolted on afterwards get worked around by busy clinical staff.
- An audit demands evidence on request, not a reconstruction from server logs.
02 The solution
Role-based access control, encryption in transit and at rest, immutable audit logging and network isolation.
- Access is granted by clinical role, enforced at the data layer rather than in the UI.
- Patient data is encrypted at rest and in transit throughout.
- Every read and write appends to an immutable audit log, including reads.
- Telehealth video is encrypted and integrated, so consultations stay inside the system.
- Sensitive services sit on an isolated network segment.
03 Technical approach
Every choice earns its place.
- NestJSClinical API with access control at the service boundary.
- PostgreSQL (encrypted)Patient records encrypted at rest.
- RBAC & IAMRole-based access enforced below the UI.
- Immutable audit logAppend-only evidence of every access, for audit.
- AWSNetwork isolation and managed key handling.
04 Outcome
Legally-defensible handling of patient data, clinician-friendly workflows, and audit readiness.
- Defensiblelegally, in how patient data is handled
- Audit-readyevidence available on request, not reconstructed
- Clinician-friendlycontrols people do not route around