Privacy at Tri-Care

Privacy Policy

Care starts with trust. Here is how information supports your clinical workspace, and how to get answers about your privacy.

Last updated:

01

Who this policy is for

Tri-Care helps healthcare teams capture consultations, review patient records, and coordinate care. This policy explains information handling across our website and doctor portal for visitors, healthcare professionals, and people whose information is entered into a workspace.

Your hospital or healthcare organisation manages your care records and decides how its workspace is used. Read this policy alongside your healthcare provider's privacy notice, which explains its purposes for processing, legal basis, recordkeeping obligations, and contact details.

02

Information handled by the portal

Account and workspace information includes work email addresses, hospital identifiers, account credentials, user roles, and organisation contact details used to provide access to the appropriate workspace.

Clinical information may include patient identifiers and contact details, medical history, symptoms, medications, consultation notes, uploaded reports, discharge summaries, and handover information supplied by authorised users.

When voice intake is used, the portal handles audio recordings, transcripts, selected or detected languages, and the clinical notes generated from that content. Activity records may include sign-ins, record actions, timestamps, resource identifiers, and processing outcomes used for audit and troubleshooting.

03

How information is used

Information is used to authenticate users, connect them to their hospital workspace, display patient histories, prepare clinical documentation, and support care coordination. It also supports session management, troubleshooting, and reviews of important account and clinical activity.

Healthcare professionals should enter only information relevant to their work and access records only when authorised. The healthcare organisation is responsible for identifying the applicable basis for processing patient information and providing any required notices or obtaining consent.

04

Voice recordings and AI-assisted documentation

Voice features require microphone permission in your browser. Recordings and submitted documents may be processed by the services configured for your workspace to produce transcripts, extract clinical details, and prepare draft notes. Clinicians should review generated content for accuracy before using it in a patient record or care decision.

Before recording, explain the purpose to the people involved and obtain any permission required by your organisation and applicable law. You can stop a recording or revoke microphone permission through your browser settings; revoking permission does not delete information already submitted.

Ask your healthcare organisation for the AI and transcription providers used in its deployment, their processing locations, retention terms, and whether any separate model-training use is permitted under its agreements. These details depend on the services configured for that workspace.

05

Access and sharing

Access within a workspace depends on account permissions and the healthcare organisation's configuration. Clinical information may be shared with authorised care teams through handovers, reports, exports, or connected record systems when those functions are used.

Operating the service may involve hosting, storage, support, and clinical processing providers. The specific recipients, any processing outside your country, and the safeguards that apply are governed by the organisation's deployment and service agreements. Contact your organisation for these details and for information about disclosures required by applicable law.

06

Cookies and browser storage

The portal uses session cookies and browser storage to support sign-in and session security. Local storage also remembers your theme preference and can temporarily queue audit events for delivery. Session storage can hold a session-expiry message.

You can manage cookies and clear stored site data in your browser. Blocking or removing storage may sign you out, reset preferences, or interfere with portal features. Clearing your browser does not remove patient records already stored by your healthcare organisation.

07

Security and retention

The portal includes workspace-scoped access, session controls, and audit logging to support accountable use. Protect your credentials, sign out on shared devices, and report suspected unauthorised access to your workspace administrator promptly. No online service can guarantee complete security.

Retention depends on the type of information, your organisation's clinical recordkeeping requirements, service agreements, and applicable law. Patient records, audio, transcripts, backups, and audit records may have different retention periods. Ask your organisation for its schedule and deletion process; closing an account does not necessarily erase records that must be retained.

08

Your choices and privacy requests

Depending on applicable law and the circumstances, you may be able to request access to your information, correction of inaccurate details, a copy of your records, deletion, or restrictions on particular uses. Where processing relies on consent, you may be able to withdraw it. Some requests may be limited by clinical recordkeeping requirements or other obligations.

Contact the hospital or healthcare provider responsible for your records to make a request. It may need to verify your identity and authority before responding. For a child's records, a parent, guardian, or other authorised representative should contact the care provider, subject to applicable rules.

09

Questions, concerns, and updates

For patient record questions or privacy concerns, contact your healthcare provider through its published contact details and ask for the privacy officer or records team. Workspace users can also contact their hospital administrator using the organisation contact information available in workspace settings. Avoid sending medical records or passwords through an unsecured message.

If a concern remains unresolved, you may be able to contact the relevant data protection authority in your jurisdiction. This policy may be updated as the portal evolves; the date at the top identifies the latest revision. Your healthcare organisation's notice remains the source for its specific data handling arrangements.