Trust information for clinics, practices, and transcription teams.

Use this page to understand how HeliQore approaches security, privacy, data handling, and compliance-sensitive workflow design.

HIPAA

HeliQore is designed with HIPAA-aligned safeguards in mind for health-sensitive transcription workflows. In practice, that means focusing on access controls, secure transmission, private storage, audit-aware workflow design, least-privilege access, retention limits, and administrative and technical measures intended to reduce inappropriate access, use, or disclosure of protected health information.

HIPAA is a regulatory framework rather than a certification, so HeliQore describes this as safeguard alignment rather than claiming a formal HIPAA certification.

Read the HHS HIPAA Security Rule overview.

Australian Privacy Act

Privacy handling is designed with current Australian health privacy requirements in mind. For health information, that generally means collecting only what is reasonably necessary, usually with consent, limiting use and disclosure to the purpose it was collected for unless an exception applies, protecting it from misuse and unauthorised access, destroying or de-identifying it when no longer needed, and assessing whether any eligible data breach must be notified.

Read the Privacy Act 1988 or review the OAIC guide to health privacy.

Certifications

HeliQore does not currently claim formal certifications on this page. We are currently undertaking ISO 27001 alignment work, and certification priorities may shift over time if customer demand or market requirements call for different frameworks. Any certification statements will reflect the live status of the program.

What HeliQore Stores

HeliQore stores transcript output and job metadata needed to run the service securely. Audio is handled through temporary private cloud storage during upload and processing rather than being kept as a permanent recording archive.

Customer data is not used to train HeliQore models. The current implementation is designed around limited retention, including 30-day expiry for uploaded audio and 1-day expiry for temporary transcription and formatted output as a backstop.

Data Handling Summary

  • Transcript output is available to the user through the authenticated workflow
  • Audio and temporary processing artifacts are not intended for indefinite retention
  • Job metadata is retained only for workflow, status, usage, and operational security purposes
  • Customer data is not used to train AI models

Subprocessors

HeliQore uses a small number of service providers to support hosting, transcription workflows, and secure billing operations.

AWS

Cloud infrastructure, private storage, access controls, and core application hosting.

OpenAI

Speech-to-text transcription and transcript formatting workflows used by the product.

Stripe

Subscription billing, payment processing, and secure customer billing management.

Open the public subprocessor summary for a buyer-facing page that explains vendor roles and customer-data handling at a higher level.

How We Talk About Compliance

HIPAA and the Australian Privacy Act are regulatory frameworks. They are not the same thing as a certification, and HeliQore does not present them that way.

Where security programs or formal standards are still in progress, the public wording should stay precise and current.

Public Legal Pages