How data would be handled
The principles a production build would be held to.
- Data minimisation
- Collect only the measures a view needs. If a dimension can be explained without a data type, that data type is not requested.
- Local-first where possible
- Index maths, summaries and charts run on the device where they can, so fewer raw readings need to leave it.
- Encryption in transit and at rest
- Every connection encrypted, every stored record encrypted, keys managed separately from the data.
- Australian data residency
- Data stored and processed in Australia, with no cross-border disclosure.
- Audit and access logs
- Every read is logged with who, what and when, including an invited clinician and AI agents, and the person can see that log.
- Export and delete
- Download everything as a FHIR R4 Bundle or CSV at any time. Delete means delete, including backups on a stated schedule.
- No selling, no advertising
- Health information is never sold, never used for advertising and never used to profile people for anyone else.
- Grounded AI explanations
- Explanations draw only on the person’s own records and cite them. In the demo, summaries are generated from templates and every sentence links to its records.
What the export looks like
One blood-pressure reading from the synthetic record, as it appears in the FHIR R4 Bundle the explorer builds. The reading is a panel (LOINC 85354-9) with systolic and diastolic components in UCUM mm[Hg], and every resource is marked as test data.
{
"resourceType": "Observation",
"meta": {
"security": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code": "HTEST",
"display": "test health data"
}
]
},
"status": "final",
"category": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/observation-category",
"code": "vital-signs",
"display": "Vital Signs"
}
]
}
],
"code": {
"coding": [
{
"system": "http://loinc.org",
"code": "85354-9",
"display": "Blood pressure panel with all children optional"
}
],
"text": "Blood pressure"
},
"subject": {"display": "Malik (fictional)"},
"effectiveDateTime": "2026-09-21",
"device": {"display": "Home blood-pressure monitor (synthetic)"},
"component": [
{
"code": {
"coding": [
{
"system": "http://loinc.org",
"code": "8480-6",
"display": "Systolic blood pressure"
}
],
"text": "Blood pressure, systolic"
},
"valueQuantity": {"value": 127, "unit": "mmHg", "system": "http://unitsofmeasure.org", "code": "mm[Hg]"}
},
{
"code": {
"coding": [
{
"system": "http://loinc.org",
"code": "8462-4",
"display": "Diastolic blood pressure"
}
],
"text": "Blood pressure, diastolic"
},
"valueQuantity": {"value": 83, "unit": "mmHg", "system": "http://unitsofmeasure.org", "code": "mm[Hg]"}
}
]
}
Trimmed for reading: identifiers, notes and the full Patient and Device references are left out. The full Bundle uses base FHIR R4 resources; AU Core is the design target but is not declared, because the export has not been validated against it.