Industries · Health
Clinical software and security, from a team that builds and runs it in production.
We build and run clinical software on Azure in Australia, so health obligations are our daily work.
Health information is sensitive information under the Australian Privacy Principles, and everything around it is held to a higher bar: who can see a record, where it is stored, and whether the trail would survive scrutiny. Software that touches clinical work inherits all of it.
Aurii, clinical software we built and operate, runs on Azure in the Australia East region: Container Apps, PostgreSQL with row-level security isolating tenant health data, Key Vault for secrets, and tamper-evident audit trails throughout. We build for clients to the same standard.
What you carry, and what we do about it.
Health records are sensitive information under the APPs: collection, use, and disclosure all sit at the strictest end of the Privacy Act.
We map the data you hold and where it lives, review the gaps against the Australian Privacy Principles, and leave you ready for the 2026 Privacy Act reforms.
Privacy Act / APP upliftClinical software carries clinical-grade obligations: access discipline, auditability, and data that never leaks across tenants.
We ship this architecture in production: Aurii isolates tenant health data with PostgreSQL row-level security and keeps tamper-evident audit trails throughout, and client builds get the same.
See the Aurii buildWhere the data lives matters: Australian health data is expected to stay in Australian regions, and you will be asked to prove it.
We architect and run on Azure in Australian regions, on the stack we operate in production: Container Apps, PostgreSQL, Key Vault, and delivery pipelines with secrets kept out of code.
Cloud engineering on AzureWhen something goes wrong the questions are immediate: who touched the record, when, and would you even see an attack underway?
We review your logging and alerting coverage, write an incident response playbook your team can run, and pressure-test it with a tabletop exercise.
Detection & response advisory
The obligations in play
- Privacy Act 1988, health information
- Health information is sensitive information under the APPs, with a higher bar for collection, use, and disclosure.
- Notifiable Data Breaches scheme
- Breaches likely to cause serious harm must be assessed and notified to the OAIC and affected individuals.
- State health-records regimes
- New South Wales and Victoria layer their own health-privacy statutes over the Commonwealth regime.
- My Health Records Act 2012
- Additional obligations apply where systems connect to My Health Record.
Not legal advice; your advisers own the interpretation.
Built and running
Aurii
Voice-driven clinical notes, letters, and billing for Australian private-hospital specialists. Built end to end by Black Shard on Azure in the Australia East region, with row-level security on tenant data and tamper-evident audit trails.
See the workThe services behind this work.
Software engineering
We design, build and operate applications, internal systems and cloud infrastructure for Australian businesses.
Read more
Compliance readiness
Black Shard works with organisations preparing for the Essential Eight, SMB1001 and ISO 27001, as well as businesses reviewing their obligations under the Australian Privacy Principles.
Read more
Secure development
Black Shard reviews source code and system architecture for vulnerabilities that automated tooling cannot reliably identify on its own.
Read more
Clinical software built to Australian obligations.
Brisbane head office. Work delivered across Australia.

