Search all 478 artefacts by title, document ID or content.
Disclosure | Family 3, Security, Privacy & Trust Disclosures
The Australian fork of DIS-GL-029 and the Australian analogue of the integration boundary published for India (DIS-GL-024). This document is the honest conformance answer. It states what is built, what is not, and what each unbuilt item would take.
This document is the source of truth for: au-conformance-status, au-national-systems-boundary, au-track-a-track-b-definition, au-fhir-conformance-position, au-byoc-credential-position
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
DIS-AU-029 | Version 1.0.0 | Last Modified On 01 August 2026
The Australian fork of DIS-GL-029 and the Australian analogue of the integration boundary published for
India (DIS-GL-024). This document is the honest conformance answer. It states what is built, what is
not, and what each unbuilt item would take.
DM-1 |
DM-2 |
DM-3 |
DM-4 |
|---|---|---|---|
| Yes | Yes | Yes | Yes |
Conformance status is a property of the software, not of where it runs. The one exception is the processing-location constraint in Section 4, which is a property of where Pensieve's people are.
To let an Australian hospital's CIO decide, in the first call rather than in week three, whether the deal it is contemplating is a fourteen-day deal or a nine-month one, and to make the distinction sellable rather than embarrassing.
There is no Australian licence, registration, certification or approval a software vendor must hold to sell, install, operate or be paid for a hospital operating system in a private hospital. There are five government conformance programmes, and each one gates connecting to a specific national system, not selling. Pensieve holds none of the five, and the entire Australian go-to-market rests on that distinction being stated at qualification rather than discovered at cutover.
| # | National system / standard | Operator | Pensieve status | Hard gate for a private hospital deal? | What it would take |
|---|---|---|---|---|---|
| 1 | My Health Record: Notice of Connection, conformance declaration, Register of Conformity | Australian Digital Health Agency | Not built. Not registered | No, unless the hospital requires Pensieve to be its My Health Record system, or authors its own pathology or imaging reports | 6 to 12 months of engineering, plus an Australian-resident support tier (Section 4). No published fee [UNVERIFIED] |
| 2 | Healthcare Identifiers Service: IHI, HPI-I, HPI-O handling | Services Australia and the Agency | Not built. Pensieve does not store Individual Healthcare Identifiers (Section 5) | No. Publish the non-collection boundary instead | Bundled with #1 |
| 3 | Medicare Online, ECLIPSE and the Australian Immunisation Register: Notice of Integration | Services Australia | Not built. No Notice of Integration | No for a first deal where the hospital keeps its existing claiming path. Yes the moment Pensieve must lodge the claim | 3 to 9 months against a government test harness [ESTIMATE]. No fees; large engineering |
| 4 | Electronic prescribing conformance | Australian Digital Health Agency | Not built | No for inpatient-only scope. Yes for community or discharge prescriptions | 6 to 12 months [ESTIMATE] |
| 5 | Secure messaging conformance | Australian Digital Health Agency | Not built | No. Soft expectation only | 3 to 6 months [ESTIMATE] |
| 6 | My Health Record Connecting Systems: Security Conformance Profile | Australian Digital Health Agency | Not applicable until #1 | Prerequisite to #1 | Evidence submission against each requirement plus an observation session. Aligned to the Essential Eight (see Section 11) |
| 7 | AU Core FHIR profile set | HL7 Australia / the Sparked accelerator | Self-declaration in progress (Section 7) | No. No register, no conformance test, no legal requirement. A fast-appreciating soft expectation | 2 to 4 weeks for the resources in Section 7 |
| 8 | NASH PKI certificate | Services Australia, issued to the hospital | Not applicable to Pensieve. It is the hospital's credential (Section 6) | Hard for the hospital, not for Pensieve | None |
| 9 | HL7 v2 messaging, DICOM, SNOMED CT-AU, AMT, LOINC | Not applicable | See DIS-GL-029 Section 1 and Section 2 for the global position; Australian terminology editions in Section 8 |
No | Not applicable |
None of the five conformance programmes is required to sell, install, run or be paid for a hospital operating system. All five are required to replace a specific incumbent capability.
| Track A: Scoped | Track B: Full replacement | |
|---|---|---|
| What Pensieve does | Administration, clinical records, revenue cycle up to claim preparation, pharmacy, inventory, human resources, scheduling, theatre and bed management, analytics | Everything in Track A, plus claim lodgement, My Health Record upload and community electronic prescribing |
| What the hospital keeps | Its existing path for Medicare and ECLIPSE claim lodgement, My Health Record upload and community prescribing. Pensieve integrates with, or exports to, that path | Nothing of the above |
| Prerequisites | Items 7 to 9 of Section 2, plus the paperwork set in REG-AU-002 |
Track A plus items 1 to 6 of Section 2 |
| Time to first payment | 10 to 18 days for a single-site hospital on DM-1 with standard paper |
6 to 9 months minimum, driven by conformance |
| Time to go-live | 14 to 25 days | 9 to 15 months |
| Additional cost to reach the starting line | The paperwork set only | Track A plus 2 to 4 engineer-years [ESTIMATE] of conformance engineering, plus an Australian-resident support tier if My Health Record is in scope |
| Fits | Single-site private hospitals, day hospitals, private psychiatric and rehabilitation operators, the not-for-profit mid-tier (where pathology and imaging are provided by an external provider) | Any Australian hospital, including groups |
Pensieve sells Track A today, says so in the first call, prices it accordingly, and records the excluded
national systems on the Order Form as an express exclusion. MSA-AU-001 AU-11.8 is the contractual
form of that boundary.
Two qualification questions decide the track, and they belong in the first conversation:
A "yes" to either makes the deal Track B. A hospital that answers yes to the second has a statutory
upload obligation Pensieve cannot discharge, and must retain a system that can (DIS-AU-008 Section 6).
Status: Pensieve is not connected, is not on the Register of Conformity, and does not hold a Notice of Connection.
What it would take, in order:
Step 5 is the one that is not an engineering task. Section 77 of the My Health Records Act 2012
prohibits a registered contracted service provider from processing or handling information relating to
My Health Record records outside Australia, with imprisonment among the penalties. Pensieve's
engineering and support function is in India. A contractual promise, an encryption control or a data
processing agreement does not satisfy that provision. DIS-AU-033 Section 4 states the position in full and
MSA-AU-001 AU-11 is the operative restriction.
Pensieve therefore does not offer My Health Record connectivity and will not represent to a hospital, a tender or the Agency that it does. A hospital that requires it should treat it as a roadmap item with a hiring and identity-architecture dependency measured in months.
The direction of travel is one-way. From 1 July 2026 pathology and diagnostic imaging written reports must be uploaded to My Health Record within the prescribed period, subject to documented exceptions, and further categories have been announced. The set of information that must reach My Health Record is expanding, and Pensieve treats connectivity as a dated roadmap commitment rather than an indefinite exclusion.
Pensieve does not collect, store, adopt, use or disclose Individual Healthcare Identifiers.
This is the same architectural move Pensieve publishes for India's national digital health programme, and it is stated the same way: affirmatively, deliberately, without apology.
Why. The Healthcare Identifiers Act 2010 limits the purposes for which identifiers may be collected, used, disclosed and adopted, imposes data quality and security obligations, and attaches criminal and civil penalties to unauthorised handling. Connecting to the Healthcare Identifiers Service requires the hospital's organisation identifier, a NASH PKI certificate, and software that has passed conformance Pensieve does not hold.
What follows for the product, and each is a real engineering rule:
Until then: the hospital must not enter an Individual Healthcare Identifier into a free-text field, and
DPA-AU-001 Section 6.4 records the handling if one arrives.
Every connection to an Australian national system is authenticated with a credential issued to the hospital, not to the vendor.
| Credential | Issued to | Obtained by | Held how |
|---|---|---|---|
| Healthcare Provider Identifier (Organisation) | The hospital | The hospital, through the Services Australia provider portal | Supplied to Pensieve as configuration |
| NASH PKI certificate | The hospital, against its organisation identifier | The hospital's organisation maintenance officer | Installed into the hospital's instance, encrypted at rest in a per-tenant key vault |
| Provider Digital Access device credential | The hospital | The hospital | Same |
| Services Australia minor customer identifier | The hospital | The hospital | Same |
| Private health insurer and payer credentials | The hospital | The hospital | Same |
Pensieve operates a bring-your-own-credential model. It calls national and third-party systems as the hospital, on the hospital's own authority, using the hospital's own credential. Pensieve is not the registered participant, does not hold those credentials in its own name, and does not represent that it does.
Custody, encryption, rotation, revocation, scope of use and destruction on offboarding are governed by
ADD-GL-007 and described in DIS-GL-025. The Australian credential names differ; the model does
not.
AU Core is the Australian profile set defining the minimum expectations on FHIR resources for Australian implementations, developed by the national FHIR accelerator and published under HL7 Australia governance, on FHIR R4. There is no register, no conformance test and no legal requirement for a private hospital's software to be AU Core conformant. It is a soft expectation that is appreciating quickly, and it is the cheapest credibility purchase available in an Australian technical conversation.
Pensieve's position and its status:
| Item | Status |
|---|---|
| FHIR R4 application programming interface over the Pensieve data model | Pensieve au fhir api status |
| AU Core profile conformance for Patient, Practitioner, PractitionerRole, Organization, Encounter, Condition, AllergyIntolerance, MedicationStatement, Observation, DiagnosticReport | Pensieve au au core status |
| Published FHIR CapabilityStatement | Pensieve au capability statement URL |
| Conformance declaration | Self-assessed. Not independently assessed and not listed on any register, because no register exists for it |
Pensieve labels this self-assessed, every time. A self-declaration described as a certification is the single fastest way for an uncertified vendor to lose an Australian technical reviewer.
Why it is worth doing. A published CapabilityStatement is a machine-checkable artefact. It answers the "will we be locked in" question better than any contractual exit clause, and it positions the hospital for the national health information exchange programme without Pensieve committing to a conformance programme it has not started.
The global position (which terminologies the Platform carries, which version, and how versions are
managed) is DIS-GL-029 Section 2 and the Terminology and Code System Version Register it names. The
Australian editions the Platform must be configured to are SNOMED CT-AU, the Australian Medicines
Terminology, and the Australian LOINC subset used in pathology reporting, and the register records the
version in use for each Australian tenant.
Pensieve does not maintain these terminologies and is not their publisher. Licensing of the Australian editions to the hospital is the hospital's, obtained through the national terminology service, and is a bring-your-own-credential item under Section 6.
To lodge Medicare claims, private health insurer claims through ECLIPSE, or immunisation encounters, the software must be built against Services Australia's specifications, pass integration testing and receive a Notice of Integration. Only software holding a Notice of Integration may transmit claims.
ECLIPSE is the one that matters for a private hospital, because it carries the combined Medicare and insurer claim in a single transaction: in-patient medical claims, eligibility checks and hospital claims. A hospital operating system that does revenue cycle in Australia and cannot lodge an ECLIPSE claim is not doing the whole of revenue cycle in Australia.
Pensieve's honest position: this is a multi-quarter engineering programme against a government test harness, free of charge and expensive in time. For the first Australian deals the hospital retains its existing claiming path, and Pensieve:
This is said in the first call. It is the difference between a scoped deal that goes live in weeks and a failed one that does not.
Electronic prescribing. Pensieve holds no conformance. For an inpatient-only scope (prescribing, administration and pharmacy supply inside the hospital), no national conformance applies. For community or discharge prescriptions, conformance to the national prescription delivery infrastructure is required and Pensieve does not have it. The hospital retains its existing path.
Secure messaging. Pensieve holds no conformance. Clinical correspondence is exchanged by the transport
mechanisms in DIS-GL-029 Section 1 and by the hospital's existing secure messaging provider, to which Pensieve
delivers documents. This is a soft expectation, not a gate.
The security baseline the Agency applies to systems connecting to My Health Record is aligned to the
Essential Eight. Pensieve is not in that programme. The relevance is sequencing: the Essential Eight
work Pensieve does for ordinary commercial procurement is the same work that would later underpin Agency
security conformance. It is the one place in the Australian programme where a free early action buys
down a later expensive one. Pensieve's self-assessed maturity position, per control, with dated gaps, is
in REG-AU-002 Section 4.
The Essential Eight has been announced for retirement and replacement by a new series, with retirement
beginning in 2027 and completing around 2028, and existing investment stated by the issuing authority not
to be made redundant. REG-AU-002 Section 4 records that transition and Pensieve's re-baselining commitment.
| System | Who connects | Whose credential |
|---|---|---|
| My Health Record | The hospital, through its existing system. Not Pensieve (Section 4) | The hospital's |
| Healthcare Identifiers Service | The hospital. Not Pensieve (Section 5) | The hospital's |
| Medicare, ECLIPSE, immunisation register | The hospital, through its existing claiming system (Section 9) | The hospital's |
| Community and discharge electronic prescribing | The hospital (Section 10) | The hospital's |
| Secure messaging | The hospital's provider; Pensieve delivers documents to it (Section 10) | The hospital's |
| Private health insurers and payers | Pensieve, as the hospital, on the hospital's credential | The hospital's |
| Pathology and imaging providers, analysers, image archives | Pensieve, on the hospital's connection | The hospital's |
| Payment gateways, messaging and e-mail providers | Pensieve, as the hospital, on the hospital's credential | The hospital's |
The responsibility matrix, the sequencing and the acknowledgement the hospital signs are the Australian
equivalent of DIS-GL-026, and are recorded on the Order Form as express exclusions so that no hospital
is surprised at go-live.
[ESTIMATE] is exactly that. Pensieve has not run any of the
five programmes. Do not quote them to a hospital as commitments.REG-AU-002 carries the live position.[UNVERIFIED: the Agency does not publish a fee schedule; confirm directly if this ever becomes a funded programme.]REG-AU-002 Section 6
carries verification with an Australian practice-software vendor as an open item.| Document | For |
|---|---|
DIS-GL-029 |
The global standards position, transports, terminologies and export formats |
DIS-GL-024, DIS-GL-025 |
The integration boundary model and credential handling, of which Section 5 and Section 6 are the Australian instance |
ADD-GL-007 |
The contractual form of the bring-your-own-credential model |
DIS-AU-008 Section 6 |
Residency and the pathology and imaging upload obligation |
DIS-AU-033 Section 4 |
Why section 77 is a support-model constraint |
DIS-AU-028 Section 7 |
What Pensieve can evidence for accreditation, including the My Health Record advisory gap |
MSA-AU-001 AU-11 |
The contractual restriction and the claiming scope boundary |
REG-AU-002 |
The Australian gating table, the Essential Eight position and the open items |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Engineering | First issue. Australian conformance status table for all five national programmes, the Track A / Track B distinction with elapsed and cost, the My Health Record and healthcare identifier boundaries, the Australian bring-your-own-credential credential set, the self-assessed FHIR position, and the claiming gap stated plainly. |