Search all 478 artefacts by title, document ID or content.
Disclosure | Family 3, Security, Privacy & Trust Disclosures
The Australian fork of DIS-GL-028. Read this document for an Australian deployment. The global statement covers India, the European Union and the United Arab Emirates and is not repeated here.
This document is the source of truth for: au-tga-exclusion-position, au-clinical-feature-boundary-rules, au-nsqhs-standard-8-boundary, au-cdss-exemption-non-reliance, au-clinical-language-control
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
DIS-AU-028 | Version 1.0.0 | Last Modified On 01 August 2026
The Australian fork of DIS-GL-028. Read this document for an Australian deployment. The global
statement covers India, the European Union and the United Arab Emirates and is not repeated here.
Written for the Director of Clinical Governance and the Quality Manager. It answers one question: is this software a medical device, and if not, prove it, with item numbers rather than assurances, and it states the product rules that keep the answer true. It is also written for Pensieve's own implementation consultants, because the person most likely to destroy this position is not a regulator; it is a well-meaning consultant configuring an observation chart.
DM-1 |
DM-2 |
DM-3 |
DM-4 |
|---|---|---|---|
| Yes | Yes | Yes | Yes |
Regulatory status does not vary by deployment model. It is determined by what the software is intended to do, not by where it runs. The rules in Section 4 bind every model identically, and they bind a hospital's own configuration as much as they bind Pensieve's code.
To state Pensieve's Australian therapeutic goods position, the five numbered exclusions it relies on, the testable product rules that keep it inside them, and, explicitly, the two places where the position is most likely to be lost: the clinical decision support exemption, and an implementation of National Safety and Quality Health Service Standard 8.
Software meeting the definition of a medical device in section 41BD of the Therapeutic Goods Act 1989 (Cth) is regulated by the Therapeutic Goods Administration unless it is exempt or excluded. The three states are not interchangeable and the difference is commercially decisive.
| State | Legal effect | Oversight retained | Entry in the Australian Register of Therapeutic Goods |
|---|---|---|---|
| Regulated | The full medical device framework applies | All of it | Required |
| Exempt | Relieved of the inclusion requirement, subject to conditions | Advertising restrictions, adverse event reporting and notification obligations remain. It is still a medical device | Not required, but the Administration must be notified |
| Excluded | Not regulated by the Therapeutic Goods Administration at all | None | Not required |
Pensieve is excluded. Pensieve is not exempt. The distinction matters because an exempt product is still a medical device with a manufacturer's post-market obligations, and because "is Pensieve a medical device?" then becomes a question with a nuanced answer instead of a one-word one. Section 8 explains why Pensieve declines the exemption route deliberately rather than by oversight.
Pensieve holds no entry in the Australian Register of Therapeutic Goods and does not require one.
The Therapeutic Goods (Excluded Goods) Determination 2018 was amended in 2021 to insert software exclusions into Schedule 1. Five of them cover Pensieve's functional footprint, and each is a numbered item rather than an argument.
| Item | What the item covers | Pensieve capability relying on it |
|---|---|---|
| 14G | Software for the administration or management of health processes or facilities, including financial records, claims, billing, appointments, operating theatre management, hospital bed management, schedules, business analytics and admissions | Registration, admission/discharge/transfer, billing and revenue cycle, theatre and bed management, scheduling, procurement, inventory, pharmacy stock, human resources, rostering, operational analytics, incident capture and open disclosure workflow |
| 14M | Software that is an electronic health record, however named, intended to be used in clinical practice by healthcare providers to collect, use, disclose and otherwise manage patient clinical data within or between healthcare facilities | The clinical record itself: notes, clinician-recorded observations, documents, results filing, orders as records, care plans, discharge summaries, consent records |
| 14N | Data analytics for the collection and analysis of class, group or population data | Population dashboards, quality indicators, casemix, key performance reporting, accreditation reporting, provided no output drives an outcome for an identified individual |
| 14O | Laboratory information management systems, however named | Laboratory workflow, instrument integration, sample management, result reporting and annotation |
| 14I | Software for the sole purpose of providing alerts to health professionals in relation to patient care | Non-urgent clinical alerts, reminders and prompts, and information-only reference alerts as described in Section 4 |
[UNVERIFIED: the item numbers above were each corroborated from two independent retrievals of the Administration's guidance. Before this document is cited in a tender response or a clinical governance submission, verify each item number against the current text of the Determination on the Federal Register of Legislation. A wrong item number in a clinical governance artefact is a credibility event, and it is cheaper to check than to recover from.]
Storage and transmission are separately excluded from analysis. Pensieve stores and transmits images and reports; it does not analyse them. That distinction is load-bearing and appears again in Section 4.
Every one of the five exclusions carries the same condition, expressed slightly differently in each. Software falls out of the exclusion if it is intended by its manufacturer to diagnose, screen for, prevent, monitor, predict, make a prognosis of, alleviate, treat, or make a recommendation or decision about the treatment of, a disease, condition, defect or ailment, or if it is intended to replace the clinical judgement of a health professional.
Two consequences follow, and both are product constraints rather than legal opinions:
These are binding on Pensieve engineering, on Pensieve implementation consultants, and on the hospital's
own configuration. They are written so that each one can be tested by a person who is not a lawyer.
They are incorporated into the Australian contract by MSA-AU-001 AU-8.
| Rule | Why the rule exists |
|---|---|
| Do not compute or display an early warning score, deterioration score, sepsis score, risk score or acuity score derived from patient observations | Monitoring the state or progression of a condition. Outside 14M and 14I. This is the rule most often broken in an Australian implementation (see Section 6) |
| Do not produce a patient-specific dose calculation or dose recommendation | A recommendation about treatment. Also outside the general calculator exclusion, which covers general calculation only |
| Do not run an interaction-severity engine that suppresses, escalates or ranks alerts by clinical severity | Moves from providing an alert to making a recommendation about treatment, and so out of 14I |
| Do not directly process or analyse a medical image, waveform or signal from another medical device | The explicit bright line in the classification rules and in the exemption Pensieve declines |
| Do not triage, prioritise or order patients by predicted clinical risk | Prediction and prognosis |
| Do not present an output a clinician is expected to act on without independently reviewing its basis | Replacing clinical judgement |
| Do not originate, route or deliver a clinical alarm that must be actioned urgently | Section 5 |
| Do not describe any feature using the words diagnose, screen, predict, prognose, triage, or recommend treatment (in marketing, documentation, a user interface label, a release note, a proposal or a contract) | Section 9 |
| Capability | Why it is excluded |
|---|---|
| Information-only drug interaction alert sourced from a published reference, with the source shown and reviewable by the clinician | 14I. The Administration's own worked example is an alert drawn from a published medicines reference, sent as an information-only alert to a health professional. It does not replace clinical judgement |
| Rule-based administrative reminders: overdue observation, missing consent, unsigned note, allergy not recorded, discharge summary outstanding | Administrative prompts, not clinical determinations. 14G and 14I |
| Recording observations entered by a clinician, and displaying them as entered, including in a chart or trend view | 14M. Recording and displaying is record-keeping. Computing a score from them is not |
| Displaying the hospital's own documented escalation criteria as static reference content that a clinician reads and applies | The hospital's clinical protocol, displayed. Pensieve makes no determination (Section 6) |
| Store and transmit images, reports and documents without analysing them | Storage and transmission is separately excluded; analysis is not |
| Population and cohort analytics that do not drive an outcome for an identified individual | 14N |
| General calculators: body mass index, unit conversion, gestational age from a date | The calculator exclusion |
| Machine learning for non-clinical functions: coding suggestion, denial prediction, demand forecasting, document classification, roster optimisation, transcription without clinical interpretation | No therapeutic purpose. The intended purpose is administrative. DIS-GL-027 lists each feature and its status |
For any feature, ask three questions in order. A "yes" to any of them means the feature is outside the exclusions and must not ship in Australia without the programme in Section 10.
The exclusion for alert software does not apply to software that provides alarms to health professionals that must be actioned urgently. The Administration's own example is a ventilator alarm requiring an intensive care nurse to act immediately.
Product rule: Pensieve is not the delivery path for any time-critical clinical alarm. No physiological monitor alarm routing. No code-blue paging derived from device signals. No escalation triggered by a vital-sign threshold.
What Pensieve does instead: it integrates with the system that performs that function and records the event for the clinical record and for audit. It does not originate the event.
Where this belongs. This rule is in the Order Form exclusions list, not only in this document, because a hospital that asks for alarm routing at week three of an implementation must meet the answer in the contract rather than in a policy debate.
This section is the reason this document exists in its current form.
Every Australian hospital, public and private, must be accredited against the National Safety and Quality Health Service Standards. The second edition is operative; a third edition is in development and is anticipated later this decade. Standard 8, Recognising and Responding to Acute Deterioration, requires recognition systems and escalation processes.
The collision. A hospital implementing a new core platform will ask for a track-and-trigger observation chart with automatic escalation. That is exactly the function Section 4.1 prohibits. It is a monitoring function, it is outside all five exclusions, and configuring it would convert Pensieve into an unregistered medical device.
The rules that resolve it, and they are configuration rules, not legal ones:
| Pensieve may | Pensieve must not |
|---|---|
| Record observations exactly as the clinician enters them | Compute a total, a subscore or a colour-band from those observations |
| Display observations in a chart or trend, unmodified | Apply a trigger threshold that changes the display's meaning |
| Display the hospital's own escalation criteria as static reference text, alongside the observations, for the clinician to read and apply | Evaluate those criteria against the recorded observations and tell the clinician the outcome |
| Record that an escalation occurred, who made it, when, and what the response was | Initiate the escalation, page a responder, or determine that escalation is required |
| Integrate with, and receive events from, the hospital's existing recognition-and-response system | Replace that system |
The instruction to the implementation team, in one sentence: if a field, a form rule, a calculated column, a conditional format or an automation would tell a clinician something about the patient's clinical state that the clinician did not enter, stop and escalate to Legal before configuring it.
Why the risk is real. The person who breaks this will be a consultant configuring a form under time pressure at week two of a go-live, not a lawyer reading a determination. This rule therefore appears in the implementation runbook and the configuration freeze checklist, not only here. A deviation is a configuration defect with a regulatory consequence and is treated as a blocking item.
Pensieve is not selling only software into an Australian hospital; it is selling accreditation evidence. The following is what Pensieve can evidence at survey, and, honestly, what it cannot.
| Standard and area | Pensieve capability | Evidence at survey | Status |
|---|---|---|---|
| Standard 1: healthcare records available at the point of care | The record is available to clinicians at the point of care, including a documented downtime procedure | Availability reporting under DIS-GL-030; the downtime procedure in SLA-GL-001 |
Supported |
| Standard 1: accurate and complete records | Completeness controls, mandatory fields, unsigned-note and missing-document reporting | Record quality reports the Quality Manager can run without Pensieve | Supported |
| Standard 1: audit of the healthcare record system | Built-in record-quality and access audit reports | Reports run by the hospital, exportable | Supported |
| Standard 1: security and privacy compliance | The privacy and security artefact set | DPA-AU-001, POL-AU-053, ADD-GL-001, DIS-AU-008 |
Supported |
| Standard 1: incident management and open disclosure | Clinical incident capture, escalation workflow and reporting. Recording and routing only: no clinical determination | Incident register and reports | Supported, inside 14G |
| Standard 4: medication safety | Medicines list management and reconciliation workflow at transitions of care. Information-only. No severity ranking, no dose recommendation | Reconciliation completion reporting | Supported, inside the Section 4 limits |
| Standard 5: comprehensive care | Care plan documentation, retrieval and audit | Care plan completion reporting | Supported |
| Standard 6: communicating for safety | Patient identification with three approved identifiers, procedure matching, structured handover, documented allergy and adverse reaction alerts (information-only) | Identification and handover compliance reporting | Supported, inside the Section 4 limits |
| Standard 8: acute deterioration | Observation recording and the display of the hospital's own criteria as static reference content | Observation completeness reporting | Partially supported. The recognition-and-response function itself is not Pensieve's (Section 6) |
| Advisory on providing clinical information to My Health Record | Not applicable | Not applicable | Not supported. DIS-AU-029 Section 4 states why and what it would take |
Pensieve does not warrant an accreditation outcome, and MSA-AU-001 AU-8.4 says so. What it warrants
is that the evidence above exists, is retrievable by the hospital without a Pensieve service request, and
is accurate.
The 2021 reforms created an exemption for clinical decision support software, available where the software is intended solely to provide or support a recommendation to a health professional about prevention, diagnosis, curing or alleviating a disease, ailment, defect or injury; and is not intended to directly process or analyse a medical image or a signal from another medical device; and is not intended to replace the clinical judgement of a health professional.
Pensieve does not build to it, and the reasoning is deliberate:
Position: stay inside items 14G, 14M, 14N, 14O and 14I, where the answer is "no, and here is the item number." Exempt ≠ excluded, and the difference is not cosmetic.
Because intended purpose is determined by what the manufacturer says, language is a regulatory control and is treated as one.
Stated so that the cost is known in advance rather than discovered in response to a regulatory query.
Edsol Edtech Pvt. Ltd. would have to appoint one or
establish an Australian subsidiary.WPR-GL-005 records
that Pensieve holds neither.Caution The decision this section forces, and it is the founder's. The exclusion position is correct, cheap and defensible today. It also permanently constrains the roadmap: no early warning score, no sepsis prediction, no imaging triage, no dose calculator, no severity-ranked interaction engine, no readmission risk score attached to an identified patient. If any of those is on the twenty-four month roadmap, the correct sequencing is a separately branded, separately regulated product line with ISO 13485 and IEC 62304 started twelve months before ship, not a retrofit after a regulatory query. The decision to record is not "buy the certificates"; it is "is a clinical-determination feature on the roadmap at all?" The answer must be written down, dated and signed, because every Australian clinical governance conversation depends on it.
REG-AU-002Section 7 carries it as an open decision with a named owner.
The exclusions depend on intended purpose, and a hospital can change intended purpose by configuration.
The hospital therefore undertakes, in MSA-AU-001 AU-8.2, not to configure, extend, integrate, label or
describe the Platform so that it does anything in Section 4.1.
In practice this means the hospital should:
Pensieve will decline a change request that would put the Platform outside Section 2, will say so in writing,
and will name the exclusion that would be lost. A refusal on that ground is not a breach and is not a
service-level failure: MSA-AU-001 AU-8.3.
REG-AU-002 Section 7 carries the opinion as a costed, open
item.| Document | For |
|---|---|
DIS-GL-028 |
The global clinical safety boundary statement: India, European Union, United Arab Emirates |
DIS-GL-027 |
Feature-by-feature machine learning disclosure, including endpoint regions |
DIS-AU-029 |
Conformance status for My Health Record, identifiers, claiming and prescribing |
MSA-AU-001 AU-8 |
The contractual form of Section 4, Section 6 and Section 11 |
ADD-GL-005 |
Use case restrictions and prohibited uses |
POL-GL-132 |
Model risk governance behind DIS-GL-027 |
WPR-GL-005 |
Assurance overview, including what Pensieve does not hold |
REG-AU-002 |
The Australian gating table and the open decisions referenced in Section 10 and Section 12 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Legal | First issue. Australian fork of DIS-GL-028: the regulated/exempt/excluded structure, the five numbered exclusions with a function map, the disqualifying condition, testable bright-line product rules, the alarm carve-out, the Standard 8 implementation boundary, express non-reliance on the clinical decision support exemption, language control, and the accreditation evidence map with its honest gap. |