Bonded
Security & compliance

How Bonded protects patient data.

Bonded holds clinical records, diagnostic imaging and payment data for orthodontic practices. It is hosted in-region, encrypted in transit and at rest, and operated to the health-data regime of every market it serves.

HIPAAUK GDPR & DPA 2018Privacy Act 1988 & APPsPCI-DSS
01

Data residency

Each region is an independent deployment with its own database. Your practice's data is stored and processed in your region.

ap-southeast-2
Australia & New Zealand
Practices in Australia and New Zealand are hosted in Sydney. Clinical records, imaging and documents remain in the Australian region.
eu-west-2
United Kingdom
UK practices are hosted in London. Clinical records, imaging and documents remain in the UK region.

Backups are encrypted and retained in the same region as the data they protect. Sub-processors and the safeguards governing any cross-border transfer are named in the privacy policy.

02

Regulatory compliance

Bonded is operated to the standard that applies where your practice is.

Australia & New Zealand
Privacy Act 1988
The Australian Privacy Principles govern the collection, holding, use and disclosure of personal and health information, alongside applicable State health records legislation.
United Kingdom
UK GDPR & DPA 2018
Lawful basis, data subject rights, records of processing and breach reporting under the UK General Data Protection Regulation and the Data Protection Act 2018.
United States
HIPAA
Protected Health Information is handled under the HIPAA Privacy and Security Rules. Business Associate Agreements are executed on request.
Payments
PCI-DSS
Card details are captured by PCI-DSS compliant payment providers and returned to Bonded as a token. Card numbers are never stored in a Bonded system. Direct-debit and PayTo mandates are held by the provider; Bonded stores the mandate reference and a masked account number.
03

Technical controls

Encryption

AES-256 at rest across databases, object storage and backups. TLS 1.2 or higher in transit, including API traffic, the mobile applications and file transfer.

Access control

Identity-based access to production with mandatory multi-factor authentication. Inside a practice, staff see the records and functions their role permits, enforced server-side.

Tenant isolation

Every query against patient data is scoped to the clinic that owns it. Isolation is enforced in the data layer, not in the interface.

Testing and monitoring

Independent penetration testing annually, vulnerability scanning quarterly, and continuous monitoring of the production stack.

Documentation

For your security review.

Business Associate Agreements, data processing agreements, sub-processor lists and completed security questionnaires are available on request from our Privacy Officer.

privacy@bondedpayments.comPrivacy policy