Healthcare
Compliant infrastructure, not just compliant advice.
Healthcare IT carries obligations most industries don't — the Privacy Act 2020, the Health Information Privacy Code, and regulators paying closer attention to how patient data is handled. We manage the infrastructure, run the security, and build software that works inside those constraints, not around them.
Healthcare gets sold IT built for offices, then told to make it fit the Privacy Act on its own. The result is usually a workaround: staff using tools the legal team never approved, on devices nobody manages, because the approved option was too slow or didn't exist.
We build for the constraints instead of around them. Infrastructure and security that assume patient data matters, and software — like Polly and Anonamoose — that gives clinicians modern AI without the data ever leaving the building.
AI the legal team says no to
Clinicians want the same AI tools the rest of the world is using. The legal team says no because generic AI was not built for NZ health legislation. Staff use it anyway, on their phones.
Documentation load
Notes, referrals, letters and codes — clinicians spending more time typing than seeing patients. The admin overhead is not getting lighter on its own.
PMS integration gaps
Clinical systems that don't talk to each other, data that lives in the wrong place, and staff navigating between four systems to complete one task.
Inadequate backup and recovery
Clinics that lose access to records — even briefly — face real consequences. Most practices have backups. Far fewer have tested recovery procedures.
Run: Managed IT for Clinics
Workstations, networks, M365 and clinical system support managed proactively. A helpdesk your reception staff can reach without logging a ticket.
Protect: Privacy-first Security
Backup and recovery with tested RTOs, endpoint protection and identity management. Security posture scored continuously by RiskSense.
Improve: Compliance Advisory
Privacy Act 2020, HIPC and audit readiness handled by people who understand the actual obligations — not just the acronyms. Tracked year-round in ClearMark, our health-sector compliance platform.
Build: Compliant AI & Custom Software
Self-hosted frontier AI with our Anonamoose PII redaction proxy — patient data stays inside your environment. PMS integrations, automation and custom clinical tools built to the same standard.
Software we made for the job
Not side projects. Software we built for a real client problem in this sector, run in production, and offered to anyone with the same problem.
Polly
Self-hosted frontier AI for NZ healthcare. ChatGPT-class power, without patient data ever leaving the building.
In productionAnonamoose
A PII redaction proxy that lets you use the AI tools you want without exposing sensitive data.
In productionClearMark
Self-service cyber-security compliance for NZ health providers — assess against the HISF / CS-CMM / HIPC framework, with Bridge Point reviewing and approving.
In productionCryogenic Storage
Cryogenic inventory for breeding genetics — every sample tracked by tank, canister and position, with full ownership and chain-of-custody records. In production for elite NZ and Australian breeding programs.
Straight answers
Is AI even allowed under NZ health privacy law?
It can be, done right. The problem with generic AI is that patient data leaves your environment. Polly and Anonamoose are self-hosted, so the data never goes anywhere it shouldn't — which is what makes the legal team comfortable instead of nervous.
We've already got a PMS. Do you replace it?
No. We work with your practice management system, fill the gaps between it and everything else, and build integrations so staff stop navigating four systems to finish one task.
Who handles the compliance side — us or you?
We do the IT and security parts, and we speak the actual obligations — Privacy Act 2020, the Health Information Privacy Code — not just the acronyms. Where it's a clinical or legal call, that stays with you, and we make sure the technology backs it up.
What happens if we lose access to records?
That's the question most practices can't answer confidently, and it's the one we fix first. Backups are common; tested recovery is rare. We document how long getting back takes and prove it, rather than hoping.
Our staff are already using ChatGPT on their phones. Isn't that the real risk?
Yes, and pretending it isn't happening doesn't help. Give clinicians a compliant tool as good as the one they're sneaking, and the shadow IT problem mostly solves itself. That's exactly what Polly is for.