
Trust center_
Surgical Performance Pty Ltd
Last updated: 31 July 2026
Related: Privacy Policy · HIPAA & Security · Sample BAA
Straight answers
You’re trusting SurgicalPerformance with information about your patients and your own surgical outcomes. Here are direct answers to the questions we’re most often asked.
Do you sign a Business Associate Agreement (BAA)?
Yes. When you create a US location, you accept a BAA at that step — before entering patient data for that location. Read the sample BAA or accept yours then. A countersigned copy can be downloaded from your profile in the SurgicalPerformance app.
Is my data confidential?
Yes — this has always been core to how the platform works. Your performance data is never shown to anyone but you without your explicit agreement, and it is not sold for third-party marketing. De-identified data may be used for research, audit, and benchmarking as described in our Privacy Policy.
Do you store patient names and dates of birth?
Yes, by design. The platform supports identifiable patient fields (including name and date of birth) so you can run follow-up and PROMS properly. Where your workflow allows, you can still use coded internal IDs as a minimisation practice. Details: HIPAA & Security Policy.
Where is my data hosted?
Primary application and database hosting is on Amazon Web Services in Asia Pacific (Sydney) / ap-southeast-2, including the API and PROMS databases. HIPAA does not require US data residency; US customer PHI can be hosted in Australia under a BAA with appropriate safeguards. See the vendor table below and our Privacy Policy for more information.
What happens if there’s a data breach?
We have a documented response process. Report concerns to [email protected]. We will notify you promptly — within the timelines in your BAA (including within 10 business days of discovery for US PHI breaches) and applicable law (including Australian NDB requirements). See HIPAA & Security Policy — Breach.
What about text messages patients get for PROMS?
PROMS follow-up messages may be sent by SMS via Twilio and email via Amazon SES. Messages contain patient first name and no PHI or identifiable data.
Do you use AI on my data?
We use Google Vertex AI / Gemini for certain AI-assisted data entry and reporting features. Data is not used for AI training purposes and these features are optional.
How we protect your data
We host primary clinical systems on Amazon Web Services. Clinicians use unique logins with optional MFA. Connections to the Services use encryption in transit (TLS). Our team’s access is limited to what they need to run the service. We maintain backups and a documented incident process. Full detail: HIPAA & Security Policy.
Vendors that support the platform
Outside services involved in running SurgicalPerformance, and whether they may see patient information:
Who What they do
Amazon Web Services Runs app servers, databases, and backups (via our deployment tooling)
Twilio Sends PROMS follow-up SMS to patients
Stripe Subscription billing
Intercom Customer support messaging
Sentry Application error / crash monitoring
Google Vertex AI AI-assisted report features
Google Analytics Marketing-site analytics
Where a vendor handles PHI on our behalf for US customers, we require appropriate contractual safeguards (including a BAA where required).
Questions?
Privacy / security / BAA: [email protected]
Surgical Performance Pty Ltd
Last updated: 31 July 2026
Related: Privacy Policy · HIPAA & Security · Sample BAA
Straight answers
You’re trusting SurgicalPerformance with information about your patients and your own surgical outcomes. Here are direct answers to the questions we’re most often asked.
Do you sign a Business Associate Agreement (BAA)?
Yes. When you create a US location, you accept a BAA at that step — before entering patient data for that location. Read the sample BAA or accept yours then. A countersigned copy can be downloaded from your profile in the SurgicalPerformance app.
Is my data confidential?
Yes — this has always been core to how the platform works. Your performance data is never shown to anyone but you without your explicit agreement, and it is not sold for third-party marketing. De-identified data may be used for research, audit, and benchmarking as described in our Privacy Policy.
Do you store patient names and dates of birth?
Yes, by design. The platform supports identifiable patient fields (including name and date of birth) so you can run follow-up and PROMS properly. Where your workflow allows, you can still use coded internal IDs as a minimisation practice. Details: HIPAA & Security Policy.
Where is my data hosted?
Primary application and database hosting is on Amazon Web Services in Asia Pacific (Sydney) / ap-southeast-2, including the API and PROMS databases. HIPAA does not require US data residency; US customer PHI can be hosted in Australia under a BAA with appropriate safeguards. See the vendor table below and our Privacy Policy for more information.
What happens if there’s a data breach?
We have a documented response process. Report concerns to [email protected]. We will notify you promptly — within the timelines in your BAA (including within 10 business days of discovery for US PHI breaches) and applicable law (including Australian NDB requirements). See HIPAA & Security Policy — Breach.
What about text messages patients get for PROMS?
PROMS follow-up messages may be sent by SMS via Twilio and email via Amazon SES. Messages contain patient first name and no PHI or identifiable data.
Do you use AI on my data?
We use Google Vertex AI / Gemini for certain AI-assisted data entry and reporting features. Data is not used for AI training purposes and these features are optional.
How we protect your data
We host primary clinical systems on Amazon Web Services. Clinicians use unique logins with optional MFA. Connections to the Services use encryption in transit (TLS). Our team’s access is limited to what they need to run the service. We maintain backups and a documented incident process. Full detail: HIPAA & Security Policy.
Vendors that support the platform
Outside services involved in running SurgicalPerformance, and whether they may see patient information:
Who What they do
Amazon Web Services Runs app servers, databases, and backups (via our deployment tooling)
Twilio Sends PROMS follow-up SMS to patients
Stripe Subscription billing
Intercom Customer support messaging
Sentry Application error / crash monitoring
Google Vertex AI AI-assisted report features
Google Analytics Marketing-site analytics
Where a vendor handles PHI on our behalf for US customers, we require appropriate contractual safeguards (including a BAA where required).
Questions?
Privacy / security / BAA: [email protected]
Surgical Performance Pty Ltd
Last updated: 31 July 2026
Related: Privacy Policy · HIPAA & Security · Sample BAA
Straight answers
You’re trusting SurgicalPerformance with information about your patients and your own surgical outcomes. Here are direct answers to the questions we’re most often asked.
Do you sign a Business Associate Agreement (BAA)?
Yes. When you create a US location, you accept a BAA at that step — before entering patient data for that location. Read the sample BAA or accept yours then. A countersigned copy can be downloaded from your profile in the SurgicalPerformance app.
Is my data confidential?
Yes — this has always been core to how the platform works. Your performance data is never shown to anyone but you without your explicit agreement, and it is not sold for third-party marketing. De-identified data may be used for research, audit, and benchmarking as described in our Privacy Policy.
Do you store patient names and dates of birth?
Yes, by design. The platform supports identifiable patient fields (including name and date of birth) so you can run follow-up and PROMS properly. Where your workflow allows, you can still use coded internal IDs as a minimisation practice. Details: HIPAA & Security Policy.
Where is my data hosted?
Primary application and database hosting is on Amazon Web Services in Asia Pacific (Sydney) / ap-southeast-2, including the API and PROMS databases. HIPAA does not require US data residency; US customer PHI can be hosted in Australia under a BAA with appropriate safeguards. See the vendor table below and our Privacy Policy for more information.
What happens if there’s a data breach?
We have a documented response process. Report concerns to [email protected]. We will notify you promptly — within the timelines in your BAA (including within 10 business days of discovery for US PHI breaches) and applicable law (including Australian NDB requirements). See HIPAA & Security Policy — Breach.
What about text messages patients get for PROMS?
PROMS follow-up messages may be sent by SMS via Twilio and email via Amazon SES. Messages contain patient first name and no PHI or identifiable data.
Do you use AI on my data?
We use Google Vertex AI / Gemini for certain AI-assisted data entry and reporting features. Data is not used for AI training purposes and these features are optional.
How we protect your data
We host primary clinical systems on Amazon Web Services. Clinicians use unique logins with optional MFA. Connections to the Services use encryption in transit (TLS). Our team’s access is limited to what they need to run the service. We maintain backups and a documented incident process. Full detail: HIPAA & Security Policy.
Vendors that support the platform
Outside services involved in running SurgicalPerformance, and whether they may see patient information:
Who What they do
Amazon Web Services Runs app servers, databases, and backups (via our deployment tooling)
Twilio Sends PROMS follow-up SMS to patients
Stripe Subscription billing
Intercom Customer support messaging
Sentry Application error / crash monitoring
Google Vertex AI AI-assisted report features
Google Analytics Marketing-site analytics
Where a vendor handles PHI on our behalf for US customers, we require appropriate contractual safeguards (including a BAA where required).
Questions?
Privacy / security / BAA: [email protected]

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

