# HotDoc > HotDoc is an Australian patient-engagement platform (founded 2012, Melbourne; acquired by Potentia in February 2026) used by roughly one in three Australians and more than 21,000 practitioners. It provides clinics with online bookings, telehealth, appointment reminders, SMS recalls, mobile/kiosk check-in, digital new-patient registration, online repeat-prescription requests, and preventative-health outreach. HotDoc operates as an engagement layer on top of Australian practice-management systems (Best Practice, MedicalDirector, Zedmed, Genie, Cliniko, Nookal), consuming their APIs rather than publishing its own REST/OpenAPI. It does run a real OpenID Connect / OAuth 2.0 authorization server for clinic/partner sign-in; there is no self-serve public developer API, FHIR CapabilityStatement, or SDK. ## Identity - [Website](https://www.hotdoc.com.au/): Consumer patient booking directory (Find a Doctor / GP / Dentist). - [For Practices](https://practices.hotdoc.com.au/): Clinic-facing patient-engagement product. - [Blog](https://www.hotdoc.com.au/blog/): HotDoc blog. - [Status](https://status.hotdoc.com.au/): Public service status page. - [GitHub](https://github.com/htdc): HotDoc GitHub organization (internal tooling/forks; no public spec/SDK). - [LinkedIn](https://www.linkedin.com/company/hotdoc): Company profile. ## Authentication (OpenID Connect / OAuth 2.0) - [OpenID Configuration](https://www.hotdoc.com.au/.well-known/openid-configuration): OIDC discovery document (issuer, endpoints, claims). - [OAuth Authorization Server Metadata](https://api.hotdoc.com.au/.well-known/oauth-authorization-server): RFC 8414 metadata on the api host. - [JWKS](https://www.hotdoc.com.au/oauth/discovery/keys): RS256 signing keys. - Flows: authorization_code, implicit; scope: openid; id_token alg RS256; pairwise subjects. Client registration is partner/clinic-gated. ## Security & Compliance - [Security, Privacy and Compliance](https://practices.hotdoc.com.au/security/): SOC 2 Type II; data hosted in Australia on AWS; AES-256 at rest, 256-bit TLS in transit; Australian Privacy Act 1988 / APPs; RACGP guidelines. - [Help Centre](https://support.hotdoc.com.au/hc/en-gb): Support and product help. ## Legal - [Privacy Policy](https://practices.hotdoc.com.au/privacy-policy/) - [Terms of Service (Clinics)](https://practices.hotdoc.com.au/terms-of-services-clinics/) - [Terms of Service (Patients)](https://practices.hotdoc.com.au/terms-of-services-patients/) ## Notes - No public REST/OpenAPI, GraphQL, MCP server, or HL7 FHIR surface is published; integration is via the clinic's practice-management-system API key entered into the HotDoc dashboard. - Artifacts in this repo (authentication, scopes, well-known, conformance, security, lifecycle) are searched/probed from HotDoc's live public surfaces; nothing was fabricated.