Skip to content
Your first appointment is a video call. Start your assessment →

Legal

Privacy policy

We hold health information about you. This policy explains what we collect and why we collect it. It also explains who we share it with, how long we keep it, and what you can do about it. Because we are a health service, it covers your clinical records as well as the everyday details a website collects.

Effective
On publication
Review cycle
Annually
Owner
Aurem Health Pty Ltd, ABN 78 695 908 420
Jurisdiction
New South Wales, Australia
Daylight falling through a skylight in a quiet modern building

Who we are and what this covers

This policy is issued by Aurem Health Pty Ltd, ABN 78 695 908 420. In this policy, Aurem, we and us mean that company.

It covers this website, our enquiry and intake forms, your appointments, your clinical record, our billing, and our email. It applies to our staff and to the practitioners and other clinicians who consult through Aurem.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles in it. As a private sector health service provider we are also bound by state and territory health records legislation, including the Health Records and Information Privacy Act 2002 (NSW). A copy of the Australian Privacy Principles is available at oaic.gov.au.

What we mean by health information

Health information is sensitive information. It gets a higher level of protection under the Privacy Act than an email address does. It covers much more than a diagnosis, so we have listed it in full below.

For us, your health information includes all of the following.

  • Your medical history, your current and past conditions, and the symptoms you describe
  • The medicines you take, their doses, and any allergies or adverse reactions
  • Clinical notes written by your practitioner during and after an appointment
  • Pathology requests and results, and any other test or imaging results we receive
  • Your care plan, your review schedule, and any prescription issued to you
  • Referrals to your GP or another doctor, and letters to and from them
  • Consultation metadata: the date, time, length and mode of an appointment, and who attended
  • Medicare, Department of Veterans' Affairs and private health fund claim details
  • Payment and billing records connected to your care
  • Family history, lifestyle information and anything else you enter in an intake form
  • Photographs or images you send us for a clinical reason
  • The fact that you are a patient of ours at all, and which area of care you booked

The other information we collect

Alongside your health information, we collect everyday personal information. This includes your name, date of birth, address, email address and phone number. Where we need to verify who you are, we also collect your identity documents. Your payment details are processed by our payment provider and are not stored by us.

We also collect technical information when you use this website. That includes your IP address, your browser and device type, the pages you visit and the links you follow, and any campaign parameters attached to the link that brought you here.

Anonymity and pseudonymity

Australian Privacy Principle 2 gives you the option of dealing with an organisation anonymously or under a false name. Health care is one of the situations where that is not workable, and the law recognises it.

Due to the nature of the health services we provide, it is generally impracticable for us to deal with individuals who have not identified themselves. Accurate identification is required to ensure the safety and continuity of clinical care, to comply with our legal and professional obligations under applicable health legislation, and to meet the requirements of Medicare and private health insurance billing.

You can still browse this website without telling us who you are. You can also ask a general question by phone without giving your name. For anything clinical, we will need your legal name and date of birth.

How we collect it

Wherever it is reasonable and practicable, we collect information about you from you. Most of what we hold comes from your intake form and from what you tell your practitioner in an appointment.

We also receive information about you from other people, with your consent or where the law allows it.

  • From a pathology provider, when a test your practitioner ordered comes back
  • From your GP or another treating practitioner, in reply to a request or a referral
  • From a hospital or another health service involved in your care
  • From a family member, carer or advocate you have asked to speak for you
  • From Medicare or your health fund, where a claim is made

Information we did not ask for

From time to time, we may receive personal or health information that we did not solicit. Where we receive unsolicited personal information, we will promptly assess whether that information is of a kind we could have collected under our standard collection practices.

If it is, we handle it under this policy. If it is not, and no law requires us to keep it, we destroy it or de-identify it as soon as practicable.

Why we collect and use it

The primary purpose is your care. The rest follows from that.

  • To assess and advise you, and to treat you where your practitioner deems it medically appropriate
  • To book, run and follow up your appointments and reviews
  • To order tests, write referrals and correspond with your other providers
  • To keep an accurate clinical record, which the law requires us to keep
  • To bill you and process payments, and to make a claim where one applies
  • To answer your questions and handle a complaint
  • To meet our legal, professional and insurance obligations
  • To audit and improve the quality and safety of our own service, using de-identified information wherever that is enough
Secondary use
We may use your information for a purpose closely related to the one above, where you would reasonably expect it. An example is contacting you about a test result you are waiting on.
Consent for health information
Under APP 3.3 we collect health information with your consent, or where the law permits it. Ticking the consent box on an intake form is how you give that consent. You can withdraw it, though we may still have to keep the record.

Who we share it with

We disclose your information only for the reasons set out here, and only as much of it as the recipient needs.

  • The pharmacy you choose, if you are given a prescription. You choose it, not us.
  • The pathology provider that collects and analyses a sample
  • Your usual GP or another treating practitioner, with your consent
  • An emergency service or a hospital, where there is a serious and imminent risk to someone's life, health or safety
  • Our service providers, under contract and only for the job they do for us: the platform that holds your clinical record, our video consultation provider, our booking system, our payment provider, our email provider and our IT support
  • Our insurers and legal advisers, where we need advice or have to defend a claim
  • A court, a tribunal, a regulator or a government agency, where the law requires or authorises it
  • Anyone else you ask us in writing to send it to
What we never do
We do not sell your information. We do not disclose your health information to an advertising platform, and we do not use it to build an advertising audience.

Sending information overseas

Australian Privacy Principle 8 governs disclosure outside Australia, and it keeps us accountable for what an overseas recipient does with your information.

We choose providers that store data in Australia wherever we can. Some of the software we use may store or process data overseas.

Where a provider does hold information overseas, we take reasonable steps to make sure it handles that information consistently with the Australian Privacy Principles, and we say so in the contract. We do not send your health information overseas for a clinical purpose without asking you first.

Government and healthcare identifiers

Your Medicare number, your Department of Veterans' Affairs number and your Individual Healthcare Identifier are government identifiers. Australian Privacy Principle 9 and the Healthcare Identifiers Act 2010 (Cth) limit what we may do with them.

We collect and use them only to identify you for a health purpose, to make or support a claim, or where the law requires it. We do not adopt any of them as our own reference number for you, and we do not disclose them except for those purposes.

My Health Record

Our current position is that we are not registered with the My Health Record system. We do not upload anything to your My Health Record and we do not view it.

If that changes, we will update this policy before we upload anything, and we will tell you. Your My Health Record is yours to control. You can set access controls, see who has looked at it, or cancel it at myhealthrecord.gov.au.

Marketing and how to stop it

We send marketing only to people who have ticked the marketing box. Agreeing to care is not the same as agreeing to marketing, and we do not treat it that way.

Every marketing message we send has a working unsubscribe link. You can also reply to any message, or email us, and ask to be taken off the list. We act on that within 5 business days.

We never use your health information to decide what marketing to send you. We do not target you on the basis of a condition, a care area, a test result or a medicine. We do not upload your details to an advertising platform to build a lookalike or a retargeting audience.

Cookies, analytics and tracking

This website uses cookies and similar technologies. Some are necessary to make the site work and to keep a form session secure. Others measure how the site is used so we can improve it.

What you browse on a health website can say something about you. A page about sleep or weight management can reveal an interest that you would treat as private. We take that seriously, so we do not pass page-level browsing data about care areas to an advertising platform, and we do not run advertising cookies that build a health interest profile.

We capture campaign parameters from the link that brought you here, such as utm_source and gclid, and store them in your browser for up to 30 days so we can tell which campaigns work. That data is not attached to your clinical record.

We use a website feedback and support widget, which sets its own cookie so a conversation can continue between visits.

You can block or delete cookies in your browser settings. Necessary cookies aside, blocking them does not stop you using the site or booking an appointment.

Privacy in a telehealth appointment

A video appointment raises privacy questions that an in-person one does not, so we handle them at the start of every consultation.

Your practitioner confirms who you are and where you are before anything clinical happens. That is a safety requirement as well as a privacy one. It establishes that emergency help could reach you, and that your notes go on the right record.

Your practitioner will tell you if anyone else is present at their end and will ask whether anyone is present at yours. You are welcome to have a support person, carer or interpreter with you. Say so at the start so it can be noted.

We do not record consultations unless there is a specific clinical reason. We never record without asking you first and noting your answer in the record. You must not record a consultation without your practitioner's knowledge and agreement.

Please take the appointment somewhere you can speak freely. We cannot control the privacy of the space you are in or the network you are on.

Automated tools and artificial intelligence

We use software to help with administrative work. That can include transcription of an appointment, drafting a letter, scheduling, and sorting enquiries so they reach the right person.

No automated tool makes a clinical decision at Aurem. A prescribing decision is always made by your practitioner. Anything an automated tool drafts is read and corrected by a person before it goes into your record or is sent to you.

You can ask us whether an automated tool was used in your care, and we will tell you. You can also ask us not to use transcription in your appointments.

How we store and protect it

Your record is held electronically. Access is limited to the people who need it to do their job, and it is logged.

We encrypt information in transit and at rest. We require multi-factor authentication for staff accounts, and we review access rights. We bind everyone who works with us to a confidentiality obligation, and that obligation continues after they leave. Our providers are held to the same standard by contract.

No system is completely safe. If something does go wrong, the next section explains what we have to do.

If there is a data breach

The Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), sections 26WA to 26WR, applies to us.

If we suspect a breach, we assess it within 30 days. If we decide the breach is likely to result in serious harm to you, we must notify you and the Office of the Australian Information Commissioner as soon as practicable.

Our notice tells you what happened, what kind of information was involved, what we have done about it, and what we recommend you do. Where we cannot reach you individually, we publish the notice on this website.

How long we keep your records

Clinical records are kept for a set period, and the clock runs from the last entry in the record, not from the day you first contacted us.

Aurem Health Pty Ltd is registered in New South Wales. Under the Health Records and Information Privacy Act 2002 (NSW), a private sector health provider must keep a health record for at least 7 years from the date of the last entry. Where the patient was under 18 at the date of the last entry, the record is kept until that person turns 25. We consult adults only, so the first period is the one that applies to you.

Where the health records law of another state or territory applies to your care and requires a longer period, we apply the longer period.

Information that is not part of a clinical record, such as an unrelated website enquiry, is destroyed or de-identified once we no longer need it.

Seeing and correcting your record

You can ask for a copy of the information we hold about you. Please put your request in writing. We will check who you are before we release anything.

We respond within 30 days. There is no charge to make a request. We may charge a reasonable fee for the cost of producing a copy, and we tell you the amount before we do the work.

We can refuse access only in the limited situations the Privacy Act and the health records legislation allow. An example is where giving access would pose a serious threat to the life, health or safety of any person. If we refuse, we tell you why in writing, and we tell you how to complain.

If something we hold is wrong, out of date or incomplete, tell us and we will correct it. A clinical note is a record of what was thought at the time, so we do not delete it. Where we do not agree with a correction you have asked for, you can ask us to attach your statement to the record, and we will.

Complaining about privacy

Email us to tell us what happened and what you would like us to do. We acknowledge a privacy complaint within 3 business days and give you a substantive response within 30 days.

You do not have to come to us first. You can go to a regulator at any point.

OAIC
The Office of the Australian Information Commissioner handles complaints under the Privacy Act 1988 (Cth). oaic.gov.au, or 1300 363 992.
IPC NSW
The Information and Privacy Commission New South Wales handles complaints about health information under the Health Records and Information Privacy Act 2002 (NSW). ipc.nsw.gov.au.
Your state or territory
Other states and territories have their own privacy or health complaints body. We will tell you which one applies to you if you ask.

Changes to this policy

We update this policy when what we do changes, and at least once a year. The effective date at the top of the page tells you which version you are reading.

Where a change materially affects how we handle your health information, we tell you before it takes effect.

How to contact us

Write to the privacy officer at Aurem Health Pty Ltd, ABN 78 695 908 420.

Questions about any of this?

Tell us a little about yourself first. Then see a registered Australian practitioner on a video call. You'll leave with a plan and your next review booked.

Contact us