

OUR PRIVACY POLICY
InTouch Health Co.
1004/31C Lasso Road, Gregory Hills NSW 2557
Phone: (02) 4648 3500
Effective: August 2026
Last reviewed: August 2026
1. Our commitment to your privacy
InTouch Health Co. is committed to protecting the privacy, confidentiality and security of the personal and health information entrusted to us.
We are a multidisciplinary private allied health clinic providing a range of health services. We recognise that health information is sensitive and take our obligations concerning the collection, storage, use, disclosure and protection of this information seriously.
We manage personal and health information in accordance with applicable privacy legislation, including:
● the Privacy Act 1988 (Cth);
● the Australian Privacy Principles (APPs);
● the Health Records and Information Privacy Act 2002 (NSW) (HRIP Act);
● the Health Privacy Principles (HPPs); and
● other applicable professional, regulatory and legal requirements.
This Privacy Policy explains how InTouch Health Co. collects, holds, uses, discloses and protects personal and health information and how you may access or correct your information or make a privacy complaint.
2. Who this policy applies to
This policy applies to personal and health information handled by InTouch Health Co., including information relating to patients, prospective patients, parents, guardians, carers and other individuals who interact with our clinic.
Our multidisciplinary clinic provides services that may include:
● Osteopathy
● Remedial Massage
● Acupuncture and Traditional Chinese Medicine
● Psychology
● Speech Pathology
● Dietetics and Nutrition
● Naturopathy
● Midwifery and Lactation Consulting
● other allied and complementary healthcare services offered by the clinic from time to time.
Practitioners providing services at InTouch Health Co. may include employees and independent health practitioners or contractors.
3. What information we collect and hold
The information we collect depends on the services you receive and your individual circumstances.
Personal and contact information
We may collect information including:
● your name;
● date of birth;
● address;
● telephone number;
● email address;
● emergency contact details;
● parent, guardian or carer information;
● relevant demographic information;
● Medicare details;
● private health insurance details;
● DVA, NDIS, workers compensation, CTP or other funding or insurer information;
● referral information;
● billing and payment information; and
● information reasonably necessary to identify, communicate with and provide services to you.
Health and sensitive information
We may collect health and sensitive information relevant to the healthcare we provide, including:
● current and previous health conditions;
● symptoms and presenting concerns;
● medical and surgical history;
● medications and supplements;
● allergies;
● injuries;
● diagnoses;
● physical and mental health information;
● psychological history where relevant;
● pregnancy, fertility, birth, infant feeding and reproductive health information where relevant;
● developmental history;
● speech, communication or feeding information;
● nutrition and lifestyle information;
● family health history where relevant;
● previous treatment and healthcare providers;
● referrals;
● medical reports;
● pathology and imaging results;
● assessments and clinical findings;
● treatment and management plans;
● progress and clinical notes; and
● correspondence relating to your healthcare.
We aim to collect only information reasonably necessary for our functions and activities and for the provision and management of your healthcare.
4. How we collect information
Where reasonable and practicable, we collect personal and health information directly from you.
Information may be collected when you:
● make an appointment;
● contact the clinic;
● complete an online or paper registration, health history or consent form;
● attend an appointment;
● communicate with your practitioner or our administration team;
● provide medical reports, referrals or other documents;
● use our website or online booking system;
● communicate with us by telephone, SMS, email or another authorised method; or
● make a payment or health fund, Medicare or other claim.
Where appropriate and permitted by law, we may also receive information from third parties including:
● your GP;
● medical specialists;
● hospitals;
● allied health practitioners;
● maternity care providers;
● pathology or diagnostic imaging providers;
● parents, guardians or carers;
● schools or childcare providers where relevant and appropriately authorised;
● Medicare;
● private health insurers;
● NDIS nominees, plan managers or other authorised participants;
● workers compensation or CTP schemes;
● solicitors or authorised representatives; and
● other people or organisations involved in your healthcare.
Where we collect health information about you from another person, we will take reasonable steps to notify you where required by law.
5. Why we collect, hold, use and disclose information
The primary purpose for collecting your personal and health information is to provide and manage your healthcare.
We may collect, hold, use and disclose information for purposes including:
● assessing your healthcare needs;
● providing healthcare and treatment;
● developing and reviewing treatment plans;
● maintaining appropriate clinical records;
● communicating with you about your healthcare;
● arranging, confirming and managing appointments;
● managing referrals;
● communicating with other healthcare providers involved in your care;
● preparing reports where appropriately authorised;
● processing accounts and payments;
● processing Medicare, private health insurance, NDIS, DVA, workers compensation, CTP or other claims;
● clinical governance and patient safety;
● responding to enquiries, complaints and requests;
● operating and administering the clinic;
● meeting professional, insurance, regulatory and legal requirements; and
● other purposes permitted or required by law.
We will not use or disclose health information for an unrelated secondary purpose unless you have consented or the use or disclosure is otherwise authorised or required by law.
6. Multidisciplinary care and sharing information within the clinic
InTouch Health Co. is a multidisciplinary healthcare clinic.
Patients may receive treatment from more than one practitioner within the clinic. However, working within the same clinic does not give a practitioner an unrestricted right to access another practitioner’s patient records.
Access to identifiable patient information must have a legitimate clinical or administrative purpose and be limited to information reasonably necessary for that purpose.
Where practitioners are directly involved in a patient’s care, relevant information may be shared where the patient has consented, where the patient would reasonably expect the information to be shared for their healthcare and the disclosure is permitted by law, or where another lawful basis permits or requires the sharing of information.
Only information reasonably necessary for the relevant purpose should be shared.
7. Peer consultation, supervision and clinical case discussion
Our practitioners may consult with other practitioners or participate in clinical case discussions for legitimate professional purposes, including:
● peer consultation;
● clinical supervision;
● obtaining another practitioner’s professional perspective;
● professional development;
● clinical education;
● quality improvement; and
● improving the safety and quality of healthcare provided at InTouch Health Co.
Where the patient’s identity is not necessary for the purpose of the consultation or discussion, patient information will be de-identified wherever reasonably practicable.
Practitioners participating in de-identified case discussions should avoid using a patient’s name, date of birth, contact details or other information that could reasonably identify the patient.
All practitioners and staff participating in clinical discussions remain subject to confidentiality, privacy, professional and ethical obligations.
A de-identified discussion of a clinical case does not provide another practitioner with permission to access that patient’s clinical record.
If identifiable health information needs to be shared for direct patient care, supervision, training or another purpose, this will only occur where there is an appropriate lawful basis, including consent where required, or where the use or disclosure is otherwise permitted or required by law.
8. Access by administration staff
Authorised administration staff may access personal and health information where reasonably necessary to perform their role.
This may include access required for:
● appointment management;
● patient communications;
● billing and payment;
● Medicare and health fund claiming;
● managing referrals;
● sending or receiving appropriately authorised correspondence;
● responding to records requests; and
● other legitimate clinic administration.
Administrative access does not permit staff to access patient records out of curiosity or for purposes unrelated to their duties.
9. Sharing information with external healthcare providers
Where appropriate and permitted by law, relevant health information may be communicated to healthcare professionals involved in your care.
This may include:
● GPs;
● medical specialists;
● allied health practitioners;
● hospitals;
● maternity care providers; and
● other treating health professionals.
Where consent is required, we will obtain it before disclosing the information.
We aim to disclose only information reasonably necessary for the relevant purpose.
10. Children and young people
We take particular care when handling the information of children and young people.
Depending on the child’s age, maturity, circumstances and capacity, consent may be obtained from:
● the child or young person;
● a parent;
● a legal guardian; or
● another person with lawful authority.
A child or young person who has sufficient understanding and capacity may have privacy and confidentiality rights independently of their parent or guardian.
Requests by parents or guardians for access to a child’s records will therefore be considered individually, taking into account the child’s capacity, applicable privacy legislation, the child’s circumstances and other legal and professional obligations.
11. Particularly sensitive health information
All health information is treated as sensitive information.
Particular care may be required when managing information relating to matters such as:
● psychology and mental health;
● trauma;
● reproductive and sexual health;
● fertility and pregnancy;
● family circumstances;
● children and young people; and
● other particularly sensitive clinical matters.
Information will not automatically be released to a spouse, partner, parent, family member, employer or other person merely because of their relationship with the patient.
Appropriate consent, authority or another lawful basis for disclosure must exist.
12. Appointment reminders and healthcare communications
We may use your contact details to communicate with you about your healthcare and our relationship with you.
This may include:
● appointment confirmations;
● appointment reminders;
● appointment changes;
● waitlist notifications;
● recalls and recommended follow-up appointments;
● practitioner availability relevant to your care;
● requests to complete forms;
● information relating to referrals or treatment; and
● other clinical or administrative communications.
Please tell us if there is a particular telephone number, email address or communication method that should or should not be used to contact you.
13. Direct marketing
Health information is sensitive information.
We will only use or disclose health information for direct marketing where we have the consent required by applicable privacy law.
Where you separately choose to receive marketing communications, we may send information about:
● clinic services;
● practitioner updates;
● new services;
● clinic news;
● events; and
● health information.
Consent to marketing is optional and is not a condition of receiving healthcare at InTouch Health Co.
You may withdraw your marketing consent or unsubscribe from marketing communications at any time.
Withdrawing marketing consent will not affect your healthcare.
14. Our electronic systems and service providers
We use electronic systems and third-party service providers to assist with the operation of our clinic.
These may include services used for:
● electronic health and clinical records;
● practice management;
● online appointment booking;
● digital patient forms;
● SMS and email communication;
● website services;
● payment processing;
● accounting;
● Medicare and health claiming;
● secure document storage;
● data backup; and
● other clinic administration.
We take reasonable steps appropriate to the circumstances to select and use systems and service providers in a way that protects personal and health information.
Access to systems containing patient information is restricted to authorised persons as reasonably necessary for their role.
15. Interstate and overseas processing, storage and disclosure
Some of the technology providers used by InTouch Health Co. may process, store or provide authorised access to personal information outside New South Wales or Australia.
Depending on the service being used, personal information may be processed or accessible in countries including:
● Australia;
● the United States of America; and
● the United Kingdom,
and potentially other countries in which an authorised service provider or subprocessor operates.
For example:
● Cliniko uses a number of technology and infrastructure subprocessors, some of which are located in the United States and United Kingdom;
● Heidi Health provides Australian data localisation for Australian customers, although some functionality may involve international third-party service providers; and
● Mailchimp may process information in the United States and other countries in which its related entities and service providers operate.
The location of service providers may change over time.
Where personal or health information is transferred, processed or disclosed outside New South Wales or Australia, InTouch Health Co. takes reasonable steps appropriate to the circumstances to ensure the information is handled consistently with applicable privacy requirements, including the Australian Privacy Principles and the Health Privacy Principles.
InTouch Health Co. periodically reviews the privacy and security arrangements of service providers that handle patient information.
16. Artificial intelligence and clinical documentation technology
InTouch Health Co. may use appropriately selected artificial intelligence and automated technologies to support healthcare administration and clinical documentation.
Some practitioners use Heidi Health, an AI-assisted clinical documentation service, to assist in documenting consultations and preparing clinical notes.
Where this technology is used:
● information from the consultation may be processed for the purpose of generating clinical documentation;
● the treating practitioner remains responsible for reviewing, correcting and approving the final clinical record;
● AI-generated content does not replace the practitioner’s professional judgement or responsibility;
● patient information must only be used through clinic-approved systems that have undergone appropriate privacy and security consideration; and
● patient-identifiable health information must not be entered into unapproved general-purpose or publicly available generative AI systems for clinical or administrative purposes.
Heidi Health states that patient data processed through its clinical documentation service is not used to train, develop or improve its AI models and that Australian customers have Australian data localisation.
If InTouch Health Co. introduces other artificial intelligence systems that materially change the way patient information is collected, used, disclosed or processed, we will review our privacy practices and update this Privacy Policy where required.
17. Photographs, video and audio recordings
Photographs, video recordings or audio recordings that identify a patient will only be created, collected, stored or used where there is an appropriate clinical, administrative or other lawful purpose.
Where consent is required, appropriate consent will be obtained.
Consent for clinical photography or recording does not constitute consent for marketing, advertising or social media use.
Separate express consent will be obtained before identifiable patient images, recordings, testimonials or other patient material are used for promotional or marketing purposes.
18. Security of personal and health information
We take reasonable steps to protect personal and health information from:
● misuse;
● interference;
● loss;
● unauthorised access;
● unauthorised modification; and
● unauthorised disclosure.
Depending on the circumstances, safeguards may include:
● secure electronic practice-management and clinical-record systems;
● individual user accounts;
● password and authentication controls;
● access restrictions;
● secure storage of physical records;
● appropriate device and network security;
● staff and practitioner confidentiality requirements;
● limiting access according to role and purpose;
● privacy and security procedures;
● staff training; and
● procedures for responding to suspected privacy and data breaches.
No electronic system can be guaranteed to be completely secure. We periodically review our privacy and security practices and take reasonable steps to respond to identified risks.
19. Data breaches
InTouch Health Co. maintains processes for responding to actual or suspected privacy and data breaches.
Where an actual or suspected breach occurs, we will take appropriate steps to:
● contain the incident;
● investigate what occurred;
● assess the nature and potential consequences of the breach;
● take appropriate remedial action;
● reduce the risk of further harm; and
● determine whether notification is required.
Where the Commonwealth Notifiable Data Breaches scheme or another notification obligation applies, we will notify affected individuals and the relevant regulator as required by law.
20. Retention and disposal of health records
We retain health records for the periods required by applicable NSW legislation and any other relevant professional or legal requirements.
For private health service providers in NSW, health information is generally required to be retained:
● where the patient was 18 years or older when the information was collected — for at least 7 years from the last occasion on which a health service was provided to the patient; and
● where health information was collected while the patient was under 18 years of age — until the patient reaches 25 years of age.
Information may be retained for longer where required or appropriate due to other legal, clinical, insurance or professional obligations.
When health information is lawfully destroyed or disposed of, we take reasonable steps to do so securely and maintain records of disposal where required by law.
21. Accessing your information
You may request access to personal and health information that we hold about you.
Requests may be made by contacting InTouch Health Co. using the details below.
We may need to verify your identity or authority before releasing information.
Access may be provided in an appropriate form, such as:
● an electronic copy;
● a paper copy;
● inspection of the record;
● a summary where appropriate; or
● another form permitted by law.
There are limited circumstances in which access may be refused or restricted under applicable law. Where access is refused, we will provide reasons where required and permitted to do so.
We will respond to requests within the timeframes required by applicable law.
Any fee charged for providing access will only be charged where permitted and will not be excessive.
22. Correcting your information
We take reasonable steps to ensure that personal and health information is accurate, up to date, complete, relevant and not misleading for the purposes for which it is held.
If you believe information we hold about you is incorrect, incomplete, out of date, irrelevant or misleading, you may request correction.
We will consider and respond to correction requests in accordance with applicable privacy law.
23. Requests from third parties
We do not provide patient information to another person or organisation simply because they request it.
This includes requests from:
● family members;
● spouses or partners;
● employers;
● schools;
● insurers;
● solicitors; and
● other third parties.
Before releasing information, we may need to establish that:
● the patient has provided valid consent or authority;
● the requesting person has lawful authority to act for the patient;
● disclosure is reasonably expected and permitted by law;
● disclosure is required or authorised by law; or
● another lawful exception applies.
We may require written authority and appropriate proof of identity before releasing information.
24. Disclosure required or authorised by law
There are circumstances in which personal or health information may be used or disclosed without the patient’s consent.
These may include circumstances where disclosure is:
● required or authorised by legislation;
● required by a court, tribunal or other lawful process;
● necessary in certain circumstances involving a serious threat to life, health or safety;
● required to meet mandatory reporting obligations; or
● otherwise permitted under applicable privacy legislation.
Where appropriate, we aim to disclose only information reasonably necessary for the relevant purpose.
25. Anonymity and pseudonyms
Where lawful and practicable, individuals may have the option of dealing with us anonymously or using a pseudonym.
However, this will often not be practicable when providing healthcare, maintaining clinical records, processing claims, communicating with other healthcare providers or where identification is required by law.
26. Privacy complaints
If you believe we have not handled your personal or health information appropriately, please contact us.
We take privacy concerns seriously and encourage you to raise the matter with us so that we have an opportunity to investigate and respond.
A privacy complaint should include sufficient information for us to understand the concern and investigate what occurred.
We will:
1. acknowledge the complaint;
2. review and investigate the circumstances;
3. seek further information where necessary;
4. take appropriate remedial action where required; and
5. provide a response within a reasonable period.
We generally aim to respond to privacy complaints within 30 days, although more complex matters may require additional time.
Contact our Privacy Officer
Privacy Officer
InTouch Health Co.
1004/31C Lasso Road
Gregory Hills NSW 2557
Phone: (02) 4648 3500
Email: [INSERT PRIVACY/CONTACT EMAIL]
If you are not satisfied with our response, you may also have the right to contact the:
Office of the Australian Information Commissioner (OAIC)
for matters concerning the Privacy Act 1988 and Australian Privacy Principles.
and/or
Information and Privacy Commission NSW (IPC NSW)
for matters concerning the Health Records and Information Privacy Act 2002 (NSW) and Health Privacy Principles.
27. Changes to this Privacy Policy
Privacy law, healthcare practices and technology change over time.
We may update this Privacy Policy to reflect:
● legislative or regulatory changes;
● changes to our services;
● changes to technology or service providers;
● changes to our information-handling practices; or
● updated professional or privacy guidance.
The current version of this policy will be available on our website.
Effective date: August 2026
Last reviewed: August 2026