Privacy Policy

Atlas Physiotherapy Pty Ltd

Last updated: 13th July 2026

 

Our commitment to your privacy

We are committed to handling personal information about you, including health information about you, in accordance with the requirements of the Commonwealth Privacy Act 1988 (Cth) (Privacy Act), including the Australian Privacy Principles (APPs).

The Privacy Act was significantly reformed by the Privacy and Other Legislation Amendment Act 2024 (Cth), most of which took effect from 10 December 2024. These reforms increased the penalties that can apply for privacy breaches, expanded the powers of the Office of the Australian Information Commissioner (OAIC), and introduced a new statutory tort allowing individuals to sue directly for serious invasions of privacy (in effect from 10 June 2025). This policy has been updated to reflect those changes.

In this Policy, we explain:

•    what kind of personal information we collect and hold about you

•    how and why we collect it

•    what we do with that information and who we share it with (and when)

•    how we store and protect your information, and what we do if there is a data breach

•    whether we use any automated decision-making that affects you

•    your right to seek access to, and if required correction of, the records we hold about you

•    your right to make a privacy complaint, to us and others

•    whether we are likely to disclose information about you to overseas recipients.

What kind of personal information do we collect about you?

We collect and hold the following kind of information about you:

•    your name, address, date of birth, email and contact details

•    information about your family or relatives, and your emergency contact

•    information about other health professionals involved in your care

•    any government identifiers such as Medicare number, DVA number, NDIS number or WorkCover/CTP claim number. However, we do not use these for the purposes of identifying you in our practice

•    other health information about you such as a record of your symptoms, your relevant medical history, the diagnosis made and the treatment we give you, including:

◦    specialist and referral reports

◦    test and imaging results

◦    your appointment and billing details

◦    your prescriptions

◦    your healthcare identifier

◦    your health fund or insurer details

◦    clinical photos, videos or movement recordings taken as part of your assessment or treatment (only with your consent)

◦    information collected through wearables, apps or home exercise programs you choose to share with us

◦    other information about you collected for the purposes of providing care to you.

How do we collect and hold your personal information?

We will generally collect personal information about you in these ways:

•    directly from you when you give us your details (eg. face-to-face, over the phone, via a registration form, our website, an online booking system or a patient portal)

•    from a person responsible for you

•    from a third party where we are permitted by law to do that (eg. other health care professionals involved in your care, from your health insurer, from the My Health Record system, or from a referring GP or specialist).

•    The practice used Cliniko as the practice management system, online booking system and for telehealth. Online bookings can be made through Hotdoc. These systems often store data on cloud servers, which is relevant to the 'overseas disclosure' section below.

Why do we collect and use information about you?

We primarily collect and use personal information about you to provide our physiotherapy services to you and to communicate with you and others involved in your care in relation to those services.

We also sometimes use that information for other purposes, including:

•    to help us manage our accounts and administrative services, including billing, arrangements with health funds, pursuing unpaid accounts, and management of our IT systems

•    to conduct accreditation, quality assurance or internal audits

•    to send you appointment reminders, recall notices or health-related communications (you can opt out of marketing communications at any time).

When and why might we share information about you with others?

We may disclose information about you to others outside of our practice as permitted or required under law. This will include situations where we disclose information about you in order:

•    to comply with our legal obligations (eg. mandatory reporting under legislation, responding to a court order or subpoena)

•    to consult with other health professionals involved in your healthcare

•    to get test results from diagnostic and pathology services

•    to claim on insurance

•    to communicate with your health fund, with government and other regulatory bodies such as Medicare, NDIS or WorkCover

•    to help us manage our accounts and administrative services (eg. billing or debt recovery, arrangements with health funds, pursuing unpaid accounts etc.)

•    to lessen or prevent a serious threat to a patient's life, health or safety, or a serious threat to public health or safety

•    to help in locating a missing person

•    to establish, exercise or defend an equitable claim through the My Health Record

•    to prepare the defence of anticipated or existing legal proceedings

•    to discharge notification obligations to liability insurers

•    to our external service providers who support our practice (eg. IT support, cloud storage/software providers, billing or accounting services), under confidentiality obligations, and only for the purposes of providing those services to us.

Do we use automated decision-making?

From 10 December 2026, businesses must explain in their privacy policy if they use computer programs to make, or materially assist in making, decisions that could significantly affect an individual's rights or interests.  [UPDATED 2026]

We do not currently use automated decision-making that significantly affects your rights or interests. If this changes, we will update this policy accordingly.

Your right to seek access to and to seek correction of the information we hold about you

You have the right to seek access to and correction of the personal information we hold about you. A fee may apply for giving access.

We will normally respond to your request within 30 days. To make the request, you should contact the clinic in writing through the details at the bottom of the document.

If you think that the information we hold about you is not correct, let us know in writing. We will take reasonable steps to correct your personal information where it is not accurate or up-to-date. From time to time, we may also ask you to verify that the information we hold about you is correct and current. Please notify us if and when your contact details change (see 'How to contact us').

Security: how we hold and protect your personal information

We take reasonable technical and organisational steps to protect the information we hold about you. These are designed to prevent unauthorised access, modification or disclosure, and to prevent misuse and loss. This includes:

•    holding physical records in a lockable cabinet with restricted access

•    holding information on an encrypted, cloud-based practice management system

•    multi-factor authentication and strong, unique passwords for accessing our systems

•    access to information restricted on a 'need to know' basis

•    getting staff to sign confidentiality agreements, and providing staff with training or induction about privacy, confidentiality and cyber-security

•    keeping our software, devices and systems up to date with security patches

•    only retaining personal information for as long as we need it for the purpose we collected it, or as required by law (health records are generally required to be kept for at least seven years after your last consultation, or, for patients who were minors, until they turn 25 and taking reasonable steps to destroy or de-identify it securely once it is no longer needed.

What we do if there is a data breach

Despite our precautions, no system is completely secure. If we experience a data breach that is likely to result in serious harm to you (an 'eligible data breach'), the Notifiable Data Breaches scheme in the Privacy Act requires us to notify both the OAIC and any individuals at likely risk of serious harm, and to explain the steps you can take in response.  [UPDATED 2026]

We maintain a data breach response plan so that, if a breach occurs, we can contain it quickly, assess the risk of harm, and notify affected individuals and the OAIC as required.

Your right to receive treatment from us anonymously (or by using a pseudonym)

Where it is lawful and practicable for us to do so, you can be treated anonymously or through the use of a pseudonym (a name other than yours).

Disclosing information about you overseas

Cliniko is used by businesses around the world. Cliniko meets the privacy requirements in many regions, including abiding by GDPR, HIPAA, PIPEDA, UK Data Protection Act, and the Australian Privacy Principles.

We may disclose your personal information to the following overseas recipients:

•    any health professional who helps us to provide our physiotherapy services to you (eg. health professionals who treated you when you were overseas) or anyone else you authorise us to contact

•    our overseas-based cloud storage and software providers (eg. our practice management, booking or telehealth platforms) - [note: name the provider(s) and, if known, the country/countries where your data is hosted]

 

If we want to transfer your personal information overseas, we will first seek your consent, unless we are required or permitted by law to do the transfer, or the overseas recipient is subject to a law or scheme that the Australian Government has recognised as providing a comparable level of privacy protection.

 

If you have a privacy-related concern about us

If you have concerns about the way we've handled your privacy, let us know. You should do that in writing. We will then try to respond to you within 30 days.

If you are not satisfied with our response, you can refer your complaint to the Office of the Australian Information Commissioner (OAIC), whose contact details are:

Phone: 1300 363 992

Email (complaints): oaicintake@oaic.gov.au

Email (general enquiries): enquiries@oaic.gov.au

Post: GPO Box 5288, Sydney NSW 2001

Website: https://www.oaic.gov.au/privacy/privacy-complaints/

Separately, under the statutory tort for serious invasions of privacy introduced by the 2024 reforms, you may also have a personal right to bring a civil claim against us if you believe we have seriously invaded your privacy - for example, by intruding on your seclusion or misusing your personal information. This is independent of, and in addition to, your right to complain to us or to the OAIC.  [UPDATED 2026]

Our website and online tools

If you visit our website or use our online booking system, we may collect information such as your IP address, browser type, the pages you visit and how you found our website, using cookies or similar tracking technologies. We may use this information, and tools such as Google Analytics, to understand how our website is used and to improve our services. You can adjust your browser settings to limit or block cookies, though this may affect how our website functions. We may run targeted advertising (eg. Meta/Facebook Pixel) or use online tracking for marketing purposes.

Updating this policy

We will update this policy from time to time to reflect any changes in our information-handling practices or the law, or both, by displaying the updated policy at reception, or posting it on your website.

 

 

How to contact us

To contact us about any privacy-related issues, please approach:

Tom Dixon

0431 740 942

tom@atlasphysiosydney.com.au