Pandion Health is committed to best practice in the management of information we collect, in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains the kinds of information we collect and hold, how we collect and hold personal information, the purposes for which we collect, hold, use and disclose personal information, the limited circumstances in which we may disclose it without your consent, how you can access and correct your personal information, and how you can make a complaint about a breach of the APPs.
1. Types of personal information collected
The information we collect may include:
- Personal details: name, address, date of birth, email, contact details.
- Identifiers: Medicare number, DVA number, and other government identifiers, used for healthcare claiming and identity verification but not as our internal patient identifier.
- Health information:
- Clinical notes, symptoms, diagnoses, treatments, test results, and specialist reports.
- Appointment and billing details.
- Prescriptions and pharmaceutical purchase history.
- Genetic information.
- Healthcare identifiers.
- Information about race, sexuality, or religion where relevant to your care.
- Technical and website data:
- IP address, device type, browser, operating system, referring URL, and pages visited.
- Form submission metadata (date, time, completion status).
- Cookies and similar tracking technologies (see Section 11).
2. How we collect and hold personal information
We collect personal information:
- Directly from you (in person, by phone, via forms, online registration).
- From a person responsible for you.
- From third parties, where permitted by law (e.g. your treating team, hospitals, diagnostic centres, Medicare, My Health Record, electronic prescription services).
Online intake and triage forms. Intake and triage forms are provided through Halaxy, our practice management and clinical records platform. You receive a secure link by email that opens the form, and the link expires after a set period. Before submission, you give explicit consent to Pandion Health collecting and using your health information, and that consent is recorded with your submission.
When you submit the form, your responses are saved directly into your clinical record in Halaxy. There is no separate transfer between systems. Halaxy stores Australian practice data in Australia. Halaxy’s own disclosures to overseas service providers are described in Section 8.
We hold personal information in secure, access-controlled electronic systems, and where applicable, in locked physical storage.
3. Purposes for collecting personal information
We use and disclose your personal information for purposes including:
- Providing health services to you.
- Communicating with you about your care.
- Liaising with other healthcare providers involved in your treatment.
- Managing accounts, billing, IT systems, and administrative functions.
- Meeting legal obligations, including mandatory reporting — see Section 4, When we may use or disclose your information without your consent.
- Identification and health insurance claiming.
- Using electronic prescription and secure messaging systems.
- Liaising with health funds, Medicare, DVA, and regulatory bodies as required.
- Reviewing the quality and safety of the care we provide, including clinical audit and peer review within our practice.
- Sending you optional marketing and educational communications about Pandion Health services, where you have opted in. You can withdraw consent at any time by clicking “unsubscribe” in any email or by emailing reception@pandionhealth.com.au.
- Improving our website, intake forms, and services through aggregate analytics.
Quality assurance and clinical audit
From time to time we review our own clinical records to check and improve the quality of our care and our documentation. This is known as clinical audit and peer review. It is carried out by our own practitioners, within the practice, using our normal record systems. We do not share your information outside Pandion Health for this purpose, and the findings we record are de-identified. This is a standard part of maintaining professional standards and meeting our practitioners’ continuing professional development obligations.
4. When we may use or disclose your information without your consent
Confidentiality is central to the care we provide. In almost all situations, your health information stays between you and your treating team, and is used and disclosed only as described in Section 3.
Australian law, however, requires or permits us to disclose personal information without your consent in a small number of circumstances:
- Where required or authorised by law, including:
- Mandatory reporting of suspected child abuse or neglect under state and territory child protection laws. As a national telehealth practice, our clinicians’ reporting obligations generally follow the state or territory where the patient is located.
- Mandatory notification of certain infectious diseases to public health authorities.
- Court orders, subpoenas and coronial requests.
- Compliance and audit activities by Medicare, DVA and other government agencies.
- Mandatory notifications about registered health practitioners to AHPRA under the Health Practitioner Regulation National Law.
- Where we reasonably believe disclosure is necessary to lessen or prevent a serious threat to the life, health or safety of any person, including you, or to public health or safety. For example, if we hold serious concerns for your immediate safety, or the safety of a child or another person, we may contact emergency services, a crisis team, your emergency contact or the relevant authority.
- Other situations permitted under the Privacy Act 1988 (Cth), such as assisting to locate a missing person, or where reasonably necessary to establish, exercise or defend a legal claim, including disclosure to our insurers, medical defence organisation and professional advisers.
In every case, we disclose only the minimum information necessary, and only to the appropriate person or authority. Where it is possible, safe and appropriate to do so, we will tell you that a disclosure has been made.
5. AI scribe and artificial intelligence tools
- We may utilise a note-taking AI scribe to accurately and efficiently capture the details of our discussions and the outcomes of our appointments.
- The use of an AI scribe is at the discretion of your individual clinician — not all Pandion Health clinicians use one.
- We only permit our clinicians to use AI scribe tools whose providers are required to handle personal information in accordance with Australian privacy law, including the Australian Privacy Principles, and who apply appropriate security safeguards to sensitive health information. You can opt out at any time as described below.
- Some AI scribe providers may store or process information outside Australia. Regardless of where a provider is located, the requirements above apply. See also Section 8, Overseas disclosure of personal information.
- AI scribes allow us to focus more on our conversation and less on manual notetaking, enhancing the quality of care you receive.
- The use of this tool is aimed solely at improving your healthcare experience.
- Please discuss with your clinician if you do not wish to use AI scribe during your consultation and your preference will be accommodated.
Your rights and consent
- When you consent to AI scribe tools being used for the purpose of session notes, this consent applies to all appointments unless you specify that you do not wish to have AI scribe active.
- You have the right to opt out at any time, and your preference will be recorded in your health record.
- If you opt out, no audio will be recorded, and only manual note-taking will occur.
- AI scribe data is used only for clinical documentation purposes and is not used for training AI models without your consent.
6. Access and correction
- You may request access to, or correction of, the personal information we hold about you. Requests can be sent to reception@pandionhealth.com.au.
- We may require you to verify your identity before releasing or correcting personal information, to protect against unauthorised access.
- We will respond within 30 days. If we refuse access or correction, we will provide written reasons and information about how to lodge a complaint.
7. Storage and security
We take reasonable steps to protect your information from misuse, loss, and unauthorised access. Security measures include:
- Clinical records, intake and triage form submissions are held in Halaxy, which stores Australian practice data in Australia.
- Administrative documents — correspondence, reports and scanned documents that are not part of the clinical record — are held on Microsoft SharePoint Online, hosted in Australian data centres.
- Encryption of electronic records in transit and at rest.
- Multi-factor authentication and role-based access controls for all staff.
- Staff training in privacy, confidentiality, and information security.
- Regular review of our security practices and processor agreements.
We comply with the Notifiable Data Breaches Scheme under the Privacy Act 1988 (Cth). If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.
8. Overseas disclosure of personal information
Some of the service providers we use to deliver our services are located outside Australia, are part of corporate groups headquartered outside Australia, or engage service providers of their own who are located overseas. In line with Australian Privacy Principle 8, we disclose these arrangements to you below.
Wherever an overseas provider processes your personal information, we take reasonable steps to ensure they handle that information consistently with the Australian Privacy Principles, including through written agreements.
| Provider | Location | Purpose |
|---|---|---|
| Halaxy Pty Ltd | Australia. Australian practice data is stored in Australia | Practice management, clinical records, and intake and triage forms. Halaxy engages service providers of its own, some located overseas — including in the United States — for hosting infrastructure, messaging, error monitoring and analytics. Halaxy publishes a current list of these providers in its privacy policy at halaxy.com/privacy/au and requires them to protect the information they handle |
| Microsoft Corporation | United States parent; data hosted in Australia | SharePoint Online (administrative document storage) and Microsoft 365 |
| Google LLC | United States | Website analytics and reCAPTCHA bot protection on forms |
| Vision6 | Australia | Email and SMS marketing communications (only if you have opted into our mailing list) |
| AI scribe providers (clinician-selected) | Varies by provider | Clinical note-taking during consultations, only where your clinician uses an AI scribe and you have not opted out. All providers are required to handle your information consistently with the Australian Privacy Principles |
Where we, or the providers we use, disclose your information outside Australia, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
The list above reflects our principal overseas-touching providers at the time this policy was published. We review this list periodically. If we add a new overseas provider that materially affects how your information is handled, we will update this policy.
9. How long we keep your information
We retain personal information only as long as necessary for the purposes it was collected, or as required by law.
- Intake and triage form submissions. These are saved into your clinical record on submission, and retained on the same basis as the rest of that record (see the next point).
- Clinical records. We retain clinical records in line with our legal obligations under Australian state and territory health records legislation. For adult patients, this typically means at least 7 years from the date of last contact. For patients who were under 18 at the time of their care, records are kept until they turn 25, or 7 years from last contact, whichever is later.
- Marketing contacts. If you have opted into marketing communications, we retain your contact details until you withdraw consent or we cease offering the service.
- Website analytics. Aggregate analytics data is retained in line with the settings of our analytics provider (currently 14 months for Google Analytics).
Where information is no longer needed and is not required to be retained by law, we securely delete or de-identify it.
10. Children and young people
Pandion Health provides clinical services to children, adolescents and adults.
For younger children, intake forms and consent are completed by a parent or legal guardian on the child’s behalf. A child’s clinical information is treated with the same level of confidentiality as any adult patient’s.
There is no single fixed age at which a young person can consent for themselves. As young people mature, many develop the capacity to consent to their own care and to make decisions about how their health information is handled. Where a clinician assesses that a young person has this capacity, we will discuss what this means for how their information is shared — including with parents and guardians — with the young person and their family before treatment begins.
Our clinicians are mandatory reporters under state and territory child protection laws. See Section 4, When we may use or disclose your information without your consent.
If you believe a child has provided us with personal information without appropriate parental or guardian involvement, please contact us at reception@pandionhealth.com.au.
11. Cookies and website analytics
Our website uses cookies and similar technologies to understand how visitors use the site and to improve performance. We use:
- Essential cookies required for the site to function.
- Analytics cookies provided by Google Analytics (via Google Tag Manager), which help us understand visitor behaviour in aggregate. These cookies do not identify you personally.
- reCAPTCHA, provided by Google, on our intake forms to detect and prevent automated abuse.
You can disable cookies through your browser settings. Disabling essential cookies may affect site functionality.
12. Complaints
If you believe we have breached your privacy, please contact us in writing:
- Email: reception@pandionhealth.com.au
- Post: Privacy Contact, Pandion Health, Level 1, 22-28 Edgeworth David Avenue, Hornsby NSW 2077
We will acknowledge your complaint within 5 business days and respond substantively within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC):
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
- Website: www.oaic.gov.au
13. Anonymity and pseudonyms
Where possible, you may choose not to identify yourself or to use a pseudonym. However, in many cases, accurate identification is required for safe and effective healthcare delivery.
14. Updates to this policy
We review this policy at least annually and publish updates at www.pandionhealth.com.au/privacy-policy. The “last updated” date at the top of this policy reflects the most recent change.
Where we make material changes to how we handle your personal information, we will take reasonable steps to notify you — for example, by email to active patients or by a notice on our website.
If you have any privacy-related queries, please contact reception@pandionhealth.com.au.