Privacy Policy
Last updated: 14 August 2026
The purpose of this policy is to give you, our patient, clear information on how NexaHealth collects and uses your personal information. Sometimes we also need to share your personal information to involve others in your healthcare. This policy explains when, how and why we share it. Health information is some of the most sensitive information there is, so this policy is written so you can understand exactly what happens to yours.
Who we are
- NexaHealth Pty Ltd
- ABN 72 686 304 638
- 67A Taylor Street, 3, Condell Park NSW 2200
- Email: [email protected]
- Phone: 0402 602 528
We are an Australian telehealth service. Consultations happen by live video with a qualified Australian practitioner. We operate across every state and territory. We do not have a clinic you can visit.
Who can you contact about this policy?
For any enquiry about this policy, contact our privacy officer at [email protected]. That address is monitored, and it is the right place to send a question, an access request, a correction request or a privacy complaint.
The law we follow
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in it. Health information is "sensitive information" under that Act, which means stricter rules apply to it than to ordinary personal information.
Because we are registered in New South Wales, the Health Records and Information Privacy Act 2002 (NSW) also applies to us. We operate Australia-wide, so the health records law of your own state or territory may apply as well. Victoria has the Health Records Act 2001 (Vic). The Australian Capital Territory has the Health Records (Privacy and Access) Act 1997 (ACT). In the remaining states and territories there is no separate health records statute, and the Privacy Act 1988 (Cth) applies. Where two laws cover the same thing, we follow the stricter one.
You can read the Australian Privacy Principles on the website of the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
When and why is your consent necessary?
When you register as a patient, you consent to our practitioners and our team accessing and using your personal information to deliver your healthcare. Access to your personal information is limited to the people who need it for your care or for running the service.
By acknowledging this policy, you consent to us collecting, holding, using, retaining and disclosing your personal information in the ways described below. If we ever want to use your information for a purpose that is not described here, we will ask you first. You can withdraw your consent at any time by contacting us, though that may limit the care we are able to provide.
Why do we collect, use, store and share your personal information?
We collect, use, store and share your personal information mainly to manage your health safely and effectively. That includes:
- providing your care and running your consultation safely
- keeping an accurate clinical record, so your history carries forward to your next consultation
- arranging referrals, tests, reviews and follow-up
- verifying your identity
- taking payment and managing billing and claims
- contacting you about your appointment, your results or your care
- answering your enquiries and handling feedback and complaints
- internal quality and safety improvement, such as audit and team training
- meeting our legal, professional and regulatory obligations
What personal information is collected?
The information we collect about you includes:
- your name, date of birth, gender and contact details
- your residential address, email address and phone number
- emergency contact details, and the details of a parent, guardian, carer or authorised representative where one is involved
- identity verification details, which may include a photo ID check
- the name and contact details of your usual GP, if you have one
- your Medicare number, where it is available, for identification and claiming
- healthcare identifier numbers
- your Department of Veterans' Affairs number and health fund details, where they are needed for a claim, a referral, or a pathology or imaging request
- the fees you have paid and the services they relate to
- payment details, which are processed by our payment provider. We do not store your full card number
What health information is collected?
Health information is far more than your name and email. For our patients it includes:
- the reason for your consultation and the symptoms you describe
- your medical history, current and past conditions, family history and immunisation history
- social history and risk factors, where they are relevant to your care
- diagnoses and clinical impressions
- clinical notes made during and after your consultation, including the advice you were given
- medicines you take, allergies and adverse reactions
- prescriptions issued, and any repeats
- referrals to another doctor or health service, and the letters that go with them
- pathology and imaging requests, and the results that come back
- care plans, scheduled reviews and follow-up arrangements
- medical certificates and letters we issue
- consultation metadata, which means the date, time and length of your consultation, the practitioner you saw, the service booked, and technical connection details
- any health details you choose to send us in an email or a form
Can you deal with us anonymously?
Due to the nature of the health services we provide, it is generally impracticable for us to deal with individuals who have not identified themselves. Accurate identification is required to ensure the safety and continuity of clinical care, to comply with our legal and professional obligations under applicable health legislation, and to meet the requirements of Medicare and private health insurance billing.
You can still ask us a general question about how the service works without giving your name. You cannot book or attend a consultation anonymously.
How is personal information collected?
We may collect your personal information in several ways:
- directly from you, when you register, book, complete an intake form or speak to a practitioner
- when you visit our website, send us an email, telephone us, book online or send us a message through the website
- from our contact form, when you send us an enquiry. That form is for general questions. Please do not put detailed medical information in it
- from your guardian, carer or another responsible person acting for you
- from other healthcare providers involved in your care, such as your usual GP, another doctor, a hospital, a community health service, or a pathology or diagnostic imaging service
- from Medicare, the Department of Veterans' Affairs or your health fund, where a claim is involved
We always comply with our privacy obligations when we collect personal information from a third party. We are open with you about it, we obtain the consents we need, we keep the information accurate, we secure it, and we use it only for the purposes described here. When we collect information from a source other than you, we take reasonable steps to let you know.
The pre-screening quiz
The quiz on our website runs entirely inside your browser. Your answers stay on your device. They are not sent to us, and we do not store them or see them. Nothing you enter in the quiz is collected by NexaHealth. The quiz does not diagnose you and it does not decide anything about your care.
Information we did not ask for
From time to time, we may receive personal or health information that we did not solicit. Where we receive unsolicited personal information, we will promptly assess whether that information is of a kind we could have collected under our standard collection practices.
If we could have collected it, we handle it under this policy. If we could not have collected it, and the law does not require us to keep it, we destroy it or de-identify it as soon as it is lawful and practicable to do so.
When, why and with whom do we share your personal information?
We sometimes share your personal information:
- with the practitioner treating you
- with members of our team who need it to do their job, and no further
- with other healthcare providers, for example in a referral letter to another doctor or health service, and with your consent
- with your usual GP, so your care stays joined up, and with your consent
- with a pathology or imaging provider, where a test is requested
- with the pharmacy you choose, where a prescription is issued. You choose your own pharmacy. We do not direct you to one
- with third parties for business purposes, such as the providers that host and support our systems. They are under contract, they must comply with the Australian Privacy Principles and this policy, and they may use the information only to provide that service to us
- when it is required or authorised by law, for example a court order or a subpoena
- when it is a statutory requirement, for example the mandatory notification of certain diseases, a notification under the Health Practitioner Regulation National Law, or child protection reporting
- when it is necessary to lessen or prevent a serious threat to a patient's life, health or safety, or to public health or safety, or when it is impractical to obtain the patient's consent
- to assist in locating a missing person
- to establish, exercise or defend an equitable claim
- for the purpose of a confidential dispute resolution process
Only people who need to access your personal information will be able to do so. Other than providing medical services, or as otherwise described in this policy, we will not share your personal information with any third party without your consent. We do not sell your information and we do not give it to advertisers.
We do not share your personal information with anyone outside Australia (unless under exceptional circumstances that are permitted by law) without your consent.
Government and healthcare identifiers
Some of the numbers we handle are government identifiers. They include your Medicare number, your Department of Veterans' Affairs number and your Individual Healthcare Identifier (IHI).
- We collect them only where they are needed for your care, for a claim, for a referral, or for a pathology or imaging request.
- We use and disclose them only where the Privacy Act, the Healthcare Identifiers Act 2010 (Cth) and the Health Insurance Act 1973 (Cth) allow it.
- We never adopt a government identifier as our own account number for you. Your NexaHealth record has its own identifier.
- We never use a government identifier for marketing, profiling or research.
My Health Record and electronic prescribing
NexaHealth does not currently participate in My Health Record. Our practitioners do not view your My Health Record and they do not upload anything to it. We do not currently use electronic prescribing. If either of these changes, we will update this policy and tell our patients.
My Health Record is a national system run by the Australian Government, and it is separate from the record we keep. It has its own privacy rules under the My Health Records Act 2012 (Cth). You control your My Health Record, including who can see it and what is in it. You can set your own access controls, or cancel it, through myhealthrecord.gov.au.
Privacy during a video consultation
A telehealth consultation raises privacy questions that an in-person visit does not. Here is how we handle them.
- Identity. Your practitioner confirms who you are at the start of every consultation. You may be asked for your date of birth, your address, or to show photo ID.
- The connection. Consultations run over an encrypted video connection.
- Who else is present. Tell your practitioner at the start if anyone else is in the room with you or can hear you. If someone from our side needs to be present, for supervision or training, your practitioner will tell you who they are and ask your permission before the consultation goes ahead. You can say no.
- Your surroundings. Please take the consultation somewhere private, and use headphones if you can. We cannot control who is around you.
- If telehealth is not suitable. Telehealth is not right for every health concern. Your practitioner may recommend in-person assessment, urgent care, a GP review, a referral to another doctor, further investigation or no treatment, depending on your circumstances. If that happens, the information you have already given us stays in your clinical record and we keep handling it under this policy.
Will your information be used for marketing purposes?
We will not use your personal information to market any goods or services directly to you without your express consent. If you do consent, you can opt out of direct marketing at any time by notifying us in writing.
- Marketing consent is a separate tick box. It is never bundled into a booking, a payment or a health form, and it is never pre-ticked.
- We never choose who receives marketing based on your health information, the service you booked, the conditions in your record, or the health pages you looked at.
- Every marketing email carries an unsubscribe link. You can also opt out at any time by emailing [email protected]. We action it promptly and we do not ask you why.
- Messages about your own appointment, your results or your care are not marketing. You keep receiving those while you are a patient.
How is your information used to improve services?
We may use your personal information to improve the quality of the services we offer, through research, analysis of patient data for quality improvement, and training activities with our team.
We may provide de-identified data to other organisations to improve population health outcomes. If we provide this information to other organisations, patients cannot be identified from the information we share, the information is secure, and it is stored within Australia. You can let us know at [email protected] if you do not want your de-identified information included.
At times, health services are approached by research teams to recruit suitable patients into specific studies that require access to identifiable information. A member of our team may approach you about taking part in research. Researchers will not approach you directly without your express consent having been provided to us. If you provide consent, you would then receive specific information on the research project and how your personal health information will be used, and you can decide to take part or not. Declining has no effect on your care.
How are document automation technologies used?
Document automation is where a system uses existing data to generate electronic documents relating to medical conditions and healthcare.
We use document automation to create documents such as referrals, which are sent to other healthcare providers. These documents contain only your relevant medical information. Document automation runs through secure clinical software.
All users of that software have their own unique login and password, and can only access information that is relevant to their role. We comply with Australian privacy legislation and the Australian Privacy Principles to protect your information. All data, electronic and paper, is stored and managed in line with the Royal Australian College of General Practitioners guidance on privacy and managing health information.
How are artificial intelligence and automated tools used?
- We do not use an AI scribe. Your consultation is not recorded or transcribed by an AI note-taking tool.
- No clinical decision about you is made by software. A qualified practitioner reviews your information and makes every clinical decision, including whether a prescription, certificate, referral or test is issued, if deemed medically appropriate. Advice, a referral, monitoring or no treatment at all are equally possible outcomes.
- The pre-screening quiz on our website is a simple rule-based tool that runs on your own device. It does not diagnose, it does not assess you, and it does not send anything to us.
- We do not use your health information to train any artificial intelligence model, and we do not allow our service providers to do so.
How is your personal information stored and protected?
Your personal information is held as an electronic record. We store all personal information securely, with measures that include:
- individual logins for every staff member and practitioner, with access limited to what their role requires
- encrypted connections for consultations and data transfer
- confidentiality agreements for staff, practitioners and contractors
- regular backups, and access logging
- secure disposal of any paper record or device that has held health information
We do not publish the detail of our security controls, because that would weaken them. No system connected to the internet can be made completely secure, and email and web forms are not fully secure. That is why we ask you to keep clinical detail inside a consultation rather than in an email.
How long we keep your information
We keep your clinical record for at least 7 years from the date of the last entry in it. The clock runs from the last time information was added, which is usually your most recent consultation, not from the date you first became a patient. If you were under 18 at the time of the last entry, we keep the record until you turn 25.
These periods come from the health records law that applies to us and to you. In New South Wales, where we are registered, it is section 25 of the Health Records and Information Privacy Act 2002 (NSW). In Victoria it is the Health Records Act 2001 (Vic). In the Australian Capital Territory it is the Health Records (Privacy and Access) Act 1997 (ACT). In the other states and territories the Privacy Act 1988 (Cth) and our professional obligations apply. Where the law of your state or territory sets a longer period, we keep the record for the longer period.
Information that is not part of a clinical record, such as a general website enquiry, is kept only while we need it, and is then destroyed or de-identified.
If there is a data breach
We are covered by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), sections 26WA to 26WR. If we suspect that personal information has been lost, or accessed or disclosed without authorisation, this is what happens:
- We start assessing it straight away, and we complete that assessment within 30 days.
- We take immediate steps to contain the breach and to reduce the harm it could cause.
- If the breach is likely to result in serious harm and we cannot stop that harm, it is an eligible data breach. We then notify you and the Office of the Australian Information Commissioner as soon as practicable.
- The notice will tell you what happened, what information was involved, what we are doing about it, and what you should do to protect yourself.
- We keep a register of breaches and near misses, and we review what went wrong.
Our privacy officer is responsible for handling a suspected data breach. You can reach them at [email protected].
How can you access and correct your personal information?
You have the right to request access to, and correction of, your personal information. To make a request, email [email protected] and tell us what you need.
- We may ask you to verify your identity first.
- We will respond to a request to access or correct your personal information within 30 days. If we need longer, we will tell you why.
- There is no charge for making a request. A fee may apply for the cost of complying with it, such as copying or posting a large record. Any fee will be reasonable, and we will tell you the amount before we do the work.
- In limited cases the law allows us to refuse access, for example where giving it would pose a serious threat to someone's life, health or safety, or where it relates to legal proceedings. If we refuse, we tell you why in writing, and how to complain about it. Where we can, we offer another way to give you what you need, such as a summary or access through another health practitioner.
We will take reasonable steps to correct your personal information where it is not accurate or up to date. Sometimes we will ask you to check that the information we hold is correct and current. If we correct your record, we may keep the original entry alongside the correction, because a clinical record has to show its own history. If we do not agree that the information is wrong, you can ask us to add a statement to the record saying that you disagree, and we will attach it.
How can you lodge a privacy-related complaint, and how will it be handled?
We take complaints and concerns about privacy seriously. Please tell us about any privacy concern you have, and we will try to resolve it. You can contact us:
- by email at [email protected]
- by phone on 0402 602 528
- by post to NexaHealth Pty Ltd, 67A Taylor Street, 3, Condell Park NSW 2200
We acknowledge your complaint within 2 business days and aim to give you a written response within 30 days. Our feedback and complaints policy sets out the full process.
If you do not feel we have resolved your issue, you can contact the Office of the Australian Information Commissioner. The OAIC will require you to give us time to respond before they investigate. For more information visit www.oaic.gov.au or call 1300 363 992. Depending on where you live, your state or territory privacy or health complaints body may also be able to help. Those bodies are listed on our feedback and complaints page.
How is privacy on the website maintained?
Which pages you look at on a health website can reveal a lot about you, so we treat website data carefully. Any personal information you share with us through our website, by email or through social media is handled securely and confidentially.
- We use essential cookies to make the website work, for example to keep your session going and to keep forms secure. These cannot be switched off without breaking the site.
- We use website analytics and a support and feedback tool, so we can see how the site is used and so you can send us a message from it. These tools may set cookies on your device.
- We may collect standard technical information, such as your browser type, your device type, the pages you visited and the approximate region you visited from. On its own this does not identify you.
- We do not build an advertising profile of you based on the health services or conditions you read about, and we do not pass that information to advertising networks.
- We do not connect website browsing data to your clinical record.
Most browsers let you block or delete cookies in their settings. If you block essential cookies, parts of the website may stop working.
Related policies
- Communication Policy, for how we handle calls, emails, messages, results and after-hours contact.
- Feedback and Complaints, for how to raise a concern with us or with an external body.
- Terms and Conditions, for the terms that apply to using our service.
- Medical Disclaimer, for the limits of the information on this website.
Policy review statement
We review this policy regularly, at least once a year, and whenever the way we work changes or the law changes. If we make any changes:
- they will be reflected on this page
- we may tell patients directly, by email or by other means, if the change is significant
Please check this page from time to time for updates. If you have any questions, please contact us.
Contact us
For any question about this policy, or about how we handle your information, contact us:
- NexaHealth Pty Ltd, ABN 72 686 304 638
- 67A Taylor Street, 3, Condell Park NSW 2200
- [email protected]
- 0402 602 528