Skip to main content
Skip to content

For Australian allied health practices

Your clients' most sensitive information. Could you prove how it is protected?

For health service providers, the Privacy Act can apply regardless of business size.

Clinical notes, mental health assessments, Medicare and NDIS detail, referrals and reports. Health information is sensitive information, which lifts what counts as reasonable steps.

Your practice software secures the records. Cleverer proves the rest: who carries which obligation, what each person completed and acknowledged, and when the practice last reviewed it.

Five minutes, no email required to see your result. Built for practices with clinicians and admin teams, from a single clinic to a multi-site group.

Where the confidence usually runs out
1
"Our practice software handles privacy." It secures the records. It does not record what your team was required to do with them.
2
"Everyone here knows not to share client information." Almost certainly true. Also unprovable, which is the part that matters afterwards.
3
"We are too small to be looked at." Size affects what is reasonable. It does not decide whether the Act applies to you.
Sound familiar

Almost everything that moves through the front desk is sensitive information.

Psychology, physiotherapy, occupational therapy, speech pathology, exercise physiology and multidisciplinary clinics all run on the same flow of documents.

  • Clinical notes and assessments Including mental health notes, risk assessments and observations a client would never expect to be read by anyone else.
  • Referrals and practitioner correspondence GP referrals, specialist letters, discharge summaries and reports that travel by email between organisations.
  • Medicare, DVA and health fund detail Card numbers, item numbers, care plan documentation and claiming history.
  • NDIS participant information Plans, goals, funding detail, support coordinator correspondence and progress reporting.
  • Third party reports Insurer, WorkCover, school, employer and court reports, each with its own disclosure expectations.
  • Guardian, parent and carer records Detail about people who are not the client, held because the client's care requires it.

Reception, intake, billing and practice management staff handle most of this before a clinician ever opens the file. Their obligations are the ones least often written down.

The bit most practices have wrong

What the Act actually says about a practice your size.

The $3 million small business exemption is real, and a lot of allied health owners assume it covers them. For a practice that provides a health service and holds health information, it does not. The OAIC's position is that all organisations that provide a health service and hold health information are covered by the Privacy Act, whether or not they are a small business, and it names allied health professionals among them. A sole practitioner and a twenty-clinician group are both APP entities.

Health information is also sensitive information under the Act, which raises the bar. Reasonable steps under APP 11 are assessed against the nature of the information held, and the OAIC's guidance treats those steps as both technical and organisational measures, listing governance, culture and training first among the areas to consider. APP 1.2 goes further and asks for practices, procedures and systems that are implemented, not simply written.

The wider context is that enforcement has changed character. In March 2026 the Privacy Commissioner described an intentional shift toward a greater focus on enforcement over the preceding 12 months. The first civil penalty under the Privacy Act, $5.8 million, was imposed on a pathology provider after a Federal Court finding that it failed to take reasonable steps to protect the information it held. None of this makes a small clinic a target. It does mean the standard is now being tested rather than described.

The gap

Practice software protects the records. It does not answer for the practice.

Already handled

  • Clinical record storage, encryption and backup in your practice management system
  • User logins and role permissions inside that system
  • Endpoint protection and device management, through your IT provider
  • Professional registration and clinical scope of practice

Cleverer replaces none of it and supplies no technical security controls.

Usually nobody's job

  • Which privacy obligations each role carries, clinical and administrative
  • Dated proof each person completed their training
  • Dated acknowledgement of the current privacy and handling policy
  • A recurring practice review that leaves a record
  • A log of concerns raised, and how each was resolved

This is what gets asked for after a misdirected report or a complaint.

The honest test

If someone asked today, what could your practice actually prove?

Answer as though you had to reply in writing this week, with documents attached.

  1. Can you produce a dated training record for every person who can open a client file? Clinicians, students on placement, reception, intake, billing and practice managers.
  2. Can you show who acknowledged the current version of your privacy and handling policy? An induction signature from four years ago does not describe the policy you run today.
  3. Can you name the person accountable for privacy in the practice? In writing, attached to a role rather than to whoever happens to be available.
  4. Can you show that access was removed when a clinician or admin staff member left? Practice software, shared email, the referrals inbox and any cloud folder they used.
  5. Can you show what happened after the last report or referral went to the wrong recipient? Raised by whom, assessed against the notifiable data breach threshold, and closed when.
  6. Can you show a practice review of privacy in the last 12 months? Dated, with who was involved and what changed as a result.
  7. Can you show why you still hold the files of clients you have not seen for years? Health records carry retention obligations. APP 11.2 also asks you to consider when information is no longer needed.
Score it

Ten questions, and an honest read on where the practice stands.

Short version of the full check. No email needed to see the result.

Step 1 of 3

Data & Handling

1. Does your business have a documented process for how personal information is collected, stored, and disposed of?

2. Have all staff who handle personal data completed cyber compliance obligations appropriate to their role?

3. Can you produce evidence of compliance if requested by an insurer, client, or regulator today?

Step 2 of 3

Processes & Evidence

4. Does your business have a documented data breach response plan that staff have been made aware of?

5. Are compliance certifications tracked with expiry dates and renewal processes?

6. Do managers and team leaders understand their oversight responsibilities for cyber compliance?

Step 3 of 3

Governance & Oversight

7. Has a director or senior leader reviewed the organisation's cyber compliance posture in the last 12 months?

8. Does your business differentiate compliance obligations by role (staff, managers, directors)?

9. Are third-party access and data sharing arrangements documented and reviewed?

10. Does your business review and update its compliance measures at least annually?

What changes

Structure that fits how a clinic actually runs.

Assigned by role, completed in short pieces, and recorded as it happens. It sits alongside your practice software rather than inside it.

  • Responsibility Clinical and administrative roles each carry their own named obligations. A receptionist handling intake forms and a psychologist writing risk notes do not have the same job, and should not have the same list.
  • Training Produce a dated training record without searching inboxes or spreadsheets. Useful when a funder, an insurer or a referring organisation asks how your team is prepared.
  • Policies Know exactly who has acknowledged each current policy, and when. Revise your handling policy and the practice can see who still needs to accept the new version.
  • Oversight See overdue responsibilities and gaps before someone else finds them. Practice owners get one view across sites, clinicians and admin without chasing individuals.
  • Review cycles Recurring reviews that happen on schedule and leave a record behind. Reminders escalate rather than expiring quietly, so a review becomes a dated event with an owner.
  • Issues Log a concern, show what was done about it, and close it out. A misdirected report that was caught and handled properly becomes evidence of a working practice.
Defensibility

What the practice can put in front of someone who asks.

Reasonable steps are judged on what was in place at the time. Confidence is easier when the record already exists.

  • A dated register of who holds which privacy responsibility, and how that changed So the practice can answer for last year, not only for today.
  • Training completion and certification per person, per role Retrievable as a report instead of assembled by hand the week it is requested.
  • Policy acknowledgement history against each version Who accepted what, on what date, against which version of the document.
  • A practice review trail Evidence that oversight recurs, which is the distinction APP 1 draws between holding a policy and running a practice.
  • An issues and escalation log Concerns raised, actions taken, dates closed. Often the most persuasive record a small practice holds.

Cleverer maintains organisational evidence. It does not provide technical security controls, it does not prevent breaches, and nothing on this page is legal advice.

Next step

Be able to answer the question before it is asked.

The Compliance Check scores the controls and the evidence separately. Most practices are comfortable with the first number. The second one is what decides how defensible you look.

© 2026 Cleverer. Human-layer cyber compliance for Australian businesses.