For Australian allied health practices
Your clients' most sensitive information. Could you prove how it is protected?
For health service providers, the Privacy Act can apply regardless of business size.
Clinical notes, mental health assessments, Medicare and NDIS detail, referrals and reports. Health information is sensitive information, which lifts what counts as reasonable steps.
Your practice software secures the records. Cleverer proves the rest: who carries which obligation, what each person completed and acknowledged, and when the practice last reviewed it.
Five minutes, no email required to see your result. Built for practices with clinicians and admin teams, from a single clinic to a multi-site group.
Almost everything that moves through the front desk is sensitive information.
Psychology, physiotherapy, occupational therapy, speech pathology, exercise physiology and multidisciplinary clinics all run on the same flow of documents.
- Clinical notes and assessments Including mental health notes, risk assessments and observations a client would never expect to be read by anyone else.
- Referrals and practitioner correspondence GP referrals, specialist letters, discharge summaries and reports that travel by email between organisations.
- Medicare, DVA and health fund detail Card numbers, item numbers, care plan documentation and claiming history.
- NDIS participant information Plans, goals, funding detail, support coordinator correspondence and progress reporting.
- Third party reports Insurer, WorkCover, school, employer and court reports, each with its own disclosure expectations.
- Guardian, parent and carer records Detail about people who are not the client, held because the client's care requires it.
Reception, intake, billing and practice management staff handle most of this before a clinician ever opens the file. Their obligations are the ones least often written down.
What the Act actually says about a practice your size.
The $3 million small business exemption is real, and a lot of allied health owners assume it covers them. For a practice that provides a health service and holds health information, it does not. The OAIC's position is that all organisations that provide a health service and hold health information are covered by the Privacy Act, whether or not they are a small business, and it names allied health professionals among them. A sole practitioner and a twenty-clinician group are both APP entities.
Health information is also sensitive information under the Act, which raises the bar. Reasonable steps under APP 11 are assessed against the nature of the information held, and the OAIC's guidance treats those steps as both technical and organisational measures, listing governance, culture and training first among the areas to consider. APP 1.2 goes further and asks for practices, procedures and systems that are implemented, not simply written.
The wider context is that enforcement has changed character. In March 2026 the Privacy Commissioner described an intentional shift toward a greater focus on enforcement over the preceding 12 months. The first civil penalty under the Privacy Act, $5.8 million, was imposed on a pathology provider after a Federal Court finding that it failed to take reasonable steps to protect the information it held. None of this makes a small clinic a target. It does mean the standard is now being tested rather than described.
Practice software protects the records. It does not answer for the practice.
Already handled
- Clinical record storage, encryption and backup in your practice management system
- User logins and role permissions inside that system
- Endpoint protection and device management, through your IT provider
- Professional registration and clinical scope of practice
Cleverer replaces none of it and supplies no technical security controls.
Usually nobody's job
- Which privacy obligations each role carries, clinical and administrative
- Dated proof each person completed their training
- Dated acknowledgement of the current privacy and handling policy
- A recurring practice review that leaves a record
- A log of concerns raised, and how each was resolved
This is what gets asked for after a misdirected report or a complaint.
If someone asked today, what could your practice actually prove?
Answer as though you had to reply in writing this week, with documents attached.
- Can you produce a dated training record for every person who can open a client file? Clinicians, students on placement, reception, intake, billing and practice managers.
- Can you show who acknowledged the current version of your privacy and handling policy? An induction signature from four years ago does not describe the policy you run today.
- Can you name the person accountable for privacy in the practice? In writing, attached to a role rather than to whoever happens to be available.
- Can you show that access was removed when a clinician or admin staff member left? Practice software, shared email, the referrals inbox and any cloud folder they used.
- Can you show what happened after the last report or referral went to the wrong recipient? Raised by whom, assessed against the notifiable data breach threshold, and closed when.
- Can you show a practice review of privacy in the last 12 months? Dated, with who was involved and what changed as a result.
- Can you show why you still hold the files of clients you have not seen for years? Health records carry retention obligations. APP 11.2 also asks you to consider when information is no longer needed.
Ten questions, and an honest read on where the practice stands.
Short version of the full check. No email needed to see the result.
Structure that fits how a clinic actually runs.
Assigned by role, completed in short pieces, and recorded as it happens. It sits alongside your practice software rather than inside it.
- Responsibility Clinical and administrative roles each carry their own named obligations. A receptionist handling intake forms and a psychologist writing risk notes do not have the same job, and should not have the same list.
- Training Produce a dated training record without searching inboxes or spreadsheets. Useful when a funder, an insurer or a referring organisation asks how your team is prepared.
- Policies Know exactly who has acknowledged each current policy, and when. Revise your handling policy and the practice can see who still needs to accept the new version.
- Oversight See overdue responsibilities and gaps before someone else finds them. Practice owners get one view across sites, clinicians and admin without chasing individuals.
- Review cycles Recurring reviews that happen on schedule and leave a record behind. Reminders escalate rather than expiring quietly, so a review becomes a dated event with an owner.
- Issues Log a concern, show what was done about it, and close it out. A misdirected report that was caught and handled properly becomes evidence of a working practice.
What the practice can put in front of someone who asks.
Reasonable steps are judged on what was in place at the time. Confidence is easier when the record already exists.
- A dated register of who holds which privacy responsibility, and how that changed So the practice can answer for last year, not only for today.
- Training completion and certification per person, per role Retrievable as a report instead of assembled by hand the week it is requested.
- Policy acknowledgement history against each version Who accepted what, on what date, against which version of the document.
- A practice review trail Evidence that oversight recurs, which is the distinction APP 1 draws between holding a policy and running a practice.
- An issues and escalation log Concerns raised, actions taken, dates closed. Often the most persuasive record a small practice holds.
Cleverer maintains organisational evidence. It does not provide technical security controls, it does not prevent breaches, and nothing on this page is legal advice.
Next step
Be able to answer the question before it is asked.
The Compliance Check scores the controls and the evidence separately. Most practices are comfortable with the first number. The second one is what decides how defensible you look.
Sources
- OAIC, What is a health service provider, and Rights and responsibilities on who the Privacy Act covers.
- OAIC, APP guidelines, Chapter 11: APP 11, and Chapter 1: APP 1.
- OAIC, Handling privacy complaints, a new approach for a new era (2 March 2026).
- OAIC, Australian Clinical Labs ordered to pay penalties, the first civil penalty under the Privacy Act.