Health data is
sensitive information

A plain look at what the Privacy Act's higher bar for health information means day to day, from patient consent through to the questions worth asking any documentation vendor.

Health information is not ordinary personal information under Australian law. The Privacy Act 1988 (Cth) and the Australian Privacy Principles set health information apart as sensitive information, and that single classification is what drives the consent, storage and vendor questions a practice has to get right before it lets any tool, including an AI scribe, near a consult.

An open drawer of a metal filing cabinet packed with aged index cards and paper records

Why health information gets a higher bar

The Privacy Act 1988 (Cth) applies to personal information generally, but the Australian Privacy Principles carve out a narrower category called sensitive information, and health information sits inside it alongside things like genetic information and biometric data. The practical effect of that classification is that the default rules for collecting personal information do not apply on their own. Collection of sensitive information generally needs the individual's consent, with defined exceptions such as providing a health service or responding to a threat to someone's life or health. Everything else in the Australian Privacy Principles, the rules on use, disclosure, security and access, still applies on top.

For a practice, this means the classification is not academic. It sets the consent threshold for every point where health information is collected, including a consult recording that becomes the source material for a clinical note. The Office of the Australian Information Commissioner (OAIC) administers the Act and publishes guidance on exactly this question, and it is the body a patient can complain to if they believe their health information was mishandled.

The record still has to earn its keep

None of this changes what makes a clinical record adequate. AHPRA's expectations for record keeping and the Medicare Benefits Schedule's requirement for contemporaneous, clinically relevant notes sit alongside the privacy rules, not instead of them. A note drafted from an ambient recording becomes the practice's clinical record once a clinician has reviewed it, corrected it where needed and signed it. Until that happens it is a draft, not a record, and the distinction is not a technicality: it is what keeps the practice able to answer for what is in the file.

The underlying audio is a separate question again. It is sensitive information in its own right, and a practice needs a clear view of how long it is kept, who can reach it, and when it is disposed of. Retention periods for health records themselves vary by state and by whether the patient was a minor at the time of the consult, so a practice's retention policy for recordings should be set deliberately, not left to whatever a vendor happens to default to.

Where the data sits, and who can reach it

Storage location is a genuine privacy question, not a technical footnote. A practice should be able to say plainly whether consult audio, transcripts and drafts are held in Australia or offshore, whether they are encrypted at rest and in transit, and which staff at the vendor, if any, can view identifiable content and under what conditions. Australian Privacy Principle 8 covers disclosure to overseas recipients, and the effect is that a practice generally remains accountable for how an overseas recipient handles health information it has disclosed, unless a specific exception applies. Sending identifiable health information offshore does not hand off the privacy obligation, it usually just adds a layer the practice has to manage.

None of this overlaps with My Health Record, which the Australian Digital Health Agency operates as a separate, patient controlled system. A scribe drafting a local clinical note is not writing to My Health Record, and a practice should not assume that one satisfies the other.

Questions worth asking any vendor

A practice does not need to become a privacy lawyer to evaluate a scribe vendor, but it should be able to get direct answers to a short list of questions before signing anything.

  • Where exactly is the data stored, and does that include backups, not just the primary copy.
  • Is the original audio kept after the note is drafted, and if so for how long, and can the practice choose to have it deleted sooner.
  • Who at the vendor can access identifiable content, under what conditions, and is that access logged.
  • Is any consult data used to train models beyond improving the output for that same practice.
  • What happens if the practice ends the contract: is data exported, and is it then deleted on a defined schedule.
  • Is there an audit trail showing who viewed or edited a note, and for how long is that trail kept.

Where Aurii fits into this

This section is about our product. Everything above is not.

Aurii is built around one governing rule that lines up with everything above: the scribe writes, the doctor decides. It listens to a consult with the patient's consent, drafts the progress note, referrer and GP letters and the discharge summary, and none of that becomes part of the record until a named clinician has reviewed it and signed it.

Consult data is captured, transcribed and stored in Australia, with Sydney as the primary location and Melbourne as backup, encrypted per record, and held under a seven-year, tamper-evident audit trail. Aurii is a documentation aid. It is not a medical device, it is not on the Australian Register of Therapeutic Goods, and it does not diagnose or recommend treatment: it drafts what was said in the room and leaves the clinician to decide what stays. For the specific mechanics of where that data sits and who can reach it, see Security and data handling.

Common questions

Yes. The classification attaches to the content, not the format. Audio of a clinical consult is health information about an identifiable patient regardless of whether it is ever transcribed, so the same storage, access and consent considerations apply to the recording itself, not just to the note drafted from it.

That should be a deliberate decision, not a default. A practice is entitled to ask a vendor exactly how long audio is retained after a note is finalised, whether it can request earlier deletion, and whether the answer changes if the practice ends the contract. Aurii's approach is to hold data under Australian storage and a defined audit trail rather than leaving retention open ended.

Yes. The Australian Privacy Principles expect an up to date privacy policy describing how personal and health information is collected, held, used and disclosed, and adding a documentation tool to a consult is a new collection point worth naming plainly rather than leaving it implied.

This article is general information only, not clinical, legal or financial advice, and practices should seek advice specific to their own circumstances. More guides sit on the resources hub. If your practice needs a question answered before it adopts AI documentation, tell us and we will write it: hello@aurii.com.au.

Read first.
Then see it on your own round.

You do not have to take any of this on faith. Request access, bring a real consult, and watch the note, letters and discharge come out the other end, yours to correct and sign.

hello@aurii.com.au

Stay in the loop.

Leave your email and we'll be in touch. No spam, unsubscribe any time.