Health information is not ordinary personal information under Australian law. The Privacy Act 1988 (Cth) and the Australian Privacy Principles set health information apart as sensitive information, and that single classification is what drives the consent, storage and vendor questions a practice has to get right before it lets any tool, including an AI scribe, near a consult.
Why health information gets a higher bar
The Privacy Act 1988 (Cth) applies to personal information generally, but the Australian Privacy Principles carve out a narrower category called sensitive information, and health information sits inside it alongside things like genetic information and biometric data. The practical effect of that classification is that the default rules for collecting personal information do not apply on their own. Collection of sensitive information generally needs the individual's consent, with defined exceptions such as providing a health service or responding to a threat to someone's life or health. Everything else in the Australian Privacy Principles, the rules on use, disclosure, security and access, still applies on top.
For a practice, this means the classification is not academic. It sets the consent threshold for every point where health information is collected, including a consult recording that becomes the source material for a clinical note. The Office of the Australian Information Commissioner (OAIC) administers the Act and publishes guidance on exactly this question, and it is the body a patient can complain to if they believe their health information was mishandled.
Consent looks different for sensitive information
Standard personal information can often be collected on the strength of a clear notice at the point of collection, with an opt out available for some secondary uses. Sensitive information is held to a stricter standard: a practice generally needs the patient's consent to collect it in the first place, not just a chance to object afterwards. That distinction matters the moment a device in the room starts recording a consult. The patient is not just the subject of a note anymore, they are a party whose sensitive information is being captured in a new form, and that new form needs its own, plainly stated consent at the point it happens, not buried in a form signed months earlier at registration.
In practice this tends to work best as a short, spoken exchange before the recording starts: what is being recorded, what it becomes (a draft note, letter or summary), who reviews it, and that declining does not affect the care the patient receives. A practice that can point to that exchange, and to a record that it happened, sits in a materially stronger position than one relying on a line in an intake pack nobody reads.
The record still has to earn its keep
None of this changes what makes a clinical record adequate. AHPRA's expectations for record keeping and the Medicare Benefits Schedule's requirement for contemporaneous, clinically relevant notes sit alongside the privacy rules, not instead of them. A note drafted from an ambient recording becomes the practice's clinical record once a clinician has reviewed it, corrected it where needed and signed it. Until that happens it is a draft, not a record, and the distinction is not a technicality: it is what keeps the practice able to answer for what is in the file.
The underlying audio is a separate question again. It is sensitive information in its own right, and a practice needs a clear view of how long it is kept, who can reach it, and when it is disposed of. Retention periods for health records themselves vary by state and by whether the patient was a minor at the time of the consult, so a practice's retention policy for recordings should be set deliberately, not left to whatever a vendor happens to default to.
Where the data sits, and who can reach it
Storage location is a genuine privacy question, not a technical footnote. A practice should be able to say plainly whether consult audio, transcripts and drafts are held in Australia or offshore, whether they are encrypted at rest and in transit, and which staff at the vendor, if any, can view identifiable content and under what conditions. Australian Privacy Principle 8 covers disclosure to overseas recipients, and the effect is that a practice generally remains accountable for how an overseas recipient handles health information it has disclosed, unless a specific exception applies. Sending identifiable health information offshore does not hand off the privacy obligation, it usually just adds a layer the practice has to manage.
None of this overlaps with My Health Record, which the Australian Digital Health Agency operates as a separate, patient controlled system. A scribe drafting a local clinical note is not writing to My Health Record, and a practice should not assume that one satisfies the other.
Questions worth asking any vendor
A practice does not need to become a privacy lawyer to evaluate a scribe vendor, but it should be able to get direct answers to a short list of questions before signing anything.
- Where exactly is the data stored, and does that include backups, not just the primary copy.
- Is the original audio kept after the note is drafted, and if so for how long, and can the practice choose to have it deleted sooner.
- Who at the vendor can access identifiable content, under what conditions, and is that access logged.
- Is any consult data used to train models beyond improving the output for that same practice.
- What happens if the practice ends the contract: is data exported, and is it then deleted on a defined schedule.
- Is there an audit trail showing who viewed or edited a note, and for how long is that trail kept.
Consent belongs in the room, not just the contract
RACGP standards for general practices treat consent and record keeping as a matter of practice culture, not paperwork alone, and that is the right frame for an AI scribe. The strongest version of consent happens out loud, at the start of the consult, in language the patient actually understands: recording is starting, here is what it becomes, here is who checks it, and choosing not to proceed does not change the care on offer. A practice that builds this into its normal opening minute will rarely have to think about it again. One that treats it as a box ticked once at registration is the one that gets asked hard questions later.
It is worth updating the practice's own privacy policy and collection notice to name the new collection point too. Patients are entitled to know, in general terms, that consults may be recorded and drafted with the help of a documentation tool, and folding that into the existing notice is a small task that closes an otherwise obvious gap.
Where Aurii fits into this
This section is about our product. Everything above is not.
Aurii is built around one governing rule that lines up with everything above: the scribe writes, the doctor decides. It listens to a consult with the patient's consent, drafts the progress note, referrer and GP letters and the discharge summary, and none of that becomes part of the record until a named clinician has reviewed it and signed it.
Consult data is captured, transcribed and stored in Australia, with Sydney as the primary location and Melbourne as backup, encrypted per record, and held under a seven-year, tamper-evident audit trail. Aurii is a documentation aid. It is not a medical device, it is not on the Australian Register of Therapeutic Goods, and it does not diagnose or recommend treatment: it drafts what was said in the room and leaves the clinician to decide what stays. For the specific mechanics of where that data sits and who can reach it, see Security and data handling.
Common questions
In practice, yes. A general registration form covers routine collection of personal information, but recording a consult creates a new piece of sensitive information, so most practices treat it as a separate, spoken consent at the start of each consult, on top of whatever the registration paperwork already covers.
Yes. The classification attaches to the content, not the format. Audio of a clinical consult is health information about an identifiable patient regardless of whether it is ever transcribed, so the same storage, access and consent considerations apply to the recording itself, not just to the note drafted from it.
That should be a deliberate decision, not a default. A practice is entitled to ask a vendor exactly how long audio is retained after a note is finalised, whether it can request earlier deletion, and whether the answer changes if the practice ends the contract. Aurii's approach is to hold data under Australian storage and a defined audit trail rather than leaving retention open ended.
Yes. The Australian Privacy Principles expect an up to date privacy policy describing how personal and health information is collected, held, used and disclosed, and adding a documentation tool to a consult is a new collection point worth naming plainly rather than leaving it implied.
This article is general information only, not clinical, legal or financial advice, and practices should seek advice specific to their own circumstances. More guides sit on the resources hub. If your practice needs a question answered before it adopts AI documentation, tell us and we will write it: hello@aurii.com.au.