1. Who this notice applies to
This notice applies to patients, prospective patients, carers, authorised representatives, website visitors, and portal users who interact with Cipher Health. Health information is sensitive information under Australian privacy law, so we treat it with higher safeguards.
3. Why we collect it
We collect information to assess suitability, triage requests, provide telehealth services, book appointments, maintain clinical records, coordinate prescriptions or pharmacy handoffs where clinically appropriate, process payments, send care communications, manage patient access/correction requests, secure the service, meet legal obligations, and improve safe operations.
4. What happens if you do not provide information
You can choose not to provide information. If required clinical, identity, consent, or contact information is missing, Cipher Health may be unable to assess your request, book a consultation, provide care coordination, release records, or meet legal obligations.
5. How we use and disclose information
We use and disclose information only for the purposes described in this notice, purposes you consent to, related purposes you would reasonably expect, or where required or authorised by law.
- Treating practitioners and authorised Cipher Health staff who need access for care, triage, booking, administration, billing, safety, or compliance.
- Approved pharmacies, pathology providers, payment processors, email/SMS providers, object-storage providers, and other vendors only where needed for the service and approved for the relevant data.
- Regulators, insurers, professional advisers, courts, or law-enforcement bodies where required or authorised by law.
- Emergency or urgent-care services where disclosure is reasonably necessary to lessen or prevent a serious threat to life, health, or safety.
5A. Our data promise — what we never do
We never sell personal information. We do not share personal information — identified, de-identified, or aggregated — with advertisers, sponsors, or data brokers, and we do not use it to build products or reports for them. Our services carry no third-party advertising trackers or analytics pixels. If our practices were ever to change, this notice would be updated first and the change would apply only to information collected after that update.
6. Storage, security, and overseas disclosure
Cipher Health uses technical and organisational safeguards such as role-based access, secure sessions, audit logging, rate limiting, private storage, and vendor review. We prefer Australian-region infrastructure for patient data. Some vendors may involve overseas support access or processing; those vendors must be reviewed and approved before real patient health information is sent to them.
7. Access and correction
You may request access to personal information we hold about you or ask us to correct information you believe is inaccurate, incomplete, or out of date. We may need to verify your identity and may need a practitioner to review changes to clinical records. Finalised clinical notes are corrected through an amendment trail rather than destructive editing.
8. Communications and marketing
We may contact you about your intake, appointment, care, prescription or pharmacy coordination, payments, safety notices, and service administration. Marketing communications require appropriate consent and must include an opt-out pathway where required.
9. Data breaches
If a data breach is likely to result in serious harm, Cipher Health will follow the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
10. Contact
For privacy questions, access requests, correction requests, or complaints, contact Cipher Health support. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
You can also review the service terms at /terms.