Skip to content
Why Cipher?Trusted by local patients
Alternative health clinic only
We do not offer GP services
100% online intake

Privacy notice

Privacy and health information collection notice

This notice explains how Cipher Health collects, uses, stores, and shares personal information and health information when you use our Australian telehealth, intake, patient portal, and care coordination services.

Last updated
15 August 2026
Notice version
privacy-collection-notice-v2026-08-15

1. Who this notice applies to

This notice applies to patients, prospective patients, carers, authorised representatives, website visitors, and portal users who interact with Cipher Health. Health information is sensitive information under Australian privacy law, so we treat it with higher safeguards.

2. What we collect

  • Identity and contact details such as name, date of birth, email, phone number, address, Medicare details, IHI, and photo-ID details where needed.
  • Health information such as symptoms, goals, medical history, medicines, allergies, pathology/ECG status, care preferences, and clinical notes.
  • Operational information such as appointment, payment, pharmacy coordination, reminder, portal, file, and audit records.
  • Technical information such as request metadata, security logs, rate-limit data, device/browser details, and bot-check results.

3. Why we collect it

We collect information to assess suitability, triage requests, provide telehealth services, book appointments, maintain clinical records, coordinate prescriptions or pharmacy handoffs where clinically appropriate, process payments, send care communications, manage patient access/correction requests, secure the service, meet legal obligations, and improve safe operations.

4. What happens if you do not provide information

You can choose not to provide information. If required clinical, identity, consent, or contact information is missing, Cipher Health may be unable to assess your request, book a consultation, provide care coordination, release records, or meet legal obligations.

5. How we use and disclose information

We use and disclose information only for the purposes described in this notice, purposes you consent to, related purposes you would reasonably expect, or where required or authorised by law.

  • Treating practitioners and authorised Cipher Health staff who need access for care, triage, booking, administration, billing, safety, or compliance.
  • Approved pharmacies, pathology providers, payment processors, email/SMS providers, object-storage providers, and other vendors only where needed for the service and approved for the relevant data.
  • Regulators, insurers, professional advisers, courts, or law-enforcement bodies where required or authorised by law.
  • Emergency or urgent-care services where disclosure is reasonably necessary to lessen or prevent a serious threat to life, health, or safety.

5A. Our data promise — what we never do

We never sell personal information. We do not share personal information — identified, de-identified, or aggregated — with advertisers, sponsors, or data brokers, and we do not use it to build products or reports for them. Our services carry no third-party advertising trackers or analytics pixels. If our practices were ever to change, this notice would be updated first and the change would apply only to information collected after that update.

6. Storage, security, and overseas disclosure

Cipher Health uses technical and organisational safeguards such as role-based access, secure sessions, audit logging, rate limiting, private storage, and vendor review. We prefer Australian-region infrastructure for patient data. Some vendors may involve overseas support access or processing; those vendors must be reviewed and approved before real patient health information is sent to them.

7. Access and correction

You may request access to personal information we hold about you or ask us to correct information you believe is inaccurate, incomplete, or out of date. We may need to verify your identity and may need a practitioner to review changes to clinical records. Finalised clinical notes are corrected through an amendment trail rather than destructive editing.

8. Communications and marketing

We may contact you about your intake, appointment, care, prescription or pharmacy coordination, payments, safety notices, and service administration. Marketing communications require appropriate consent and must include an opt-out pathway where required.

9. Data breaches

If a data breach is likely to result in serious harm, Cipher Health will follow the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner where required.

10. Contact

For privacy questions, access requests, correction requests, or complaints, contact Cipher Health support. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

You can also review the service terms at /terms.