Skip to content
Why Cipher?Trusted by local patients
Alternative health clinic

Privacy notice

Privacy and health information collection notice

This notice explains how Cipher Health collects, uses, stores, and shares personal information and health information when you use our Australian telehealth, intake, patient portal, and care coordination services.

Last updated
6 September 2026
Notice version
privacy-collection-notice-v2026-09-06

1. Who this notice applies to

This notice applies to patients, prospective patients, carers, authorised representatives, website visitors, and portal users who interact with Cipher Health. Health information is sensitive information under Australian privacy law, so we treat it with higher safeguards.

2. What we collect

  • Identity and contact details such as name, date of birth, email, phone number, address, Medicare details, IHI, and photo-ID details where needed.
  • Health information such as symptoms, goals, medical history, medicines, allergies, pathology/ECG status, care preferences, and clinical notes.
  • Operational information such as appointment, payment, pharmacy coordination, reminder, portal, file, and audit records.
  • Technical information such as request metadata, security logs, rate-limit data, device/browser details, and bot-check results.

3. Why we collect it

We collect information to assess suitability, triage requests, provide telehealth services, book appointments, maintain clinical records, coordinate prescriptions or pharmacy handoffs where clinically appropriate, process payments, send care communications, manage patient access/correction requests, secure the service, meet legal obligations, and improve safe operations.

4. What happens if you do not provide information

You can choose not to provide information. If required clinical, identity, consent, or contact information is missing, Cipher Health may be unable to assess your request, book a consultation, provide care coordination, release records, or meet legal obligations.

5. How we use and disclose information

We use and disclose information only for the purposes described in this notice, purposes you consent to, related purposes you would reasonably expect, or where required or authorised by law.

  • Treating practitioners and authorised Cipher Health staff who need access for care, triage, booking, administration, billing, safety, or compliance.
  • Approved pharmacies, pathology providers, payment processors, email/SMS providers, object-storage providers, and other vendors only where needed for the service and approved for the relevant data.
  • Regulators, insurers, professional advisers, courts, or law-enforcement bodies where required or authorised by law.
  • Emergency or urgent-care services where disclosure is reasonably necessary to lessen or prevent a serious threat to life, health, or safety.

5A. Our data promise — what we never do

We never sell personal information. We do not share personal information — identified, de-identified, or aggregated — with advertisers, sponsors, or data brokers, and we do not use it to build products or reports for them. Our services carry no third-party advertising trackers or analytics pixels. If our practices were ever to change, this notice would be updated first and the change would apply only to information collected after that update.

6. Storage, security, and overseas disclosure

Cipher Health uses technical and organisational safeguards such as role-based access, secure sessions, audit logging, rate limiting, private storage, and vendor review. We prefer Australian-region infrastructure for patient data. Some vendors may involve overseas support access or processing; those vendors must be reviewed and approved before real patient health information is sent to them.

7. Access and correction

You may request access to personal information we hold about you or ask us to correct information you believe is inaccurate, incomplete, or out of date. We may need to verify your identity and may need a practitioner to review changes to clinical records. Finalised clinical notes are corrected through an amendment trail rather than destructive editing.

8. Service communications and optional marketing

Required service communications are used to manage your intake, appointments, care, prescription or pharmacy coordination, payments, safety notices, and service administration. They may be sent by email or SMS where you have provided the required general consent and a reachable contact channel.

Marketing is separate and optional. On a first-contact form, one unchecked choice lets you opt in to Cipher Health service marketing by both email and SMS. Declining or later withdrawing marketing does not affect your care or required service communications.

After opting in, you can manage email and SMS marketing independently in the patient portal. Reply STOP to marketing SMS or use the unsubscribe link in any marketing email. A valid withdrawal updates your profile immediately; withdrawing one marketing channel does not withdraw general care consent or the other marketing channel.

9. Data breaches

If a data breach is likely to result in serious harm, Cipher Health will follow the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner where required.

10. Contact

For privacy questions, access requests, correction requests, or complaints, contact Cipher Health support. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

You can also review the service terms at /terms.