Privacy Policy
How WeMed collects, uses, and protects your personal and health information in compliance with Australian telehealth and medical practice regulations.
Effective date: 1 July 2026
This policy is governed by the Privacy Act 1988 (Cth), the Australian Privacy Principles, the My Health Records Act 2012, and the Healthcare Identifiers Act 2010. Health information is treated as sensitive information under the APPs.
1. Introduction & Scope
WeMed Pty Ltd ("we", "us", "our") operates a telehealth and medical practice connecting patients with Australian-registered health practitioners. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal and health information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the My Health Records Act 2012, and the Healthcare Identifiers Act 2010.
This policy applies to all patients, prospective patients, website visitors, and doctors who interact with our telehealth platform, website, and related services. Health information is treated as "sensitive information" under the APPs and is afforded a higher level of protection.
2. Protected Health Information (PHI) & Our Legal Duties
Protected Health Information (PHI) refers to your identifiable health information that we create, receive, store, or transmit in the course of providing telehealth and medical services. As a healthcare provider operating under Australian law, WeMed is legally required to maintain the privacy and security of your PHI and to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the My Health Records Act 2012, and applicable state and territory health records legislation. Our legal duties include maintaining the confidentiality of your PHI, providing you with this notice describing our privacy practices and your rights, notifying affected individuals following a data breach involving PHI where we are legally required to do so, and taking reasonable steps to protect PHI from misuse, interference, loss, and unauthorised access, modification, or disclosure. We will not use or disclose your PHI in a manner inconsistent with this notice and applicable law.
How we may use and disclose your PHI — We may use and disclose your PHI for treatment, payment, and healthcare operations. For treatment, we share PHI with the practitioners, specialists, pathology and imaging providers, and pharmacies involved in your care, and with other health services for referral and continuity of care. For payment, we use and disclose PHI for billing, Medicare and DVA claiming, private health fund processing, and account management. For healthcare operations, we use PHI for quality assurance, practice management, appointment coordination, staff training, and regulatory compliance. We may also disclose your PHI when required or authorised by law, for public health and safety activities, to avert a serious threat to life, health, or safety, for law enforcement and court or tribunal proceedings, in response to subpoenas or statutory notices, for research approved by a Human Research Ethics Committee, or with your written consent. Except in these circumstances, we will not use or disclose your PHI for any other purpose without your written authorisation, which you may revoke at any time by contacting us in writing.
Your rights regarding your PHI — You have the following rights concerning your PHI. To exercise any of these rights, please contact our Privacy Officer using the details in the Contact section below. We will respond within a reasonable timeframe and may ask you to verify your identity before acting on your request. In limited circumstances permitted by law, we may refuse a request; if we do, we will provide our reasons in writing.
Filing a complaint with WeMed — If you believe your privacy rights have been violated or that we have improperly used or disclosed your PHI, you may file a complaint with WeMed by contacting our Privacy Officer in writing or by email using the details in the Contact section below. Please provide a description of your concern, the relevant dates if known, and your contact details. We will investigate and respond to your complaint in a timely manner, and we will not retaliate against you for filing a complaint. If you remain dissatisfied, you may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
- Right to access and inspect — You may request to access and inspect the PHI we hold about you, including your clinical health record.
- Right to obtain a copy — You may request a copy of your PHI in electronic or paper form. A reasonable fee may apply to cover the cost of copying and supplying the records.
- Right to amend — You may request that we correct PHI that is inaccurate, out of date, incomplete, or misleading. If we refuse a correction, we will provide reasons and attach a statement of your requested correction to the record.
- Right to request restrictions — You may request that we limit how we use or disclose your PHI for treatment, payment, or healthcare operations. We are not legally required to agree to all requests, but we will comply with any restriction we agree to in writing.
- Right to withdraw consent — You may withdraw your consent to the use or disclosure of your PHI at any time, subject to legal or clinical obligations that require us to retain or disclose certain information.
- Right to confidential communications — You may request that we communicate with you by alternative means or at alternative locations where it is reasonable to do so.
- Right to an accounting of disclosures — You may request a record of certain disclosures of your PHI we have made, where applicable under law.
3. Personal & Health Information We Collect
We collect personal information you provide when booking a consultation, registering as a patient, or communicating with us. This includes your full name, date of birth, email address, phone number, residential address, and Medicare/DVA number where applicable.
Health information we collect includes your medical history, reason for consultation, current medications, allergies, previous diagnoses, specialist referrals, pathology and imaging results, and records of consultations conducted via telehealth or face-to-face.
We also collect technical information when you use our platform, such as IP address, device details, browser type, and consultation metadata (date, time, duration, and type of consultation). Telehealth video consultations are not recorded or stored by us unless explicit consent is provided.
4. How We Collect Information
We collect information directly from you when you complete a booking form, register on our platform, attend a consultation, or correspond with our practitioners. We also collect information with your consent from your referring doctor, previous treating practitioners, pathology providers, and imaging services.
Some information is collected automatically through our website and platform infrastructure, including usage data and cookies, as described in the Cookies section below.
5. How We Use Your Information
We use your personal and health information for the primary purpose of providing medical care, including conducting telehealth and face-to-face consultations, forming diagnoses, prescribing medications, issuing referrals, and maintaining your clinical health record.
We also use your information for related secondary purposes where you would reasonably expect this, such as billing and Medicare claiming, appointment reminders, follow-up communications, practice administration, quality assurance, and meeting our legal and regulatory obligations under healthcare and telecommunications legislation.
6. Disclosure of Your Information
We only disclose your health information to authorised recipients for purposes directly related to your care. This may include your nominated general practitioner, referring and treating specialists, pathology and imaging providers, pharmacies, and other health practitioners involved in your treatment, with your consent or where permitted by law.
We may disclose limited personal information to Medicare, the Department of Veterans' Affairs, private health funds, and regulatory authorities where required by law. We do not sell, rent, or commercially trade your personal or health information to any third party.
7. Telehealth & Cross-Border Data
Our telehealth consultations are conducted over encrypted communications platforms. Video and audio data are transmitted in real time and are not recorded or retained by WeMed unless you provide explicit written consent and understand the purpose of the recording.
Some platform infrastructure and third-party service providers may store or process data outside Australia. Where this occurs, we take reasonable steps to ensure the overseas recipient handles your information in accordance with the APPs, and you consent to this cross-border disclosure by using our telehealth services. Under APP 8, we remain accountable for information handled overseas.
8. Data Security & Storage
We protect your personal and health information using industry-standard security measures, including encryption in transit (TLS), restricted access controls, secure authentication, and regular security reviews. Access to clinical records is limited to authorised practitioners and administrative staff who require access to perform their duties.
Your health records are stored within accredited practice management systems that comply with Australian healthcare data security standards. We maintain audit logs of access to sensitive health information in accordance with best-practice clinical governance.
9. Data Retention
We retain your health records for the period required by Australian medical record-keeping requirements and relevant state health legislation, which generally requires adult records to be retained for a minimum of seven years from the date of last entry, and records relating to children until the child reaches 25 years of age.
When records are no longer required, we destroy or de-identify the information in a secure manner in accordance with the APPs and relevant health record legislation.
10. Your Rights — Access & Correction
Under APP 12 and APP 13, you have the right to request access to the personal and health information we hold about you, and to request correction of information that is inaccurate, out of date, incomplete, or misleading.
To request access or correction, please contact us using the details below. We may charge a reasonable fee for providing access and will respond to your request within a reasonable period. In limited circumstances permitted by law, we may refuse access; if we do, we will provide reasons for the refusal.
11. Consent
By using our telehealth services and providing your information, you consent to the collection, use, and disclosure of your personal and health information as described in this policy. You may withdraw consent at any time by contacting us in writing, however this may affect our ability to continue providing medical care.
For telehealth consultations, we obtain your consent prior to the consultation confirming your agreement to receive care via telehealth and acknowledging the associated benefits and limitations.
13. Third-Party Service Providers
We engage trusted third-party service providers to support our operations, including accredited practice management systems, secure video conferencing, payment processing, and email communications. Each provider is bound by confidentiality and security obligations consistent with the APPs.
These providers may process data in cloud infrastructure located outside Australia. We take reasonable steps to ensure each provider handles your information in line with Australian privacy requirements.
14. Children & Dependents
Where we provide care to patients under 18 years of age, we collect information with the consent of a parent or legal guardian. Health information relating to minors is subject to the same retention and security requirements described above, with extended retention periods as required by law.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. The updated version will be published on this page with the revised effective date. We encourage you to review this page periodically.
16. Complaints & Contact
If you believe we have breached your privacy or mishandled your information, please contact us using the details below. We will investigate and respond to your complaint in a timely manner.
If you remain dissatisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992. The OAIC oversees privacy compliance under the Privacy Act 1988 (Cth).
Contact Our Privacy Officer
For access, correction, consent withdrawal, or privacy enquiries, please contact our Privacy Officer.
privacy@wemed.au
Phone
0494 618 595
Postal
17 Randle Street, Surry Hills, NSW 2010