top of page

Privacy Policy

‘Privacy Policy of Briese Physiotherapy Pty Ltd, [Sole Practice covering Isabel Street, St Andrew’s Hospital, Mobile Physiotherapy and Telehealth locations], updated June 2026’ 

 

OUR COMMITMENT TO YOUR PRIVACY

 

We are committed to handling personal information about you, including your health information, in accordance with the requirements of the Privacy Act 1988. 

In this policy, we explain: 

  • what kind of information we collect and hold about you

  • how and why, we collect it

  • what we do with your information, who we share it with and when

  • your right to seek access to, and if required correction of, the records we hold about you

  • your right to make a privacy complaint, to us and others

  • whether we disclose information about you to overseas recipients.

 

WHAT KIND OF PERSONAL INFORMATION DO WE COLLECT ABOUT YOU?

 

We collect and hold the following kind of information: 

  • your name, address, date of birth, email and contact details

  • information about your family or relatives

  • information about other health professionals involved in your care

  • any government identifiers such as Medicare number, DVA number. However,

  • we do not use these for the purposes of identifying you in our practice

  • digital identifiers, such as IP addresses, collected during online services like telehealth.

  • other health information about you such as:

    • a record of your symptoms

    • your relevant medical history

    • the diagnosis made and the treatment we give you

    • specialist reports

    • test results

    • your appointment and billing details

    • your prescriptions

    • your healthcare identifier

    • your health fund details

    • other information about you collected for the purposes of providing care to you.

 

HOW DO WE COLLECT AND HOLD YOUR PERSONAL INFORMATION?

 

We collect personal information: 

  • directly from you when you give us your details (eg, face-to-face, over the phone,

  • via registration form or an online form)

  • from a person responsible for you

  • from a third party where we are permitted by law to do so (eg, other health care professionals involved in your care, from your health insurer, from the My Health Record system etc.).

  • with your consent, with the assistance of AI technology whilst in consultation. More information regarding this can be found here. https://pracsuite.com/ai/au/patientconsent

  • At times, we may, with your consent, take a photograph or video to assist in delivering care to you and for record keeping. Typically, this would be done on your own device and not stored or held by us. If, however, there was a need for us to collect and hold a photograph or video, it would be stored in the same manner as other personal information as mentioned in this policy. We do not hold information on devices such as smartphones or tablets. Once this data is stored in accordance to our policies it is deleted from that device.

 

We hold your information securely using technical and organisational measures, such as encrypted databases, secure telehealth platforms and restricted-access systems, in line with the Privacy Act’s updated security requirements. If you use My Health Record, we access or upload your information securely as permitted by law. All of your personal information is held in our practice management system, ‘PracSuite’. PracSuite holds ISO 27001 certification, the gold standard for information security management. More information can be found here: https://www.pracsuite.com/security 

WHY DO WE COLLECT AND USE INFORMATION ABOUT YOU?

We primarily collect and use personal information about you to provide our physiotherapy services to you and to communicate with you and others involved in your care in relation to those services. 

 

We also sometimes use that information for other purposes, including: 

  • to help us manage our accounts and administrative services, including billing, arrangements with health funds, pursuing unpaid accounts, management of our IT systems

  • to conduct accreditation, quality assurance or internal audits.

 

We may also use de-identified data (where you cannot be identified) to improve our services, such as analysing treatment outcomes for quality assurance. 

WHEN AND WHY MIGHT WE SHARE INFORMATION ABOUT YOU WITH OTHERS?

 

We may disclose information about you to others outside of our practice as permitted or required under law. This will include situations where we disclose information about you to: 

  • comply with our legal obligations (eg, mandatory reporting under legislation,

  • responding to a court order or subpoena)

  • consult with other health professionals involved in your healthcare

  • get test results from diagnostic and pathology services

  • claim on insurance

  • communicate with your health fund, with government and other regulatory

  • bodies such as Medicare

  • help us manage our accounts and administrative services (eg. billing or debt recovery, arrangements with health funds, pursuing unpaid accounts etc.)

  • if you have My Health Record, to upload and download personal information from it

  • lessen or prevent a serious threat to a patient’s life, health or safety or a serious threat to public health or safety

  • help in locating a missing person

  • establish, exercise or defend an equitable claim through the My Health Record

  • prepare the defence of anticipated or existing legal proceedings

  • discharge notification obligations to liability insurers

  • share limited information during a data breach to reduce harm, as directed by law under the 2024 amendments.

 

We never share your information maliciously (eg, through doxxing, which is now a criminal offence) and only disclose what is necessary for the purpose. 

 

YOUR RIGHT TO SEEK ACCESS TO AND TO SEEK CORRECTION OF THE INFORMATION WE HOLD ABOUT YOU

 

You have the right to seek access to and correction of the personal information we hold about you. We will usually charge a small fee to cover the administrative costs associated with your request. This fee is commensurate with the nature of your request and will be discussed with you at the time of request of access. 

 

We will normally respond to your request within 30 days. To make the request, you should contact our office on 07 4599 3007 or via email admin@briesephysio.com.au 

 

You may request for information verbally. However, it is our preference that all requests are made both verbally and in writing to assist with legal compliance and recording keeping.  

 

If you think that the information we hold about you is not correct, let us know in writing. We will  take reasonable steps to correct your personal information where the information is not accurate or up-to-date. From time to time, we may also ask you to verify that the information we hold about  you is correct and current. Please notify us if your contact details change. (see ‘how to contact us’). 

 

SECURITY: HOW WE HOLD YOUR PERSONAL INFORMATION

We take reasonable steps to protect the information we hold about you. These are designed to prevent unauthorised access, modification or disclosure and to prevent misuse and loss.  

 

We protect your information using technical measures (eg. ISO 27001 certified practice management systems and databases, strong passwords) and organisational measures (eg, staff training, confidentiality agreements, access restricted to need-to-know). We do not store paper records containing patient personal information. Any paper-based records are converted to digital documents and stored in our practice management system, PracSuite, before being destroyed. Digital records are held on cloud storage compliant with Australian law in PracSuite. We also maintain a data breach response plan to act swiftly if unauthorised access occurs, in line with the 2024 Privacy Act updates. We use secure, encrypted platforms for telehealth, complying with the Privacy Act’s technical security requirements to protect your information during virtual consultations.  

 

YOUR RIGHT TO RECEIVE TREATMENT FROM US ANONYMOUSLY (OR BY USSING A PSEUDONYM)

 

Where it is lawful and practicable for us to do so, you can be treated anonymously or through use of a pseudonym (a name other than yours).  

Note that anonymity may not be possible for services requiring identification, such as Medicare or health fund claims. 

 

DISCLOSING INFORMATION  ABOUT YOU OVERSEAS

 

We do not disclose your information overseas. If we use cloud storage, we ensure providers comply with Australian privacy laws. Should we need to transfer your information abroad, we’ll seek your consent unless required by law. 

 

Our practice management software system PracSuite ‘PracSuite is hosted using Australian government-approved hosting providers, and, for Australian users, your data will be hosted only on Australian servers. All data is encrypted at rest and in transit. PracSuite enforces two-factor authentication for all users, and also includes several user-configurable security settings, such as IP barring, access schedules and an extensive set of role-based permissions, which work together to limit where, when and what users can access in PracSuite’. 

https://help.smartsoft.com.au/en/articles/4200079-pracsuite-frequently-asked-questions 

 

WHAT WILL WE DO IF WE HAVE A DATA BREACH?

 

We follow the OAICs recommended Data Breach Plan. If we suspect a data breach, we’ll assess it promptly, notify the OAIC and affected patients within 30 days (or sooner if required) and take steps to prevent harm, as mandated by the 2024 Privacy Act amendments. 

IF YOU HAVE A PRIVACY-RELATED CONCERN ABOUT US

 

If you’re concerned about how we’ve handled your privacy, contact us in writing at admin@briesephysio.com.au or call 07 4599 3007. We’ll respond within 30 days. You may also complain to the Office of the Australian Information Commissioner (details below) or seek redress for serious privacy breaches under the 2024 Privacy Act amendments, even without proving harm.  

Office of the Australian Information Commissioner 

Phone: 1300 363 992 

Email:  enquiries@oaic.gov.au 

Post:  GPO Box 5218 Sydney New South Wales 2001 

Website: www.oaic.gov.au/privacy/privacy-complaints/ 

 

UPDATING THIS POLICY

 

We will update this policy from time to time, to reflect any changes in our information-handling  practices or the law (including the 2024 Privacy Act amendments) or both. We’ll notify you by updating this document on our website: www.briesephysio.com.au or by emailing you directly.  

 

HOW TO CONTACT US

 

To contact us about any privacy related issues, please approach our practice manager at admin@briesephysio.com.au or by calling 07 4599 3007. 

bottom of page