Legal Requirements for Setting Up a Health Practice in Australia
Quick Answer
Every private health practice in Australia is bound by the Privacy Act 1988 (Cth), no matter how small it is. Health information is sensitive information, and a business that provides a health service and holds health records cannot rely on the small business threshold that applies to other businesses. At a minimum your practice needs a Privacy Policy that meets Australian Privacy Principles (APP), a patient collection and consent process, and a data breach response plan. Practices in New South Wales, Victoria and the Australian Capital Territory must also comply with their own State or Territory health records legislation.
Key Requirements
- A Privacy Policy written for health information, not a generic website Privacy Policy
- A collection notice and consent process that satisfies APP 3 and APP 5
- A data breach response plan under the Notifiable Data Breaches scheme
- Patient record retention that meets your State or Territory rules
- Website terms and conditions if you take bookings or payments online
In our experience working with over 10,000 Australian businesses, the most common mistake we see in health practices is a website Privacy Policy published on a practice site. It covers contact forms and cookies. It says nothing about clinical records, retention periods or disclosure to other treating practitioners.
This guide covers the legal documents an Australian health practice actually needs, how the three layers of privacy obligation stack on top of each other, what changes on 10 December 2026, and which of our profession guides applies to you.
Key Takeaways
- The Privacy Act 1988 (Cth) applies to every private health practice in Australia, whatever its turnover, because the practice provides a health service and holds health information.
- Health service providers reported more data breaches than any other sector in 2025, with 225 notifications, or 19% of the national total (OAIC, published 6 July 2026).
- New South Wales, Victoria and the ACT have their own health records laws that sit on top of the Privacy Act, and they set their own record retention periods.
- Ahpra registers about 959,858 practitioners across 15 professions (Ahpra Annual Report 2024/25), but unregistered practitioners such as counsellors, massage therapists and naturopaths carry the same privacy obligations.
- From 10 December 2026, APP 1.7 and APP 1.8 require your Privacy Policy to disclose automated decision-making that significantly affects a patient’s rights or interests.
- Legal123 sells a Health Practice Privacy Policy Template for $249 +GST, generated from a short set of questions about your practice and your State.
Click on any of the questions below to jump to that section of this legal guide.
Legal issues covered in this guide
If you still have a question after reading this legal guide, get in touch, as we’d love to keep adding your questions to this comprehensive guide.
What Legal Documents Does an Australian Health Practice Need?
Every health practice needs four documents before it sees its first patient: a Privacy Policy, a patient collection notice, a consent form, and a data breach response plan. Everything after that depends on how you practise.
The Privacy Policy is the one that is not optional. APP 1.3 requires every APP entity to have a clearly expressed and up-to-date policy about how it manages personal information, and to make that policy available free of charge.
The rest of the stack depends on whether you take online bookings, employ staff, contract other practitioners, or run group programs.
| Document | What it does | Who needs it |
|---|---|---|
| Privacy Policy | Explains how you collect, use, store and disclose health information | Every practice |
| Collection notice | The short notice given at the point you collect information (APP 5) | Every practice |
| Patient consent form | Records consent to treatment and to information sharing | Every practice |
| Data breach response plan | Sets out who does what in the first 30 days of a breach | Every practice |
| Website terms of use | Governs use of your site, including any booking function | Practices with a website |
| Terms of service | Sets your fees, cancellation policy and scope of service | Practices billing patients directly |
| Employment contracts | Covers confidentiality and record handling by staff | Practices with employees |
| Contractor agreements | Covers practitioners renting rooms or working under your banner | Multi-practitioner clinics |
| Telehealth consent | Covers the extra risks of remote consultation | Practices offering telehealth |
| Supervision agreement | Records the terms of clinical supervision | Practitioners supervising others |
Did you know?
Health service providers reported more data breaches than any other sector in Australia in 2025. The Office of the Australian Information Commissioner recorded 225 notifications from health service providers, which is 19% of all 1,205 notifications received that year. (OAIC, published 6 July 2026)
Does the Privacy Act Apply to My Health Practice?
Yes. The Privacy Act 1988 (Cth) applies to every private health practice in Australia, regardless of annual turnover.
Some small businesses in Australia sit outside the Privacy Act. Health practices do not, because the small-business exclusion does not apply to a business that provides a health service and holds health information.
That means a sole practitioner massage therapist working from a spare room has the same core privacy obligations as a 40-person medical centre. The size of the practice changes nothing.
Health information is also classified as sensitive information under the Privacy Act, which triggers a higher standard than ordinary personal information. You generally need consent to collect it, and the rules on using it for any secondary purpose are tighter.
The Three Layers of Legal Obligation for a Health Practice
Australian health practices sit under three separate sets of rules, and they apply at the same time:
- Federal privacy law.
- State or Territory health records law, which only exists in three jurisdictions.
- Professional regulation, through Ahpra for registered practitioners and through professional associations for everyone else.
Most compliance failures happen because a practice satisfies one layer and assumes the others are covered.
What are the 13 Australian Privacy Principles?
The 13 Australian Privacy Principles are the rules in Schedule 1 of the Privacy Act 1988 (Cth) that govern how you handle personal information across its whole life, from collection to destruction.
For a health practice, here are the six most important:
- APP 1 requires you to manage personal information openly and transparently, and to have a Privacy Policy that says how
- APP 3 limits what you collect and requires consent for sensitive information such as health records
- APP 5 requires you to tell patients, at or before the time of collection, what you are collecting and why
- APP 6 limits what you can use the information for after you have collected it
- APP 8 requires you to disclose if your practice management software, cloud storage or email provider stores data overseas
- APP 11 requires you to take reasonable steps to protect it, and to destroy or de-identify it when you no longer need it
Note that APP 8 matters more than most practices realise.
Which States have their own health records laws?
New South Wales, Victoria and the Australian Capital Territory each have their own health records legislation that operates alongside the Privacy Act.
- New South Wales: Health Records and Information Privacy Act 2002 (NSW), which contains 15 Health Privacy Principles and sets retention and security under HPP 5
- Victoria: Health Records Act 2001 (Vic), which contains 11 Health Privacy Principles and sets record retention under HPP 4
- Australian Capital Territory: Health Records (Privacy and Access) Act 1997 (ACT), which gives patients a right of access on shorter timeframes than the Privacy Act
Queensland, South Australia, Western Australia, Tasmania and the Northern Territory have no equivalent private sector health records statute. Practices in those States and Territories rely on the Privacy Act alone, plus their professional standards.
Illustrative Case study
A physiotherapy clinic in Melbourne bought an online Privacy Policy template, published it, and treated the job as done. Two years later, a former patient asked for their full file. The clinic could not produce records from the first year because its old software had been decommissioned and nothing had been exported. HPP 4 of the Health Records Act 2001 (Vic) requires health records to be kept for at least seven years from the date the patient was last provided with a health service, or if they were last treated under 18, until they turn 25. The template said nothing about data retention because it was written for a website, not a practice. The clinic was also unaware of its obligations.
What does Ahpra require of a registered practitioner?
Ahpra requires registered practitioners to meet the Code of Conduct and the professional standards set by their National Board, which includes specific obligations on records, confidentiality and advertising.
Ahpra registers about 959,858 practitioners across 15 regulated professions (Ahpra Annual Report 2024/25), including psychology, physiotherapy, occupational therapy, chiropractic, osteopathy, Chinese medicine, podiatry and pharmacy.
If you are not registered with Ahpra, you are not off the hook. Counsellors, psychotherapists, naturopaths, massage therapists, kinesiologists and nutritionists are self-regulated through their associations, and those associations impose their own codes on record-keeping and confidentiality.
The privacy obligations are identical either way. Registration status changes who audits you, not what the law requires.
What Changes on 10 December 2026?
From 10 December 2026, APP 1.7 and APP 1.8 require your Privacy Policy to disclose your use of automated decision making (AI), where a computer program makes, or substantially helps make, a decision that could reasonably be expected to significantly affect an individual’s rights or interests.
Your Privacy Policy will need to set out three things: the kinds of personal information used in those computer programs, the kinds of decisions made solely by a computer program, and the kinds of decisions where a computer program substantially helps a human make the final call.
This matters more to health practices than it first appears, because AI is already being widely used. AI scribes that draft clinical notes, triage tools that sort intake forms, and booking systems that decline appointments on rules you never wrote are all candidates.
AI Warning
If you are using an AI scribe, an AI triage tool, or any software that screens patients automatically, your current Privacy Policy almost certainly does not disclose it. The requirement starts on 10 December 2026, which means the policy needs to be updated before that date, not after.
Two other changes are already in force. The statutory tort for serious invasions of privacy commenced on 10 June 2025, and it is broader than the Privacy Act because it reaches individuals and entities that are not APP entities. Doxxing offences were also added to the Criminal Code.
Legal Setup Checklist for a New Health Practice
Setting up a practice has a natural order. Some things must exist before your first patient walks in, some can follow in the first month, and some are annual tasks.
What do you need before you see your first patient?
Five things have to be in place before you treat anyone:
- Professional indemnity and public liability insurance, at the level your National Board or association requires
- Ahpra registration, or membership of the relevant professional association
- A Privacy Policy that covers health information and is available free of charge
- A collection notice for the point at which you take patient details
- A consent form covering treatment and information sharing
- An ABN, and GST registration if you expect turnover of $75,000 or more
What do you need in your first month?
In the first month, turn the documents into a working system: a data breach response plan, a records retention rule, and written terms for anyone you work with.
Your data breach response plan needs to name a person, set a timeline, and explain how you will assess whether a breach is likely to cause serious harm. The Notifiable Data Breaches scheme gives you 30 days to complete an assessment.
Set your retention rule now, not later. Seven years from last service is the common baseline, and longer for children, but check the rule in your State.
If you rent rooms to other practitioners, or engage anyone as a contractor, get the agreement in writing before the arrangement starts. Verbal room rental arrangements are the most common source of disputes we see in multi-practitioner clinics.
What should you review every year?
Review your Privacy Policy, your insurance, your software list and your retention practice once a year, and diarise it.
The software list is the one people skip. Every time you add a new booking system, telehealth platform, AI tool or cloud backup, you may have changed where patient data is stored and who can reach it. Your Privacy Policy has to keep up.
Practical advice
Put the review in your calendar for the same week every year, and tie it to your registration renewal so it never gets lost. Most practices we work with pick the week they renew their indemnity insurance.
Legal Guides by Profession
We publish detailed legal guides for the health professions where the rules differ most from the general position.
Mental health practices
Mental health practitioners carry extra obligations around mandatory reporting, capacity and duty of care, and the rules differ by profession.
- Legal Guide for Psychologists, covering mandatory reporting and the Psychology Board requirements
- Legal Guide for Psychiatrists, covering private practice setup and Medical Board obligations
- Legal Guide for Counsellors and Therapists, covering the unregistered professions and association codes
Telehealth and online practices
Telehealth adds a layer of complexity, because you might be treating patients across State borders and storing consultations in software you do not control.
Our telehealth compliance guide covers consent, recording, cross-border issues and the practical steps for psychologists, psychiatrists and counsellors.
Complementary and natural therapies
Naturopaths, massage therapists, kinesiologists and nutritionists are not Ahpra registered, but they hold health information and the Privacy Act applies to them in full.
Our legal guide for complementary and alternative medicine practitioners covers advertising restrictions, therapeutic claims and record keeping.
Which Health Practices Does This Cover?
The obligations in this guide apply to any practice that provides a health service and holds health information, which is a much wider group than most practitioners expect.
- Psychologists and clinical psychologists
- Psychiatrists
- Counsellors and psychotherapists
- Social workers in private practice
- General practitioners and specialists
- Physiotherapists
- Occupational therapists
- Speech pathologists
- Exercise physiologists
- Dietitians and nutritionists
- Chiropractors
- Osteopaths
- Podiatrists
- Acupuncturists and Chinese medicine practitioners
- Naturopaths and herbalists
- Remedial massage therapists
- Myotherapists
- Kinesiologists
- Audiologists
- Optometrists
Remember, if your work involves assessing, maintaining or improving someone’s health, and you write anything down about them, you are holding health information.
Need a Privacy Policy Written for a Health Practice?
Our Health Practice Privacy Policy Template is written for Australian health practices, not for websites. Answer a short set of questions about your practice, your State, your software and your telehealth setup, and the template generates a Privacy Policy that covers health information, retention, overseas storage and patient access. Drafted by an Australian lawyer, updated for the 2026 changes.
Health Practice Privacy Policy Template $249 +GST
Frequently Asked Questions
Do I need a Privacy Policy if I am a sole practitioner?
Yes. A sole practitioner who provides a health service and holds health information is covered by the Privacy Act 1988 (Cth) in the same way as a large clinic.
There is no exemption based on the number of practitioners, the number of patients, or annual turnover. If you keep clinical notes, you need a health practice Privacy Policy.
A sole practitioner’s policy might be shorter because there are fewer systems to describe, but it still must include every required element.
Can I use a generic website Privacy Policy for my practice?
No. A website Privacy Policy is written to cover contact forms, cookies, and marketing lists, and it does not address the issues a health practice must cover.
A health practice Privacy Policy has to cover clinical record retention periods, disclosure to other treating practitioners, patient access and correction rights, third-party requests such as insurers and lawyers, and the handling of records when a practitioner leaves, or the practice closes.
Publishing a website policy on a practice site creates a specific risk. You have made public promises about how you handle information that do not match what you actually do. That mismatch is what a complaint is built on.
How long do I have to keep patient records in Australia?
Seven years from the date of last service is the common baseline, and for a patient who was a child, until they turn 25.
That period comes from State legislation rather than the Privacy Act. New South Wales sets it under HPP 5 of the Health Records and Information Privacy Act 2002 (NSW) and Victoria under HPP 4 of the Health Records Act 2001 (Vic).
In States without health records legislation, the retention period comes from your professional standards and from the limitation period for negligence claims. Seven years is still the working rule for most practices.
What happens if my practice has a data breach?
You must assess the breach within 30 days, and if it is likely to result in serious harm, you must notify both the affected patients and the Office of the Australian Information Commissioner.
The Notifiable Data Breaches scheme sits in Part IIIC of the Privacy Act 1988 (Cth). It applies to your practice for the same reason the rest of the Act does.
Health information carries a higher risk of serious harm than most other categories of data, which means health breaches are more likely to be notifiable than an equivalent breach in another industry. This is part of why health service providers top the notification statistics.
Does the Privacy Act apply if I do not bill Medicare?
Yes. Medicare billing has nothing to do with whether the Privacy Act applies to you.
The test is whether you provide a health service and hold health information. A counsellor seeing private clients for cash, with no Medicare provider number and no rebates, meets that test.
Not billing Medicare removes some obligations, such as those attached to the My Health Records Act 2012 (Cth), but it does not remove your privacy obligations.
Do I need a lawyer to write my Privacy Policy?
No, as long as the template you use is written for health practices in Australia and reflects current law.
Most practices do not need custom drafting. Statute sets the obligations, the required disclosures are known, and a well-built template covers them. But you also need to know and follow your privacy obligations.
Custom drafting is worth it when your practice has something unusual: at-risk patients, a research arm, a group program with shared information, a multi-state corporate structure, or a data-sharing arrangement with another organisation. If that is you, book a call, and we will help you make the right choice.
Further Information
- Health Practice Privacy Policy Template (Australia)
- Legal Guide for Psychologists
- Legal Guide for Psychiatrists
- Legal Guide for Counsellors & Therapists in Australia
- How to Run a Compliant Telehealth Practice
- Legal Guide for Complementary and Alternative Medicine Practitioners
References
- Office of the Australian Information Commissioner, Data breach notifications increase to all-time high in 2025, new NDB stats show (published 6 July 2026)
- Office of the Australian Information Commissioner, Australian Privacy Principles guidelines, Chapter 1: APP 1 Open and transparent management of personal information (version 1.2, 7 October 2025)
- Office of the Australian Information Commissioner, Guide to health privacy (updated May 2025)
- Office of the Australian Information Commissioner, Statutory tort for serious invasions of privacy (commenced 10 June 2025)
- Office of the Australian Information Commissioner, State and territory privacy legislation
- Federal Register of Legislation, Privacy Act 1988 (Cth) (compilation as at 4 June 2026)
- NSW Legislation, Health Records and Information Privacy Act 2002 No 71 (NSW)
- Victorian Legislation, Health Records Act 2001 (Vic) (version 050, in force 1 May 2026)
- Health Complaints Commissioner Victoria, Health records: Providers
- ACT Legislation Register, Health Records (Privacy and Access) Act 1997 (ACT) (Republication 32, 16 November 2025)
- Australian Health Practitioner Regulation Agency, Annual report highlights workforce growth and stronger safeguards in changing health sector, 14 November 2025
- Australian Health Practitioner Regulation Agency, Annual Report 2024/25
Health Practice Privacy Policy Template
Answer eight questions and get a finished Privacy Policy built for your health services and your State.
- State health records law written in
- Telehealth and online bookings covered
- Updated for the December 2026 rules
- Plain text, WordPress and Word formats
- Free updates when the law changes
- Time to complete: Under 15 minutes
- Email & telephone support
Health Practice Privacy Policy Template $249 +GST