Legal Requirements for Setting Up a Health Practice in Australia


In our experience working with over 10,000 Australian businesses, the most common mistake we see in health practices is a website Privacy Policy published on a practice site. It covers contact forms and cookies. It says nothing about clinical records, retention periods or disclosure to other treating practitioners.

This guide covers the legal documents an Australian health practice actually needs, how the three layers of privacy obligation stack on top of each other, what changes on 10 December 2026, and which of our profession guides applies to you.

Key Takeaways

  • The Privacy Act 1988 (Cth) applies to every private health practice in Australia, whatever its turnover, because the practice provides a health service and holds health information.
  • Health service providers reported more data breaches than any other sector in 2025, with 225 notifications, or 19% of the national total (OAIC, published 6 July 2026).
  • New South Wales, Victoria and the ACT have their own health records laws that sit on top of the Privacy Act, and they set their own record retention periods.
  • Ahpra registers about 959,858 practitioners across 15 professions (Ahpra Annual Report 2024/25), but unregistered practitioners such as counsellors, massage therapists and naturopaths carry the same privacy obligations.
  • From 10 December 2026, APP 1.7 and APP 1.8 require your Privacy Policy to disclose automated decision-making that significantly affects a patient’s rights or interests.
  • Legal123 sells a Health Practice Privacy Policy Template for $249 +GST, generated from a short set of questions about your practice and your State.

Click on any of the questions below to jump to that section of this legal guide.

If you still have a question after reading this legal guide, get in touch, as we’d love to keep adding your questions to this comprehensive guide.


Every health practice needs four documents before it sees its first patient: a Privacy Policy, a patient collection notice, a consent form, and a data breach response plan. Everything after that depends on how you practise.

The Privacy Policy is the one that is not optional. APP 1.3 requires every APP entity to have a clearly expressed and up-to-date policy about how it manages personal information, and to make that policy available free of charge.

The rest of the stack depends on whether you take online bookings, employ staff, contract other practitioners, or run group programs.

DocumentWhat it doesWho needs it
Privacy PolicyExplains how you collect, use, store and disclose health informationEvery practice
Collection noticeThe short notice given at the point you collect information (APP 5)Every practice
Patient consent formRecords consent to treatment and to information sharingEvery practice
Data breach response planSets out who does what in the first 30 days of a breachEvery practice
Website terms of useGoverns use of your site, including any booking functionPractices with a website
Terms of serviceSets your fees, cancellation policy and scope of servicePractices billing patients directly
Employment contractsCovers confidentiality and record handling by staffPractices with employees
Contractor agreementsCovers practitioners renting rooms or working under your bannerMulti-practitioner clinics
Telehealth consentCovers the extra risks of remote consultationPractices offering telehealth
Supervision agreementRecords the terms of clinical supervisionPractitioners supervising others
information

Did you know?

Health service providers reported more data breaches than any other sector in Australia in 2025. The Office of the Australian Information Commissioner recorded 225 notifications from health service providers, which is 19% of all 1,205 notifications received that year. (OAIC, published 6 July 2026)


Does the Privacy Act Apply to My Health Practice?

Yes. The Privacy Act 1988 (Cth) applies to every private health practice in Australia, regardless of annual turnover.

Some small businesses in Australia sit outside the Privacy Act. Health practices do not, because the small-business exclusion does not apply to a business that provides a health service and holds health information.

That means a sole practitioner massage therapist working from a spare room has the same core privacy obligations as a 40-person medical centre. The size of the practice changes nothing.

Health information is also classified as sensitive information under the Privacy Act, which triggers a higher standard than ordinary personal information. You generally need consent to collect it, and the rules on using it for any secondary purpose are tighter.


Australian health practices sit under three separate sets of rules, and they apply at the same time:

  1. Federal privacy law.
  2. State or Territory health records law, which only exists in three jurisdictions.
  3. Professional regulation, through Ahpra for registered practitioners and through professional associations for everyone else.

Most compliance failures happen because a practice satisfies one layer and assumes the others are covered.

What are the 13 Australian Privacy Principles?

The 13 Australian Privacy Principles are the rules in Schedule 1 of the Privacy Act 1988 (Cth) that govern how you handle personal information across its whole life, from collection to destruction.

For a health practice, here are the six most important:

  • APP 1 requires you to manage personal information openly and transparently, and to have a Privacy Policy that says how
  • APP 3 limits what you collect and requires consent for sensitive information such as health records
  • APP 5 requires you to tell patients, at or before the time of collection, what you are collecting and why
  • APP 6 limits what you can use the information for after you have collected it
  • APP 8 requires you to disclose if your practice management software, cloud storage or email provider stores data overseas
  • APP 11 requires you to take reasonable steps to protect it, and to destroy or de-identify it when you no longer need it

Note that APP 8 matters more than most practices realise.

Which States have their own health records laws?

New South Wales, Victoria and the Australian Capital Territory each have their own health records legislation that operates alongside the Privacy Act.

Queensland, South Australia, Western Australia, Tasmania and the Northern Territory have no equivalent private sector health records statute. Practices in those States and Territories rely on the Privacy Act alone, plus their professional standards.

light bulb blue

Illustrative Case study

A physiotherapy clinic in Melbourne bought an online Privacy Policy template, published it, and treated the job as done. Two years later, a former patient asked for their full file. The clinic could not produce records from the first year because its old software had been decommissioned and nothing had been exported. HPP 4 of the Health Records Act 2001 (Vic) requires health records to be kept for at least seven years from the date the patient was last provided with a health service, or if they were last treated under 18, until they turn 25. The template said nothing about data retention because it was written for a website, not a practice. The clinic was also unaware of its obligations.

What does Ahpra require of a registered practitioner?

Ahpra requires registered practitioners to meet the Code of Conduct and the professional standards set by their National Board, which includes specific obligations on records, confidentiality and advertising.

Ahpra registers about 959,858 practitioners across 15 regulated professions (Ahpra Annual Report 2024/25), including psychology, physiotherapy, occupational therapy, chiropractic, osteopathy, Chinese medicine, podiatry and pharmacy.

If you are not registered with Ahpra, you are not off the hook. Counsellors, psychotherapists, naturopaths, massage therapists, kinesiologists and nutritionists are self-regulated through their associations, and those associations impose their own codes on record-keeping and confidentiality.

The privacy obligations are identical either way. Registration status changes who audits you, not what the law requires.


What Changes on 10 December 2026?

From 10 December 2026, APP 1.7 and APP 1.8 require your Privacy Policy to disclose your use of automated decision making (AI), where a computer program makes, or substantially helps make, a decision that could reasonably be expected to significantly affect an individual’s rights or interests.

Your Privacy Policy will need to set out three things: the kinds of personal information used in those computer programs, the kinds of decisions made solely by a computer program, and the kinds of decisions where a computer program substantially helps a human make the final call.

This matters more to health practices than it first appears, because AI is already being widely used. AI scribes that draft clinical notes, triage tools that sort intake forms, and booking systems that decline appointments on rules you never wrote are all candidates.

warning red 3

AI Warning

If you are using an AI scribe, an AI triage tool, or any software that screens patients automatically, your current Privacy Policy almost certainly does not disclose it. The requirement starts on 10 December 2026, which means the policy needs to be updated before that date, not after.

Two other changes are already in force. The statutory tort for serious invasions of privacy commenced on 10 June 2025, and it is broader than the Privacy Act because it reaches individuals and entities that are not APP entities. Doxxing offences were also added to the Criminal Code.


Setting up a practice has a natural order. Some things must exist before your first patient walks in, some can follow in the first month, and some are annual tasks.

What do you need before you see your first patient?

Five things have to be in place before you treat anyone:

  • Professional indemnity and public liability insurance, at the level your National Board or association requires
  • Ahpra registration, or membership of the relevant professional association
  • A Privacy Policy that covers health information and is available free of charge
  • A collection notice for the point at which you take patient details
  • A consent form covering treatment and information sharing
  • An ABN, and GST registration if you expect turnover of $75,000 or more

What do you need in your first month?

In the first month, turn the documents into a working system: a data breach response plan, a records retention rule, and written terms for anyone you work with.

Your data breach response plan needs to name a person, set a timeline, and explain how you will assess whether a breach is likely to cause serious harm. The Notifiable Data Breaches scheme gives you 30 days to complete an assessment.

Set your retention rule now, not later. Seven years from last service is the common baseline, and longer for children, but check the rule in your State.

If you rent rooms to other practitioners, or engage anyone as a contractor, get the agreement in writing before the arrangement starts. Verbal room rental arrangements are the most common source of disputes we see in multi-practitioner clinics.

What should you review every year?

Review your Privacy Policy, your insurance, your software list and your retention practice once a year, and diarise it.

The software list is the one people skip. Every time you add a new booking system, telehealth platform, AI tool or cloud backup, you may have changed where patient data is stored and who can reach it. Your Privacy Policy has to keep up.

light bulb blue

Practical advice

Put the review in your calendar for the same week every year, and tie it to your registration renewal so it never gets lost. Most practices we work with pick the week they renew their indemnity insurance.


We publish detailed legal guides for the health professions where the rules differ most from the general position.

Mental health practices

Mental health practitioners carry extra obligations around mandatory reporting, capacity and duty of care, and the rules differ by profession.

Telehealth and online practices

Telehealth adds a layer of complexity, because you might be treating patients across State borders and storing consultations in software you do not control.

Our telehealth compliance guide covers consent, recording, cross-border issues and the practical steps for psychologists, psychiatrists and counsellors.

Complementary and natural therapies

Naturopaths, massage therapists, kinesiologists and nutritionists are not Ahpra registered, but they hold health information and the Privacy Act applies to them in full.

Our legal guide for complementary and alternative medicine practitioners covers advertising restrictions, therapeutic claims and record keeping.


Which Health Practices Does This Cover?

The obligations in this guide apply to any practice that provides a health service and holds health information, which is a much wider group than most practitioners expect.

  • Psychologists and clinical psychologists
  • Psychiatrists
  • Counsellors and psychotherapists
  • Social workers in private practice
  • General practitioners and specialists
  • Physiotherapists
  • Occupational therapists
  • Speech pathologists
  • Exercise physiologists
  • Dietitians and nutritionists
  • Chiropractors
  • Osteopaths
  • Podiatrists
  • Acupuncturists and Chinese medicine practitioners
  • Naturopaths and herbalists
  • Remedial massage therapists
  • Myotherapists
  • Kinesiologists
  • Audiologists
  • Optometrists

Remember, if your work involves assessing, maintaining or improving someone’s health, and you write anything down about them, you are holding health information.

Need a Privacy Policy Written for a Health Practice?

Our Health Practice Privacy Policy Template is written for Australian health practices, not for websites. Answer a short set of questions about your practice, your State, your software and your telehealth setup, and the template generates a Privacy Policy that covers health information, retention, overseas storage and patient access. Drafted by an Australian lawyer, updated for the 2026 changes.

Health Practice Privacy Policy Template $249 +GST


Frequently Asked Questions

Do I need a Privacy Policy if I am a sole practitioner?

Yes. A sole practitioner who provides a health service and holds health information is covered by the Privacy Act 1988 (Cth) in the same way as a large clinic.

There is no exemption based on the number of practitioners, the number of patients, or annual turnover. If you keep clinical notes, you need a health practice Privacy Policy.

A sole practitioner’s policy might be shorter because there are fewer systems to describe, but it still must include every required element.

Can I use a generic website Privacy Policy for my practice?

No. A website Privacy Policy is written to cover contact forms, cookies, and marketing lists, and it does not address the issues a health practice must cover.

A health practice Privacy Policy has to cover clinical record retention periods, disclosure to other treating practitioners, patient access and correction rights, third-party requests such as insurers and lawyers, and the handling of records when a practitioner leaves, or the practice closes.

Publishing a website policy on a practice site creates a specific risk. You have made public promises about how you handle information that do not match what you actually do. That mismatch is what a complaint is built on.

How long do I have to keep patient records in Australia?

Seven years from the date of last service is the common baseline, and for a patient who was a child, until they turn 25.

That period comes from State legislation rather than the Privacy Act. New South Wales sets it under HPP 5 of the Health Records and Information Privacy Act 2002 (NSW) and Victoria under HPP 4 of the Health Records Act 2001 (Vic).

In States without health records legislation, the retention period comes from your professional standards and from the limitation period for negligence claims. Seven years is still the working rule for most practices.

What happens if my practice has a data breach?

You must assess the breach within 30 days, and if it is likely to result in serious harm, you must notify both the affected patients and the Office of the Australian Information Commissioner.

The Notifiable Data Breaches scheme sits in Part IIIC of the Privacy Act 1988 (Cth). It applies to your practice for the same reason the rest of the Act does.

Health information carries a higher risk of serious harm than most other categories of data, which means health breaches are more likely to be notifiable than an equivalent breach in another industry. This is part of why health service providers top the notification statistics.

Does the Privacy Act apply if I do not bill Medicare?

Yes. Medicare billing has nothing to do with whether the Privacy Act applies to you.

The test is whether you provide a health service and hold health information. A counsellor seeing private clients for cash, with no Medicare provider number and no rebates, meets that test.

Not billing Medicare removes some obligations, such as those attached to the My Health Records Act 2012 (Cth), but it does not remove your privacy obligations.

Do I need a lawyer to write my Privacy Policy?

No, as long as the template you use is written for health practices in Australia and reflects current law.

Most practices do not need custom drafting. Statute sets the obligations, the required disclosures are known, and a well-built template covers them. But you also need to know and follow your privacy obligations.

Custom drafting is worth it when your practice has something unusual: at-risk patients, a research arm, a group program with shared information, a multi-state corporate structure, or a data-sharing arrangement with another organisation. If that is you, book a call, and we will help you make the right choice.


Further Information

References

vanessa emilio of legal123

About the Author: Vanessa Emilio

Vanessa Emilio (BA Hons, LLB, ACIS, AGIA) is the Founder and CEO of Legal123.com.au and Practice Director of Legal123 Pty Ltd. Vanessa is a qualified Australian lawyer with 20+ years experience in corporate, banking and trust law. Click for full bio of or follow on LinkedIn.

Need legal documents written specifically for your business? Vanessa and her team draft custom legal documents for Australian online businesses, or you can book a 30-minute call to talk through what you need.

Disclaimer: We hope you found this article helpful, but please be aware that any information, comments or recommendations are general in nature, do not constitute legal advice and may not be suitable for your specific circumstances. Whilst we try our best to ensure that the information is accurate, sometimes there may be errors or new information that has yet to be included. Any decisions you take based on information on this website are made at your own risk and we cannot be held liable for any losses you suffer. Contact us directly before relying on any of this information.

Health Practice Privacy Policy Template

Answer eight questions and get a finished Privacy Policy built for your health services and your State.

  • State health records law written in
  • Telehealth and online bookings covered
  • Updated for the December 2026 rules
  • Plain text, WordPress and Word formats
  • Free updates when the law changes
  • Time to complete: Under 15 minutes
  • Email & telephone support
  • Rated

Health Practice Privacy Policy Template $249 +GST