top of page
section bg1.png

Privacy Policies

Intrahealth provides electronic medical record and clinical software to healthcare organisations in Canada, Australia and New Zealand. Privacy and health information law differs in each of these countries, as do our obligations to the people whose information we handle.

 

Rather than publish a single generic statement, we maintain a separate privacy policy for each country in which we operate, each written to the law that applies there and to the Intrahealth entity that operates in that market.

Please select the policy for your country.

multi-clinic.webp
doctor-computer-office.webp
doctor-and-business-person.webp

New Zealand — Intrahealth New Zealand Limited

How we handle personal information in New Zealand, aligned to the Privacy Act 2020 and the Health Information Privacy Code 2020.

Canada — Intrahealth Canada Limited

How we collect, use, disclose and protect personal information in Canada, aligned to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and to the provincial privacy and health information legislation that applies where our customers operate — including British Columbia's Personal Information Protection Act and E-Health (Personal Health Information Access and Protection of Privacy) Act, Ontario's Personal Health Information Protection Act, 2004, and New Brunswick's Personal Health Information Privacy and Access Act. The policy also describes our role as a service provider, information manager or health information network provider to the custodians and public bodies who use our software.

Australia — Intrahealth Australia Solutions Pty Limited

How we handle personal information in Australia, aligned to the Privacy Act 1988 (Cth), the Australian Privacy Principles, and applicable state and territory health records legislation.

Three country policies, one security standard

Privacy at Intrahealth

Which policy applies to me?

In most cases, the policy for the country in which you are located, or in which the Intrahealth entity that holds your information operates. Where more than one could apply, the more protective standard governs. If you are unsure, contact our Privacy Office and we will tell you which policy applies to your information.

Information we hold on behalf of our customers

Much of the health information within Intrahealth software is not ours. Where a healthcare organisation uses our products to deliver care, that organisation remains responsible for the clinical record, and Intrahealth acts as a service provider handling that information under contract and on their documented instructions.

 

If you are a patient seeking access to, or correction of, your health record, please contact your healthcare provider in the first instance. Each country policy explains this relationship and the safeguards that apply.

How we protect information across all three countries

While our privacy commitments are country-specific, they rest on a single information security management system that applies group-wide. This includes ISO/IEC 27001 certification, defined access control, encryption, vendor and sub-processor governance, security incident and breach response procedures, and independent audit. A summary of our security program is available at https://trust.intrahealth.com; additionally, customers may request our current audit reports under NDA from our trust centre.

Contact our Privacy Office

Questions, access requests and privacy complaints can be directed to our Privacy Office at privacy@intrahealth.com. We acknowledge enquiries within 5 business days and respond substantively within the timeframe required by the applicable law.

 

If you are not satisfied with our response, each country policy sets out your right to escalate to the relevant regulator — the Office of the Privacy Commissioner of Canada or the applicable provincial commissioner, the Office of the Australian Information Commissioner, or the Office of the Privacy Commissioner (New Zealand).

Changes to these policies

We review each policy at least annually and whenever there is a material change to our services or legal obligations. Each policy carries its own version number and effective date, and material changes are notified as described within it.

bottom of page