top of page

Privacy Policy Australia

1. Introduction

Intrahealth Systems Limited (“Intrahealth,” “we,” “us,” or “our”) is a HEALWELL AI Inc. company that provides electronic medical record (EMR), practice management, interoperability, and related digital health solutions for healthcare organizations and providers. Our solutions support clinical documentation, scheduling, billing, care coordination and operational workflows across healthcare settings.

This Privacy Policy explains how Intrahealth collects, uses, discloses, retains, and safeguards personal information (“PI”) and health information in connection with:

  • the provision of Intrahealth products and services; and

  • use of the Intrahealth website and related digital platforms.

Because Intrahealth is part of the HEALWELL group, certain general privacy practices (including governance, security standards, and corporate oversight) are described in the HEALWELL AI Inc. Privacy Policy, which can be accessed here.

The Intrahealth Privacy Policy (“this policy”) provides additional detail specific to Intrahealth’s products and operations. This policy has been drafted in accordance with the privacy and health information laws that apply to us within Australia.

2. Our Role

Intrahealth provides technology solutions to healthcare organisations and healthcare providers. In most cases, we act as a technology service provider on behalf of healthcare organisations or healthcare providers that determine the purposes for which personal and health information are collected, used, and disclosed. Unless expressly stated otherwise, Intrahealth does not independently determine the purposes for which patient health information is processed and does not use patient health information for its own independent commercial purposes.

Where Intrahealth processes personal and health information on behalf of a healthcare organisation or healthcare provider, we do so:

  • in accordance with our contractual arrangements with that organisation or provider,

  • solely for the purposes of delivering the requested products and services,

  • in accordance with applicable privacy and health information laws, and

  • subject to appropriate technical, organisational, and contractual safeguards designed to protect the confidentiality, integrity, and security of the information entrusted to us.

Where we collect personal information directly through our website or in connection with our own business operations (such as responding to enquiries, providing customer support, managing business relationships, or marketing its products and services), we are responsible for determining how that information is collected, used, and disclosed in accordance with this policy.

3. Information We Collect

3.1 Sources of Personal and Health Information  

Intrahealth collects personal information directly from healthcare providers, healthcare organisations, authorised users, and other individuals who interact with us. We may also receive personal information through authorised integrations with third-party clinical systems, healthcare organisations, and other parties acting on behalf of our customers. Depending on the services provided, we may collect personal information:  

  • directly from you when you use our products or services or communicate with us,

  • from healthcare organisations or authorised users who use our systems,

  • through integrations with electronic medical record (EMR) systems and other authorised healthcare systems,

  • automatically through the use of our products, websites, and digital services (such as system logs, audit trails, cookies, and similar technologies,

  • from third parties where authorised by the relevant healthcare organisation or otherwise permitted by law.

Where Intrahealth receives health information relating to patients, that information is generally provided by the relevant healthcare organisation or healthcare provider using our systems.

3.2 Information related to healthcare providers and authorized users

When healthcare providers, healthcare organisations, or authorised users interact with Intrahealth products, services, or our website, we may collect:

  • account and contact information (such as your name, organisation, job title, email address, telephone number, and business address),

  • credentials and authentication information,

  • administrative and configuration information required to establish and manage your account,

  • Billing and invoicing details,

  • communications with us, including support requests, implementation activities, feedback, and enquiries, and

  • technical and usage information, including IP addresses, device identifiers, browser information, audit logs, and system activity data.

Where we collect personal information directly from you, we will generally explain whether the information is required by law or is necessary to provide the requested products or services, and the consequences of not providing it. Where you choose not to provide information that is reasonably necessary for us to establish your account, provide support, or deliver requested services, we may be unable to provide those services or respond to your request.

3.3 Information related to patients

Intrahealth does not generally collect health information directly from patients. Instead, healthcare organisations and healthcare providers make patient information available through our systems so that we can provide authorised services on their behalf. Depending on the services being provided, patient information processed through our systems may include:

  • electronic medical record (EMR) information,

  • demographic information and healthcare identifiers,

  • appointment, scheduling, billing, and administrative information,

  • clinical documentation, diagnoses, medications, treatment information, and clinical notes, 

  • information generated through clinical interactions, including virtual care services and telephony services where applicable,

  • program-specific healthcare information,

  • de-identified or aggregated information where authorised by the relevant healthcare organisation or otherwise permitted by law.

Health information is considered sensitive information under the Privacy Act 1988 and receives a higher level of protection. Intrahealth processes health information solely in accordance with the instructions of the relevant healthcare organisation or healthcare provider and only for authorised purposes.  

4. How we use the information we collect

Intrahealth uses personal information relating to healthcare providers, healthcare organizations, and authorized users to:

  • Deliver, configure, and administer our products and services, 

  • Authenticate users and manage access to our systems,

  • Provide onboarding, implementation, training, customer support, and service communications,

  • Monitor, maintain, and improve the performance, reliability, security, and functionality of our products and services,

  • Process billing and manage contractual relationships,

  • Investigate, prevent, and respond to security incidents, fraud, misuse, or other activities that may affect the integrity of our systems,

  • Comply with applicable legal, regulatory, and contractual obligations.

Health information processed through Intrahealth systems is used only for purposes authorized by the relevant healthcare organization or healthcare provider, including to:

  • Support the delivery, coordination, and continuity of healthcare services,

  • Enable EMR and practice management functionality,

  • Facilitate authorised interoperability and secure exchange of health information between healthcare systems,

  • Support quality improvement, reporting, and healthcare operations as authorised by the relevant healthcare organisation or healthcare provider,

  • Provide technical support and system maintenance where access to health information is necessary to diagnose or resolve service issues, and

  • Maintain the security, integrity, availability, and reliability of our systems.

Intrahealth processes patient personal and health information only for the purposes for which it was collected, or for related purposes that are authorized by the relevant healthcare organization or healthcare provider, permitted by law, or reasonably expected by the individual.

5. Artificial Intelligence (AI) and analytics

Intrahealth systems may incorporate analytics and AI-assisted features designed to support operational and administrative efficiency, improve service delivery, and enhance the performance and usability of our products and services. These technologies may be used to:

  • Support operational reporting and business process improvement,

  • Assist with customer support, service delivery, and administrative functions,

  • Improve product functionality, system performance, and user experience, and

  • Support internal compliance, quality assurance, and operational activities.

These tools are used exclusively for non-clinical purposes and are not designed to process, analyse, or interact with identifiable patient health information. We do not use identifiable personal or health information in any AI system for independent model training, profiling, or automated decision-making. Where AI-assisted functionality is used, outputs are reviewed and validated by an authorised Intrahealth employee before being relied upon. AI-assisted technologies are intended to support human decision-making and do not replace professional or clinical judgement.

6. Website information and cookies

When healthcare providers, authorised users, or other individuals visit our website, we may collect:  

  • Contact information that you voluntarily provide when completing online forms, requesting information, registering for events, or contacting us,

  • Technical information such as your IP address, browser type, device information, operating system, and website usage data,

  • Cookies and similar technologies used to support website functionality, improve user experience, analyse website performance, and understand how visitors interact with our website.

Where lawful and practicable, you may browse our website anonymously or use a pseudonym. However, certain features or services, including requesting product information, demonstrations, customer support, or other communications, require us to collect sufficient personal information to respond to your request(s). We use cookies and similar technologies to:

  • operate and maintain our website,

  • analyse website usage and performance,

  • improve website functionality and user experience, and

  • support communications regarding our products and services where permitted by law.

 

You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

7. Disclosure of information

Intrahealth discloses health information only where necessary to deliver the services requested by the relevant healthcare organisation or healthcare provider, or as otherwise permitted under applicable privacy legislation. Health information may be disclosed to:

  • the relevant healthcare organisation or healthcare provider using our services,

  • authorised third-party service providers that support the operation, hosting, maintenance, or security of our systems,

  • organisations involved in the secure exchange of health information where authorised by the relevant healthcare organisation or healthcare provider, and

  • regulators, law enforcement agencies, courts, or other authorities where disclosure is required or authorised by law.

All third-party service providers are contractually required to protect personal and health information, act only on Intrahealth's instructions, and implement appropriate privacy and security safeguards.

We may disclose personal information relating to healthcare providers, authorised users, and website visitors to:

  • contracted service providers that support our products, website, hosting, communications, analytics, or customer support,

  • professional advisers, including legal, financial, and accounting advisers,

  • regulators, courts, law enforcement agencies, or government authorities where required or authorised by law, and

  • prospective purchasers or business partners in connection with a merger, acquisition, financing, or other corporate transaction, subject to appropriate confidentiality obligations.

8. Overseas Disclosure of Personal Information

Intrahealth is committed to protecting personal information and health information wherever it is processed. As a general principle, core EMR health information is not transferred outside the jurisdiction in which it is generated or hosted. Core clinical information remains stored and processed within the applicable jurisdiction in accordance with customer contractual requirements and applicable privacy and health information laws. In limited circumstances, certain operational services or optional integrations (for example, communications services, telehealth functionality, cloud-based infrastructure, or technical support) may involve authorised third-party service providers located outside Australia. Where such services are used:

  • the involvement of the third-party service provider is disclosed to the relevant healthcare organisation through contractual arrangements,

  • only the minimum personal information necessary to provide the requested service is disclosed,

  • access is limited to authorised personnel with a legitimate business need, and

  • appropriate contractual, technical, and organisational safeguards are implemented before any overseas access or disclosure occurs.

Before disclosing personal information overseas, Intrahealth takes reasonable steps to ensure that overseas recipients handle personal information in a manner that is consistent with the Australian Privacy Principles or are otherwise subject to privacy obligations that provide protections that are substantially similar to those required under the Australian Privacy Principles. These safeguards may include:

  • contractual privacy, confidentiality, and security obligations,

  • encryption of personal information in transit and at rest,

  • role-based access controls and least-privilege access principles,

  • data minimisation practices,

  • ongoing monitoring and security oversight of systems processing personal information, and

  • due diligence assessments of third-party service providers before engagement and periodically thereafter.

Where required by law or by contractual arrangements with our customers, Intrahealth will notify relevant healthcare organisations of any overseas disclosures relating to the services we provide.

9. Data Security

Intrahealth is committed to protecting the personal and health information entrusted to us. We implement reasonable technical, physical, and organisational measures designed to protect personal and health information from misuse, interference, loss, and unauthorised access, modification, or disclosure, in accordance with applicable privacy laws and recognised information security standards and practices. We regularly review and update our security practices to respond to evolving technologies, security threats, and legal requirements. Although we take reasonable steps to protect the information we hold, no method of electronic transmission or storage can be guaranteed to be completely secure. Where Intrahealth becomes aware of an eligible data breach, we will comply with our obligations under applicable privacy laws, including the Notifiable Data Breaches Scheme under the Privacy Act 1988, as applicable.

10. Data Retention 

Intrahealth retains personal and health information only for as long as reasonably necessary to:

  • deliver the products and services requested by our customers,

  • comply with applicable legal, regulatory, and contractual obligations,

  • support authorised healthcare operations, and

  • resolve disputes, enforce our agreements, or meet other legitimate business requirements where permitted by law.

Where Intrahealth processes health information on behalf of a healthcare organisation or healthcare provider, we retain that information only in accordance with our contractual arrangements and the instructions of the relevant healthcare organisation or healthcare provider. Where authorised, Intrahealth may retain or use de-identified or aggregated information for purposes such as service improvement, analytics, quality assurance, product development, or statistical reporting. Intrahealth does not de-identify identifiable health information without appropriate authorisation from the relevant healthcare organisation or healthcare provider. When personal information is no longer required for the purposes for which it was collected, and we are not otherwise required or authorised to retain it, we will take reasonable steps to securely destroy or permanently de-identify the information in accordance with applicable privacy laws and our records management practices. 

11. Access, Correction and Complaints

Subject to applicable law, individuals may request access to, or correction of, the personal information that Intrahealth holds about them. Where Intrahealth acts as a service provider on behalf of a healthcare organisation or healthcare provider, that organisation remains responsible for responding to requests relating to patient health information. Where we receive a request directly, we may refer the individual to the appropriate healthcare organisation or assist that organisation in responding to the request in accordance with our contractual arrangements.

If you believe that the personal information we hold about you is inaccurate, incomplete, or out of date, you may request that it be corrected. We will take reasonable steps to correct the information where appropriate or assist the relevant healthcare organisation in doing so.

If you have a concern about how Intrahealth has handled your personal information, we encourage you to contact us first using the contact details provided below so that we can investigate and attempt to resolve your concerns. We will acknowledge the receipt of your complaint and work with you to investigate and resolve it within a reasonable timeframe. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) - https://www.oaic.gov.au/

For any questions or concerns about Intrahealth’s privacy practices or this policy, please contact our Privacy Office at privacy@intrahealth.com

12. Changes to this Privacy Policy

We may update this policy from time to time to reflect changes to our products and services, applicable laws, technology, or our information handling practices. The most current version of this policy will always be available on our website and will include the date on which it was last updated. Where changes are material, we may take additional steps to bring those changes to your attention where appropriate. Your continued use of our website or our products and services following the publication of an updated privacy policy constitutes your acceptance of those changes to the extent permitted by applicable law.

bottom of page