
Privacy Policy New Zealand
1. Introduction
Intrahealth Systems Limited (“Intrahealth,” “we,” “us,” or “our”) is a HEALWELL AI Inc. company that provides electronic medical record (EMR), practice management, interoperability, and related digital health solutions for healthcare organizations and providers. Our solutions support clinical documentation, scheduling, billing, care coordination and operational workflows across healthcare settings.
This Privacy Policy explains how Intrahealth collects, uses, discloses, retains, and safeguards personal information (“PI”) and personal health information (“PHI”) in connection with:
-
the provision of Intrahealth products and services; and
-
use of the Intrahealth website and related digital platforms.
Because Intrahealth is part of the HEALWELL group, certain general privacy practices (including governance, security standards, and corporate oversight) are described in the HEALWELL AI Inc. Privacy Policy, which can be accessed here.
The Intrahealth Privacy Policy (“this policy”) provides additional detail specific to Intrahealth’s products and operations. This policy has been drafted in accordance with the privacy and health information laws that apply to us within New Zealand.
2. Our Role
Intrahealth provides technology solutions to healthcare organisations and healthcare providers. In most cases, we act as a technology service provider on behalf of healthcare organisations or healthcare providers that determine the purposes for which personal and health information are collected, used, and disclosed. Unless expressly stated otherwise, Intrahealth does not independently determine the purposes for which patient health information is processed and does not use patient health information for its own independent commercial purposes.
Where Intrahealth processes personal and health information on behalf of a healthcare organisation or healthcare provider, we do so:
-
in accordance with our contractual arrangements with that organisation or provider,
-
solely for the purposes of delivering the requested products and services,
-
in accordance with applicable privacy and health information laws and other applicable legal requirements, and
-
subject to appropriate technical, organisational, and contractual safeguards designed to protect the confidentiality, integrity, and security of the information entrusted to us.
Where we collect personal information directly through our website or in connection with our own business operations (such as responding to enquiries, providing customer support, managing business relationships, or marketing its products and services), we are responsible for determining how that information is collected, used, and disclosed in accordance with this policy.
3. Information We Collect
3.1 Sources of Personal and Health Information
Intrahealth collects personal information directly from healthcare providers, healthcare organisations, authorised users, and other individuals who interact with us. We may also receive personal information through authorised integrations with third-party clinical systems, healthcare organisations, and other parties acting on behalf of our customers. Depending on the services provided, we may collect personal information:
-
directly from you when you use our products or services or communicate with us,
-
from healthcare organisations or authorised users who use our systems,
-
through integrations with electronic medical record (EMR) systems and other authorised healthcare systems,
-
automatically through the use of our products, websites, and digital services (such as system logs, audit trails, cookies, and similar technologies,
-
from third parties where authorised by the relevant healthcare organisation or otherwise permitted by law.
Where Intrahealth receives health information relating to patients, that information is generally provided by the relevant healthcare organisation or healthcare provider using our systems. Where we collect personal information indirectly through healthcare organisations, healthcare providers, or other authorised third parties, we will take reasonable steps to provide any notifications required under applicable New Zealand privacy laws, unless an exception applies.
3.2 Information related to healthcare providers and authorized users
When healthcare providers, healthcare organisations, or authorised users interact with Intrahealth products, services, or our website, we may collect:
-
account and contact information (such as your name, organisation, job title, email address, telephone number, and business address),
-
credentials and authentication information,
-
administrative and configuration information required to establish and manage your account,
-
Billing and invoicing details,
-
communications with us, including support requests, implementation activities, feedback, and enquiries, and
-
technical and usage information, including IP addresses, device identifiers, browser information, audit logs, and system activity data.
Where we collect personal information directly from you, we will generally explain why we are collecting the information, how it will be used, who it may be shared with, and the consequences (if any) of not providing it, in accordance with applicable privacy laws. Where you choose not to provide information that is reasonably necessary for us to establish your account, provide support, or deliver requested services, we may be unable to provide those services or respond to your request.
3.3 Information related to patients
Intrahealth generally receives patient information from healthcare organisations and healthcare providers through their use of our systems. In certain circumstances, including through patient-facing services such as HealthConnect, patients may also provide information directly to us. Intrahealth processes this information in accordance with its contractual arrangements with the relevant healthcare organisation or healthcare provider. Depending on the services being provided, patient information processed through our systems may include:
-
electronic medical record (EMR) information,
-
demographic information and healthcare identifiers,
-
appointment, scheduling, billing, and administrative information,
-
clinical documentation, diagnoses, medications, treatment information, and clinical notes,
-
information generated through clinical interactions, including virtual care services and telephony services where applicable,
-
program-specific healthcare information,
-
de-identified or aggregated information where authorised by the relevant healthcare organisation or otherwise permitted by law.
Health information is protected under New Zealand’s Privacy Act 2020 and the Health Information Privacy Code 2020. Intrahealth applies additional safeguards appropriate to the sensitive nature of health information. We process health information solely in accordance with the instructions of the relevant healthcare organisation or healthcare provider and only for authorised purposes.
HealthConnect Patient Portal: Where a healthcare provider makes HealthConnect available to its patients, the functionality enabled by the healthcare provider may allow patients to provide account and authentication information, contact information, demographic updates, appointment and prescription refill requests, responses to forms, questions and messages to healthcare providers, patient-authored clinical notes and observations, measurements, photographs, and file attachments.
HealthConnect may also generate technical and activity information associated with use of the portal, such as login information and audit records. The healthcare provider determines which HealthConnect functionality is made available to patients and remains responsible for determining how patient personal information and health information processed through the portal are collected and used. Intrahealth operates HealthConnect as a technology service provider on behalf of the healthcare provider and does not independently determine the purposes for which patient personal information or health information submitted through HealthConnect is collected or used.
4. How we use the information we collect
Intrahealth uses personal information relating to healthcare providers, healthcare organizations, and authorized users to:
-
Deliver, configure, and administer our products and services,
-
Authenticate users and manage access to our systems,
-
Provide onboarding, implementation, training, customer support, and service communications,
-
Monitor, maintain, and improve the performance, reliability, security, and functionality of our products and services,
-
Process billing and manage contractual relationships,
-
Investigate, prevent, and respond to security incidents, fraud, misuse, or other activities that may affect the integrity of our systems,
-
Comply with applicable legal, regulatory, and contractual obligations.
Health information processed through Intrahealth systems is used only for purposes authorized by the relevant healthcare organization or healthcare provider, including to:
-
Support the delivery, coordination, and continuity of healthcare services,
-
Enable EMR and practice management functionality,
-
Facilitate authorised interoperability and secure exchange of health information between healthcare systems,
-
Support quality improvement, reporting, and healthcare operations as authorised by the relevant healthcare organisation or healthcare provider,
-
Provide technical support and system maintenance where access to health information is necessary to diagnose or resolve service issues, and
-
Maintain the security, integrity, availability, and reliability of our systems,
Intrahealth processes patient PI and PHI only for the purposes for which it was collected, or for directly related purposes that are authorized by the relevant healthcare organization or healthcare provider, permitted by law, or otherwise consistent with the applicable privacy and health information obligations.
Where patients use HealthConnect, information submitted through the portal is processed on behalf of the applicable healthcare provider and used to support the clinical and administrative functions made available by that provider. This may include:
-
Updating or contributing to the patient's health record,
-
Facilitating clinical review and communications with the care team,
-
Managing appointments and prescription refill requests,
-
Supporting account and authentication functions, and
-
Maintaining appropriate security and audit records.
HealthConnect may also facilitate communications to patients, including appointment reminders, account or authentication communications, and messages from their healthcare provider.
5. Artificial Intelligence (AI) and analytics
Intrahealth systems may incorporate analytics and AI-assisted features designed to support operational and administrative efficiency, improve service delivery, and enhance the performance and usability of our products and services. These technologies may be used to:
-
Support operational reporting and business process improvement,
-
Assist with customer support, service delivery, and administrative functions,
-
Improve product functionality, system performance, and user experience, and
-
Support internal compliance, quality assurance, and operational activities.
These tools are used exclusively for non-clinical purposes and are not designed to process, analyse, or interact with identifiable patient health information. We do not use identifiable personal information or health information in any AI system for independent model training, profiling, or for solely automated decision-making. Where AI-assisted functionality is used, outputs are reviewed and validated by an authorised Intrahealth employee before being relied upon. AI-assisted technologies are intended to support human decision-making and do not replace professional or clinical judgement.
6. Website information and cookies
When healthcare providers, authorised users, or other individuals visit our website or interact with our online services, we may collect:
-
Contact information that you voluntarily provide when completing online forms, requesting information, registering for events, or contacting us,
-
Technical information such as your IP address, browser type, device information, operating system, and website usage data,
-
Cookies and similar technologies used to support website functionality, improve user experience, analyse website performance, and understand how visitors interact with our website.
Where practicable, you may browse our website anonymously or use a pseudonym. However, certain features or services, including requesting product information, demonstrations, customer support, or other communications, require us to collect sufficient personal information to respond to your request(s). We use cookies and similar technologies to:
-
operate and maintain our website,
-
analyse website usage and performance,
-
improve website functionality and user experience, and
-
support communications regarding our products and services where permitted by law.
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
7. Disclosure of information
Intrahealth discloses PI and PHI only where necessary to deliver the services requested by the relevant healthcare organization or healthcare provider, or as otherwise permitted or required under the applicable privacy and health information laws. Health information may be disclosed to:
-
the relevant healthcare organisation or healthcare provider using our services,
-
authorised third-party service providers that support the operation, hosting, maintenance, or security of our systems,
-
organisations involved in the secure exchange of health information where authorised by the relevant healthcare organisation or healthcare provider, and
-
regulators, law enforcement agencies, courts, or other authorities where disclosure is required or authorised by law.
All third-party service providers are contractually required to protect PI and PHI, use the information only for authorized purposes, and implement appropriate privacy and security safeguards.
We may disclose personal information relating to healthcare providers, authorised users, and website visitors to:
-
contracted service providers that support our products, website, hosting, communications, analytics, or customer support,
-
professional advisers, including legal, financial, and accounting advisers,
-
regulators, courts, law enforcement agencies, or government authorities where required or authorised by law, and
-
prospective purchasers or business partners in connection with a merger, acquisition, financing, or other corporate transaction, subject to appropriate confidentiality obligations.
8. Overseas Disclosure of Personal Information
Intrahealth is committed to protecting personal information and health information wherever it is processed. As a general principle, core EMR health information is not transferred outside the jurisdiction in which it is generated or hosted. Core clinical information remains stored and processed within the applicable jurisdiction in accordance with customer contractual requirements and applicable privacy and health information laws. In limited circumstances, certain operational services or optional integrations (for example, communications services, telehealth functionality, cloud-based infrastructure, or technical support) may involve authorised third-party service providers located outside New Zealand. Where such services are used:
-
the involvement of the third-party service provider is disclosed to the relevant healthcare organisation through contractual arrangements,
-
only the minimum personal information necessary to provide the requested service is disclosed,
-
access is limited to authorised personnel with a legitimate business need, and
-
appropriate contractual, technical, and organisational safeguards are implemented before any overseas access or disclosure occurs.
Before disclosing personal information outside New Zealand, Intrahealth takes reasonable steps to ensure that any overseas recipient is required to protect the information in a manner that provides safeguards comparable to those required under New Zealand privacy laws or that another lawful basis for the disclosure applies under the Privacy Act 2020. These safeguards may include:
-
contractual privacy, confidentiality, and security obligations,
-
encryption of personal information in transit and at rest,
-
role-based access controls and least-privilege access principles,
-
data minimisation practices,
-
ongoing monitoring and security oversight of systems processing personal information, and
-
due diligence assessments of third-party service providers before engagement and periodically thereafter.
Where required by law or by our contractual arrangements with our customers, Intrahealth will notify relevant healthcare organizations of any overseas disclosures relating to the services we provide.
9. Data Security
Intrahealth is committed to protecting the personal and health information entrusted to us. We implement reasonable technical, physical, and organizational measures designed to protect PI and PHI from loss, misuse, unauthorised access, use, modification, or disclosure, in accordance with applicable New Zealand privacy and health information laws. Depending on the nature of services provided, these safeguards may include encryption, access controls, audit logging, secure infrastructure, staff training, and contractual security requirements for third-party service providers. We regularly review and update our security practices to respond to evolving technologies, security threats, and legal requirements. Although we take reasonable steps to protect the information we hold, no method of electronic transmission or storage can be guaranteed to be completely secure. If we become aware of a notifiable privacy breach, we will take prompt steps to respond and, where required, notify affected individuals and the Privacy Commissioner in accordance with applicable New Zealand law.
10. Data Retention
Intrahealth retains personal and health information only for as long as reasonably necessary to:
-
deliver the products and services requested by our customers,
-
comply with applicable legal, regulatory, and contractual obligations,
-
support authorised healthcare operations, and
-
resolve disputes, enforce our agreements, or meet other legitimate business requirements where permitted by law.
Where Intrahealth processes health information on behalf of a healthcare organization or healthcare provider, we retain that information only in accordance with our contractual arrangements and the instructions of the relevant healthcare organization or healthcare provider. Where authorized, Intrahealth may retain or use de-identified or aggregated information for purposes such as service improvement, analytics, quality assurance, product development, or statistical reporting. Intrahealth does not de-identify identifiable health information without appropriate authorization from the relevant healthcare organization or healthcare provider. When personal information is no longer required for the purposes for which it was collected, and we are not otherwise required or authorised to retain it, we will take reasonable steps to securely destroy or permanently de-identify the information in accordance with applicable privacy laws and our records management practices.
11. Access, Correction and Complaints
Subject to applicable law, individuals may request access to, or correction of, the personal information that Intrahealth holds about them. Where Intrahealth acts as a technology service provider on behalf of a healthcare organization or healthcare provider, that organization remains responsible for responding to requests relating to patient health information. Where we receive a request directly, we may refer the individual to the appropriate healthcare organization or assist that organization in responding to the request in accordance with our contractual arrangements.
If you believe that the personal information we hold about you is inaccurate, incomplete, or out of date, you may request that it be corrected. We will take reasonable steps to correct the information where appropriate or assist the relevant healthcare organization in doing so. If we do not make a requested correction, we will take reasonable steps to record the requested correction where required by applicable law.
If you have a concern about how Intrahealth has handled your personal information, we encourage you to contact us first using the contact details provided below so that we can investigate and attempt to resolve your concerns. We will acknowledge receipt of your complaint and work with you to investigate and resolve it within a reasonable timeframe. If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner (New Zealand).
More information is available at https://www.privacy.org.nz.
For any questions or concerns about Intrahealth’s privacy practices or this policy, please contact our Privacy Office at privacy@intrahealth.com
12. Changes to this Privacy Policy
We may update this policy from time to time to reflect changes to our products and services, applicable laws, technology, or our information handling practices. The most current version of this policy will always be available on our website and will include the date on which it was last updated. Where changes are material, we may take additional steps to bring those changes to your attention where appropriate.
Your continued use of our website or our products and services following the publication of an updated Privacy Policy constitutes your acceptance of those changes to the extent permitted by applicable law.
