1. About This Policy
Elevate Health Care (ABN: 13 632 674 246) is committed to protecting your privacy. This policy explains how we manage personal information, including health information, in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Health Records Act 2001 (Vic).
Health information is classified as sensitive information under the APPs and attracts a higher standard of protection. We collect and use health information only where it is necessary to provide you with care, or where you have given explicit consent.
By using our website or attending our clinic, you agree to the collection and use of your information as described in this policy. If you do not agree, please do not use our services or provide us with your personal information.
2. What Information We Collect
Personal information
- Name, date of birth, address, phone number, and email address
- Emergency contact details
- Health fund membership details
- Payment information (processed securely — we do not store full card details)
Health information
- Medical history, current symptoms, medications, and previous treatments
- Clinical notes, assessment findings, and treatment records
- Referral letters and reports from other health practitioners
- Imaging reports and results
Website information
- Browser type, device type, and IP address (collected automatically via analytics)
- Pages visited, time on site, and referral source
- Information submitted via contact forms or booking enquiries
3. How We Collect Information
We collect information directly from you where possible — through intake forms completed before or at your appointment, during consultations, via our online booking system (Jane App), through our website contact forms, and by telephone.
We may also collect information from third parties with your consent, including referring practitioners, specialists, or diagnostic imaging providers.
4. Why We Collect and Use Your Information
We use your personal and health information to:
- Provide chiropractic and related health care services to you
- Communicate with you about appointments, treatment plans, and clinical progress
- Process payments and manage health fund claims
- Comply with legal and regulatory obligations (including AHPRA registration requirements)
- Improve the quality and safety of the care we provide
- Contact you about clinically relevant information or services (you may opt out at any time)
We will not use your health information for marketing purposes without your explicit consent.
5. Direct Marketing
We will not use your health information for direct marketing purposes. We may occasionally use your contact details (name and email) to send you clinically relevant information, appointment reminders, or updates about our services. These communications are not marketing in the commercial sense — they are part of our care relationship with you.
If you do not wish to receive any such communications, you may opt out at any time by contacting us or by using the unsubscribe link in any email we send. We will action your request promptly and at no cost to you.
We will never sell, share, or disclose your contact details to third parties for marketing purposes.
6. Disclosure of Your Information
We may disclose your information to:
- Other treating health practitioners involved in your care (with your knowledge or consent)
- Your nominated emergency contact (in an emergency)
- Health funds, Medicare, or other insurers as required to process claims
- Government agencies or regulators where required by law (e.g. mandatory reporting obligations)
- Our software and service providers (e.g. practice management software, secure cloud storage) — these providers are bound by confidentiality obligations and are not permitted to use your information for any purpose other than providing services to us
We will not sell, rent, or otherwise disclose your personal information to third parties for commercial purposes.
7. Storage and Security
Your health records are stored securely in our practice management system (Jane App). We take reasonable steps to protect your information from misuse, loss, and unauthorised access, including password protection, encryption, and access controls limited to treating practitioners and authorised clinic staff.
Patient records are retained for a minimum of seven years from the date of last entry, or until the age of 25 for patients who were minors at the time of treatment, in accordance with Victorian legislative requirements.
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme (Privacy Act 1988, Part IIIC).
8. Patients Under 18
Where a patient is under 18 years of age, we collect health information with the consent of a parent or legal guardian. A parent or guardian must be present at the initial consultation.
Health records for patients who were minors at the time of treatment are retained until that patient reaches the age of 25, in accordance with Victorian requirements.
A parent or legal guardian may request access to the health records of a child in their care. Where a young person is of sufficient maturity to understand the nature of their health information, we may exercise discretion in providing access to the parent — consistent with the young person's right to confidentiality.
9. Access and Correction
You have the right to request access to the personal and health information we hold about you, and to request corrections if the information is inaccurate, incomplete, or out of date. To make a request, contact us at the details below. We will respond within 30 days. There is no charge for making an access or correction request.
In some circumstances we may decline to provide access — for example, where access would pose a risk to another person's health or safety, or where we are required by law to withhold the information. If we decline, we will explain why in writing.
10. Website Analytics and Cookies
Our website may use cookies and analytics tools (such as Google Analytics) to understand how visitors use the site. This data is aggregated and does not identify individuals. You can disable cookies through your browser settings, though this may affect some website functionality.
11. Links to Third-Party Websites
Our website contains links to third-party websites, including our online booking system (Jane App) and Google Maps. We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies.
12. Complaints
If you believe we have not handled your personal information in accordance with this policy or the Australian Privacy Principles, please contact us in the first instance. We will investigate and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
For complaints relating to health records specifically, you may also contact the Health Complaints Commissioner (Victoria) at hcc.vic.gov.au.
13. Changes to This Policy
We may update this policy from time to time. The current version will always be available on this page. Material changes will be notified to active patients by email where reasonably practicable.
14. Contact Us
For privacy-related enquiries, access requests, or complaints:
- Elevate Health Care
- Suite 30 (Level 1), 93 Wells Road, Chelsea Heights VIC 3196
- (03) 9787 0600