Privacy, consent and the compliant practice: What the Privacy Act reforms mean for your clinic right now
In this article
- Your Privacy Policy no longer reflects your real systems
- Consent is being treated as a form, not a process
- Your website and patient communications are creating advertising risk
- Your internal processes do not match your documents
- You have not reviewed privacy, consent and website terms together
- Why periodic agreement reviews matter
Most healthcare practices assume their privacy and consent processes are compliant until something tests them.
That test may be a patient complaint, a data breach, an Australian Health Practitioner Regulation Agency (‘AHPRA’) advertising concern, a staff mistake, a website review, or a question from a prospective buyer during due diligence. By that stage, the issue is rarely just the wording of a policy. It is often a gap between what the clinic says it does and what actually happens day to day.
For practice owners, privacy and consent are no longer “set and forget” documents. Clinics now collect, store and use patient information through online booking platforms, patient management software, automated reminders, telehealth systems, payment portals, website forms, email marketing tools and, increasingly, artificial intelligence (‘AI’) enabled systems.
The Privacy Act 1988 (Cth) applies to health service providers that hold health information, including small businesses that may otherwise assume they fall outside privacy regulation. The 2024 privacy reforms introduced additional obligations and enforcement mechanisms, reinforcing the importance of ensuring that privacy systems are current, practical and defensible. While many of the reforms commenced on 11 December 2024, the introduction of the new statutory tort for serious invasions of privacy from 10 June 2025 also reflects the broader regulatory focus on how organisations collect, use and protect personal information. Together, these developments signal increased expectations that healthcare providers can demonstrate privacy compliance in practice, not just on paper.
This means practice owners should be asking a practical question: do our privacy policy, consent forms, website terms and conditions, and internal processes reflect how our clinic actually operates?
1. Your Privacy Policy no longer reflects your real systems
One of the most common issues we see is a Privacy Policy that looks acceptable on the surface but does not describe the clinic’s current systems and actual use of patient information.
Many practices have introduced online booking tools, cloud based patient management software, SMS reminders, offshore support, telehealth platforms, digital intake forms, payment gateways or analytics tools since their Privacy Policy was last reviewed. Each of these systems can affect how patient information is collected, stored, accessed, used and disclosed.
Having a Privacy Policy is one thing. Having a Privacy Policy that accurately reflects how patient information actually moves through the practice is another.
Warning signs that your Privacy Policy may be outdated
- it has not been updated since new software was introduced;
- the policy does not mention online bookings, SMS reminders or telehealth;
- staff cannot explain where patient information is stored;
- the practice uses third party platforms that are not reflected in patient facing documents;
- the website collects patient enquiries, but the Privacy Policy is generic.
The 2024 reforms clarified that reasonable steps to protect personal information include technical and organisational measures. For practice owners, this means privacy compliance is not just an IT issue. It includes documentation, governance, staff training, access controls, escalation processes and a clear understanding of who is responsible for what.
2. Consent is being treated as a form, not a process
Consent is often treated as something that happens once, usually when a patient completes an intake form or signs a treatment document.
That approach may not be enough for modern healthcare practices. Consent needs to reflect the specific service, the information being collected, how that information will be used, and any material change in the patient’s care, communication preferences or data handling.
For example, a clinic may need to consider consent for:
- collection and use of sensitive health information;
- telehealth appointments;
- photography or clinical images;
- sharing information with other practitioners or third party providers;
- AI scribing or automation tools;
- marketing communications;
- treatment plans involving therapeutic goods or higher risk services.
The practical risk is inconsistency. One practitioner may explain consent carefully, another may rely on a standard form, and reception staff may be unsure what to say when patients ask how their information will be used.
Practice owners regularly come to us after discovering that their consent forms do not align with how services are actually delivered. In many cases, the form is not wrong because it was badly drafted. It is wrong because the clinic has changed since it was initially prepared.
A well structured consent framework should clearly explain what patients are agreeing to, when consent should be updated, and how the practice keeps an accurate record of that consent.
3. Your website and patient communications are creating advertising risk
Privacy, consent and advertising compliance are increasingly connected.
A clinic website may contain treatment pages, practitioner profiles, patient resources, social media links, online booking functions, email sign ups, blog content and promotional statements. Each piece of content can create risk if it is inaccurate, misleading, unsupported or inconsistent with AHPRA or Therapeutic Goods Administration (‘TGA’) requirements.
Under AHPRA’s advertising guidelines, advertising for regulated health services must not be false, misleading or deceptive, use testimonials or purported testimonials, create unreasonable expectations of beneficial treatment, or encourage indiscriminate or unnecessary use of regulated health services.
For clinics offering cosmetic, skin, weight management, medicinal cannabis, injectables or other services involving therapeutic goods, TGA regulation is also important to consider. The TGA states that prescription only medicines and some other therapeutic goods cannot be advertised to the public, and that health service advertising may still trigger therapeutic goods advertising rules if it directly or indirectly promotes those goods.
The September 2025 AHPRA Cosmetic Procedure Advertising Guidelines also demonstrate the regulator’s increasing focus on ensuring advertising for higher risk cosmetic procedures is responsible, balanced and patient focused. While these guidelines apply specifically to certain cosmetic procedures, they reinforce broader advertising principles that all regulated health service providers should keep in mind.
Warning signs that your advertising may not comply with AHPRA or TGA requirements
- treatment pages that glamourise procedures, minimise their complexity or risks, or overstate likely outcomes;
- patient testimonials appearing on clinic controlled platforms;
- social media posts that imply guaranteed results;
- website terms that do not limit reliance on general health information;
- references to prescription medicines or therapeutic goods in public facing advertising;
- marketing campaigns prepared by external agencies without an understanding of AHPRA or TGA advertising requirements, particularly where they promote regulated health services or therapeutic goods.
For practice owners, the issue is not whether marketing is allowed. Clinics can educate patients and explain their services. The issue is whether communications are accurate, balanced and aligned with the regulatory environment.
Want to talk it through with a lawyer?
Daniela Cecere-Palazzo, Senior Lawyer at You Legal, works with practice owners on privacy, consent and risk. Book a time that suits you.
Book a call with Daniela4. Your internal processes do not match your documents
A privacy policy, consent form or website terms and conditions is only useful if it reflects the actual operations of the clinic.
Regulators and accreditation bodies will not only look at what your documents say. They may also look at staff behaviour, system permissions, training records, incident response steps, email practices, file access, audit logs and how complaints are handled.
This is where many practices are exposed. The documents say one thing, but the operational reality says another.
For example:
- the policy says access is restricted, but all staff use shared logins;
- the consent form says patients can ask questions, but no one records the discussion;
- the privacy policy says data is stored securely, but staff email records to personal accounts;
- the website says information is general only, but booking forms invite detailed clinical disclosures;
- the data breach plan exists, but staff do not know who to notify.
These gaps can be especially concerning in healthcare because patient information is sensitive and personal. The Office of the Australian Information Commissioner (‘OAIC’) health privacy guidance is directed specifically at health service providers handling sensitive health information and embedding privacy into practice operations.
For practice owners, the goal is alignment. Your systems, documents and staff processes should tell the same story.
5. You have not reviewed privacy, consent and website terms and conditions together
Many clinics review documents in isolation. The Privacy Policy is updated by one provider, the website terms and conditions are copied from a template, the consent forms are prepared by a practitioner, and the social media content is managed by an agency.
That can create conflict and uncertainty.
Privacy, consent, advertising and website terms and conditions should work together. The Privacy Policy explains how patient information is handled. Consent forms record patient agreement to specific information handling and treatment processes. Website terms manage reliance on online content and digital interactions. Internal policies direct staff what to do in practice.
When these documents are not reviewed together, gaps appear. A patient may consent to one thing in a form, read something different on the website, and experience a different process at reception.
This matters for risk management, but it also matters for patient trust. Patients are increasingly aware of privacy, data security and the way clinics communicate online. A clear and consistent framework helps patients understand what to expect.
For practice owners, the need for this review often aligns with four key stages in the practice lifecycle. When starting a practice, privacy and consent frameworks help establish compliant foundations. As practices scale, introducing new services, staff, technology or locations often requires those documents and processes to evolve. While strengthening your practice, reviewing privacy, consent and website documentation helps ensure systems remain consistent, defensible and ready for accreditation, investment or future growth opportunities. By the time a practice is preparing for a sale or succession, well maintained legal frameworks can also streamline due diligence and reduce avoidable risk.
Why periodic agreement reviews matter
Periodic agreement reviews matter because privacy, consent and communication documents shape how a practice actually operates.
They influence how patient information moves through the clinic, who is responsible for managing it, how consent is obtained, how services are promoted, and how risk is handled when something goes wrong.
APP Entities, such as medical and health businesses that collect sensitive health information from patients, must comply with the Australian Privacy Principles and be aware of and understand their obligations under the Notifiable Data Breach (‘NDB’) Scheme.
Our Notifiable Data Breach Package includes nine documents that work together to guide you through all phases of the NDB Scheme.
For healthcare practices, these documents also sit alongside other operational agreements, including practitioner services agreements, software agreements, website terms, third party provider terms, employment agreements and marketing arrangements. If one part of the framework is outdated, the whole structure can become inconsistent.
Many practices are still relying on documents drafted several years ago, before telehealth expansion, AI tools, online booking systems, updated privacy reforms and tighter advertising scrutiny became part of everyday clinic management.
A periodic review gives practice owners the opportunity to ask:
- do our documents reflect current legal obligations?
- do they reflect how the clinic operates in practice?
- do staff understand the process?
- are patient communications consistent across the website, forms and front desk?
- would our systems withstand review if tested?
This does not need to be overwhelming. A practical review can identify the key gaps, prioritise the documents that matter most, and help the practice align its systems before a complaint, breach or regulatory issue arises.
If your clinic is unsure whether its privacy policy, consent forms, website terms or AHPRA and TGA communications are still fit for purpose, contact our team here.
Related Fast Track Solutions
Related articles
This article is general information only and is not legal advice. Every practice is different and the law can differ across Australian jurisdictions. Please seek advice tailored to your circumstances before acting.