Do you need a privacy policy on your health website? Yes. Here’s what goes in it.
bdog builds websites for clinics. We are not lawyers and this is not legal advice. It’s a map of what the law requires, drawn from the OAIC’s own guidance, so you know what to ask for. Get the policy itself checked by someone qualified, or start from your professional association’s template.

On This Page
There's a widely believed rule that small businesses under $3 million turnover don't have to comply with the Privacy Act. It's true. It just doesn't apply to you.
The Act carves health service providers out of the small business exemption. If you provide a health service and hold health information, you're covered, whether you're a hospital or a sole-practitioner physio working three days a week. That's section 6D(4)(b), and the OAIC's list of who it catches includes GPs, dentists, allied health, psychologists, podiatrists, chiropractors and naturopaths. Cosmetic clinics performing health services are in. So is every practice type bdog builds for, with one exception covered below.
So yes, you need a privacy policy. Here's what it has to contain, the second document most clinics don't know they also need, and the two tracking pixel determinations from June this year that changed what "compliant" means for a health website.
Who's covered, and the vet question
Everyone above, regardless of size. If you're in New South Wales, Victoria or the ACT, a state health records law applies as well: the Health Records and Information Privacy Act in NSW, the Health Records Act in Victoria, and the Health Records (Privacy and Access) Act in the ACT. NSW's applies to every private health service provider regardless of turnover and has its own 15 Health Privacy Principles, so a Sydney clinic answers to two regulators. Other states rely on the federal Act alone.
Vets are the exception. Records about animals aren't health information about a person, so a veterinary practice under $3 million turnover generally still sits inside the small business exemption. Your clients' names, numbers and payment details are personal information all the same, and we'd still recommend a policy. The OAIC hasn't published anything vet-specific that we could find, so if you're a vet, treat this as a reason to get advice rather than a pass.
Two documents, not one
This is the part almost every clinic website gets wrong.
The privacy policy is your standing document. Australian Privacy Principle 1 requires it to be clearly expressed, up to date, free, and available in an appropriate form, which for a business with a website means a link in the footer.
The collection notice is different. Australian Privacy Principle 5 requires that at or before the moment you collect someone's information, you tell them who you are, what you're collecting, why, what happens if they don't provide it, who you usually disclose it to, and where to find your policy. The OAIC says plainly that a privacy policy is not an APP 5 notice.
On a clinic website there are three places you collect information, and each needs a notice or a clear link to one:
- the contact form
- the booking widget or booking page
- the newsletter or resource sign-up
A single sentence under the form, linking to a fuller notice, does the job. "We collect your name, contact details and reason for booking to provide your appointment. See how we handle your information." Then the link. Most clinic sites have none of this.
What the policy must contain
Australian Privacy Principle 1.4 lists it. Your policy has to cover:
- the kinds of personal information you collect and hold
- how you collect it and how you hold it
- why you collect, hold, use and disclose it
- how a patient can access their information and ask for corrections
- how a patient can complain, and how you'll handle the complaint
- whether you're likely to disclose information to anyone overseas
- if so, which countries, where it's practicable to say
The list is a floor, not a ceiling. And from 10 December 2026, there's an eighth item: if you use a computer program to make decisions that could significantly affect someone, the policy has to say so. For most clinics that won't apply. If you've added AI triage or automated booking decisions, it might.
The things on your website the policy has to be honest about
Health information is sensitive information
The reason for a visit, a condition mentioned in a booking form, an intake questionnaire. All health information, all classed as sensitive under the Act, and collecting it normally requires consent. Health service providers get an exception: where the collection is necessary to provide the service and the patient would reasonably expect it, you can collect without separate consent. An intake form asking why someone's booking sits inside that exception. A marketing pixel watching them read your endometriosis page does not. Which brings us to the determinations.
Tracking pixels: the June 2026 decisions
On 11 June 2026 the Privacy Commissioner published two determinations, against Monash IVF and against Medmate. Both had used third-party tracking pixels, the small pieces of code that Meta, Google and others provide for advertising and analytics. Monash had run seven of them, some since 2012, until December 2024. People researching egg freezing, prostate conditions and contraception were tracked and later shown ads.
The Commissioner found both companies had collected sensitive information without consent, failed to notify people it was being collected, and used it for direct marketing without a lawful basis. Three breaches each, of Australian Privacy Principles 3.3, 5.1 and 7.1. The determinations are Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 and Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41, both dated 11 June 2026 and published on 24 June.
The OAIC had warned this was coming. It published guidance on tracking pixels on 4 November 2024 and around the same time scanned 50 health provider websites for them. That scan, published alongside the determinations, found 96 per cent were running tracking technology of some kind, 52 per cent had at least one third-party pixel, and 77 per cent of those didn't mention it in their privacy policy. The OAIC noted that many organisations didn't know which pixels were on their own sites, because marketing had been outsourced and nobody told privacy. Advertising technology is on its list of enforcement priorities for this financial year.
What it means for your site: a Meta Pixel or a Google Analytics tag on a page about a specific condition or treatment can infer a health fact about the visitor. That's collection of sensitive information. The safe position is no third-party marketing or analytics tags on condition and service pages unless you have genuine, informed consent and a matching collection notice. Every bdog site is built without them by default. If you want analytics, we'll talk about what can be done privately.
Cookies
Australia has no cookie banner law. There's no requirement for the pop-up that every European site has. What the OAIC does say is that cookies, IP addresses and device identifiers can be personal information where someone is reasonably identifiable, and that transparency matters. For a health site, given the pixel decisions, offering a real choice about non-essential tracking is sensible even though no law demands the banner. Essential cookies for the booking system don't need consent.
Where the data goes
If your booking system or website host stores information outside Australia, Australian Privacy Principle 8 applies, your policy has to say so, and it should name the countries where practicable. Cliniko states that accounts created outside the EU and UK are hosted in Australia, with some third-party services in the United States. For any other vendor, including Halaxy, Zanda, Squarespace, Wix and Webflow, check their current security page and write down what it says. Hosting locations change with plans and regions.
The contact form that emails everything
The Act requires "reasonable steps" to secure personal information, and since December 2024 the law spells out that this includes technical and organisational measures. The OAIC's security guide talks about access controls, encryption in transit, multi-factor authentication, vendor contracts and destroying information when it's no longer needed.
The most common failure we see is a website contact form that emails the patient's details, including the reason they're getting in touch, to a shared reception inbox with no encryption and no expiry. That is health information sitting in an email account, indefinitely. It's hard to call that reasonable steps. Route form submissions into your practice system, or at minimum into a secured mailbox with MFA, and set a deletion rule.
If something goes wrong
The Notifiable Data Breaches scheme requires you to assess a suspected breach within 30 days and, if serious harm is likely, notify the OAIC and the people affected. Your policy should say you have a plan for this and will notify where required.
You'll want that plan. In 2025 the OAIC received 1,205 breach notifications, the highest annual total since the scheme began. Health service providers were the most affected sector with 225, about a fifth of the total. Health has topped every reporting period since 2018.
What it costs to get wrong
Maximum civil penalties for serious or repeated interference with privacy are the greater of $50 million, three times the benefit obtained, or 30 per cent of turnover for a company, and $2.5 million for an individual. The 2024 reforms added lower tiers and gave the OAIC infringement and compliance notice powers.
Those were theoretical numbers until October 2025. On 8 October, the Federal Court ordered Australian Clinical Labs to pay $5.8 million over the Medlab Pathology breach, which affected more than 223,000 people. The first civil penalty ever imposed under the Privacy Act, and it went to a health provider. The judgment also set out that "reasonable steps" for security are risk-based and have to keep up with known threats. Medibank and Optus proceedings are still running.
Nobody is suggesting a suburban physio faces a $5.8 million penalty. But the regulator has shown it will take health providers to court, and its June determinations show it will go after tracking pixels on ordinary websites.
What changed and what's coming
The Privacy and Other Legislation Amendment Act 2024 received assent on 10 December 2024. Since then:
- a new criminal offence of doxxing, from 11 December 2024
- "reasonable steps" for security defined to include technical and organisational measures, from 11 December 2024
- a statutory tort for serious invasions of privacy, from 10 June 2025
- automated decision-making disclosure in privacy policies, from 10 December 2026
- a Children's Online Privacy Code, due by 10 December 2026, which excludes health service providers and so generally won't touch clinic sites
The second tranche of reform is in exposure draft, released 31 August 2026, with consultation closed as of 18 September 2026. It proposes a "fair and reasonable" test for handling personal information and 72-hour breach notification. It does not remove the small business exemption. None of it is law yet. We'll update this article when it moves.
The skeleton
Fourteen headings, built from the APP 1.4 list and the OAIC's guide to developing a policy. This is a structure, not a policy. Fill it with what's true for your practice and have it checked.
- Who we are. Practice name, ABN, contact details, that you're bound by the Privacy Act and, if applicable, your state health records law.
- The kinds of personal and health information we collect.
- How we collect it and how we hold it.
- Why we collect, hold, use and disclose it.
- Consent and sensitive information.
- Who we disclose it to and why.
- Overseas disclosure and the countries involved.
- Our website, cookies and analytics.
- Data security and how long we keep records.
- Data breaches and our response.
- How to access and correct your information.
- How to complain, to us and to the OAIC or your state commissioner.
- Automated decision-making, from 10 December 2026 if it applies.
- When this policy was last updated.
Templates exist, and they're a better starting point than a blank page. The RACGP publishes a privacy policy template for general practices, developed with the OAIC's help. The Australian Physiotherapy Association has a member template. The OAIC publishes a guide to developing an APP privacy policy. There's no OAIC generator, whatever a search result tells you; the one you'll find belongs to the UK regulator.
The fourteen headings are above. These are the three short notices your site needs alongside them, one for each place you collect something.
Page one: Clinic privacy policy skeleton Built from Australian Privacy Principle 1.4 and the OAIC's guide. Current at September 2026. bdog.com.au. Not legal advice.
- Who we are · Practice name, ABN, contact. Bound by the Privacy Act 1988. State health records law if NSW, Vic or ACT.
- What we collect · Identity and contact. Medicare and fund details. Health information. Payment. Website data.
- How we collect and hold it · In person, phone, web form, booking system, referrers. Where it's stored. Who can see it.
- Why · To provide care, bill, claim, recall, meet legal obligations.
- Consent and sensitive information · How consent works. Reliance on the health service exception.
- Disclosure · Other providers, funds, contractors, referrers. When and why.
- Overseas · Which vendors store data outside Australia. Which countries.
- Website, cookies and analytics · What's collected online. Any third-party tools. How to opt out.
- Security and retention · Reasonable steps taken. How long records are kept. How they're destroyed.
- Breaches · Response plan. Notification commitment.
- Access and correction · How to ask. How long you take.
- Complaints · How to complain to you. Escalation to the OAIC (and state commissioner).
- Automated decision-making · From 10 December 2026, if a program makes significant decisions.
- Last updated · Date. Review commitment.
Page two: The three collection notices
Under the contact form:
We collect your name, contact details and the reason for your message so we can respond. We don't share them without your consent unless the law requires it. See our privacy policy for how we handle your information and how to access it.
Under or beside the booking widget:
To book, we collect your name, contact details, date of birth and the reason for your visit so we can provide your appointment. Bookings are processed through [booking system], which stores data in [country]. See our privacy policy.
Under the newsletter or resource sign-up:
We collect your email address to send you [what]. You can unsubscribe at any time. We don't share it. See our privacy policy.
Before you publish
- Policy linked from the footer of every page
- A collection notice at each of the three places
- No third-party marketing pixels on condition or service pages
- Overseas hosting named for every vendor
- Form submissions go somewhere secure, not an open inbox
- Date on the policy
- Checked by someone qualified
Questions we get asked
I'm under $3 million turnover. Do I still need a privacy policy?
Yes. The small business exemption doesn't apply to health service providers.
What has to be in it?
The seven items in Australian Privacy Principle 1.4, listed above, plus automated decision-making from 10 December 2026 if it applies.
Is the policy the same as the notice on my booking form?
No. The policy is the standing document. The collection notice goes at the point of collection. You need both.
Can I keep the Meta Pixel on my treatment pages?
The June 2026 determinations found that collecting sensitive information that way, without consent, breaches the Act. Remove it, or get advice on a consent model.
Do I need a cookie banner?
Not by law. For a health site, offering a choice about non-essential tracking is sensible anyway.
My booking system is overseas. Do I have to say so?
Yes, and name the country where practicable.
Is emailing intake forms a problem?
Unencrypted health information in an inbox is hard to defend as reasonable steps. Route it somewhere secure.
What do I do if we have a breach?
Assess within 30 days. If serious harm is likely, notify the OAIC and the affected people.
Can I share a five-star Google review on the site?
Not if it mentions treatment. That's an Ahpra matter, and the same confidentiality duty means you never confirm someone is a patient in a public reply.
Is there a template?
RACGP for general practice, APA for physios, the OAIC guide for everyone. Then have it checked.
What changes in December 2026?
Automated decision-making disclosure becomes part of the policy requirement.
About this guide
Sources are named in the text; where the rules come from a regulator we link to the regulator, not to a summary of it. This is general information about building a website, not legal advice.


