The Australian Privacy Principles

Thirteen principles under the Privacy Act 1988 (Cth).

APP compliance 13 principles mapped Updated

aurii is designed to comply with the Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth). No APP certification exists. This is general information, not legal advice.

Open and transparent management

RequiresManage personal information openly, under a current privacy policy.

aurii does
  • The Privacy Policy is versioned and dated at each change.
  • Privacy enquiries go to hello@aurii.com.au.

Anonymity and pseudonymity

RequiresOffer anonymity where that is lawful and practicable.

aurii does
  • Patients are identified. The clinical and billing record requires it by law.
  • General enquiries need no account, only the address you write from.

Collection of solicited information

RequiresCollect only what is reasonably necessary, and sensitive information with consent.

aurii does
  • Collection covers the consult audio, the transcript, the drafts, patient identifiers, billing items, and documents a clinician uploads or photographs.
  • Health information is handled as sensitive information.

Unsolicited information

RequiresAssess unsolicited personal information; destroy or de-identify what you could not have collected.

aurii does

Notification of collection

RequiresTell people what you collect, why, and who you share it with.

aurii does
  • What is collected, why, where it is held and every sub-processor are stated in the Privacy Policy.
  • Patients are told through the clinician or hospital that controls the record.

Use and disclosure

RequiresUse or disclose information only for the purpose it was collected, or a directly related one.

aurii does
  • Clinical information is used to transcribe the consult, draft the documentation and record billing for the clinician to review and sign.
  • Disclosure happens where the clinician directs it, such as a signed letter to a GP, and where Australian law requires it. Clinical information is not sold.

Direct marketing

RequiresDo not use personal information for direct marketing without expectation and an opt-out.

aurii does
  • Patients' clinical information is not used for marketing.
  • The clinical application carries no third-party advertising or tracking.

Disclosure to service providers

RequiresTake reasonable steps to ensure a recipient of disclosed information handles it consistently with the APPs.

aurii does
  • Every sub-processor is engaged under a data processing agreement and listed by function in the Privacy Policy.
  • Your content is not used to train models.
  • Clinical information is stored and backed up in Australia. The hosting arrangement.

Government related identifiers

RequiresDo not adopt or use a government identifier as your own identifier.

aurii does
  • Patients are identified by the hospital's own medical record number.
  • A Medicare number recorded for billing is encrypted at the application layer and is not written back into documents.

Quality of information

RequiresKeep the information you hold accurate, up to date and complete.

aurii does
  • The treating clinician remains responsible for the clinical content. Clinical safety.

Security of information

RequiresProtect information from misuse, interference, loss and unauthorised access.

aurii does
  • Clinical data is encrypted in transit and at rest with AES-256 in Australian Azure regions. The highest-risk fields carry a second application-layer encryption, with keys in Azure Key Vault in Australia.
  • Access is least-privilege with multi-factor authentication. Each practice's data is isolated from every other tenant.
  • Changes made from the fleet-wide support console are written to the practice's audit chain; console reads are not. Named accounts at aurii and at Black Shard hold fleet-wide access to production, and a practice cannot grant, extend or revoke that access. Vendor access.

Access to information

RequiresGive people access to their personal information on request.

aurii does
  • A clinician can see the personal information held against their account.
  • Patient information is held on behalf of the hospital or specialist who controls the record, so a patient access request runs through them.

Correction of information

RequiresCorrect personal information that is inaccurate, out of date, incomplete or misleading.

aurii does
  • A signed document can be amended, and the amendment is written to the hash-chained audit log.
  • Account corrections run on request; patient corrections run through the hospital that controls the record.

Other obligations

Notifiable Data Breaches. Part IIIC of the Privacy Act 1988 (Cth) binds aurii as an APP entity. An eligible breach likely to result in serious harm is notified to the affected individuals and to the Office of the Australian Information Commissioner, under the Privacy Policy.

State and territory health records law. Health records statutes in New South Wales, Victoria and the Australian Capital Territory apply alongside the Privacy Act. aurii operates inside the record-keeping agreement held with your organisation.

My Health Record. There is no My Health Record connection.

Compliance enquiries go to hello@aurii.com.au.

Start the free trial

Free 30-day trial. Create an account in the iPhone app or at app.aurii.com.au/signup.

A$199 + GST per clinician per month. Full pricing.