An AI use policy settles which tools are on the register, who approves a new one, what may never go into a general purpose tool, who reviews and signs clinical output, and what happens when something goes wrong.
Legal basis
No Australian law names an AI use policy as a mandatory practice document. Australian Privacy Principle 1 requires reasonable steps to implement practices, procedures and systems that will ensure compliance with the Australian Privacy Principles. Health service providers are covered by the Privacy Act whatever their turnover, so the small business exemption is not available to a practice.
Ahpra and the National Boards have published guidance on artificial intelligence in healthcare that keeps the practitioner accountable for the care delivered and the record kept. The OAIC's guidance on privacy and the use of commercially available AI products, published in October 2024, recommends a privacy impact assessment before deployment and treats information a tool generates or infers about a person as a collection of personal information under Australian Privacy Principle 3.
The clause table
The right-hand column is drafted to be lifted into a practice document, with the bracketed placeholders filled in.
AI use policy clauses, what each settles, and wording to lift Clause What it settles Wording to lift Scope Which tools and which people the document covers. This policy applies to any software using artificial intelligence used in practice work, on any device, including free trials and personal subscriptions. It binds employees, contracted practitioners, registrars, locums, students and agency staff. Register The list of approved tools and what is recorded against each. [Name] keeps a register of approved AI tools recording the tool and plan in use, who uses it and for what, whether patient information goes into it, where data is stored and processed, whether inputs train the vendor's models, retention and deletion periods, and the approval and next review dates. Approval That a tool is assessed before it sees patient information, trials included. No AI tool is used with patient information until it is approved and entered on the register. A free trial counts as use. [Name] records the approval before first use, with the vendor's breach notification commitment and what happens to practice data when the practice stops using the product. Permitted and prohibited use The tool staff use for each task, and the one prohibition. Patient information is not entered into general purpose chatbots or consumer AI tools, including de-identified cases and letters with the name removed. The approved tool for each documentation task is named on the register, and any use not listed goes to [name] before it starts. Consent to record How consent is taken and where it is recorded. Recording is explained to the patient and consent is obtained before recording starts, and the consent is recorded in the clinical record. A patient who declines is consulted without recording. State and territory listening device legislation applies. Review and sign The standard the signing clinician is held to. The clinician who signs AI-drafted content is its author, reads it in full, and checks it against their own recollection of the encounter before signing. A draft the clinician can no longer verify from memory is rewritten before it is signed. Accountable person Who owns the register, the approvals, the incidents and the review. [Name], [role], owns this policy, the register, approval decisions and the incident log, with [name] as delegate during leave. Clinical responsibility for a signed record stays with the treating practitioner. Patient transparency What the practice publishes, and when it is updated. The practice privacy policy states that AI tools are used in producing clinical records and correspondence, where that information is stored and processed, whether any of it leaves Australia, how long audio and drafts are kept, and how a patient declines. It is updated whenever a tool joins the register. Non-employee practitioners Whether the policy reaches doctors under service agreements. Service and facility agreements take up practice policies as varied from time to time. The approval gate applies to any tool used against practice records. [The practice entity / each practitioner] holds the health information for Privacy Act purposes. Incidents What is reported, to whom, and inside what time. Reportable events go to [name] in writing on the day they are found. Where there are reasonable grounds to suspect an eligible data breach, the assessment is completed within 30 days and, where the threshold is met, a statement goes to the OAIC and the affected individuals are notified as soon as practicable. A My Health Record breach is also notified to the Australian Digital Health Agency as System Operator. Correcting a record How an affected clinical record is fixed. An affected record is corrected by dated addendum that leaves the original visible, after the practice's medical defence organisation has been contacted. Acknowledgement and review The evidence staff have read it, and when it is reopened. Each staff member signs an acknowledgement on induction and on each revision. The policy is reviewed on [date], and earlier when a tool is approved, a vendor changes its terms, sub-processors or processing location, a regulator publishes guidance, an incident occurs, or the clinical software changes.
Undeclared tools
A register built from the procurement list misses the browser extension summarising specialist letters, the consumer chatbot rewriting recall messages, and the meeting assistant inside the video conferencing account.
Run the first pass as a disclosure round in a staff meeting, principals naming their own tools first, with no consequence attached. A technical sweep finds the rest:
- Browser extensions on shared consulting room machines.
- Applications installed on practice devices.
- Third-party connections and API tokens authorised inside the clinical software.
- Add-ins on the practice mailbox and the video conferencing account.
- Personal subscriptions appearing on expense claims.
The incident log
These go on the incident log whether or not a notification threshold is reached:
- A drafted note attached to the wrong patient, whether or not it was signed.
- Patient information entered into a tool that is not on the register.
- Signed content describing something that did not happen in the consultation.
- A recording that continued after the consultation ended.
- A patient asking which tool was used and nobody being able to answer.
Acknowledgement records
Acknowledgement records, a dated attendance record for the session that introduced the policy, and coverage in the induction pack are what a practice hands over when asked how staff know the rules. Training the team.
aurii on the register
aurii records the consultation and drafts a structured note or letter for the treating clinician to edit and sign. The register fields:
Register fields, answered for aurii Register field Entry Tool and plan A$199 + GST per clinician per month. Full pricing. Who signs Nothing leaves aurii until a clinician signs it. Clinical safety. Where data is stored Hosting and backups are in Australian regions. Where the data sits. Model training Your content is not used to train models. Retention and deletion Deletion runs on request. What is deleted and what the practice keeps. Evidence the review step happened Every action a practice user takes is written to a hash-chained audit log. How the chain works.
No Australian law names one as a mandatory practice document. Australian Privacy Principle 1 requires reasonable steps to implement practices, procedures and systems that will ensure compliance with the Australian Privacy Principles, and accreditation surveyors ask how staff know the rules.
No, and the clause is written without qualifiers, including for de-identified cases and letters with the name removed. A consumer tool carries no contract with the practice. A presentation, an age, a suburb and a referring specialist together identify a patient.
Only where their engagement picks it up. Doctors under service or facility agreements are bound where the agreement refers to practice policies as varied from time to time, and the approval gate has to reach any tool used against practice records.
This is general information about practice governance and privacy obligations in Australia. It is not clinical or legal advice.