Privacy
How MedDocFlow handles personal and health information under the Australian Privacy Principles.
Last reviewed: 1 July 2026
About this notice
MedDocFlow is a clinical-document portal used by healthcare practices to route inbound documents into their Cliniko account. This notice explains what personal and health information passes through the service and how it is handled, consistent with the Australian Privacy Principles (APPs)under the Privacy Act 1988 (Cth). Because it handles health information, MedDocFlow is itself bound by the Privacy Act and the APPs, so these protections are our own obligations, not only the practice’s. Patients with questions should contact their practice in the first instance.
Information we handle
- Health informationcontained in uploaded documents — for example referrals, results and letters — which may include a patient’s name, date of birth, referrer, clinical details and the document file itself.
- Account information for practice staff who use the portal, managed through Amazon Cognito (such as email address and role).
- Audit metadata about actions taken in the system, kept free of patient identifiers.
Why we collect and use it
Health information is collected directly when an authorised staff member uploads a document; MedDocFlow does not crawl, purchase or otherwise acquire patient information from third parties. It is collected for a single purpose (APP 3 and APP 6): to read an inbound clinical document, match it to the correct existing patient, let a reviewer confirm the details, and file it into the practice’s Cliniko account. An AI vision model helps extract and classify the relevant fields, but no decision that significantly affects a patient is made by the model alone— a human reviewer checks every document before anything is written to Cliniko. Patient information is never used for advertising, marketing, profiling, or sold to any third party. How the AI processing, data residency and security controls work is described in detail on our compliance page.
Disclosure and data location
Document content is disclosed only to the practice’s own Cliniko account — the destination the practice has configured. MedDocFlow keeps patient information in Australia (the AWS Sydney region), including AI inference, so there is no cross-border disclosureto manage under APP 8. The technical controls behind this — onshore AI processing, encryption, access control and retention — are set out on the compliance page.
Security and retention
We hold information securely and for the shortest time practical (APP 11): once a document is verified as written to Cliniko, its extracted health information and stored file are deleted from MedDocFlow, and documents that fail or are rejected are automatically removed after 30 days. Cliniko then holds the record. Encryption, authentication and audit-logging details are on the compliance page.
Access and correction
Because the patient record lives in the practice’s Cliniko account (and MedDocFlow purges its copy once filing succeeds), requests to access or correct patient information (APP 12 and APP 13) are handled by the practice through Cliniko. Practice staff seeking changes to their own portal account should contact their administrator.
Data breaches
MedDocFlow is built to support the practice’s obligations under the Notifiable Data Breaches scheme. A suspected eligible data breach is assessed promptly — within 30 days — and, where the serious-harm threshold is met, reported to affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
Tracking
MedDocFlow uses Google Analyticsto measure aggregate product usage — page views and feature events such as a document being uploaded or approved. Analytics events never include document content, patient details, or any other personal or health information. MedDocFlow does not use advertising trackers or set marketing cookies. Authentication uses a session cookie that is necessary for the portal to function, and typefaces are self-hosted.
Complaints and contact
Patients should raise privacy questions or complaints with their practice first. If a concern cannot be resolved, it can be referred to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes to this notice
We may update this notice as the service evolves. The “last reviewed” date at the top of this page reflects the most recent change.
This page is general information for transparency, not legal advice. For specifics, contact us.