Privacy Policy ‹ Back to setup

Privacy Policy

v1.2 · effective 28 June 2026

This policy explains how Clinically handles personal information when a medical practice uses our platform to capture a patient's electronic Assignment of Benefit (AoB) consent for a Medicare bulk-billed service. We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

For routine questions about your own information, your first port of call is the practice that sent you the link — under the APPs they are the entity that collected the information and Clinically processes it on their behalf.

1. Who we are

The platform is operated by CCMX PTY Limited t/a Clinically (ABN 24 693 129 056) ("Clinically", "we", "us"). We provide an electronic Assignment of Benefit consent tool to Australian medical practices. We do not provide medical advice and we are not a party to the doctor–patient relationship.

2. What we collect

We collect two categories of personal information:

The patient's date of birth is entered by the patient on the consent screen — it is deliberately never carried in the SMS or email link. Where a practice sends the link from its own appointment or messaging system, we never receive the patient's mobile number. Where a practice instead enables Clinically's patient communications, we hold the patient's mobile number and email address so we can send the link on the practice's behalf — see "When your practice sends the link through Clinically" below.

3. Why we collect it

We collect this information so the practice can capture a Medicare-compliant electronic Assignment of Benefit and so the signed record can be retained as evidence of the patient's consent. This is the primary purpose under APP 6, and the regulatory basis is the bulk-bill assignment regime under the Health Insurance Act 1973 (Cth), as amended by the Health Insurance Amendment (Assignment of Medicare Benefits) Regulations 2025. We do not reuse the information for marketing or for any unrelated purpose. The patient is notified of the collection at the point it occurs — on the consent screen, before they sign — consistent with APP 5.

4. How we store and protect it

We take the following reasonable steps under APP 11 to protect personal information from misuse, loss, and unauthorised access:

A summary of our security controls is published at /security.

When your practice sends the link through Clinically

A practice can send the consent link from its own appointment system, or it can enable Clinically's patient communications and have us send the SMS or email on its behalf. The section above describes the first case. When a practice uses our messaging instead:

5. Who can access it

A signed consent record is visible only to authorised members of the practice that captured it. Clinically support staff may access a record only on a strict need-to-know basis (for example, to diagnose a fault the practice has reported), and that access is audit-logged. We do not sell, rent, or trade personal information.

6. How long we keep it

Practices are required under Services Australia guidance to retain the completed Assignment of Benefit for at least two years from the date the claim is made. Clinically retains the signed record for at least that period so the practice can meet its retention obligation. Beyond the regulatory floor, retention and destruction settings are being formalised — please contact us at privacy@clinically.com.au for the current schedule or to request earlier deletion of practice-owned records.

Patient contact details and unsigned links. Where a practice enables patient communications, the patient's mobile number and email address are held only while they remain in the practice's patient directory. The practice controls those records directly — it can edit or delete any patient, or clear its entire directory, from its dashboard at any time, and all patient contact details are deleted when the practice closes its account. A consent link sent by SMS or email expires about seven days after it is issued; an unsigned link that expires captures no consent record. We do not retain patient contact details for any purpose beyond letting the practice send the consent message and find that patient again in its own directory, and we never use them for marketing.

7. Access and correction

Under APP 12 and APP 13, an individual may request access to, or correction of, their personal information. Because the practice is the entity that collected the information, please make routine access and correction requests to the practice directly — they can produce the signed record from their dashboard. If the practice is unable to assist, you may contact us at privacy@clinically.com.au. We do not charge a fee for making an access or correction request.

Under the bulk-bill assignment regime, a copy of the signed Assignment of Benefit is available on request — please ask the practice in the first instance.

8. Complaints

If you believe we have mishandled your personal information, write to privacy@clinically.com.au or Suite 2, 710 Hunter Street, Newcastle West NSW 2302. We will acknowledge your complaint and respond within a reasonable period. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner — see oaic.gov.au.

9. Data breach response

We comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of a suspected eligible data breach affecting personal information we hold, we will assess it and, where the scheme requires, notify the Office of the Australian Information Commissioner and the individuals at likely risk of serious harm as soon as practicable. Practices using the platform will be notified within 72 hours of confirmation of an eligible data breach affecting their records.

10. Cross-border transfers

We host personal information on cloud infrastructure located in Australian regions and we design the service to keep personal information onshore. Some operational sub-processors we rely on (for example, transactional email delivery or document rendering services) may process information outside Australia. Where that is the case, we take reasonable steps under APP 8 to ensure the recipient handles the information consistently with the APPs. The current list of sub-processors and their processing locations is published at /sub-processors.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to practice administrators by email and reflected in the in-app onboarding flow. The version number and effective date at the top of this page indicate when the policy was last revised; prior versions are archived on request.

12. Contact

Privacy enquiries: privacy@clinically.com.au.
Postal address: Suite 2, 710 Hunter Street, Newcastle West NSW 2302.

Informational only — not legal advice. This policy describes how Clinically handles personal information; the practice that sent you the link is the APP entity that collected the information and is your first port of call for routine access or correction requests.