Privacy policy
Last updated: 1 October 2026
1. About this policy
1.1This Privacy Policy (Policy) is issued by Injury Management Doctors Pty Ltd (ABN 56 700 490 884), trading as Injury Management Doctors (IMD, we, us or our).
1.2This Policy sets out how we collect, hold, use, disclose and otherwise handle personal information, including health information and other sensitive information, in accordance with the Privacy Act 1988 (Cth) (Privacy Act), the Australian Privacy Principles (APPs), the Health Records and Information Privacy Act 2002 (NSW) (HRIP Act) and the Health Privacy Principles (HPPs), and any other applicable law, including the Workers Compensation Act 1987 (NSW), the Workplace Injury Management and Workers Compensation Act 1998 (NSW) and the Motor Accident Injuries Act 2017 (NSW).
1.3This Policy applies to all personal information collected by or on behalf of IMD, whether through our website and any associated online forms, portals or communications (together, the Website), in person, by telephone, by email, by facsimile, through telehealth, or from third parties in the course of providing our services.
1.4In this Policy, personal information, sensitive information and health information have the meanings given to them in the Privacy Act and the HRIP Act. A reference to you includes patients, injured workers, claimants, employers, insurers, referrers, legal representatives, Website visitors and any other person whose personal information we handle.
1.5By accessing the Website, submitting information to us, or engaging our services, you acknowledge that you have read and understood this Policy. Where this Policy refers to consent, consent may be express or, where permitted by law, implied by your conduct.
2. Personal information we collect
2.1The kinds of personal information we collect and hold depend on your relationship with us and may include:
- Identity and contact information: name, date of birth, gender, address, telephone numbers, email address, emergency contact and next of kin details;
- Health information: medical history, details of the injury or illness, presenting symptoms, diagnoses, clinical notes, examination findings, imaging and pathology results, medications, treatment plans, capacity assessments, certificates of capacity, referrals, reports and correspondence relating to your care;
- Claim and scheme information: claim numbers, insurer and case manager details, scheme agent details, employer details, date and circumstances of injury, return-to-work and recover-at-work plans, and determinations or disputes relating to a claim;
- Employment information: occupation, employer, role and duties, work hours, pre-injury duties, suitable duties and workplace contacts;
- Government identifiers and billing information: Medicare number, and payment and invoicing details (we do not adopt government identifiers as our own identifiers);
- Communications: records of telephone calls, emails, SMS, form submissions, telehealth sessions and other correspondence with or about you, including call recordings where you have been notified;
- Technical and usage information: as described in section 5; and
- Other information you or an authorised third party choose to provide, or that is reasonably necessary for one or more of our functions or activities.
2.2Health information and certain other information we collect is sensitive information. We collect sensitive information only with your consent, or where the collection is required or authorised by or under an Australian law or otherwise permitted under the Privacy Act and the HRIP Act.
2.3If you do not provide information we request, we may be unable to provide our services, issue certificates or reports, communicate with your insurer or employer, or process your claim-related requirements.
3. How we collect personal information
3.1Where reasonable and practicable, we collect personal information directly from you, including when you attend a consultation, complete a registration or intake form, submit an enquiry through the Website, communicate with us, or participate in a consultation.
3.2We may also collect personal information about you from third parties where it is unreasonable or impracticable to collect it from you directly, or where you have consented or the law permits, including from:
- your employer, workers' compensation insurer, scheme agent, self-insurer, CTP insurer or case manager;
- treating and referring practitioners, specialists, allied health providers, hospitals, pathology and imaging providers;
- workplace rehabilitation providers and return-to-work coordinators;
- your legal representative, authorised representative, guardian or family member;
- regulators and government agencies, including the State Insurance Regulatory Authority (SIRA), icare and the Personal Injury Commission; and
- publicly available sources.
3.3Where we collect personal information about you from a third party, we will take reasonable steps to ensure you are made aware of the matters set out in APP 5 and HPP 4, unless an exception applies.
3.4If you provide us with personal information about another person, you warrant that you are authorised to do so and that the person has been made aware of this Policy.
3.5If we receive unsolicited personal information, we will determine within a reasonable period whether we could have lawfully collected it. If not, and it is lawful and reasonable to do so, we will destroy or de-identify it.
4. Purposes for which we collect, hold, use and disclose personal information
4.1We collect, hold, use and disclose personal information for the primary purpose of providing medical, injury management and related health services to you, and for the following related purposes:
- assessing, diagnosing, treating and managing your injury or condition, and coordinating care with other practitioners;
- preparing certificates of capacity, medical reports, independent or treating opinions, and other documentation required under workers' compensation, CTP and other insurance or compensation schemes;
- communicating with your employer, insurer, scheme agent, case manager and rehabilitation provider regarding your claim, capacity and return to work;
- billing, invoicing, debt recovery and processing payments from you, insurers, employers or other payers;
- managing appointments, reminders, follow-ups, referrals and recalls, including by SMS and email;
- responding to enquiries, requests, feedback and complaints;
- meeting our legal, regulatory, professional, accreditation, insurance and record-keeping obligations;
- quality assurance, clinical audit, peer review, accreditation, staff training and supervision;
- practice management, business planning, service development and improvement of our operations, systems and Website;
- risk management, incident management, and the establishment, exercise or defence of legal or equitable claims;
- managing our relationships with referrers, employers, insurers and other business clients;
- the purposes set out in sections 5, 8 and 9; and
- any other purpose for which you have given consent, or which is required or authorised by or under an Australian law or a court or tribunal order.
4.2We may use or disclose personal information for a secondary purpose where:
- you have consented;
- you would reasonably expect us to use or disclose it for that purpose and the secondary purpose is related (or, for sensitive information, directly related) to the primary purpose;
- it is required or authorised by or under an Australian law or a court or tribunal order;
- we reasonably believe it is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety;
- it is reasonably necessary for an enforcement-related activity, or to take appropriate action in relation to suspected unlawful activity or serious misconduct;
- it is reasonably necessary to establish, exercise or defend a legal or equitable claim, or for a confidential alternative dispute resolution process; or
- another permitted general situation, permitted health situation or exemption under the Privacy Act or HRIP Act applies.
4.3Automated decision-making. We may use computer programs, including software tools and artificial intelligence technologies, to assist with administrative and clinical support functions such as transcription, document drafting, scheduling, triage of enquiries and data analysis. Where a computer program is used to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect your rights or interests, we will identify that in this Policy as required by the Privacy Act. Clinical decisions about your care are made by qualified practitioners.
5. Website logging, cookies, analytics and tracking
5.1Server and access logs. When you access the Website, we and our hosting, security and IT service providers automatically log technical information, which may include your IP address, approximate location derived from your IP address, browser type and version, operating system, device identifiers, referring and exit URLs, pages and files accessed, date and time stamps, session duration, clickstream data and error logs.
5.2Form and interaction data. We record information you enter into Website forms, including partially completed submissions where technically captured, along with the time and date of submission and associated technical metadata.
5.3Cookies and similar technologies. The Website uses cookies, pixels, tags, scripts, local storage and similar technologies, including Google Tag Manager and Google Analytics. These may be set by us or by third parties and may collect information about your use of the Website and other websites over time.
5.4Purposes. We use logged, cookie and analytics data to operate, maintain and secure the Website; detect, investigate and prevent fraud, abuse, unauthorised access and security incidents; diagnose technical problems; measure traffic and usage patterns; evaluate the effectiveness of our content, campaigns and referral sources; and improve the Website and our services.
5.5Advertising and remarketing. If we use advertising or remarketing tools (such as Google Ads or Meta Pixel), third-party providers may use cookies to show you advertisements based on your prior visits to the Website. We do not use health information for advertising, and we do not configure these tools to transmit information you submit through clinical or claim-related forms.
5.6Your choices. You can block, disable or delete cookies through your browser settings, and you can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on. Disabling cookies may affect the functionality of the Website.
5.7Third-party handling. Information collected by third-party analytics and advertising providers is handled in accordance with their own privacy policies, and may be stored outside Australia (see section 7).
5.8Retention of logs. Technical logs are retained for as long as reasonably necessary for the purposes in section 5.4, after which they are deleted, de-identified or aggregated, unless we are required to retain them for legal, security or dispute-resolution purposes.
6. Disclosure of personal information
6.1Subject to section 4 and applicable law, we may disclose personal information to:
- medical practitioners, specialists, allied health providers, hospitals, pathology and imaging providers involved in your care;
- your employer, workers' compensation insurer, scheme agent, self-insurer, CTP insurer, case manager and return-to-work coordinator, to the extent relevant to your claim or required under the applicable scheme;
- workplace rehabilitation providers engaged in relation to your claim;
- your legal representative, authorised representative, guardian or other person you nominate;
- SIRA, icare, the Personal Injury Commission and other government agencies, regulators and tribunals;
- related bodies corporate and affiliated practices that provide or support services to IMD, under appropriate confidentiality arrangements;
- contractors and service providers who perform functions on our behalf, including practice management software, cloud hosting, IT support, transcription, telehealth, communications, payment processing, debt collection, professional advisers (legal, accounting, audit) and insurers;
- accreditation bodies, professional indemnity insurers and medical defence organisations;
- a prospective or actual purchaser, investor, financier or successor in connection with a sale, merger, restructure or transfer of all or part of our business or assets, subject to confidentiality obligations and applicable health record transfer requirements; and
- any other person where required or authorised by law, or with your consent.
6.2We require third parties to whom we disclose personal information to handle it in accordance with the Privacy Act and, where applicable, the HRIP Act, and only for the purpose for which it was disclosed.
7. Cross-border disclosure
7.1We store patient information, including health records, in Australia. We do not send it overseas.
7.2The exceptions are our Website and our outreach to employers. The Website analytics providers described in section 5 and our Website enquiry form provider process what is collected or submitted through the Website, including anything written in an enquiry, outside Australia, including in the United States. The system we use to contact employers about our services stores their business contact details in the United States.
7.3Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information, including through contractual obligations, unless an exception under APP 8 or HPP 14 applies.
8. De-identified and aggregated information
8.1We may de-identify personal information and combine it with other information to create aggregated or statistical data that does not reasonably identify any individual (De-identified Data).
8.2We may use and disclose De-identified Data for any lawful purpose, including service planning and development, benchmarking, performance and outcome reporting, business analytics, reporting to clients and stakeholders, research, and the development and improvement of systems, tools and models.
8.3We take reasonable steps to ensure De-identified Data cannot be re-identified, and we will not attempt to re-identify, or permit recipients to re-identify, any individual from De-identified Data.
8.4Research involving identifiable health information will only be undertaken with your consent or in accordance with guidelines approved under section 95 or 95A of the Privacy Act and the statutory guidelines issued under the HRIP Act.
9. Communications and direct marketing
9.1We may send you service-related communications, including appointment reminders, follow-ups, results notifications, administrative notices and claim-related correspondence, by SMS, email, telephone or post. These are not direct marketing.
9.2We may use your name and contact details to send you information about our services, events or updates, and may send business clients, referrers, employers and insurers information about our services, where you would reasonably expect this or have consented, and in accordance with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth).
9.3We will not use or disclose health information for direct marketing without your express consent.
9.4You may opt out of direct marketing at any time by using the unsubscribe facility in any message or by contacting us. We will process opt-out requests within a reasonable period and free of charge.
10. Security, retention and destruction
10.1We hold personal information in electronic and hard-copy form, including in practice management systems, cloud-based platforms and secure physical storage.
10.2We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These may include access controls, multi-factor authentication, encryption, audit logging of system access, staff confidentiality obligations and training, and physical security measures.
10.3No method of electronic transmission or storage is completely secure. You provide information to us over the internet at your own risk, and we recommend you do not send sensitive information by unencrypted email.
10.4We retain health records for the minimum periods required by law, including, under the HRIP Act, at least 7 years from the last occasion a health service was provided to an adult, or until a person who was a child at that time turns 25. We may retain records for longer where required for legal, regulatory, insurance or dispute purposes.
10.5When personal information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we will take reasonable steps to securely destroy or de-identify it.
11. Your rights and other matters
11.1Access and correction. You may request access to, or correction of, personal information we hold about you by contacting us in writing. We will respond within a reasonable period, generally within 30 days. We may refuse access where permitted by the Privacy Act or HRIP Act, in which case we will give written reasons. We may charge a reasonable fee for providing access, but not for making a request or for correction. We may need to verify your identity before releasing information.
11.2Anonymity and pseudonymity. You may deal with us anonymously or using a pseudonym for general enquiries. Because of the nature of our services and our obligations under workers' compensation and CTP legislation, it is generally impracticable to provide clinical or claim-related services without identifying you.
11.3Notifiable data breaches. If we experience a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with Part IIIC of the Privacy Act.
11.4Complaints. If you believe we have breached the Privacy Act, the APPs, the HRIP Act or the HPPs, please contact our Privacy Officer in writing. We will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you may contact:
- the OAIC at oaic.gov.au (opens in a new tab) or 1300 363 992; or
- the NSW Information and Privacy Commission at ipc.nsw.gov.au (opens in a new tab) or 1800 472 679, in relation to health information.
11.5Changes to this Policy. We may amend this Policy at any time to reflect changes in law, technology or our practices. The current version will be published on the Website with its effective date. Continued use of the Website or our services after an update constitutes acknowledgement of the amended Policy, except where the law requires your fresh consent.
11.6Third-party websites. The Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites.
11.7Contact us. Privacy Officer, Injury Management Doctors Pty Ltd, 13/35 Birch Street, Condell Park NSW 2200 · (02) 8530 7588 · Fax (02) 7241 5556 · info@injurymanagementdoctors.com.au · Contact page
