Australia Privacy Act

How CureCast supports
Australian requirements.

Built to support the 13 Australian Privacy Principles and the Notifiable Data Breaches scheme, for plastic surgery, aesthetic, dermatology and medical spa practices handling health information.

AWS infrastructure, encrypted at rest with AES-256, TLS 1.3 in transit
No Australia-only data residency requirement under the Privacy Act
Staff access, audit trail and device management scoped per clinic
Confidential Patient Access for sensitive health information
Also supports compliance for
UAE PDPL GDPR PHIPA
๐Ÿ‡ฆ๐Ÿ‡บ
Australia Account
APP-aligned controls
Active
Staff Access Control
Module & action-level, scoped per clinic
Audit Trail
Staff, device, IP & timestamp on every event
Device Management
End sessions on lost or stolen devices
Encryption
AES-256 at rest, TLS 1.3 in transit
๐Ÿ‡ฆ๐Ÿ‡บ Hosted on AWS ยท no Privacy Act residency requirement
NDB scheme
30-day assessment window
Aligned with
13 Australian Privacy Principles

The regulation that applies to your practice

Australian healthcare practices, including plastic surgery, aesthetic surgery, dermatology, and medical spa practices handling patient data, are subject to the Privacy Act 1988 and its 13 Australian Privacy Principles (APPs), overseen by the Office of the Australian Information Commissioner (OAIC).

Health service providers are covered by the Privacy Act regardless of annual turnover. The small-business exemption that applies to some other sectors does not apply to practices handling health information.

What Counts as Sensitive Data Here

Health information, including patient photos, clinical notes, and any identifying information collected in the course of providing a health service, is treated as sensitive information under the Privacy Act, subject to stricter handling requirements than general personal information.

 

Australia’s Notifiable Data Breaches (NDB) scheme requires practices to notify both affected individuals and the OAIC when a data breach is likely to result in serious harm. An eligible data breach involves unauthorised access to, unauthorised disclosure of, or loss of personal information, where that risk hasn’t been prevented through remedial action. Practices generally have 30 days to assess a suspected breach, then must notify as soon as practicable once the breach is confirmed.

Data residency & Data Processing Agreement

CureCast hosts Australia data on AWS’s secure cloud infrastructure, encrypted at rest with AES-256 and protected in transit with TLS 1.3, with TLS 1.2 supported as a fallback.

The Australian Privacy Act doesn’t require patient data to stay within Australia for a platform like CureCast. A stricter residency rule does exist in Australia, but it’s scoped narrowly to the My Health Record national system under the My Health Records Act, which CureCast operates independently of. CureCast’s AWS infrastructure is built to support the Australian Privacy Principles’ cross-border disclosure requirements.

If your practice needs a specific regional hosting arrangement, our team can discuss it directly.

How CureCast supports Australia Requirements

Staff Access Control

Administrators control staff access to patient records, clinical photos, albums, and sensitive actions through module-level and action-level permissions. For multi-location practices, access is scoped to each clinic account.

See how staff permissions work โ†’

Audit Trail

CureCast records defined activity across patient records, files, clinical modules, consent workflows, and exports with staff, device, IP, and timestamp context. Filter and export in CSV or PDF.

 

See how audit trail works โ†’

Device Management

Administrators can review every device connected to their account and end a session when a device is lost, stolen, or no longer trusted. Deactivating a staff account ends sessions across their devices.

 

See how device-management work โ†’

Session Timeout

CureCast automatically ends inactive sessions after 2 hours on desktop and 4 hours on supported mobile devices, with a warning before logout and a required sign-in to continue.

 

Learn about reauthentication โ†’

Encryption

Patient records and clinical photos are encrypted at rest using AES-256 and protected in transit using TLS, with TLS 1.3 as the primary protocol and TLS 1.2 supported as a fallback.

 

Learn about Encryption โ†’

Confidential Patient Access

Mark a patient confidential and their record no longer appears in search results, patient lists, or before-and-after galleries for staff who don’t hold that specific permission. Only an administrator can grant it, per staff member.
Learn about Confidential Patient Access โ†’

1M+
Patient records managed on CureCast
10M+
Photos, videos and documents stored
4M+
Appointments managed
0%
Churn โ€” clinic stay because it works

Frequently asked Questions

Is CureCast compliant with the Australian Privacy Act?

CureCast supports Australian Privacy Act requirements. There is no official third-party certification against the Australian Privacy Act for software vendors. Each practice remains responsible for its own compliance.

Is patient data stored in Australia?

The Australian Privacy Act doesn’t require patient data to stay within Australia. CureCast hosts Australia accounts on AWS’s secure cloud infrastructure, encrypted at rest with AES-256. This is separate from the My Health Record system, which has its own, stricter residency rule under the My Health Records Act.

What counts as a data breach under the Australian Privacy Act?

An eligible data breach occurs when unauthorized access, disclosure, or loss of personal information is likely to cause serious harm to the individuals involved, and the risk can’t be remedied in time. Entities generally have 30 days to assess a suspected breach, and must notify the OAIC and affected individuals as soon as practicable once it’s confirmed.

Do I need a separate agreement with CureCast for Australia use?

An Australia-specific Data Processing Agreement is separate from any US-facing agreement. Contact CureCast to confirm the right agreement for your account.

How do patients send photos to CureCast securely in Australia?

Patients can upload photos through CureCast’s secure remote upload link. No app download or account creation is required on their end.

Book a demo for CureCast clinical photo management software

See How CureCast Fits Your Practice

Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.

 

Prefer email? [email protected]