Privacy Policy.
This Privacy Policy explains how Med Mend Pty Ltd (ABN 88 689 179 422) collects, uses, holds and discloses your personal information and health information. We are bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
Section 01: About This Policy
1.1 Who We Are
Med Mend Pty Ltd (ABN 88 689 179 422) (“Med Mend”, “we”, “us” or “our”) operates a digital platform that connects patients, carers and referrers with independent specialist medical practitioners for the purpose of obtaining second medical opinions. We are an Australian Privacy Act entity and are bound by the 13 Australian Privacy Principles (APPs) set out in Schedule 1 of the Privacy Act 1988 (Cth).
1.2 Scope of This Policy
This Policy applies to all personal information and health information we collect, hold, use and disclose in connection with the Med Mend platform, our website (medmend.app), mobile application, and all associated services. It applies to patients, carers, referrers, registered users and visitors to our website.
It does not govern the privacy practices of independent specialists who participate on the platform. Those practitioners are subject to their own professional obligations under applicable health privacy legislation and their registration conditions with the Australian Health Practitioner Regulation Agency (AHPRA) or equivalent authority.
Section 02: Information We Collect
Health information is sensitive information under APP 3 and attracts a higher standard of protection. We collect health information only with your express consent and only to the extent necessary to facilitate your second opinion service.
Health information we collect includes:
- Medical history, diagnoses and clinical notes you upload or describe
- Imaging, pathology results and specialist reports you submit
- Referral letters and treating doctor correspondence
- Information shared during a teleconsultation with a specialist
- Records of the second opinion report provided to you through the platform
2.3 Information About Others
If you are submitting a case on behalf of another person (for example, as a carer or parent), you confirm that you have that person’s consent to provide their personal and health information to Med Mend and that you are authorised to act on their behalf in connection with the service.
2.4 Information We Do Not Collect
We do not collect government-issued identifiers (such as Medicare numbers or tax file numbers) unless you provide them voluntarily as part of your medical records and they are necessary for your service. We do not seek such identifiers for our own administrative purposes in accordance with APP 9.
Section 03: How We Collect Your Information
3.1 Direct Collection
We collect most information directly from you when you:
- create an account on the platform
- submit a case for second opinion review
- upload medical records, imaging or other documents
- participate in a teleconsultation facilitated through the platform
- contact us by email, phone or through the platform
- complete surveys, provide feedback or respond to our communications
3.2 Automatic Collection
When you use our platform or website, we may automatically collect certain technical information, including your IP address, device identifiers, browser type and version, operating system, referring URL, pages viewed, time and date of access, and session duration. This information is collected through server logs, cookies and similar technologies as described in Section 13 of this Policy.
3.3 Collection from Third Parties
In some circumstances we may receive personal information about you from third parties, including:
- referrers (such as your treating doctor or a hospital) who initiate a case on your behalf
- your authorised carer or legal representative
- payment processors confirming transaction status
Where we receive information about you from a third party, we will take reasonable steps to notify you of that collection in accordance with APP 5, unless doing so would be impracticable or is otherwise permitted by law.
3.4 Notification at Collection (APP 5)
At or before the point of collecting your personal information, we will take reasonable steps to notify you of: the fact of collection; the purposes for which it is collected; the types of third parties to whom it may be disclosed; and your rights of access and correction. This Policy serves as that standing notice, supplemented by collection-point disclosures within the platform.
Section 04: Purposes for Which We Hold Your Information
We collect and hold your personal and health information for the following primary purposes:
- facilitating your second medical opinion service, including case submission, specialist matching, report delivery and teleconsultation
- creating and managing your account
- processing payments and maintaining billing records
- communicating with you about your case, account or service
- complying with our legal and regulatory obligations, including under the Privacy Act, health records legislation and applicable clinical governance standards
- responding to complaints and resolving disputes
- improving the platform and our services through analysis of anonymised usage data
- sending you service-related communications and, where you have opted in, relevant health information updates
Section 05: Use and Disclosure of Your Information
5.1 Primary Purpose (APP 6)
We will use and disclose your personal and health information only for the primary purpose for which it was collected, or for a directly related secondary purpose that you would reasonably expect. We will not use or disclose your information for any other purpose without your consent, except as required or permitted by law.
5.2 Disclosure to Specialists
Your health information will be disclosed to the specialist assigned to your case for the sole purpose of enabling that specialist to provide a second medical opinion. Specialists are independent practitioners who receive your information under strict confidentiality obligations arising from their professional registration conditions, their Med Mend Platform Participation Agreement and applicable law. Specialists are not permitted to use your health information for any purpose other than providing your second opinion.
5.3 Disclosure to Service Providers
We may disclose your personal information to trusted third-party service providers who assist us in operating the platform, including:
- cloud infrastructure and data hosting providers
- payment processing providers
- customer support and case coordination tools
- email and communications platforms
These providers are permitted to use your information only to deliver services to us and are contractually bound to maintain appropriate privacy and security standards consistent with this Policy and the APPs.
5.4 Disclosure Required by Law
We may disclose your information where required or authorised by law, including in response to a valid court order, subpoena, regulatory demand, or where disclosure is necessary to prevent a serious threat to life, health or safety.
5.5 What We Will Not Do
Med Mend will not:
- sell, rent or trade your personal or health information to any third party
- use your health information for commercial, marketing or research purposes without your separate, express consent
- disclose your information to your employer, insurer or any third party without your consent except where required by law
Section 06: Cross-Border Disclosure (APP 8)
6.1 International Specialists
Med Mend connects patients with specialist doctors located around the world. Where your case is assigned to a specialist located outside Australia, your health information will be transferred to or accessed from that overseas location. This is an inherent feature of the second opinion service and you consent to such transfer when you submit a case for specialist review.
6.2 Protections Before Transfer
Before disclosing your health information to an overseas recipient, Med Mend takes reasonable steps to ensure that the receiving party (the specialist or relevant infrastructure) is subject to a standard of privacy protection that is substantially similar to the APPs, or that the transfer is otherwise permitted under APP 8. These steps include:
- contractual obligations in the Specialist Platform Participation Agreement requiring overseas specialists to handle health information in a manner consistent with Australian privacy standards
- verification that the specialist holds current professional registration and is subject to professional confidentiality obligations in their jurisdiction
- use of encrypted data transmission and access controls for all case materials
6.3 Your Acknowledgement
You acknowledge that where you expressly consent to an overseas specialist reviewing your case, and Med Mend has taken the steps described above, Med Mend will not be accountable under APP 8.1 for any subsequent breach by that specialist of Australian privacy standards, though we will take reasonable steps to assist you in pursuing a complaint against that specialist through their relevant professional regulatory authority.
6.4 Countries to Which Information May Be Transferred
Depending on the specialist matched to your case, your information may be transferred to specialists located in countries including but not limited to the United Kingdom, United States of America, Canada, Germany, New Zealand. We maintain an updated list of active specialist jurisdictions, which is available on request by contacting privacy@medmend.app
Section 07: How We Hold and Protect Your Information (APP 11)
7.1 Security Framework
Med Mend protects your personal and health information using a layered security framework aligned with the Australian Government Information Security Manual (ISM) and ISO/IEC 27001 Information Security Management standards. Our security controls include:
- AES-256 encryption of all personal and health information stored on the platform at rest
- TLS 1.2 or higher encryption of all data transmitted between your device and our platform
- role-based access controls ensuring that only authorised personnel and the assigned specialist can access your case information
- multi-factor authentication required for all platform accounts
- tamper-evident audit logging of all access to health information
- annual independent security assessments and penetration testing conducted by qualified third parties
- a documented Information Security Management System (ISMS) reviewed annually by the Chief Technology Officer
7.2 Data Storage Location
Personal and health information is stored on servers located in Australia. Where cloud infrastructure providers are used, we select providers that maintain Australian data residency options and meet the security standards required by our ISMS.
7.3 Staff Training and Access
Access to personal and health information is limited to Med Mend staff who require access to perform their role. All staff with access to personal information receive privacy and security training on commencement and annually thereafter. Access is revoked immediately upon cessation of employment or role change.
7.4 Retention of Records
We retain personal and health information for as long as is necessary to fulfil the purposes described in this Policy and to comply with our legal obligations. Case records are retained for a minimum of seven (7) years from the date of the second opinion report for adult patients, and for a minimum of seven (7) years after a minor patient reaches the age of 18, in accordance with applicable Australian record-keeping standards. After the applicable retention period, information is securely destroyed or de-identified.
7.5 Destruction of Unsolicited Information (APP 4)
If we receive personal information that we did not solicit and that we could not have collected lawfully, we will destroy or de-identify that information as soon as practicable and to the extent that it is lawful and reasonable to do so.
Section 08: Notifiable Data Breaches
8.1 Our Obligations
Med Mend is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we have reasonable grounds to believe that an eligible data breach has occurred — that is, a breach that is likely to result in serious harm to any individual whose information is involved — we are required to notify both the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.
8.2 Our Response Process
In the event of a suspected or confirmed data breach, Med Mend will:
- take immediate action to contain the breach and limit any further exposure
- notify the Privacy Officer and Chief Executive Officer within 24 hours of becoming aware of the suspected breach
- conduct an assessment of whether the breach is an eligible data breach within 30 days
- where the breach is notifiable, notify the OAIC using the approved form and notify affected individuals with sufficient information to enable them to take protective steps
- conduct a post-breach review to identify root cause and prevent recurrence, with findings reported to the Clinical Governance Committee
8.3 Notifying You
If your personal or health information is involved in an eligible data breach, we will contact you using the contact details you have provided to us as soon as reasonably practicable. Our notification will describe what happened, the type of information involved, the steps we have taken in response and the steps you may wish to take to protect yourself.
Section 09: Your Rights - Access and Correction
9.1 Right of Access (APP 12)
You have the right to request access to the personal and health information Med Mend holds about you. To make an access request, contact us in writing at privacy@medmend.app. We will respond to your request within 30 days. In most cases we will provide access free of charge, though we may charge a reasonable fee to cover the cost of locating, compiling and providing access to information where the request is complex or involves a large volume of data.
We may decline your access request in limited circumstances permitted by the Privacy Act, including where access would unreasonably impact the privacy of another individual, where the information relates to legal proceedings or where access is restricted by law. Where we decline, we will explain the reason in writing and advise you of any applicable complaint or review pathway.
9.2 Right of Correction (APP 13)
If you believe that personal or health information we hold about you is inaccurate, incomplete, out of date, irrelevant or misleading, you have the right to request that we correct it. We will take reasonable steps to correct the information within 30 days of your request. If we decline to make a correction, we will provide written reasons and, upon your request, attach a statement to the relevant record noting that you dispute the accuracy of the information.
9.3 Anonymity and Pseudonymity (APP 2)
You may browse our public website without identifying yourself. However, you cannot submit a case for specialist review or access the second opinion service without creating an account and providing sufficient personal information for us to verify your identity and deliver the service. We do not offer pseudonymous accounts for the clinical service given the need to match information accurately to your case records.
Section 10: Direct Marketing (APP 7)
We may use your personal information to send you communications about the Med Mend platform, health information relevant to the services we offer and updates we consider may be of interest to you, only where you have opted in to receive such communications or where we are otherwise permitted to do so under the Privacy Act and the Spam Act 2003 (Cth).
You may opt out of direct marketing communications at any time by clicking the unsubscribe link in any marketing email, by replying STOP to any marketing SMS, or by contacting us at privacy@medmend.app. Opting out of marketing will not affect service communications that are necessary for the administration of your account or the delivery of your service.
Section 11: Cookies and Online Tracking
11.1 What We Use
Our website and platform use cookies and similar tracking technologies to support platform functionality, remember your preferences and analyse how visitors use our services. The types of cookies we use include:
- Essential cookies: required for the platform to function, including session management and security features
- Functional cookies: remember your preferences and settings across sessions
- Analytics cookies: help us understand how users interact with the platform so we can improve it; we use anonymised or aggregated data for this purpose
11.2 Your Choices
You may configure your browser to refuse cookies or to alert you when cookies are being sent. Please note that disabling essential cookies may impair your ability to use certain features of the platform. We do not use cookies to serve third-party advertising.
Section 12: Minors, Capacity-Impaired Adults and Authorised Representatives
12.1 Minors (Under 18)
The Platform is not available to persons under 18 years of age acting independently. Consultations on behalf of a minor may only be booked by a parent or legal guardian (Authorised Representative) who accepts our Terms of Service on the minor’s behalf.
Collection with consent. All personal information and health information collected about a minor — including medical history, case materials, specialist reports, and consultation records — is collected with the express consent of the minor’s Authorised Representative. This consent is given at the point of registration or booking in accordance with our Terms of Service s.1.2.
Access and correction. The Authorised Representative of a minor has the same rights to access, correct, and manage the minor’s personal information and health information as the minor would if they were an adult. These rights are exercisable by the Authorised Representative for as long as the minor remains under 18. Upon the minor turning 18, all privacy rights and access control transfer exclusively to that person. Med Mend will not disclose a former minor’s health information to a previous Authorised Representative after that transition without the adult’s separate consent.
Health information protections. All health information relating to a minor is treated as sensitive information under the Privacy Act 1988 (Cth) and is subject to the full protections described in this Policy, including the APP 11 security framework (Section 7) and the NDB scheme obligations (Section 9).
12.2 Capacity-Impaired Adults
Where a person lacks decision-making capacity, their personal information and health information may be collected, used and disclosed with the consent of their Authorised Representative — being a person who holds legal authority to make healthcare decisions on that person’s behalf, whether as an enduring guardian, an attorney under an enduring power of attorney, a person responsible, or pursuant to a guardianship order under applicable Australian or equivalent law.
The Authorised Representative of a capacity-impaired adult has the same rights to access, correct, and manage that person’s personal information as the individual would if they had capacity. These rights are exercisable while the incapacity subsists. If the person regains decision-making capacity, privacy rights and access control revert exclusively to that person.
Med Mend may request evidence of an Authorised Representative’s authority at any time and may decline to act on a request pending verification.
12.3 How to Exercise Rights as an Authorised Representative
Authorised Representatives may exercise all privacy rights described in this Policy — including access (APP 12), correction (APP 13), and complaint rights (Section 16) — on behalf of the person in their care by contacting our Privacy Officer at privacy@medmend.app and identifying the person on whose behalf the request is made.
Section 13: Links to Third-Party Websites
Our platform may contain links to third-party websites or services, including the websites of specialists, medical institutions or related health resources. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party site you visit. This Policy applies only to information collected by Med Mend through our own platform and services.
Section 14: Quality of Information (APP 10)
We take reasonable steps to ensure that the personal information we hold about you is accurate, up to date, complete, relevant and not misleading. We rely primarily on you to provide accurate information and to notify us of any changes. If you become aware that information we hold about you is inaccurate or has changed, please contact us at privacy@medmend.app so that we can update our records.
Section 15: Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the platform or applicable law. Where a change is material, we will notify you by email or through a prominent notice on the platform before the change takes effect. The current version of this Policy is always available at medmend.app/privacy, with the version number and effective date noted on the cover.
Section 16: Contact Us and Privacy Complaints
16.1 Privacy Officer
For any privacy-related enquiries, requests or concerns, please contact our Privacy Officer:
Privacy Officer — Med Mend Pty Ltd
Email: privacy@medmend.app
Post: Privacy Officer, Med Mend Pty Ltd, 2A Cowper Street, Parramatta NSW 2150, Australia
Website: medmend.app/privacy
16.2 Internal Complaints Process
If you believe we have not handled your personal information in accordance with the Privacy Act or this Policy, we encourage you to raise your concern with us first. Please contact our Privacy Officer as set out above. We will acknowledge your complaint within 2 business days and provide a substantive response within 30 days. We will handle your complaint fairly, confidentially and without cost to you.
16.3 Complaint to the OAIC
If you are not satisfied with our response to your privacy complaint, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner (OAIC)
Website: oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001
16.4 State and Territory Health Privacy
Depending on the jurisdiction in which you receive healthcare, state or territory health privacy legislation may also apply to some of our activities. For example, the Health Records and Information Privacy Act 2002 (NSW) applies to health service providers operating in New South Wales. We will comply with applicable state and territory health privacy laws to the extent they apply to our operations.