Guidelines›Security›Australia

Australia · Privacy Act 1988 · Australian Privacy Principles · NDB scheme · state health records law

Australia has one national privacy law, eight sets of state rules on top, and no exemption for you.

Most Australian small businesses under three million dollars turnover are outside the Privacy Act altogether. A health service provider is not. A two-person psychology practice carries the same thirteen Australian Privacy Principles as a national hospital group, and since June 2025 a patient can sue over a serious invasion of privacy without waiting for a regulator.

This page goes through what applies, principle by principle, in ordinary words. It says which parts the software already does, which parts are numbers you set, and which parts are missing and why. The section about what we cannot do is not at the bottom in small type — it is section 08, and in Australia it is the section that decides most deals.

Practice owners and principals Practice managers Privacy officers NDIS and allied-health group operators
13privacy principles A$0turnover threshold for you 30 daysto assess a breach 7 yrsfrom the last entry 9Medicare rows we do not have
01 — Orientation

One federal law, and then your state

Australia does not have a single health-records statute the way Germany or the United Kingdom does. It has a federal privacy law that applies to every private health service provider in the country, and then a patchwork of state and territory law that mostly matters for one question: how long you must keep a record. Almost everything a buyer worries about sits in one of the four boxes below.

Federal · Privacy Act 1988

The thirteen Australian Privacy Principles

The APPs cover collection, notice, use, disclosure, offshore transfer, quality, security, access and correction. They are the whole of Australian privacy compliance for a private practice.

The part people get wrong: the Act exempts small businesses under A$3 million turnover — but that exemption does not reach a business that provides a health service and holds health information. Every clinic in this market is covered, from day one, at any size. Section 02.

State and territory law

Retention — and it depends where you practise

Three jurisdictions put a minimum retention period into statute: Victoria (Health Records Act 2001), New South Wales (Health Records and Information Privacy Act 2002) and the ACT (Health Records (Privacy and Access) Act 1997). Everywhere else it comes from professional standards and indemnity advice, and lands on the same numbers.

Why it matters: the common floor is seven years from the last entry for an adult, and for a child until they turn 25. Both of those are computed dates, not typed ones. Section 04.

And in NSW there is a second rulebook. The HRIP Act carries its own fifteen Health Privacy Principles that sit alongside the federal thirteen. They largely mirror them — a NSW practice is not doing the work twice — but a tender response that only cites the APPs has missed half the citation.

Federal · Part IIIC and the Cyber Security Act 2024

Breach notification, and ransomware reporting

The Notifiable Data Breaches scheme gives you 30 days to assess a suspected breach and requires notice to the OAIC and to affected individuals as soon as practicable once serious harm is likely.

Separately, since 30 May 2025, a business over A$3m turnover that pays a ransom must report the payment within 72 hours. Section 05.

The national digital-health rail

My Health Record, healthcare identifiers, Medicare

My Health Records Act 2012, the Healthcare Identifiers Act 2010, ADHA conformance, and Medicare claiming through PRODA and Medicare Web Services. This is a connected national system with its own approvals.

Why it matters: we are not on any of it. That is a boundary, not a backlog, and section 08 sets out exactly where it hurts and where it does not.

The short version, for somebody deciding whether to read on

If you run a private-pay, mixed, NDIS, EAP or telehealth-first practice, every obligation on this page is one we can meet or exceed, and the privacy argument is genuinely strong — stronger than any hosted competitor in this market can make. If bulk-billed Medicare sessions are your revenue model, read section 08 first: we cannot lodge a Medicare claim, and no amount of privacy architecture changes that.

02 — The Australian Privacy Principles

All thirteen, and what the software does about each one

The APPs are written as obligations on your practice, not on your software. But nine of the thirteen are obligations a system either supports or quietly makes impossible, and this is the table to bring to a due-diligence conversation.

Read the status column, not just the tick. Three of these are honest partials and one is a straight "your text, not ours". They are marked as such.

✓BuiltIn the platform now, and demonstrable on a live system. ⚙Built — you set the valueThe mechanism exists; the number, the wording or the policy is yours. Not a shortfall. ◐Partly builtSomething is genuinely missing. The right-hand column says exactly what. §The principle asks for lessNothing is missing. The law reaches the same place by another route, or does not bite here.
PrincipleStatusWhat it asks, and what happens here
APP 1 · Open and transparent management ⚙ You must have a clearly expressed, up-to-date privacy policy, and a way for people to complain about how their information was handled. The complaint side is built — privacy complaints are a first-class record with an owner, a clock and an outcome, not an inbox. The policy register is built too: policies are versioned, each version keeps its own effective dates, and old versions are not overwritten. The words in the policy are yours to write.
APP 2 · Anonymity and pseudonymity § People must be given the option of dealing with you anonymously or under a pseudonym — unless it is impracticable, or a law requires identification. In clinical practice it is almost always both. The principle rarely bites in this market, and where a service genuinely does run anonymous intake, a client record can be created without a legal name.
APP 3 · Collection of solicited information ✓ Health information is sensitive information, so APP 3.3 says you may only collect it with consent, or under one of the permitted health situations in s16B — of which "necessary to provide a health service" is the one almost every clinic relies on. Every document type carries a recorded reason for holding it, so the answer to "why do you have this?" is a stored field rather than a recollection. Practically, this also means relying on consent by default is a mistake: consent can be withdrawn, and treatment records must survive that.
APP 4 · Unsolicited information ⚙ Information that arrives without you asking — a referral you did not request, a document a family member sends in — must be destroyed or de-identified if you could not have collected it lawfully yourself. The disposal machinery is the same one retention uses; the decision about a particular document is a person's.
APP 5 · Notification of collection ◐ At or before collection you must tell the person who you are, why you are collecting, who you usually disclose to, how to access and correct, how to complain, and whether anything goes overseas. The machinery exists — a versioned notice, issued to a person, with an acknowledgement recorded against the date and version they actually saw. What is missing is an Australian template. The notice pack shipped today is written to the United States Notice of Privacy Practices. An Australian collection statement is text you supply into an existing mechanism, not a feature that has to be built.
APP 6 · Use and disclosure ✓ Information collected for one purpose may generally only be used for that purpose. Every disclosure out of the system is a record: what left, to whom, on what date, under which basis, and who authorised it. That register is what turns "we only share appropriately" into something you can print.
APP 7 · Direct marketing ✓ Sensitive information may not be used for direct marketing without consent, and people can opt out at any time. Beyond that, this platform treats contact channels as a safety control, not a preference: a person can say do not call this number, do not email this address — and if the only permitted channel is blocked, the message fails loudly instead of quietly falling back to the blocked one. In mental health that is the difference between a reminder and a disclosure.
APP 8 · Cross-border disclosure ✓ If you send personal information overseas you remain accountable for what the overseas recipient does with it. Our answer is that nothing has to go overseas at all. This is the strongest single argument we have in Australia and it has its own section below.
APP 9 · Government related identifiers § You may not adopt a government identifier — a Medicare number, an Individual Healthcare Identifier — as your own identifier for a person. We do not: internal identifiers are our own, and because we do not connect to the Healthcare Identifiers Service, no IHI ever enters the system. That is a consequence of the boundary in section 08, but on this principle it happens to be the safe side of it.
APP 10 · Quality ✓ Information must be accurate, up to date and complete. Correction requests are a tracked record with a deadline. Crucially, an accepted correction never overwrites the original — it creates a new version, and the earlier one remains, because a clinical record that can be silently rewritten is not evidence of anything.
APP 11 · Security, and destruction when no longer needed ✓ The longest-running obligation and the one with the most enforcement behind it. Every clinical document is encrypted with its own key; every opening of one is logged before the content appears, in a chain where a removed entry is detectable; access follows the treatment relationship rather than the job title. The second half of APP 11 — destroy or de-identify when no longer needed — is where most systems stop. Here disposal destroys the encryption key, so the content is unreadable even from a backup, while the proof of disposal survives. See the secure documents page.
APP 12 · Access ◐ A person may ask for their information and you must give it, within a reasonable period, charging no more than a reasonable cost — and no fee at all for making the request. Access requests are a tracked record with a computed deadline, a recorded format, itemised charges and a logged handover. What is partial is refusal. APP 12.3 lists a closed set of grounds — serious threat to life, health or safety; unreasonable impact on others' privacy; frivolous or vexatious; legal proceedings; commercially sensitive evaluative material. The workflow that runs a "serious harm" withholding decision properly — a named professional, a review, an expiry — exists, but it was written to the United Kingdom test and ships in the UK module. Running it in Australia works; the grounds list on the form is not the Australian one.
APP 13 · Correction ✓ You must correct information that is wrong, and — the part systems forget — if you refuse, APP 13.4 lets the person require a statement to be associated with the record saying they consider it inaccurate. That statement is built: once it exists, it travels with the record, and the disclosure register knows it must go out alongside anything disclosed afterwards. A refusal here does not end the matter and the software does not pretend it does.
The one-line summary of this table

Nine of thirteen are built and demonstrable. Two are yours to fill in. Two are honest partials — an Australian collection-notice template, and an Australian refusal-grounds list on the access form. Both are content and configuration inside machinery that already exists, not architecture that has to be designed. Neither is a reason to fail a due-diligence review, and both should be named in one before somebody else finds them.

03 — APP 8

Where your patients' records physically are

This is the argument to lead with in Australia, because it is the one no hosted competitor in this market can answer the same way.

What APP 8 actually says

Before you disclose personal information to an overseas recipient, you must take reasonable steps to ensure the recipient does not breach the APPs — and, under s16C of the Act, you remain liable for what they do with it as though you had done it yourself. A contract clause is the usual "reasonable step". It is also the reason the obligation never really goes away: you have outsourced the handling, not the accountability.

Every mainstream Australian practice system is software-as-a-service. The clinical records live on the vendor's infrastructure, under the vendor's operational control, in a region the vendor chooses. Several are excellent products run by careful people — this is not an accusation. It is a structural fact about where the data is and who can reach it, and it is a fact a privacy officer has to write down.

01Nothing is disclosed overseas

The system runs on infrastructure you choose — your own server, or a hosting arrangement in an Australian region under your control. There is no cross-border disclosure to assess, because there is no disclosure.

Answers"Which country are our records in?"
02We hold no copy of your data

Not a backup, not a replica, not an analytics extract. There is no vendor-side dataset that could be subpoenaed, breached, or migrated when we are acquired.

Answers"What happens to our data if you are bought?"
03No standing support access

There is no permanent support account and no maintenance override. Access to help you with a problem is requested, granted for that job, logged like any other access, and withdrawn.

Answers"What can your support staff see?"
04You can prove it rather than assert it

Because the software is open source and runs on your infrastructure, your own IT people or an auditor you hire can verify all three statements above. They do not have to take a supplier's word, and neither do you.

Answers"How would we actually check any of this?"
Say the whole sentence, not half of it

Self-hosting removes the APP 8 question and it hands you the operational burden that came with it. Somebody has to patch the server, test the backups, watch the scheduled jobs and hold the encryption key. A SaaS vendor was doing that. Section 10 lists what moves to your side of the line, in full, because a buyer who discovers it later is right to be annoyed.

04 — Retention

Seven years from the last entry, and until 25 for a child

Australia's retention rules are the most fragmented thing on this page, and the fragmentation is mostly cosmetic — the numbers agree almost everywhere. What differs is whether the number is in a statute or in a professional standard.

Where you practiseWhere the rule comes fromThe minimum period
VictoriaHealth Records Act 2001 — prescribed in statute7 years from the last entry; for a child, until they turn 25 — whichever is later
New South WalesHealth Records and Information Privacy Act 2002 — prescribed for private providersThe same: 7 years, or until 25 for a child
Australian Capital TerritoryHealth Records (Privacy and Access) Act 1997 — prescribed in statuteThe same
Queensland, South Australia, Western Australia, Tasmania, Northern TerritoryNo prescribed private-sector period. Professional codes, college guidance and indemnity insurersThe same numbers, treated as the standard of care. The universal advice is to follow the Victorian and NSW periods
New South Wales — after deathHRIP Act: health information about a person dead less than 30 years is still protected health informationThe privacy duties do not stop at death in NSW. The federal Privacy Act does — it protects living individuals only — which is why this is a state question and not a national one
Everywhere — the other clockStatutes of limitation, and claims that can be brought long after treatmentLonger than seven years in practice for anything that might become a claim. This is a decision for you and your insurer, not a default we can ship

Why "from the last entry" is the hard part, and why it is already solved

A retention period counted from the wrong day is wrong every single time, and the two Australian anchors are both awkward ones. "Seven years from the last entry" cannot be computed when the document is filed — the clock has not started, and it restarts every time the client comes back. "Until they turn 25" is not a period at all; it is a birthday.

This platform never stores a disposal date. It stores the rule, and computes the date from the anchor each time it is needed. Years after last contact and until the subject reaches a given age are both first-class rule kinds, and the age of majority is set per rule rather than fixed at eighteen — which is exactly what an Australian deployment needs, because the Australian number is 25. When an anchor is unknown, the rule returns do not dispose: erring towards keeping a record is recoverable, and erring the other way is not.

Two things about Australian retention that are not shipped, stated plainly

  • There is no Australian retention pack. The United Kingdom deployment ships with the NHS Records Management Code of Practice already loaded as data — twenty years after last contact for mental health, ten years after death, and the rest. Nothing equivalent is seeded for Australia. The rules above are two records somebody types once at setup, and until somebody does, nothing disposes. This is configuration, not a missing capability — but an unconfigured retention engine is an empty one.
  • "Whichever is later" cannot be expressed by a single rule. A rule is one kind with one period. "Until 25 or seven years from the last entry, whichever is later" is two computations compared against each other, and the engine does not do that today. In most cases it does not matter — a child last seen at seventeen reaches 25 well after the seven years run out, so the age rule wins on its own. It does matter for a client who began as a minor and was still in treatment into their twenties, where the seven-year clock finishes later than their twenty-fifth birthday. Today that case is handled by choosing the longer rule deliberately, which is a person's judgement rather than the system's arithmetic.
05 — Notifiable Data Breaches

What happens, in order, when something gets out

Health service providers are the most-breached sector in Australia and have been for years — in 2025 they accounted for the largest share of all notifications made to the OAIC, and most of those breaches were malicious or criminal attacks rather than accidents. This is not a hypothetical section.

Below is the actual sequence inside the software. Each step is one thing the system or a person does, in the order it happens.

1 the software does this by itself 1 a person decides or writes something ✕ the software refuses, and says why
Privacy Act 1988, Part IIIC A suspected eligible data breach The scheme's structure is unusual: the trigger is suspicion, not certainty, and the thirty days is a deadline for deciding, not for notifying. Missing that distinction is how practices end up out of time.
  1. Somebody records that a breach may have happened

    A lost laptop, an email to the wrong client, an account that behaved oddly. The record is opened on suspicion — nobody has to be sure first.

  2. The thirty-day assessment deadline appears by itself

    Computed from the day the practice became aware. Nobody types a date, so nobody types the wrong one, and the clock is visible on the record from the moment it exists.

  3. The assessment is carried out and written down

    What information was involved, how sensitive it is, whether it was protected, who could have obtained it, and what harm could follow. Health information sits at the sensitive end of every one of those questions.

  4. Whether the data was encrypted is a recorded finding, not an assumption

    Because clinical documents are encrypted with per-document keys held outside the database, the question "could anyone actually read it?" has an evidenced answer. That answer changes the serious-harm conclusion, and it has to be written down either way.

  5. Remedial action is recorded, and can end the matter

    If you act quickly enough that serious harm is no longer likely — the laptop is recovered and was encrypted, the recipient confirms deletion — there is no eligible breach to notify. That conclusion is only defensible if the remedial action and its timing were recorded when they happened.

  6. The assessment cannot be closed as "no harm" with nothing in it

    A conclusion without the reasoning behind it is the finding a regulator disbelieves. The record will not close on an empty assessment.

  7. If serious harm is likely, the notification obligations open

    A statement to the Australian Information Commissioner and notice to the affected individuals, as soon as practicable. There is no thirty-day grace on this half — thirty days was the assessment.

  8. The statement is drafted with the four required elements

    Who you are and your contact details, a description of the breach, the kinds of information involved, and what affected individuals should do in response. That last one is the element most often written badly, and it is the only one the individual actually acts on.

  9. Everything above stays as one linked record

    The suspicion, the assessment and its reasoning, the remedial action, the decision, the notifications and their dates. A breach file assembled afterwards from three mailboxes is not evidence of a process; it is evidence there was not one.

If you pay a ransom: since 30 May 2025 the Cyber Security Act 2024 requires a business with more than A$3 million annual turnover to report a ransomware or cyber extortion payment to the Australian Government within 72 hours of making it, through cyber.gov.au. This is separate from and additional to the OAIC notification, it has its own much shorter clock, and — unlike the NDB scheme — it is triggered by the payment rather than by the harm. The incident record holds the facts; lodging the report is yours.
06 — What changed, and what is coming

Australian privacy law is mid-reform, and the direction is one way

The Privacy Act sat largely unchanged for a long time. It is now moving, and a system bought this year will be in service through the rest of it. These are the four changes worth knowing about.

In force · 10 June 2025

A patient can now sue you directly

The Privacy and Other Legislation Amendment Act 2024 created a statutory tort for serious invasions of privacy, covering both intrusion into seclusion and misuse of information. An individual can bring it themselves.

Why it matters more than it sounds: the previous enforcement route ran through the OAIC, which prioritises. This one does not need a regulator to be interested, and it does not carry the small-business exemption at all.

In force · December 2024

Penalties that scale with the business

Serious or repeated interference with privacy now carries a maximum of the greater of A$50 million, three times the benefit obtained, or 30% of adjusted turnover for the relevant period. A new mid-tier and a low-tier infringement-notice regime sit underneath it.

Why it matters: the old maximum was survivable for a large group. This one is not, and it changed how boards ask the question.

From · 10 December 2026

Automated decisions must be disclosed

Where a computer program uses personal information to make — or substantially help make — a decision that could reasonably be expected to significantly affect someone's rights or interests, your APP 1 privacy policy must say so, and say what kinds of information are used.

Why it matters: triage scoring, risk flags and automated eligibility all potentially land here. If you turn on anything of that kind, the policy has to change with it.

Proposed · not yet law

The second tranche

Under consideration: a "fair and reasonable" test for collection and use regardless of consent, removal of the small-business exemption, a general right to erasure, a broader definition of personal information, and a named senior privacy role.

Why it matters to you specifically: almost nothing. You never had the small-business exemption, and a right to erasure is already built and shipping in this platform. Australian clinics are unusually well placed for tranche two.

The honest framing for a sales conversation

Do not sell reform panic. The accurate statement is narrower and lands better: the liability attached to holding Australian health records went up sharply between 2024 and 2026, the route to that liability no longer runs through a regulator's priorities, and the question "where is it and who can reach it" is now the question with money attached to it. That is the question self-hosting answers.

07 — Standards

The frameworks a buyer will name, and whether they actually apply

Australian procurement conversations reach for framework names quickly. Several of the ones that come up do not apply to a private clinic at all, and saying so accurately is worth more than nodding along. This table is as useful for ruling things out as for ruling them in.

The status marks are the same four used in section 02: ✓ built · ⚙ built, and part of it is yours · § the framework does not reach you · — we do not have it and could not.

FrameworkStatusDoes it apply, and what do we do about it
Essential Eight
ASD / Australian Cyber Security Centre
⚙ Not law for a private practice. It is mandatory for federal government entities and is the de-facto baseline everyone else is measured against — Maturity Level 1 for a small business, Level 2 for a larger group. Of the eight, three are ours (patching the application, multi-factor authentication, restricting administrative privileges — all supported and shipped), and five are your infrastructure (application control, macro settings, user application hardening, patching operating systems, regular backups). We can tell you what the software does; we cannot claim a maturity level on your behalf, and any vendor who does is describing your server, not their product.
ISO/IEC 27001 — We are not certified, and the product could not be. ISO 27001 certifies an organisation's management system, not a piece of software. What a certified competitor can show you is that their operations were audited — which matters precisely because your data is on their infrastructure. When it is on yours, the certificate you would want is your own. Say this plainly; pretending otherwise fails the first technical question.
RACGP Standards, 5th edition
Criterion C6.4 — information security
⚙ Applies to accredited general practices, and only to them — but allied health and psychology groups are increasingly asked for the same evidence by health funds and referrers. C6.4 wants a named person responsible for security, a written computer and information security policy, controlled access, backups that are tested, and business continuity. The evidence side is built: role-based access, an access log nobody can edit, a versioned policy register, a risk register, and continuity records. The named person and the backup testing are yours.
NDIS Practice Standards
Privacy and dignity · records management
✓ Applies to registered NDIS providers, which is a real part of this market. The standards want participant information kept confidential and accessible only to those who need it, records that are accurate and complete, and consent that is recorded. Access following the treatment relationship rather than the job title is exactly this standard, and it is the one thing most front-office systems in this market do not do — a shared clinic calendar is usually a shared clinic record.
NSQHS Standards
ACSQHC
§ Written for hospitals, day procedure services and public health services. A private psychology or allied-health practice is not accredited against them. Where a group runs a day procedure arm, Standard 1 (clinical governance) and Standard 2 (partnering with consumers) are the two that reach into records handling, and the governance registers cover the documentary side of both.
SOCI Act 2018
Security of Critical Infrastructure
§ It does not apply to you, and this is worth knowing because people assume it does. The health asset class is drawn around hospitals with a general intensive care unit — not clinics, not allied-health groups, not psychology practices, at any size. The heavy obligations that come with it (a critical infrastructure risk management programme, board-approved annually, 12-hour and 72-hour incident reporting) are not yours. Contrast with Germany, where NIS2 catches an ordinary practice group at around fifty staff. Australia's equivalent threshold is far higher and a growing clinic group will not cross it.
Cyber Security Act 2024
ransomware payment reporting
⚙ Applies to any business over A$3 million turnover, so it reaches a mid-sized clinic group where SOCI does not. If a ransom is paid, the payment is reported within 72 hours. The incident and its record live in the platform; the lodgement is yours. Worth pairing with the observation that encrypted-at-rest clinical documents with keys held outside the database change what an attacker actually obtains.
AHPRA registration ✓ Applies to practitioners, not to software — but proving that fifty contractors all hold current registration is a real operational problem, and it is one we solve directly: skills and certifications with expiry dates, chased automatically, with a completeness report across the workforce. Most systems in this market treat registration as a text field.
TGA — Software as a Medical Device § Bites where software makes a diagnostic or therapeutic claim. We make none, and nothing in the platform interprets clinical content or suggests a course of treatment. This stays true only for as long as it is true: any future feature that scores, triages or recommends needs this question asked again before it ships.
08 — The boundary

What we cannot do in Australia

Australia is the most competitive market this platform operates in, and it is the one where the gap is easiest to describe. Everything below is genuinely absent. None of it is close to shipping.

There are two gaps, not one. The first is the national funding rail everybody asks about. The second is quieter and sits underneath the payout engine — the part of this platform we are usually proudest of — and it is the one to read if you are running fifty contractors.

What we do not haveWhat it means in practice
Medicare claiming
Medicare Web Services · PRODA
We cannot lodge a Medicare claim. For a practice running Better Access sessions this is not a feature gap, it is the revenue model. It is a build rather than a certification — a developer registers, integrates, tests, and receives a Notice of Integration from Services Australia before production access — so nobody has to approve us as a company first. But the conformance step is real and it is not a weekend.
Bulk billing and patient claiming
Medicare Easyclaim · Tyro
No point-of-service claiming at reception.
My Health Record
ADHA conformance
We do not upload to, or read from, My Health Record, and we do not hold ADHA conformance. Note the scope of the July 2026 sharing by default change carefully: it obliges pathology and diagnostic imaging report authors to upload their written reports. It does not oblige a psychology or allied-health practice to do anything, and it is regularly mis-sold as though it did.
Healthcare Identifiers ServiceNo IHI lookup. As noted under APP 9, this also means no government identifier ever enters the system — a real benefit, arrived at accidentally.
Secure messaging
HealthLink · Medical Objects · Argus
No standards-based clinical correspondence to and from GPs and specialists. In a referral-heavy practice this is felt every day.
Electronic prescribing
eRx · MediSecure
Not built. Matters for prescribing psychiatry, not for psychology or allied health.
DVA claimingNot built.
Private health fund claiming
HICAPS · Medipass
Not built. Cards are processed, but not on-the-spot fund claiming.
NDIS claiming
PRODA / PACE bulk upload
Plan-managed obligations, contract versions, derived dates and analytic accounting by funding source are all built and are genuinely stronger than the field. The claim upload itself is not.
How to use this section rather than hide it

Put it on the table in the first conversation. If Medicare rebates are how the practice earns, say we are not the right product yet and mean it — there are four or five excellent Australian products that do that job well and cheaply. The practices we serve properly are private-pay and mixed groups, NDIS providers, EAP and corporate providers, and telehealth-first businesses — the ones where Medicare is not the revenue and the actual problem is that nobody can tell you what each practitioner is owed.

And read the next section before you quote one of them. There is a second gap, it is quieter, and it sits underneath the payout engine we just described as the reason to buy.

09 — The second gap

What an Australian payout run owes, and what ours does not know

The section above is the gap everybody expects. This one is less obvious and matters more, because it sits under the part of the platform we are proudest of.

When a payout cycle closes, the software writes one bill per practitioner from amounts frozen at the moment each booking was made, under the contract version that was in force then. That is genuinely unusual and it is why groups buy us. In Australia, that document and that payment carry four obligations the engine does not know about, and there are two more that never reach it at all.

One worked example, used for every item below

Northside Psychology, Melbourne. Fifty contractor practitioners, mostly private-pay with some WorkCover work, paid on a fortnightly cycle.

Dr Sarah Chen sees 40 sessions a fortnight at a A$180 client fee on a 65% revenue share — so A$117 a session, A$4,680 a fortnight, A$121,680 a year. Across fifty practitioners at that rate the practice pays out about A$6.08 million a year in practitioner fees.

Every number below is worked against Sarah and then scaled. They show the size of each question, not the answer to it — see the note at the end of this section.

Superannuation, and the seven-day clock

What happens now. The fortnight closes. The run creates a bill for Sarah for A$4,680. Nothing else happens.

What the law expects. Section 12(3) of the Superannuation Guarantee (Administration) Act treats a contractor as an employee for superannuation when they are engaged wholly or principally for their own labour and must do the work personally. A psychologist paid per session — who plainly cannot send somebody else to see the client — is very likely inside that test. Quoting an ABN does not take her out of it, and neither does the contract calling her a contractor. The rate is 12%, so A$561.60 a fortnight — A$14,601.60 a year for Sarah, about A$730,000 a year across fifty practitioners, none of which we calculate. And since 1 July 2026 the contribution must reach her fund within seven business days of the payment. The old habit of batching super up and paying it after the quarter has ended is gone. Getting it wrong is expensive in an unusual way: the superannuation guarantee charge is not tax-deductible, and carries a penalty of up to 60% of the shortfall plus daily interest. Size of the fix: the largest here. A design change, not a setting.

GST on the payout lines

What happens now. Sarah's line reads Session — A$117.00, with no tax code at all.

Why that is wrong either way. There are two possible treatments and the software has picked neither. The clinic's supply to the patient is generally GST-free as a recognised health service. Sarah's supply to the clinic is a different supply and is commonly taxable at 10%, though it depends how the arrangement is written. A blank tax field is not the safe middle — it is an unanswered question copied onto every line of every bill. If the taxable treatment is right, her fortnight should be A$5,148, not A$4,680: she is short A$468, and the practice never claims that back on its BAS — about A$608,000 a year of input tax credits across fifty practitioners. Size of the fix: small. Odoo Community's Australian module already ships every code needed, including GST-free and a no-ABN variant. The run has to choose one and stamp it.

Recipient created tax invoices

What happens now. Sarah does not invoice the practice — the practice invoices itself on her behalf, because it is the system that holds the session data. That is exactly what an RCTI arrangement is, and our document is an ordinary vendor bill headed "Bill".

What the ATO requires. Four things, and we have none of them: a written RCTI agreement with that practitioner in which she agrees not to issue her own tax invoices for the same work; the recipient registered for GST; the document carrying the words "Recipient created tax invoice"; and both ABNs on its face. A worked failure: Sarah leaves in March, the practice is reviewed in November, and the input tax credits on her first three months can be denied because the document was never a valid tax invoice — the same A$608,000, arriving a second time by another route. The agreement cannot be signed retrospectively by somebody who has left. Size of the fix: small to medium, and we already own the hard part — our e-signature layer signs practitioner contracts on the clinic's own instance, so the agreement is a template and a link.

No-ABN withholding

What happens now. Michael starts on the 3rd, sees clients immediately, and has not sent his ABN through. The fortnight closes and the run pays him A$2,000.

What the law expects. Where a supplier does not quote an ABN, the payer must withhold 47% and remit it. Michael should receive A$1,060 and the ATO A$940. Because we paid him the full amount, the practice now owes that A$940 out of its own pocket, plus penalties — it does not get to recover it from him, because failing to withhold makes the payer liable. Where it bites is onboarding: a practitioner who starts before the paperwork is finished, which in a growing group is the normal case rather than the exception. Size of the fix: small, and the pattern is already in the product — we withhold pay automatically when a contract is unsigned. This is the same mechanism pointed at a different field.

The ABA batch payment file

What happens now. The cycle closes and the run produces fifty approved bills. Then somebody opens the bank and keys fifty payments by hand — a BSB, an account number, an amount and a reference each. At a realistic ninety seconds apiece that is seventy-five minutes every fortnight, about thirty-two hours a year, and 1,300 chances a year to transpose a digit and pay the wrong practitioner.

What an ABA file is. A plain text file — one header, one line per payee, one trailer with a total the bank checks. Every Australian bank accepts one. Upload it once and all fifty are paid. Odoo Community does not include it; it is an Enterprise module. Size of the fix: medium and mechanically simple — the format is published and short. This is the gap an operations manager notices on day one, which makes it worth more in a demonstration than its engineering cost suggests.

Compensable schemes — and our qualifying question is wrong

What happens now. A session is billed to a client or to a company. That is the whole model.

What Australian allied health actually looks like. A Melbourne practice treats somebody injured at work. The payer is neither the patient nor Medicare — it is the employer's WorkSafe insurer. That engagement needs a claim number, an approved provider, a treatment plan approved before the sessions happen, scheme item codes on a scheme fee schedule rather than the practice's own fee, and a receivable tracked against the claim because insurers pay slowly. And it differs in every state: WorkSafe Victoria, icare NSW, WorkCover Queensland, ReturnToWorkSA, WorkCover WA, plus TAC for Victorian transport accidents and CTP insurers in NSW and Queensland. Nine schemes, not one rail. This is the strategically important one, because it is a different gap from Medicare and we have been treating it as the same gap. We qualify on "are Medicare rebates your revenue model?" — a private-pay Melbourne physiotherapy group answers no, buys, and then finds the quarter of its revenue coming through WorkSafe has nowhere to live. Size of the fix: large, and it is a market-entry decision. But the qualifying question is a sales fix available today, before any code is written.

Single Touch Payroll — the one to decline

What this is. Northside has fifty contractors and six employees — reception, a practice manager, a bookkeeper. For those six, the practice must report to the ATO on or before every payday: gross, tax withheld and super liability per person, split under Phase 2 into ordinary time, overtime, bonuses and allowances as separate components rather than one figure.

Where we stand, and the recommendation. Odoo Community carries no Australian payroll at all. We should decline this rather than build it, and say so early. Groups in this segment already run Xero, MYOB or a dedicated payroll product for their handful of employees, and replacing that is not a fight worth having. What we should do instead is make the contractor side above genuinely correct, so the boundary between the two systems is clean — employees over there, practitioners here.

Two things we can already do here, and have never said

Both are true today, both are free, and neither has appeared in anything written about Australia until now.

Already shipping

Australian accounts, GST codes and the BAS report

The Australian accounting module installs automatically alongside accounting in Odoo Community. It brings the Australian chart of accounts, the full tax set — 10% GST, GST-free sales, input-taxed, export and the contractor-reporting variants — and the BAS report itself, with its labels already wired to the tax codes.

Worked example. At quarter end the practice opens the BAS. G1 total sales, 1A GST on sales, 1B GST on purchases are filled from the transactions themselves, with no spreadsheet in between. Which is exactly why the GST item above matters: the report is already there and already correct — it is the payout lines arriving with no tax code that leave a hole in it.

Already shipping

Peppol eInvoicing on the A-NZ profile

Peppol support and the Australia–New Zealand invoice profile are both in Odoo Community.

Worked example. Northside invoices a corporate EAP client, or a government department that requires eInvoicing. Instead of emailing a PDF that somebody re-keys into their accounts-payable system, the invoice travels over the Peppol network and lands directly in the buyer's payables queue — nothing re-typed, no lost attachment, and materially faster payment. Australian government agencies are required to be able to receive these.

OrderWhatWhy this order
1Fix the qualifying questionCosts nothing and needs no code. It stops us selling into a group whose real blocker is a workers' compensation scheme rather than Medicare
2Scope superannuationThe largest liability, a design change rather than a setting, and the only one with non-deductible penalties behind it
3GST, RCTI and the ABN check togetherOne piece of work. All three are the same line and the same document, all three use tax codes that already ship, and together they are worth around A$608,000 a year to a fifty-practitioner group
4The ABA fileSmall, visible, and it demonstrates well
5Start claiming the two aboveA documentation change, not a build
—Decline Single Touch PayrollSay it in the first call rather than the fifth

None of this is tax, legal or superannuation advice, and no figure here is a quotation

Every rate, threshold and deeming test on this page should be confirmed with an Australian tax adviser before it reaches a contract, a customer document or a product decision. The superannuation position in particular turns on the facts of each engagement rather than on a general rule, and the arithmetic above exists to show how large the question is, not to answer it.

10 — Where we are stronger

Nine things that are unusual in the Australian market

Not a feature list — the Australian systems are good and have plenty of features. These are the places where the way this platform is built produces an answer the incumbents structurally cannot give.

01The records never leave the country, or the building

Self-hosted, on infrastructure you choose. APP 8 has nothing to bite on. Every hosted competitor in this market has an answer to this question; none of them has this answer.

Answers"Where is our data and who else can reach it?"
02Destruction that actually destroys

APP 11.2 requires information to be destroyed when it is no longer needed. Here that means the encryption key is overwritten, not the row deleted. A deleted row comes back from last night's backup; this does not.

Answers"How do you prove a record was really destroyed?"
03A read log nobody can edit

Every opening of a clinical record is written before the content appears, in a chain where a removed entry is detectable. Not even your own practice administrator can quietly change it.

Answers"Who has looked at this client's file?"
04Access follows the treatment relationship

Not the job title, and not the clinic. A practitioner reaches their own clients; access ends when the relationship does. In most Australian practice software a shared calendar means a shared record, which is the finding an NDIS audit writes down.

Answers"Can every clinician open every file?"
05Contact channels treated as a safety control

Do-not-call and do-not-email are enforced at the point of sending, and a blocked channel with no alternative fails loudly rather than falling back. This is APP 7 on paper and a safeguarding control in practice.

Answers"What stops a reminder going to the wrong number?"
06The entire back office, which none of them have

Practitioner payouts under the contract version in force when the booking was made, unused session credits, revenue by funding source, contracts with obligations and derived dates. Every competitor in this market scores nought, one or two of twenty-one business-operations rows.

Answers"Who is reconciling what each contractor is owed?"
07Registration currency chased automatically

AHPRA registration, working-with-children checks, insurance and supervision hours as dated credentials with expiry chasing and a completeness report across the whole workforce. At fifty contractors this stops being administration and starts being exposure.

Answers"Prove every practitioner is currently registered."
08Open source, and readable

Built on Odoo Community. Your own IT people, or testers you hire, can read every line rather than take a supplier's word for it — which is the only way any claim on this page can actually be checked.

Answers"How would we verify any of this ourselves?"
09Signing stays inside your system

Consent forms and service agreements are signed on your own instance with their own audit trail. Nothing is handed to an outside signature vendor, which would be a disclosure to assess under APP 6 and possibly APP 8.

Answers"Who else sees our signed consent forms?"
11 — Your side of the line

What stays with the practice

The Privacy Act places its duties on the APP entity — your practice — and never on the software. A supplier can hold the evidence and make the workflow real. It cannot be the entity.

Not legal advice, and no product is "Privacy Act certified"

Nothing here is legal advice, and there is no such thing as APP-certified software — that certification does not exist for products. Everything below is yours, and anything on this page that will end up in a contract or a tender response should be confirmed with an Australian privacy lawyer first.

  • Your APP 1 privacy policy and your APP 5 collection notice. The machinery for issuing, versioning and acknowledging a notice is built. The Australian words are yours, and today there is no Australian template in the box.
  • Setting the retention rules at go-live. Two records: seven years after last contact, and until age 25. Until somebody enters them, nothing is scheduled for disposal and the engine is idle rather than wrong.
  • Deciding who gets a treatment relationship. The system enforces access through care relationships. It does not decide who should have one.
  • The five Essential Eight controls that are your infrastructure — application control, macro settings, user application hardening, operating-system patching, and backups that are actually restored in a test.
  • Where the server is, and who can walk up to it. Self-hosting moved this to you along with the APP 8 answer. Both halves arrived together.
  • The encryption key. This one deserves its own reading. See the secure documents page — losing that key means losing every clinical document permanently, by design, and there is no recovery route we could build without destroying the protection it provides.
  • Lodging the reports. The OAIC statement under the NDB scheme, and the 72-hour ransomware payment report if it ever applies. We hold the facts and the timeline; the filing is an act of the practice.
  • Watching the scheduled jobs. Retention and disposal run automatically. A job that stops quietly is a compliance problem that only surfaces in an audit.
The Australian summary, in one paragraph

Every private health service provider in Australia carries the thirteen Australian Privacy Principles regardless of size, and since June 2025 a patient can enforce a serious invasion of privacy without the regulator's involvement. Nine of the thirteen principles are built here and demonstrable; two are yours to write; two are honest partials that are content rather than architecture. Retention is seven years from the last entry and until 25 for a child — both computed from the right anchor by an engine that already supports them, and neither seeded, so setup has to do it. APP 8 is the strongest argument we have in this market and self-hosting removes the question entirely, at the cost of an operational burden that is listed above in full. What we do not have is the national rail: no Medicare claiming, no My Health Record, no secure messaging. Private-pay, NDIS, EAP and telehealth-first practices are open to us. A bulk-billing Better Access practice is not, and should be told so on the first call.