Privacy Policy


Privacy Policy


In the course of Medicalnote.AI providing its Services, we manage and protect personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act), the 13 Australian Privacy Principles (APPs), and the My Health Records Act 2012 (Cth).

Medicalnote.AI is committed to providing quality services to you, and this policy outlines our ongoing obligations to you in respect of how we manage your Personal Information. We acknowledge the sensitivity of personal and health information provided to us and to this end, we are committed to protecting the privacy of this personal and health information in accordance with the law.

We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The APPs govern the way in which we collect, use, disclose, store, secure, and dispose of your Personal Information.

A copy of the Australian Privacy Principles may be obtained from the website of The Office of the Australian Information Commissioner at https://www.oaic.gov.au/.

Collection and Consent

Collection refers to the gathering, acquiring, or obtaining of personal information for inclusion in a record or generally available publication. In practice, Medicalnote.AI collects health information about a patient if Medicalnote.AI receives health information from the patient, or from another source, and the information is retained.

Examples of collection include:

  • Recording what a patient says, or recording your opinion about what a patient has said
  • Requiring a patient to complete a form requesting details such as name, address, date of birth, and medical history

Consent can be either express or implied. Express consent is given explicitly, either orally or in writing by an affirmative, unambiguous act. Implied consent arises where you can infer from the circumstances and the conduct of the patient that consent is being given to the handling of the health information.

When obtaining the consent of patients to enable your use of Medicalnote.AI’s Services, you must ensure that the patient:

  • Is adequately informed before giving consent
  • Gives their consent voluntarily
  • Has the capacity to understand and communicate their consent
  • Has given consent that is current
  • Has given specific consent

You may choose to provide a privacy notice to your patients, which may include:

  • Prominently displaying a brief notice at the check-in counter covering key information and giving the individual more detailed notice in a leaflet
  • Including a privacy notice on a paper or online form used to collect patients’ health information
  • Discussing the information orally during a consultation with a patient. To ensure all relevant matters are covered, it would be useful to also provide the patient with a written notice in this situation
  • Obtaining verbal consent from the patient by stating words to the effect of: ‘I/We will be recording this consultation today, to assist me in transcribing my patient notes. Please advise us if you do not wish to be recorded.’

What is Personal Information and why do we collect it?

All Personal Information collected in the course of providing a health service is considered health information under the Privacy Act. Health information is sensitive information under the Privacy Act, meaning that stricter requirements apply when handling it.

Health Information means:

  • Information or an opinion about:
    • The health, including an illness, disability, or injury (at any time) of an individual
    • An individual’s expressed wishes about the future provision of health services to him or her
    • A health service provided, or to be provided, to an individual
  • Other personal information collected to provide, or in providing, a health service to an individual. This includes personal details such as a patient’s name, address, admission and discharge dates, billing information, and Medicare number
  • Information about an individual’s physical or mental health
  • Notes of an individual’s symptoms or diagnosis and the treatment given
  • An individual’s healthcare identifier when it is collected to provide a health service
  • Any other personal information (such as information about an individual’s date of birth, gender, race, sexuality, or religion), collected for the purpose of providing a health service

This Health Information is obtained in many ways including interviews, correspondence, by telephone and facsimile, by email, via our website https://www.medicalnote.ai , from media and publications, from other publicly available sources, from cookies, and from third parties. We don’t guarantee website links or policies of authorized third parties.

We collect your Personal Information for the primary purpose of providing our services to you, providing information to our clients, and marketing. We may also use your Personal Information for secondary purposes closely related to the primary purpose, in circumstances where you would reasonably expect such use or disclosure.

You may unsubscribe from our mailing/marketing lists at any time by contacting us in writing.

When we collect Personal Information, we will, where appropriate and where possible, explain to you why we are collecting the information and how we plan to use it. Generally, we will seek consent from you in writing before we collect your sensitive information (including health information).

Sensitive Information

Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record, or health information.

Sensitive information will be used by us only:

  • For the primary purpose for which it was obtained
  • For a secondary purpose that is directly related to the primary purpose and is reasonably expected by you
  • With your consent; or where required or authorized by law.

Collection and Consent

Medicalnote.AI will use or disclose personal (including sensitive) or health information when:

  • The secondary purpose relates to the primary purpose of collection (or directly relates to the primary purpose in the case of sensitive or health information) and an individual would reasonably expect Medicalnote.AI to use or disclose it in this way,
  • The individual to whom the information is about has given consent for the use or disclosure, or
  • Medicalnote.AI is required, authorized, or permitted by or under law to use or disclose the information.

Third Parties

Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.

As part of the Services offered by Medicalnote.AI, the Website will use third party technology, including but not limited to Voice to Text API and Large Language Model LLM API to generate the transcribed consultation into your final medical notes. Medicalnote.AI does not warrant or represent that the transcription or medical notes generated will be accurate or correct. As the User and Practitioner, it is your sole responsibility to carefully read, review, audit, change and/or amend the Medical Notes to ensure that they are correct and accurate. Medicalnote.AI does not warrant the correctness of any transcriptions or medical notes generated, nor does it accept any liability for the transcription or medical notes being inaccurate or incorrect. A User and Practitioner must always use and rely upon your own medical training and research from trusted medical resources.

By default, audio files are only stored for as long as necessary, to allow you time to process your transcriptions and medical notes. These audio files are encrypted both when at rest and in transit. Once these audio files have been fully transcribed and proofed for any errors within the transcription by you, these audio files are then deleted.

Medicalnote.AI has opted out of data sharing with Assembly AI, therefore your data will not be shared with Assembly AI during the recording of your consultation or any transcriptions derived from the audio files.

Medicalnote.AI has done all things reasonably necessary and within its reach to ensure that Open AI does not train on any content provided through use of the Website or our Services to their consumers.

We encourage you to familiarize yourself with the respective Terms and Conditions and Privacy Policies of all the third parties that we affiliate with.

Please click here for Assembly AI’s Privacy Policy and Terms and Conditions.

Please click here for Open AI’s Privacy Policy.

Disclosure of Personal Information

Your Personal Information may be disclosed in a number of circumstances including the following:

  • Third parties where you consent to the use or disclosure; and
  • Where required or authorized by law.

Medicalnote.AI will not sell your data to third parties. In offering our Services, we will utilize third-party individuals, websites, and organizations to help us improve and deliver our Services.

We will share your personal information with third parties, including our web host provider, payment processor, and the AI providers that we utilize to facilitate the delivery of our Services.

We will take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy. We will not transfer your Personal Information unless there are adequate controls in place.

This Policy applies solely to information collected by us. Even if a third party is affiliated with us through a business partnership or otherwise, we are not responsible for the privacy practices of such third parties, including the AI websites that we will utilize to deliver our services. It is recommended that you read the privacy policies of the affiliated websites to determine how the information collected by them is used and stored.

Medicalnote.AI will use Voice to Text API and LLM API, and any other API’s that we deem as suitable and necessary, to facilitate the delivery of our Services. These third parties have access to your Personal Information but only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Storage and Security of Personal Information

Your Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorized access, modification, or disclosure.

You are responsible for helping to protect the security of your Personal Information by ensuring that you do not give out your password, safeguarding your log-in details and ensuring that other people are unable to access use of our Services from your account, without your knowledge or consent. You are responsible for maintaining the security of any personal computing device from which you utilize our Services.

When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify your Personal Information.

Medicalnote.AI will not store your Personal Information long-term, in any capacity or format, including, but not limited to:

  • Databases;
  • Hard copy files;
  • Personal devices, including laptop computers; and
  • Paper-based files.

We only store the personal information that you have provided to us during registration and account activation. This information includes your name, email, mobile number, and AHPRA registration number. This information is kept securely in our database for customer record management. You can update and amend this information on your own, except your phone number and email address. Should you wish for your phone number and email address, you must contact us to amend these details for you.

The purpose of storing your phone number and email address is to prevent duplicate registrations using one email address and phone number.

Any other usage information linked to your account is for monitoring service usage, such as your number of logins per day, hours of audio recording, and counts of using specific website features such as care plans. This usage data excludes patient personally identifiable information (PII).

When a patient consultation is recorded, the recording is securely transmitted to our server through encryption in transit via SSL certificate.

The recording is then temporarily stored on our server (encryption at rest) and passed to the Assembly AI voice-to-text API (encryption in transit and at rest) to generate the transcription.

The recording is then permanently deleted from Assembly AI as soon as the transcription is completed or if the transcription job errors. We have ensured opting out and confirmed with Assembly AI that any data provided for the transcription process will not be used for training their models.

The audio transcription is then temporarily stored (encryption at rest) on our secure servers to generate the medical note and other services provided by us.

The transcription is sent to OpenAI (encryption in transit and at rest) via their API to generate the medical note and other services based on your selections as the User. As stated in OpenAI’s policy, the data submitted through their API is not used for training their models. We have completely opted out from OpenAI using our provided data to train their models.

Our Website allows you to open multiple consultation tabs (within the browser tab) to move between consultations while waiting for transcripts and notes to be generated. The temporarily stored (and encrypted at rest) audio recordings and transcripts are automatically replaced on our server when a tab is reused.

We warrant that there are security mechanisms in place to ensure that no unauthorized access can occur to these temporary files.

When a user logs out of their account, all consultation-associated data including audio files and transcripts will be permanently deleted. Please note that simply closing the browser may not end a user’s session – data is only deleted when a User logs out of your account.

In the event of any system issue resulting in remaining consultation data being stored (transcripts and audio files), this data will be deleted once every 24 hours.

Our public website may contain links to other third-party websites outside of Medicalnote.AI. Medicalnote.AI is not responsible for the information stored, accessed, used, or disclosed on such websites and we cannot comment on their privacy policies.

Usage and Analytics Information

By accessing our Services and using our Website, you acknowledge and consent to us collecting information through the use of commonly-used information-gathering tools, such as cookies, log files, and Web beacons. This is collectively known as ‘Usage and Analytics Information’.

Medicalnote.AI will utilize standard browser cookies to allow our Website to remember details of your user session, such as resuming a session without the need to re-enter your log-in details. We note that you may choose to refuse or ‘block’ cookies when using our Website; however, if you do not accept or consent to cookies being used, you may not be able to access all of our Services.

Medicalnote.AI will collect information that will be used to analyze your browsing trends, including the number of log-ins during a business day, the date/time stamps associated with your usage of our Website, your Internet Protocol (IP) address, your browser type, your usage of our Services

This information is collected to allow for us to improve our delivery of our Services to you and to provide said Services.

Access to your Personal Information

You may access the Personal Information we hold about you and to update and/or correct it, subject to certain exceptions. If you wish to access your Personal Information, please contact us in writing.

Medicalnote.AI will not charge any fee for your access request but may charge an administrative fee for providing a copy of your Personal Information.

In order to protect your Personal Information, we may require identification from you before releasing the requested information.

Maintaining the Quality of your Personal Information

It is important to us that your Personal Information is up to date. We will take reasonable steps to make sure that your Personal Information is accurate, complete, and up to date. If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.

Responding to Data Breaches

Medicalnote.AI will take appropriate, prompt action if we have reasonable grounds to believe that a data breach may have or is suspected to have occurred. Depending on the type of data breach, this may include a review of our internal security procedures, taking remedial internal action, notifying affected parties, and the Office of the Australian Information Commissioner (OAIC).

If we are unable to notify individuals, we will publish a statement on our website and take reasonable steps to publicize the contents of this statement.

Policy Updates

This Policy may change from time to time and is available on our website.

Privacy Policy Complaints and Enquiries

An individual can make a complaint about how Medicalnote.AI manages personal information, including a breach of the APPs or the My Health Records Act 2012 (Cth) by notifying us in writing as soon as possible. We will respond to the complaint within a reasonable time (usually no longer than 30 days), and we may seek further information in order to provide a full and complete response.

Medicalnote.AI does not charge a fee for handling complaints.

If an individual is still not satisfied after all avenues of resolution have been exhausted, the complaint may be referred to the Office of the Australian Information Commissioner (OAIC). A complaint can be made using the OAIC online Privacy Complaint form or by email.

How to Contact Us

Medicalnote.AI can be contacted about this Privacy Policy or about personal information generally by: