Therapists already take privacy seriously in your clinic.
They don’t leave case notes lying around.
They don’t share sensitive details without consent.
So when it comes to choosing a tech platform to support your therapy services - why should trust practices be any different?
Before a therapist clicks “accept” on the latest shiny app or free trial, read more below about what every allied health professional and clinic owner should know about data privacy, marketing rules, and digital responsibility in Australia.
Because not all tech is built for clinics. And not all platforms protect participants (or therapists) the way they should.
1. Data Privacy: What You’re Responsible For 🔐
In Australia, therapists are required to comply with the Australian Privacy Principles (APPs) - and that includes what happens to your participants’ data when it’s handled by third-party platforms. The APPs are a set of 13 principles that sit at the core of the Privacy Act 1988.
Here’s what the Australian Privacy Principles mean in real terms:
Personal Health Information (PHI) includes anything that can identify a participant - not just names and birthdates, but goals, diagnoses, routines, and care notes.
APP6 says you can’t share or use data for any purpose beyond what it was collected for, unless your participant consents.
APP8 says if your data is stored overseas, you need to ensure that data is still protected to Australian standards (or explicitly get informed consent).
APP11 requires that you take reasonable steps to protect all personal information from misuse or loss - including digital records.
So when using a tech platform in your clinic, the question isn’t “Are they compliant?” It’s: “Can we demonstrate that we are?”
At Theratrak, we adhere to the highest standards of data privacy and the Australian Privacy Principles.
2. Data Storage: Where Does It Actually Go? ☁️
Some apps store health data in countries with different laws and weaker protections. That can be risky - and potentially non-compliant.
At Theratrak, we:
Store all data securely on Microsoft Azure, one of the most trusted cloud providers in the world
Use enterprise-grade encryption
Enable multi-factor authentication (MFA) and PIN protection for extra security
Ensure all data is only visible to consenting participants
Are HIPAA certified for use across America - Health Insurance Portability and Accountability Act (1996) is used as a benchmark for data protection
3. Marketing & AHPRA: What You Can and Can’t Say 📣
It’s not just about data - it’s about communication too.
If a tech platform offers built-in messaging, automation, or marketing features, make sure they:
Don’t encourage testimonials or claims that breach Australian Health Practitioner Regulation Agency (AHPRA) advertising guidelines
Clearly distinguish marketing from service-related communication
Comply with the Spam Act and privacy rules around direct messaging
Theratrak never sends unsolicited marketing, and all participant communication is consent-based, secure, and traceable.
4. Rules, Records & Responsibilities 📁
When you use a tech tool in your practice, you’re still responsible for:
How long data is stored (typically 7+ years - longer for minors)
Who can access what and when
What happens to that data if you stop using the platform
Theratrak makes this easy.
Therapists maintain control, with access to export records, and decide access levels for teams, families, and wider care support networks.
The 5-Point Tech Safety Checklist for Allied Health Clinics ✅
Not sure what to ask a tech company before signing up?
To make it easy for busy allied health professionals, we’ve put together this checklist for when reviewing new allied health digital tools:
1. Where is our participant data stored?
At Theratrak? Uses Microsoft Azure in accordance with local compliance.
2. Is this data encrypted and access-controlled?
At Theratrak? Yes. Enterprise-grade encryption, MFA, and app PIN protection.
3. Is the tool privacy law compliant?
At Theratrak? Yes. Theratrak aligns with Australian Privacy Principles and HIPAA certified in the US.
4. Can we control who sees what?
At Theratrak? Yes. You set visibility and access per user.
5. Do we have a clear exit plan?
At Theratrak? Yes. You can or delete data anytime.
You Don’t Need to Know Everything about Tech - You Just Need to be Able to Answer a Few FAQs 🧠
Choosing a tech platform for your clinic isn’t just about features - allied health technology needs to have high standards around trust, transparency, and responsibility.
Never be afraid to ask your digital allied health tools about their security and privacy features.
At Theratrak, we built our tools with therapists in mind. From security to privacy to clear data policies, we’re here to support how the allied health industry works - and protect who you care for.
Learn more about Theratrak’s privacy policy and application terms.
Wondering how Theratrak can impact your clinic?
Take the Clinic Quiz to see how much time you could save after implementing Theratrak into your clinic.