Privacy Policy

Last Updated: Thursday, 2 July 2026

This policy explains how we manage your personal and health information in accordance with the Privacy Act 2020, the Health Information Privacy Code 2020, and current New Zealand general practice guidance.

1. Governance and Responsibility

We have appointed a Privacy Officer responsible for ensuring compliance with privacy laws, managing privacy requests, and overseeing breach responses.

2. Staff Responsibilities and Training

All staff are required to sign confidentiality agreements and complete regular privacy training. Access to patient information is limited to what is necessary for their role.

3. What Information We Collect

We collect personal and health information including contact details, medical history, medications, diagnoses, sexual and reproductive health data, mental health information, and investigation results.

4. How We Collect Information

Information is collected directly during face-to-face and telehealth consultations, and indirectly from laboratories, medical practitioners, specialists, pharmacies, and other providers. We take reasonable steps to inform patients about indirect collection.

5. Purpose of Collection

Information is collected to provide safe, effective healthcare, coordinate services, maintain accurate records, and meet legal obligations.

6. Use and Disclosure

Information is only used for the purpose it was collected. It may be shared with other healthcare providers involved in your care (including referrals, and reports to referrers), where required by law, or to prevent serious harm.

7. Telehealth Services

Telehealth consultations may occur via phone or secure video. Patients are encouraged to ensure they are in a private setting. While we use secure systems, absolute confidentiality over the internet cannot be guaranteed. We do not record consultations without your consent.

8. Use of AI Tools

We may use approved artificial intelligence tools, such as AI-assisted note-taking, to support your care. These tools are checked for appropriate privacy and security safeguards before we use them, including where information may be processed or stored overseas. Any AI-generated notes are reviewed by your clinician before being added to your record, and AI is never used to make clinical decisions on your behalf. If you would prefer we do not use these tools during your consultation, let your clinician know.

9. Couriered Medications

Where appropriate, medications may be couriered to your nominated address. We will verify delivery details and take reasonable steps to protect confidentiality. Once dispatched, delivery involves third-party providers outside our control.

10. Storage and Security

We use secure systems and technical, procedural and physical safeguards appropriate to how we deliver care to protect your information. Access is restricted and monitored.

11. Retention

Health records are retained for at least 10 years or longer where clinically required.

12. Patient Rights

Patients have the right to access and request correction of their information. Patients also have the right to make a complaint about how we manage their information. Complaints can be made to our Privacy Officer at privacy@aucklandmensclinic.co.nz, and, if unresolved, to the Office of the Privacy Commissioner (www.privacy.org.nz).

13. Privacy Breaches

We have a documented process for managing privacy breaches. If a breach poses a risk of serious harm, we will notify affected individuals and the Privacy Commissioner.

14. Continuous Improvement and Review

This policy is reviewed at least annually and updated in response to legal or operational changes.