1. INTRODUCTION AND CORPORATE SCOPE
Connected Medical Solutions Limited (ACN 610 209 884), including its subsidiaries and businesses, and telehealth brands, provide a range of telemedicine and digital health solutions designed to partner with hospitals, primary health networks and healthcare services in the Australian healthcare system. These clinical services are delivered under several operating and brand names, including My Emergency Doctor (ABN 54 610 209 884); GP2U (ACN 151 445 715) and PSYCH2U (ABN 58 151 445 715), (collectively referred to in this Privacy Policy as “Connected Medical Solutions”, “We”, “Us” or “Our”).
The clinical and administrative services offered by Connected Medical Solutions are provided by a multidisciplinary team of highly qualified health professionals including specialist medical practitioners (such as emergency medicine specialists and psychiatrists), general practitioners and allied health practitioners (such as psychologists), all of whom are supported by our Patient Support Team. We are an Australian owned organisation based in Sydney.
We own, control and operate several digital platforms, including the websites www.myemergencydr.com psych2U.com.au and GP2U.com.au (collectively the “Websites”). We also maintain a presence on social media including Facebook, Instagram, Twitter and LinkedIn (collectively “Social Media”). This Privacy Policy is readily accessible to the public though each of our Websites. Additionally, you may also ask for a copy to be emailed to you at any time by contacting our team at info@myemergencydr.com.au
This Privacy Policy governs the collection, retention, use, storage, and disclosure of personal information (including highly confidential and sensitive health and medical information) by Connected Medical Solutions. We are committed to dealing with personal information responsibly and ethically whilst complying with our statutory obligations under the Privacy Act 1988 (Cth) (“Privacy Act”) and the associated Australian Privacy Principles (“APPs”).
By accessing any of our clinical or administrative services (“Services”), visiting or interacting with our Websites or engaging with our Social Media platforms, you agree to be bound by the terms of this Privacy Policy. If you do not agree to the terms of this Privacy Policy, you must immediately cease using our Services and accessing our Websites and Social Media.
The primary purpose of this Privacy Policy is to clearly and transparently inform you of:
- The specific kinds of personal information that we collect and hold includes your confidential/sensitive health and medical information;
- The precise methods and channels through which we collect and hold your personal information;
- The primary and secondary purposes for which we collect, hold, use and disclose your personal information;
- The technical, physical and administrative security measures we employ to hold and protect your personal information;
- The procedures by which you may request access to your personal information and seek the correction of any such information that is inaccurate, incomplete or out of date;
- The process by which you may lodge a formal complaint regarding a potential breach of the APPs or this Privacy Policy and how we investigate and resolve such a complaint; and
- Whether we are likely to disclose your personal information to overseas recipients and, if so, the countries in which such recipients are likely to be located.
2. TYPES OF PERSONAL AND SENSITIVE INFORMATION COLLECTED
General Personal and Administrative Data
Connected Medical Solutions only collects personal information that is reasonably necessary directly relevant, and proportionate to provide you with our requested Services (including clinical medical care, advice, psychiatric assessments, psychological therapy and general medical and allied health treatment) and to effectively manage our medical practice.
The general and administrative data we collect and hold may include:
- Your full name, residential and billing address, date of birth, gender, email and telephone contact details;
- Full names, contact details and relationship details of your parent, carer or guardian, next of kin or emergency contact person, where necessary, appropriate or legally required (such as in the case of minors or individuals lacking legal capacity);
- Medicare card number, DVA number and other government-issued identifiers;
- Your private health insurance provider details, policy numbers and level of cover, where applicable;
- Sensitive health information about you, including notes of your symptoms or diagnosis and the treatment given to you; previous appointments; your specialist reports and test results; medical history (including that of family members if a condition might be hereditary); current medications and allergies;
- Records of your enquiries, survey responses, feedback submissions, service requests, information requests or formal complaints;
- The referral source or referring healthcare practitioner relating to your consultation;
- Financial and billing details, including credit card numbers, bank account details, and transaction histories associated with your uses of the Services; and
- Details of your interactions with our Websites and Social Media, including technical metadata, IP addresses, and records of any digital communications you have with Us.
Where you apply to become a member of Our team (whether as an employee, independent contractor, or clinical partner), we will collect relevant professional and employment data, including your professional qualifications, employment history, clinical registrations, reference checks, national police checks, working with children checks, and other employee-related data necessary to evaluate your application.
For staff members, contractors, and other business contacts with whom we deal in the ordinary course of running our business, we collect and hold personal information directly relevant to the commercial relationship. This includes names, contact details, professional skills, employment history, bank account and credit card details used to transact with us, and comprehensive records of any communications or interactions
Sensitive Health and Clinical Information
As a provider of specialist and general medical telehealth services, Connected Medical Solutions collects and holds a significant volume of sensitive health and clinical information. Under Australian privacy standards, health information is classified as sensitive information and is afforded the highest level of legal protection.
The sensitive health and clinical information we collect, hold, and process includes, but is not limited to:
- Detailed clinical notes recorded by our treating practitioners during consultations, documenting your symptoms, clinical presentation, medical history, physical observations, and preliminary or final diagnoses;
- Comprehensive records of the medical care, advice, prescriptions, referrals, and treatments provided to you;
- Records of your previous medical appointments, consultations, and clinical interactions, both within Connected Medical Solutions and with external healthcare providers;
- Specialist reports, diagnostic imaging reports (such as X-rays, CT scans, and ultrasounds), pathology test results, and other clinical investigations;
- Comprehensive medical history, including details of pre-existing chronic conditions, past surgeries, family medical history (particularly where specific conditions may be hereditary or clinically relevant to your current presentation), current medications, and known allergies or adverse drug reactions; and
- Any other health-related information supplied by you, your treating team, or your authorised representatives during the course of your clinical management.
We apply rigorous technical, administrative, and physical safeguards to ensure that all sensitive health and clinical information is protected from unauthorised access, disclosure, or modification.
Audio and Video Consultation Recordings
As a specialised telehealth company, Connected Medical Solutions utilises advanced audio and video technology to facilitate clinical consultations between patients and our medical practitioners. In accordance with our operational procedures, we collect, process, and store complete audio and video recordings of these telehealth consultations.
These audio and video consultation recordings are explicitly classified as sensitive health and clinical information under this Privacy Policy, as they contain real-time clinical discussions, visual assessments, symptoms, and medical advice.
We capture and retain these recordings for the following key purposes:
- Quality Assurance and Clinical Governance: Enabling our clinical leadership team to conduct routine audits, peer reviews, and quality assessments to ensure our medical practitioners maintain the highest standards of clinical safety, communication, and care; and
- Confidential Record Keeping: Maintaining an indisputable, contemporaneous, and comprehensive digital record of the consultation, the clinical advice provided, and the treatment plan established.
All audio and video consultation recordings form an integral part of the patient's official clinical and medical record. Consequently, they are stored, secured, retained, and disclosed in strict accordance with the same rigorous standards applied to all other sensitive health information under this Privacy Policy
3. COLLECTION METHODS AND CONSENT PROTOCOLS
Connected Medical Solutions employs a variety of direct and indirect collection channels to gather personal and sensitive information, ensuring that all data is collected lawfully, fairly, and transparently.
We collect personal information from you in the following ways:
- When you register an account, complete an online intake form, or submit a booking request through our Websites;
- When you communicate with our Patient Support Team or administrative staff via email, telephone, web-based chat, or written correspondence;
- During the course of a telehealth consultation, where you verbally disclose information or display physical symptoms to our treating practitioners via voice and/or video calls; and
- When you submit feedback, complete surveys, or lodge formal enquiries and complaints.
Where it is unreasonable or impracticable to collect information directly from you, or where you have authorised us to do so, we may collect your personal information from third parties. These third-party sources include:
- A person responsible for your care, such as a parent, legal guardian, carer, relative, next of kin, or close friend who contacts us on your behalf or participates in your consultation;
- Other health service providers involved in your care, including your regular general practitioner, referring specialists, private and public hospitals, medical clinics, nursing homes, residential aged care facilities, and emergency service providers (such as ambulance services);
- Independent diagnostic centres, pathology laboratories, and medical imaging facilities that transmit test results and reports directly to us;
- National digital health infrastructure systems, including the My Health Record system, electronic prescription services, and the Pharmaceutical Benefits Scheme (PBS); and
- Government agencies and administrative bodies, including Medicare, the Department of Veterans' Affairs, and relevant health insurers.
Consent and Opt-Out Mechanisms for Consultation Recordings
We are committed to respecting patient autonomy and ensuring transparency regarding the recording of telehealth consultations. Accordingly, we have established strict consent and opt-out protocols:
- Notification and Transparency: Prior to the commencement of any telehealth consultation that may be recorded, you will be clearly notified that the session is subject to audio and/or video recording. This notification may be delivered via pre-consultation digital prompts on our Websites, written disclosures in our service terms, and a verbal announcement by the Patient Support Team or the treating practitioner at the start of the call.
- Express Consent: By proceeding with the consultation after receiving this notification, you provide your express consent to the recording of the session for the clinical, administrative, and quality assurance purposes detailed in this Privacy Policy.
- Right to Opt Out: You maintain the absolute right to object to the recording of your consultation. If you do not wish for your consultation to be recorded, you must clearly communicate this preference to us. You can do this by:
- Informing our Patient Support Team prior to the scheduled consultation;
- Selecting the appropriate "opt-out" or "do not record" preference within our digital booking platforms, where available; or
- Verbally instructing the treating medical practitioner at the immediate commencement of the voice or video consultation.
- Impact of Opting Out: If you request that a consultation not be recorded, we will immediately disable the recording functionality for your session. Your refusal to consent to recording will not automatically compromise, restrict, or prevent your access to necessary medical care. Our practitioners will proceed with the consultation and document your clinical care using standard written electronic medical records.
4. PURPOSES Of COLLECTION, USE AND DISCLOSURE
Primary Healthcare Delivery and Clinical Governance
The primary purpose for which Connected Medical Solutions collects, holds, uses and discloses your personal and sensitive health information is to deliver safe, effective and high-quality clinical healthcare services.
Specifically, we use and disclose your clinical information to:
- Facilitate the provision of real-time telehealth consultations, emergency medical advice, psychiatric evaluations, psychological counselling, and general practitioner services;
- Formulate accurate clinical diagnoses, develop comprehensive treatment plans, issue legal prescriptions, and generate medical referrals to specialists or diagnostic facilities;
- Coordinate your ongoing medical care with other members of your treating team, including your regular general practitioner, local hospitals, and allied health professionals; and
- Manage the administrative and operational aspects of Our Services, including scheduling appointments, processing payments, and managing patient files.
Clinical governance, risk management, and quality assurance are fundamental to our clinical operations. To maintain the highest medical standards:
- Our clinical directors, senior medical officers, and designated quality review panels may access and review your patient records, clinical notes, and audio/video consultation recordings;
- These reviews are conducted strictly for internal clinical governance, peer review, clinical auditing, incident investigation, and the ongoing training and professional development of our medical staff; and
- Any clinical information or recordings used during these quality assurance processes are treated with the strictest confidentiality and are never disclosed outside the clinical governance team without your explicit consent, unless required by law.
Please also see our Service Terms External Link for more information.
Secondary Purposes, Marketing, and Administrative Operations
In addition to primary healthcare delivery, Connected Medical Solutions may use and disclose your personal information (excluding sensitive clinical notes and consultation recordings) for necessary secondary purposes.
These secondary purposes include:
- Practice Administration and Billing: Processing Medicare claims, DVA claims, private health insurance rebates, and direct credit card transactions; managing outstanding accounts; and conducting financial audits;
- Customer Assistance: Responding to your administrative enquiries, managing your account settings, resolving technical issues with our Websites, and providing support regarding your use of our Services;
- Service Development and Research: Analysing aggregated, non-identifiable data to evaluate the efficiency of our clinical models, improve our digital platforms, and develop new telehealth solutions, and surveys for feedback on our Services; and
- Communications and Marketing: To contact you about our Services, business updates, and educational material that we believe may be of interest to you.. This educational content may also include information about our practitioners, telehealth-related instructional materials, video examples demonstrating how our Services operate, and insights derived from telehealth data and clinical studies.
You have the right to opt out of receiving any marketing or promotional communications from Us by sending an email to: info@myemergencydr.com.au with the word “unsubscribe” in the subject line of your email. You can also click the “unsubscribe” link contained at the bottom of any promotional email we send. Please note that even if you opt out of receiving such marketing and promotional material, we will still contact you in future regarding essential administrative, billing, and clinical matters directly relating to your actual use of our Services (such as appointment confirmations, prescription alerts, or clinical follow-ups).
Disclosure to Funding Partners and Third-Party Entities
To facilitate seamless healthcare delivery and comply with our commercial and legal obligations, Connected Medical Solutions may disclose your personal and sensitive health information to third-party entities.
These disclosures are strictly limited to the following circumstances:
- Treating Team and Health Providers: Disclosing clinical information to other health service entities involved in your care, including referring general practitioners, specialists, public and private hospitals, state or territory health departments, area health services, residential aged care facilities, nursing homes, allied health providers, professional interpreters, and emergency service providers (such as ambulance services);
- School-Based Services: If the patient is a student and is utilising our telehealth Services through a formal program established by their school, we may disclose relevant personal and clinical information back to the school's designated health, administrative, or pastoral care staff to ensure the student's ongoing safety and support;
- Funding Partners and Facilities: If you access our Services from a specific healthcare facility (such as a residential aged care facility) or where a third-party partner organisation (such as a primary health network, hospital board, or corporate employer) has contractually agreed to fund the cost of your consultation, we may be required to disclose specific administrative and clinical details about your consultation back to that funding party. This information is limited to what is contractually required for reporting, clinical audit, verification, and invoicing purposes;
- Legal and Regulatory Compliance: Disclosing information where we are permitted, authorised, or legally compelled to do so by law, court orders, or tribunal directives. This includes notifications to statutory authorities, public health authorities for infectious disease tracking, Medicare audits, and disclosures to police or law enforcement agencies where there is an imminent threat to public safety or individual life;
- Legal Action and Debt Recovery: In the event that you initiate legal action against Connected Medical Solutions, or fail to settle outstanding fees for Services rendered, we reserve the right to disclose relevant personal and billing information to our legal representatives, professional insurers, or authorised debt collection agents; and
- De-identified Statistical Data: Providing aggregated, completely de-identified statistical data to academic institutions, research organisations, or government bodies for the purpose of medical research and telehealth system evaluation. This data contains no identifying details and cannot be linked back to any individual patient.
5. SECURITY, STORAGE AND DATA RETENTION
Digital Infrastructure and Encryption
Connected Medical Solutions operates as a digital-first telehealth provider. Consequently, our data storage and security frameworks are heavily reliant on advanced information technology and secure software solutions.
Our digital infrastructure is governed by the following security protocols:
- Software-as-a-Service (SaaS) Security: The majority of our clinical record-keeping, video conferencing, and administrative systems are hosted on secure, enterprise-grade SaaS platforms provided by trusted IT vendors. We conduct rigorous security assessments of all IT partners and SaaS providers to ensure they maintain robust, industry-standard security certifications;
- Data Encryption: All personal and sensitive health information is encrypted both while in transit (transmitted across the internet) and at rest (stored within our databases and cloud servers) using strong, industry-standard cryptographic algorithms;
- Australian-Based Hosting: To ensure compliance with national data sovereignty and privacy standards, all primary patient databases, medical records, and telehealth platforms are hosted on secure, redundant cloud servers physically located within Australia;
- Access Controls and Database Security: We implement strict logical access controls across all databases. Access to patient records is restricted based on role-based permissions, requiring multi-factor authentication and strong passwords. Only authorised clinical and administrative staff who require access to perform their specific duties are granted permission to view sensitive data;
- Physical Security: Any physical records, paper-based intake forms, or printed clinical documents that we hold are stored in secure, locked cabinets and restricted-access rooms within our Sydney headquarters; and
- Data Integrity: To ensure the personal information we hold remains accurate, complete, and up to date, our Patient Support Team may ask you to verbally or digitally confirm your contact details, Medicare number, and clinical history prior to scheduling or commencing any new consultation. We encourage you to proactively notify us of any changes to your personal details.
Retention and Security of Consultation Recordings
Audio and video consultation recordings represent highly sensitive clinical data, requiring specialised security and retention protocols:
- Restricted Storage Environments: All digital video and audio files generated during recorded consultations are stored in highly secure, isolated cloud storage environments separate from general administrative databases. These files are encrypted using advanced encryption standards;
- Strict Access Auditing: Access to consultation recordings is strictly limited to our Clinical Directors, designated Quality Assurance Officers, and the specific treating practitioner who conducted the session. Every instance of access, playback, or download of a consultation recording is automatically logged in an immutable, permanent audit trail;
- Prohibition of Local Storage: Our medical practitioners and administrative staff are strictly prohibited from downloading, saving, or storing consultation recordings onto local hard drives, personal devices, or unauthorised external storage media; and
- Statutory Retention Periods: Connected Medical Solutions retains all clinical records, including audio and video consultation recordings, in strict compliance with state and territory medical record retention laws. Generally, these laws require:
-
- For adult patients, records must be retained for a minimum period of seven (7) years from the date of the last clinical service; and
- For patients who were minors (under the age of 18) at the time of the consultation, records must be retained until the patient reaches twenty-five (25) years of age, or for seven (7) years from the date of the last clinical service, whichever is longer.
Once the statutory retention period has expired, and the records are no longer required for clinical, legal, or administrative purposes, Connected Medical Solutions will securely and permanently delete or de-identify the digital files and recordings.
6. ACCESS, CORRECTION AND DE-IDENTIFICATION RIGHTS
At any time you have a right to seek access to, and to correct, the personal and sensitive health information which we hold about you. This right extends to all written clinical notes, specialist reports, billing histories, and any retained audio or video consultation recordings.
To exercise your rights, you must adhere to the following procedures:
- Submitting a Request: All requests for access or correction must be submitted in writing via email to our practice at: info@myemergencydr.com.au.To protect patient confidentiality, you must provide sufficient proof of identity (such as a copy of your driver's licence or passport) so that we can verify you are the authorised individual or their legally recognised representative.
- Response Timeframe: Upon receipt of a valid written request and satisfactory identity verification, Connected Medical Solutions will process your request and provide a formal response within thirty (30) calendar days.
- Correction of Records: If you demonstrate that the personal or clinical information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, we will take all reasonable steps to correct the information. If we disagree with your assessment and decline to amend the record, we will provide you with a written explanation and, at your request, associate a statement with your record noting your claim that the information is inaccurate.
- Lawful Denial of Access: In certain limited circumstances permitted by law, Connected Medical Solutions may refuse to grant you access to your medical records or consultation recordings. These circumstances include, but are not limited to, situations where:
-
- Providing access would pose a serious and imminent threat to your life, health, or safety, or to the life, health, or safety of any other individual;
- Providing access would unreasonably impact the privacy of other individuals;
- The request for access is frivolous or vexatious; or
- Denying access is required or authorised by law, a court order, or a law enforcement directive. If we deny your request for access, we will provide you with a comprehensive written statement detailing the specific reasons for our refusal and the avenues available to you to dispute our decision.
- Consequences of Information De-identification or Non-Provision: You may request that we delete or permanently de-identify the personal and health information we hold about you. However, you acknowledge that if you refuse to provide necessary personal information, request the deletion of your files, or insist on the de-identification of your records, Connected Medical Solutions may be unable to provide you with the information, medical advice, prescriptions, or Services you request.
7. OVERSEAS DATA DISCLOSURES
Connected Medical Solutions operates primarily within Australia, utilising Australian-based servers and clinical infrastructure. However, to maintain operational efficiency, 24/7 clinical availability, and administrative support, we may disclose certain personal and administrative information to overseas recipients.
These overseas disclosures occur under the following specific parameters:
- Overseas Staff and Practitioners: While all medical practitioners delivering clinical Services through Connected Medical Solutions are fully registered with the relevant Australian clinical boards and practice in accordance with Australian standards, some of our specialist doctors, general practitioners, allied health professionals, and administrative support staff may be physically located in overseas jurisdictions, including the United Kingdom and the Philippines;
- Transcription and Administrative Services: We may utilise secure, professional overseas-based transcription services, data entry partners, or administrative support teams located in the United Kingdom and the Philippines to process clinical dictations, format specialist reports, and manage billing data; and
- Patient-Directed Disclosures: We will disclose your information to overseas recipients where you explicitly direct or authorise us to do so (for example, if you are an international traveller and request that we transmit your clinical notes and treatment records back to your primary healthcare provider or insurer in your home country).
- Connected Medical Solutions takes all reasonable steps to ensure that any overseas recipients of your personal information do not breach the strict privacy standards established under Australian privacy laws. We implement robust contractual agreements, non-disclosure covenants, and secure remote-access protocols to ensure that your data is afforded a level of protection equivalent to that provided within Australia.
8. ANONYMITY AND PSEUDONYMITY LIMITATIONS
Under national privacy standards, individuals generally have the option of not identifying themselves, or of utilising a pseudonym, when interacting with organisations. However, this right is subject to practical and lawful limitations, particularly within a clinical healthcare environment.
Connected Medical Solutions has determined that it is impracticable and clinically unsafe to conduct medical consultations or deliver telehealth Services on an anonymous or pseudonymous basis.
The specific reasons for these limitations include:
- Clinical Safety and Continuity of Care: To provide safe and accurate medical treatment, prescribe medications, and issue diagnostic referrals, our treating practitioners must know your true identity, age, gender, and comprehensive medical history. Failing to verify your identity introduces significant clinical risks, including dangerous drug interactions and incorrect diagnoses;
- Prescription and Referral Regulations: Australian state and federal regulations governing the electronic transmission of prescriptions (including restricted substances) and diagnostic referrals strictly mandate the inclusion of the patient's verified full name, date of birth, and residential address;
- Billing and Funding Compliance: To process Medicare claims, DVA claims, or private health insurance rebates, we are legally required to verify your identity and match it against government records. Furthermore, if your consultation is funded under a contract with one of our partner organisations (such as a hospital, school, or primary health network), we must verify your identity to confirm you are a permitted and eligible user under that specific agreement; and
- Prior Payment Verification: We require valid billing and payment details prior to the commencement of any private consultation, which naturally necessitates the collection of identifying financial information.
Consequently, while you may browse our public Websites anonymously, you cannot access our clinical telehealth Services, speak with our doctors, or receive medical advice without fully identifying yourself and verifying your personal details.
9.PRIVACY RELATED QUESTIONS AND COMPLAINTS
Connected Medical Solutions is committed to resolving any privacy-related concerns, questions, or complaints promptly, fairly, and transparently. If you believe that we have breached our privacy obligations, mishandled your personal or sensitive health information, or failed to comply with the APPs, we encourage you to contact us immediately.
The procedure for raising enquiries and lodging formal complaints is as follows:
- Contact the Privacy Officer
In the first instance, all privacy-related enquiries, access requests, or formal complaints must be directed in writing to our designated Privacy Officer:
My Emergency Doctor
Email: info@myemergencydr.com.au
- Urgent matters
If your privacy concern is highly urgent or involves an active clinical safety issue, please contact our Patient Support Team by telephone through our general contact numbers, and request that the matter be immediately escalated to the Privacy Officer.
- Internal Investigation and Timeframe
Upon receiving a formal written complaint, our Privacy Officer will:
- Acknowledge receipt of your complaint in writing within five (5) business days;
- Conduct a thorough internal investigation into the circumstances surrounding your complaint, which may involve reviewing system access logs, interviewing relevant clinical or administrative staff, and auditing database security; and
- Provide you with a comprehensive written response detailing the findings of the investigation and any remedial actions taken within thirty (30) calendar days of receiving your complaint.
If you are dissatisfied with our response, you may refer the matter to the OAIC (Federal):
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Fax: +61 2 9284 9666
Post: GPO Box 5218
Sydney NSW 2001
Website: https://www.oaic.gov.au/individuals/how-do-i-make-a-privacy-complaint
You may also contact the NSW Health Care Complaints Commission (State):
Phone: 1800 043 159
Email: hccc@hccc.nsw.gov.au
Address: Level 13, 323 Castlereagh Street (corner of Hay St), Sydney NSW 2000
UPDATES TO THIS POLICY
This Policy will be reviewed from time to time to take account of new laws and technology, changes to our operations and other necessary developments. Updates will be published on our website. This Privacy Policy was last reviewed and updated in July 2026. We encourage all patients, staff, and website visitors to routinely review this page to ensure they are familiar with the most current version of our Privacy Policy. If you require a historical version of this policy for reference, please submit a written request to our Privacy Officer.
WHERE TO FIND THIS PRIVACY POLICY
This Privacy Policy will be published on Our Websites. It may also be, referred to on our Social Media, in our communications and marketing material.