Privacy Policy
Hearing First Audiology
Last reviewed: 20 July 2026
1. Our commitment to your privacy
Hearing First Audiology respects your privacy and is committed to protecting the confidentiality, security and integrity of your personal and health information.
We handle personal information in accordance with applicable Australian and New South Wales privacy laws, including:
the Privacy Act 1988 (Cth);
the Australian Privacy Principles (APPs);
the Health Records and Information Privacy Act 2002 (NSW);
the NSW Health Privacy Principles;
the Notifiable Data Breaches Scheme;
applicable requirements of the Australian Government Hearing Services Program (HSP);
applicable requirements of the Department of Veterans’ Affairs (DVA); and
applicable NSW workers compensation and State Insurance Regulatory Authority (SIRA) requirements.
This policy explains how we collect, hold, use, disclose and protect your information, and how you may access or correct it or make a privacy complaint.
2. Who we are
Hearing First Audiology is an independent audiology clinic providing hearing assessments, hearing aid services, tinnitus care, rehabilitation and other hearing-related services.
For the purposes of applicable privacy legislation, Hearing First Audiology is responsible for the personal and health information held by the clinic, except where records are owned or controlled by another organisation under legislation, a government program or a contractual arrangement.
Clinic: Hearing First Audiology
Privacy contact: Dr Jack Zhang
Address: PO Box2365, Burwood North NSW 2134
Telephone: 1300885583
Email: info@hearingfirstaudiology.com.au
3. Information we may collect
Depending on the services you receive, we may collect:
Personal and contact information
your name, title, date of birth and gender;
home, postal and email addresses;
telephone numbers;
preferred language and communication method;
emergency contact, representative, carer or next-of-kin details; and
details required to verify your identity.
Health and clinical information
your medical, hearing and ear-health history;
hearing difficulties, tinnitus symptoms and communication needs;
hearing assessment results and audiograms;
otoscopy and tympanometry findings;
clinical observations, diagnoses and recommendations;
hearing aid prescriptions, settings, serial numbers and usage information;
ear impressions, rehabilitation goals and outcome measures;
correspondence, reports, referrals and appointment notes;
information provided by your GP, ENT specialist, other healthcare providers, family members or carers; and
any other information reasonably required to assess or manage your hearing needs.
Government, funding and claiming information
Where relevant, we may collect:
Medicare and Individual Healthcare Identifier details;
pensioner concession or other eligibility information;
Hearing Services Program voucher and client details;
DVA file, card, eligibility or entitlement information;
workers compensation claim numbers;
employer, insurer, claims manager, solicitor or rehabilitation-provider details;
referral, approval and service-authorisation information;
private health insurance information; and
billing, payment, rebate and transaction details.
We will not generally record full credit or debit card details in your clinical file.
Website and communication information
When you use our website or communicate with us, we may collect:
information submitted through enquiry or appointment forms;
your email address and telephone number;
your IP address, browser type, device information and general location;
pages visited, referring website and website usage information;
cookie and analytics information; and
copies of emails, SMS messages, telephone messages and other correspondence.
Please avoid including detailed or urgent health information in an unencrypted website form or ordinary email.
4. How we collect information
We generally collect information directly from you when you:
make an enquiry or appointment;
complete a registration, consent or clinical history form;
attend an assessment or consultation;
communicate with us by telephone, SMS, email or through our website;
purchase, trial or receive a hearing device or related service; or
make a payment or submit a funding claim.
With your consent, authority or where permitted or required by law, we may also collect information from:
a parent, guardian, authorised representative, family member or carer;
your GP, ENT specialist, audiologist or another healthcare provider;
a hospital, medical practice, aged-care facility or rehabilitation provider;
the Hearing Services Program or Department of Health, Disability and Ageing;
DVA;
Medicare or Services Australia;
an employer, insurer, claims manager, investigator, solicitor or SIRA;
a private health insurer;
a hearing-device manufacturer, supplier or repair laboratory; or
another hearing service provider transferring your records.
If information is collected from another person or organisation, we will take reasonable steps to ensure you are aware of the collection where required.
5. Why we collect, use and disclose information
We collect, use and disclose information when reasonably necessary to:
identify you and maintain an accurate clinical record;
assess, diagnose and manage your hearing and communication needs;
provide hearing tests, hearing devices, tinnitus services and rehabilitation;
program, verify, adjust, maintain or repair hearing devices;
coordinate your care with other healthcare professionals;
obtain medical advice or make an appropriate referral;
arrange appointments and send confirmations, reminders and service recalls;
respond to your questions, requests or complaints;
obtain funding approval and submit lawful claims;
verify your HSP, DVA, Medicare, workers compensation or insurance eligibility;
prepare clinical reports, quotations, invoices and supporting documentation;
meet professional, clinical, safety, accreditation, audit and legal obligations;
improve the quality and administration of our services;
train and supervise personnel subject to confidentiality requirements;
protect patients, staff and the public from a serious threat to health or safety;
detect or respond to suspected fraud, unlawful activity or data breaches; and
establish, exercise or defend a legal or equitable claim.
If we cannot collect necessary information, we may be unable to provide a safe or appropriate service, determine your eligibility, claim funding or communicate effectively with you.
6. Consent and your choices
Because health information is sensitive information, we generally collect it with your consent unless an exception under the law applies.
You may withdraw or change your consent by contacting us. Withdrawal will not affect information already used or disclosed with valid consent. It may, however, limit our ability to continue providing services or making claims on your behalf.
You may ask to have a family member, carer, interpreter, advocate or other representative involved in your care. We may request written authority and identity verification before disclosing information to that person.
Where you have limited decision-making capacity, we may communicate with a legally authorised representative or “responsible person” as permitted by law.
7. Disclosure of your information
We may disclose relevant information to:
healthcare professionals involved in your care;
your authorised representative, carer or family member;
hospitals, medical practices, aged-care facilities or rehabilitation providers;
government departments and agencies administering health or funding programs;
insurers, claims managers, employers, solicitors and authorised workers compensation parties;
hearing aid manufacturers, suppliers, repair laboratories and software providers;
private health insurers, Medicare and payment-service providers;
professional advisers, auditors and accreditation bodies;
secure information technology, practice-management, communications, document-storage and backup providers; and
law-enforcement, regulatory or other authorities where authorised or required by law.
We limit disclosure to information reasonably necessary for the relevant purpose. Our contractors and service providers are expected to protect information and use it only for authorised purposes.
We do not sell patient information.
8. Hearing Services Program clients
If you receive services under the Australian Government Hearing Services Program, we may collect, use and disclose information to:
confirm your identity and program eligibility;
access or administer your voucher;
obtain and document informed consent;
provide and document program services;
order, fit, maintain, replace or repair devices;
submit claims and substantiate payments;
transfer records to another contracted provider at your request;
participate in program monitoring, compliance activities and audits; and
meet our obligations under the program legislation, instruments, standards and Service Provider Contract.
Relevant information may be disclosed to the Australian Government department administering the program, Services Australia, another contracted provider, an approved device supplier or other authorised party.
Certain HSP client records are owned by the Commonwealth and must be managed, retained, transferred and disposed of in accordance with HSP requirements. HSP claim forms, receipts and supporting records are generally retained for at least seven years or for any longer period required by law or the program. The HSP’s official guidance confirms the Commonwealth ownership and special management requirements applying to program client records. See the HSP Management of Client Records factsheet.
9. DVA clients
If you receive DVA-funded services, we may collect, use and disclose relevant information to:
confirm your DVA card, eligibility and accepted conditions;
obtain referrals, approvals or prior financial authorisation where required;
provide and coordinate hearing services;
prescribe or arrange approved devices and rehabilitation aids;
submit accounts and supporting documentation;
respond to DVA compliance, audit or clinical-review requests; and
meet DVA provider and record-keeping requirements.
Relevant information may be disclosed to DVA, the Hearing Services Program, Services Australia, your referring practitioner, authorised suppliers or other parties involved in administering your care or entitlement.
We will only use DVA information for an authorised purpose and will record required consent and disclosures in your patient record. DVA explains that personal information it receives is protected under the Privacy Act 1988. Read DVA’s privacy information.
10. WorkCover and workers compensation services
Where our services relate to a workplace hearing loss or workers compensation matter, relevant information may be collected from or disclosed to:
you and your authorised representative;
your employer or former employer;
the workers compensation insurer or claims manager;
SIRA or another authorised regulator;
your nominated treating doctor and other healthcare providers;
a rehabilitation provider;
an investigator, legal representative, tribunal or court; and
another person authorised under workers compensation legislation.
Information disclosed may include your occupational and noise-exposure history, assessment results, diagnosis, treatment recommendations, hearing device quotation, clinical progress, work capacity information, invoices and reports relevant to the claim.
We will seek your consent or rely on another lawful authority before disclosing health information. Participation in a workers compensation claim may require relevant information to be provided to authorised parties. We will not ordinarily provide unrelated clinical information to an employer.
SIRA requires workers to be provided with access to their personal and health information in accordance with privacy and workers compensation law. See SIRA’s worker information-access standard.
11. Direct marketing and service communications
We may contact you about appointments, device maintenance, annual reviews, clinical follow-up and other matters connected with your care. These are service communications rather than marketing.
With your consent, or where otherwise permitted by law, we may also send information about clinic services, hearing-health education or clinic updates. You may opt out of marketing communications at any time by:
selecting the unsubscribe option where available;
replying “STOP” to an SMS; or
contacting the clinic.
Opting out of marketing will not prevent us from sending necessary appointment, clinical, safety, billing or funding-program communications.
We will comply with the Privacy Act, the Spam Act 2003 and applicable telemarketing requirements.
12. Website, cookies and external links
Our website may use cookies and similar technologies to support website operation, understand general visitor activity and improve its content. You can configure your browser to reject or delete cookies, although some website functions may be affected.
Our website may contain links to external websites. Hearing First Audiology is not responsible for the privacy practices or content of those websites. You should review their privacy policies before providing personal information.
Information submitted through the internet cannot be guaranteed to be completely secure. If you have sensitive information to discuss, please telephone the clinic or speak with us in person.
13. Data storage and overseas service providers
Information may be stored in secure paper files and electronic systems, including clinical software, encrypted computers, secure cloud platforms, backup services and communications systems.
Some technology, cloud, device-manufacturer or support providers may store or process limited information outside Australia. The countries involved can vary according to the provider and system used. Where overseas handling or disclosure occurs, we take reasonable steps required by the APPs to ensure appropriate privacy protection, unless an applicable legal exception applies.
You may contact us for current information about the overseas locations used by our material service providers.
14. Information security
We take reasonable administrative, physical and technical measures to protect information from loss, misuse, interference, unauthorised access, modification or disclosure. These measures may include:
password and access controls;
multi-factor authentication where available;
encryption and secure backup systems;
antivirus and security updates;
secure premises and document storage;
confidentiality obligations;
limiting access according to role and clinical need;
secure record transfer and disposal procedures; and
procedures for identifying and responding to privacy incidents.
No storage or communication system can be guaranteed to be completely secure. If an eligible data breach is likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches Scheme. The OAIC provides a specific data breach action plan for health service providers.
15. Record retention and disposal
We retain health records for the period required by law, professional standards, funding arrangements and contractual obligations.
For health information collected in New South Wales, records are generally retained:
for an adult, for at least seven years from the last occasion on which a health service was provided; and
for a person who was under 18 when the information was collected, until that person reaches 25 years of age.
A longer period may apply to HSP, DVA, workers compensation, financial, legal, audit or other records.
When information is no longer required to be retained, we take reasonable steps to securely destroy it or permanently de-identify it, subject to any government ownership, record-transfer or disposal requirements. These NSW retention periods are set out in the Health Records and Information Privacy Act 2002.
16. Accessing your information
You may request access to personal or health information we hold about you. Depending on your request, access may be provided by:
allowing you to inspect the record;
giving you a copy;
providing an accurate summary;
explaining clinical information; or
transferring information to another healthcare provider with your authority.
We may ask you to make the request in writing and provide proof of identity. A reasonable administrative fee may apply where permitted by law, but we will not charge you merely for making a request.
Access may be refused or limited where permitted or required by law—for example, where access could create a serious threat to someone’s health or safety, unreasonably affect another person’s privacy, prejudice legal proceedings, reveal commercially sensitive decision-making, or where another lawful ground applies. If access is refused, we will generally provide written reasons and available complaint options.
Special processes may apply to Commonwealth-owned HSP records, DVA documents or workers compensation records.
17. Correcting your information
Please tell us if you believe information held by us is inaccurate, incomplete, out of date, irrelevant or misleading.
We will take reasonable steps to correct the information where appropriate. If we do not agree to a requested correction, you may ask us to associate a statement with the record explaining your position. We may also notify relevant third parties of a correction where required and reasonably practicable.
18. Anonymous and pseudonymous contact
You may make a general enquiry anonymously or using a pseudonym where practicable. However, we usually need your correct identity and other information to provide clinical care, maintain an accurate health record, verify funding eligibility, process a claim or meet legal obligations.
19. Privacy complaints
If you have a question or concern about how we have handled your information, please contact our Privacy Officer:
Privacy Officer: Dr Jack Zhang
Hearing First Audiology
Address: [Insert postal address]
Email: [Insert privacy or clinic email]
Telephone: [Insert telephone number]
Please describe your concern and include your preferred contact details. We will acknowledge and investigate your complaint and aim to provide a written response within 30 days.
If you are not satisfied with our response, or we have not responded within a reasonable period, you may contact:
Office of the Australian Information Commissioner
Telephone: 1300 363 992
Website: www.oaic.gov.au
For concerns about health information handled in New South Wales, you may also contact:
Information and Privacy Commission NSW
Telephone: 1800 472 679
Website: www.ipc.nsw.gov.au
Depending on the matter, you may also contact the Hearing Services Program, DVA, SIRA or the relevant insurer or government agency.
20. Changes to this policy
We may update this policy when our services, systems or legal obligations change. The current version will be published on our website with its effective date. Material changes may also be communicated through other appropriate channels.