Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map your health information flows
- 2. Collect less, and explain more clearly
- 3. Make sure your internal access rules are real
- 4. Check your contracts with providers
- 5. Prepare for access requests and corrections
- 6. Keep only what you need, for as long as needed
- 7. Have a privacy incident plan
- Common mistakes businesses make
FAQs
- Does every business that collects health-related details count as a health agency?
- Can we use health information for marketing if the customer gave it to us for service delivery?
- Do we need a separate privacy policy for health information?
- What if our software stores health information overseas?
- Can customers ask to see or correct their health information?
- Key Takeaways
Health information is some of the most sensitive data a business can hold, and many New Zealand businesses collect it without realising how strict the privacy rules can be. A gym storing injury notes, a telehealth startup using intake forms, a beauty clinic keeping medical history, or an employer running workplace health programmes can all end up handling health information. The common mistakes are usually practical ones: collecting more detail than you actually need, using generic privacy wording that does not explain what happens to the data, and sharing information with staff, software providers or contractors without proper controls.
The risk is not just a complaint to the Privacy Commissioner. Mishandling health information can damage trust fast, trigger access or correction disputes, create contract problems with suppliers, and raise wider compliance issues around marketing, record keeping and security. This guide explains what health information privacy means in New Zealand, when it comes up for businesses, the steps to put in place before you launch online or sign up a new provider, and the mistakes that tend to catch founders and managers out.
Overview
New Zealand businesses that collect, store, use or disclose health information need to treat it as highly sensitive personal information. The rules usually sit under the Privacy Act 2020 and, for health agencies, the Health Information Privacy Code 2020, with extra care needed around transparency, purpose, access rights, security and disclosure.
The right setup is usually a mix of privacy processes, clear customer-facing notices, well-drafted contracts and practical limits on who can see what.
- Work out whether your business is acting as a health agency for the information you collect.
- Identify exactly what health information you collect, why you need it, and whether you can collect less.
- Explain your collection and use clearly in your privacy notice, collection notice, forms, and customer communications.
- Limit access internally, and make sure software providers and contractors handle the data safely.
- Set up a process for access requests, correction requests, retention, deletion and privacy incidents.
- Check whether overseas storage, online booking tools, AI tools or marketing platforms create extra risks.
What Health Information Privacy Means For New Zealand Businesses
Health information privacy means you need a lawful, transparent and genuinely necessary reason for collecting and using health-related details, and you need stronger controls than you might use for ordinary contact information.
In New Zealand, privacy obligations generally come from the Privacy Act 2020. If your business is a health agency for the relevant activity, the Health Information Privacy Code 2020 applies. The Code sets specific rules for health information and sits alongside the wider privacy framework.
What counts as health information?
Health information is broader than a formal medical record. It can include information about a person’s physical or mental health, disability, injury, treatment, test results, appointment history, medication, health-related goals, ACC-related details, or notes about symptoms and wellbeing.
For businesses, this often shows up in places founders do not expect, such as:
- client intake forms for wellness services
- screening questionnaires before classes or treatments
- telehealth or digital health app profiles
- occupational health information collected for workplace programmes
- diet, allergy or injury records held by coaches or trainers
- cancellation or support notes that reveal medical circumstances
If the information can say something meaningful about a person’s health status, it is safer to treat it as health information.
Who is a health agency?
A business does not need to be a hospital or GP practice to be treated as a health agency for privacy purposes. The definition can capture organisations and individuals that provide health or disability services, or that hold health information in connection with those services.
This can include clinics, therapists, allied health providers, digital health platforms, aged care providers, some workplace health service providers, and businesses offering treatment, assessment or health monitoring. In mixed businesses, only part of the operation may be caught. For example, a fitness business may not be a health provider in every respect, but it may still handle health information in a way that requires close privacy compliance.
This is where founders often get caught. They assume they are just collecting customer preferences when they are actually collecting sensitive health details.
What are the main legal duties?
The key duties are straightforward in principle: only collect what you need, be open about what you are doing, keep the information secure, let people access and correct their information, and do not use or disclose it for unrelated purposes without a proper basis.
In practice, that usually means thinking carefully about:
- purpose, why you need the information at all
- necessity, whether each field on a form is really required
- collection, who gathers the information and how it is explained
- storage, where the data sits and who can access it
- use, whether staff use it only for the reason it was collected
- disclosure, whether it is shared with third parties and on what terms
- retention, how long you keep it and when you securely delete it
- rights, how people ask for access or correction
The law does not expect every small business to build a perfect enterprise-grade system. It does expect you to take privacy seriously, especially when the information is sensitive and the consequences of misuse are high.
Why this matters commercially
Health information privacy is not only a legal issue. It affects trust, onboarding, software procurement, customer complaints, investor diligence and brand reputation. If you are pitching to enterprise clients, DHB-related organisations, schools, insurers or corporate wellness partners, they will often ask what privacy safeguards you have in place before they sign.
It also intersects with contracts. Your customer terms, supplier agreements, employment contracts and contractor arrangements should all line up with the way health information is actually handled. If they do not, your business can end up making promises it cannot meet, or leaving gaps around confidentiality, security, reporting and liability.
When This Issue Comes Up
Health information privacy usually becomes a real business issue the moment you ask a customer, patient, participant or worker for health details, not only when a complaint arrives.
For many founders, the issue appears during setup. You are choosing a business structure, registering a company with the Companies Office, developing your service model, selecting booking software and drafting customer-facing documents. Privacy should be built in at that stage, before you spend money on setup that later needs to be redone.
Launching a health, wellness or care service
If you are trying to start a health business in New Zealand, privacy needs to sit alongside your other early legal requirements. That includes your business structure, key contracts, service terms, employment or contractor arrangements, branding and trade mark strategy, and any licence-style or regulatory requirements relevant to your sector.
Examples include:
- physiotherapy, counselling or therapy clinics
- telehealth or health tech platforms
- mental health or coaching services that collect symptom information
- nutrition, pregnancy, sexual health or fertility services
- beauty, cosmetic or skin treatment businesses collecting medical histories
- aged care, disability support or home care services
In these businesses, intake forms, booking systems and follow-up messages often collect sensitive details from day one. If your online forms are too broad, or your privacy policy is copied from a generic retail website, that can create problems immediately.
Selling online or using digital tools
Selling online creates extra privacy pressure because data moves through more systems. A business may collect information through a website form, pass it into a CRM, sync it to a booking platform, store it in cloud files, and discuss it in team messaging tools. Every step creates another place where health information might be exposed or mishandled.
Common trigger points include:
- online intake and consent forms
- chat functions and symptom checkers
- AI note-taking or transcription tools
- wearable integrations and app-based monitoring
- payment systems linked to health services
- marketing tools that segment users based on health-related preferences
If you use offshore providers, you also need to think about cross-border data handling. The issue is not just where the servers are. It is whether the provider’s terms, security standards and data handling arrangements line up with your obligations to customers.
Workplace health programmes and HR crossover
Health information often turns up in employment-related settings. An SME may collect vaccination history, fitness-for-work information, return-to-work notes, injury details, disability accommodation information or wellness programme data. That creates a tricky boundary between general employment records and sensitive health information.
Businesses need to be especially careful here because staff may feel pressure to provide information. The question is not only whether you can collect it, but whether you have clearly explained why it is needed, who can see it, and how long it will be kept. Internal curiosity is not a lawful purpose.
Third-party arrangements before you sign
Privacy risk often sits in supplier contracts. Before you sign with software vendors, outsourced administrators, call centres, IT providers, marketing agencies or document storage services, check how they will handle health information.
This matters when:
- a clinic uses an external booking platform
- a startup outsources customer support
- a wellness business shares customer details with partner practitioners
- an employer uses a third party for health screening or wellbeing apps
- a business stores records in a shared cloud environment
If your contracts are silent on confidentiality, security, deletion, breach reporting or subcontracting, the main risk is that you remain accountable to customers without practical control over the data.
Practical Steps And Common Mistakes
The best way to manage health information privacy is to map the data you collect, reduce it where possible, and match your documents and systems to what really happens in the business.
1. Map your health information flows
Start with the basics. List what information you collect, where it comes from, where it goes, who sees it and when it is deleted. Many privacy problems exist because no one has looked at the full path of the data.
Your map should cover:
- website and app forms
- paper forms and emails
- phone intake and call notes
- booking and CRM systems
- payment platforms
- internal file storage and messaging tools
- external practitioners, contractors and service providers
Once you can see the full flow, it becomes much easier to spot unnecessary collection and risky sharing.
2. Collect less, and explain more clearly
Many businesses ask for more health detail than they need, just in case it might help later. That is a common mistake. If a field is optional, say so. If a detail is needed for safety, treatment or service delivery, explain that plainly at the point of collection.
A good collection notice usually covers:
- what information is being collected
- why it is needed
- what happens if the person does not provide it
- who will receive or access it
- whether it may be stored or processed by third-party providers
- how the person can request access or correction
Generic privacy language is often too broad to be useful. Clear, specific wording is usually better than long legalistic text.
3. Make sure your internal access rules are real
Not every staff member needs access to all health information. Access should depend on role, not convenience. A receptionist may need appointment details but not full treatment notes. A marketing contractor should almost never need sensitive health records.
Practical controls can include:
- role-based system permissions
- confidentiality obligations in employment and contractor documents
- separate storage areas for highly sensitive records
- password and device policies
- staff training on what can and cannot be shared internally
This is one of the easiest areas to improve without major cost.
4. Check your contracts with providers
If another business handles health information on your behalf, your contract should say what they can do with it and what standards they must meet. Handshakes and generic terms are rarely enough.
Relevant contract points often include:
- confidentiality obligations
- security measures and minimum standards
- limits on use and disclosure
- subcontracting restrictions
- data location and overseas processing terms
- incident and breach notification timeframes
- return or deletion of information on exit
- audit, cooperation or information rights where appropriate
Before you sign, ask whether the vendor can support your privacy commitments in practice. If not, your customer-facing promises may be misleading.
5. Prepare for access requests and corrections
People generally have rights to access their personal information and request correction. Health information can lead to more sensitive and time-pressured requests than ordinary customer data. If your team does not know how to respond, delays and confusion can make a small issue much worse.
Create an internal process covering:
- who receives requests
- how identity is checked
- how records are located across systems
- when legal exceptions might apply
- how corrections or statements of correction are handled
- how responses are documented
You do not need a large privacy team. You do need a clear owner and a repeatable process.
6. Keep only what you need, for as long as needed
Holding health information forever is risky. The longer you keep it, the greater the chance of accidental disclosure, outdated records or security incidents. At the same time, some records need to be kept for legal, clinical or operational reasons.
Your retention approach should reflect the type of service, the reason for collection, any applicable professional or sector expectations, and your own contractual commitments. If retention is unclear, get advice before you build the wrong system. This is also a good area to discuss with an accountant or tax adviser if record-keeping overlaps with financial records.
7. Have a privacy incident plan
Health information breaches can happen through lost devices, misdirected emails, poor permissions, phishing, or staff discussing information in the wrong place. A small business still needs a response plan.
Your plan should cover:
- who must be told internally
- how the incident is contained
- what records need to be preserved
- whether affected individuals need to be notified
- whether notification to the Privacy Commissioner may be required
- how the business prevents the same issue happening again
Do not wait until after an incident to decide who is responsible.
Common mistakes businesses make
The same errors show up again and again:
- using a retail-style privacy policy for a health-related service
- asking broad medical questions without explaining why
- sharing notes freely among team members
- letting contractors use personal devices or apps without controls
- assuming software providers carry all the privacy risk
- keeping old files indefinitely
- collecting health information for service delivery, then reusing it for marketing
Another common issue is poor alignment between documents. A signup form says one thing, a privacy policy says another, staff follow a third practice, and the software provider’s terms allow something else again. Consistency matters.
FAQs
Does every business that collects health-related details count as a health agency?
Not always, but many do for the relevant activity. The answer depends on the nature of the service and why the information is held. If your business provides health or disability services, or holds health information in connection with those services, the Health Information Privacy Code may apply.
Can we use health information for marketing if the customer gave it to us for service delivery?
Usually, you should be very cautious. Using sensitive information for a new purpose can create privacy and Fair Trading Act issues, especially if customers would not reasonably expect it. Specific, well-explained consent and careful segmentation are important.
Do we need a separate privacy policy for health information?
Not necessarily a separate document, but your privacy documents and collection notices should deal properly with health information if you collect it. Generic wording for ordinary customer data is often not enough.
What if our software stores health information overseas?
Overseas storage is not automatically prohibited, but it does require careful review. You should understand where the data goes, what protections apply, and whether your contracts and notices reflect that arrangement.
Can customers ask to see or correct their health information?
Yes, in many cases they can request access to their personal information and ask for correction. Your business should have a clear process for receiving, assessing and responding to those requests.
Key Takeaways
- Health information privacy in New Zealand usually falls under the Privacy Act 2020 and, for health agencies, the Health Information Privacy Code 2020.
- Health information includes more than medical files, it can cover intake notes, injury details, symptom records, treatment history and other sensitive service data.
- Privacy issues arise early, especially before you launch online, choose software, onboard staff or sign supplier contracts.
- The safest approach is to collect only what you need, explain your purpose clearly, restrict access, and align your contracts and internal processes with actual data handling.
- Common mistakes include over-collection, generic privacy wording, weak vendor contracts, broad internal access and keeping records too long.
- Businesses handling health information should be ready for access requests, correction requests, retention decisions and privacy incidents.
If your business is dealing with health information privacy and wants help with privacy policies, customer terms, supplier contracts, data handling processes, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.








