Privacy Policies for New Zealand Private Healthcare Clinics

Alex Solo
byAlex Solo12 min read

Private healthcare clinics in New Zealand handle some of the most sensitive information a business can collect. That includes patient contact details, health history, treatment notes, billing records, referral information and sometimes payment data or online booking details. A common mistake is copying a generic website privacy policy that says nothing useful about health information. Another is treating a clinic privacy policy as a one-off website document, instead of matching it to what the clinic actually does at reception, in consult rooms, through telehealth and in practice management software. Clinics also get caught when they collect more information than they need, or fail to explain who information may be shared with.

A privacy policy for a private healthcare clinic should tell patients, in clear terms, what you collect, why you collect it, how you store it, who you disclose it to, and how patients can access or correct their information. For New Zealand clinics, the answer sits mainly within the Privacy Act 2020 and the Health Information Privacy Code, alongside practical business issues like staff processes, third party suppliers and patient communications. Here's what clinic owners and managers should sort out before problems arise.

Overview

A clinic privacy policy is not just a website formality. It is a public explanation of how your practice handles personal and health information, and it should line up with your actual systems, patient journey and legal obligations in New Zealand.

For private healthcare clinics, the main risk is not only having no policy. The bigger risk is having a policy that is too generic, incomplete, inconsistent with your processes or silent on common patient situations such as referrals, lab requests, telehealth and records access.

  • Identify exactly what personal and health information your clinic collects.
  • Explain why each type of information is needed for treatment, administration, communication and related purposes.
  • State how information is stored, protected and retained.
  • Describe when information may be shared, such as with specialists, labs, pharmacies, insurers or service providers.
  • Set out how patients can request access to or correction of their records.
  • Check your website, booking forms, consent forms and staff scripts match the privacy policy.
  • Review overseas cloud providers, telehealth platforms and practice software arrangements.
  • Train staff so front desk, clinical and management practices follow the same rules stated in the policy.

What Privacy Policy Private Healthcare Clinics Means For New Zealand Businesses

For a New Zealand private clinic, a privacy policy is part legal notice, part trust document and part operational checklist. Patients are being asked to share deeply personal information, so your clinic needs to be transparent and careful from the first point of contact.

Most clinics are covered by the Privacy Act 2020, and health agencies also need to consider the Health Information Privacy Code. In plain English, these rules set standards for collecting, using, storing, disclosing and giving access to health information. A privacy policy does not replace those obligations, but it helps show patients and staff how your clinic applies them in practice.

What counts as health information?

Health information is broader than a diagnosis or treatment note. It can include information about a patient's symptoms, appointments, medications, referrals, test results, ACC-related information, specialist reports, payment details linked to treatment, and communications with the clinic about health services.

It can also include information gathered before treatment starts. For example:

  • details entered into an online booking system
  • intake questionnaires
  • triage notes
  • copies of referrals
  • identity verification information
  • emails asking for treatment options or follow-up appointments

This is where clinic owners often get caught. They assume the only privacy issue is the patient file, when in reality the privacy footprint starts on the website, at reception and through any software provider the clinic uses.

Why your clinic needs a tailored privacy policy

A tailored privacy policy helps with more than technical compliance. It sets expectations early and reduces confusion when patients ask why a clinic needs certain details, whether information will be shared, or how they can get a copy of their records.

A proper clinic policy usually needs to reflect matters such as:

  • walk-in consultations and appointments
  • specialist referrals and co-treatment arrangements
  • online forms and patient portals
  • telehealth consultations and recordings, if any
  • payment processing and account management
  • communications by text, email or phone
  • use of external IT, cloud storage or software vendors
  • marketing communications, if the clinic sends them

If your clinic also sells products online, operates under a company structure, licences software, uses service contracts, or protects its brand with a trade mark, privacy still needs to fit into that broader business setup. Founders often focus on registration, business structure, leases and supplier agreements before launch, but privacy should be sorted out at the same time, especially before you sign with a practice management platform or telehealth provider.

What a privacy policy usually needs to cover

The exact drafting depends on the clinic, but most New Zealand private healthcare clinics should cover the following points clearly.

  • What information the clinic collects, including personal details, health information and technical website data where relevant.
  • How the information is collected, such as through patients directly, referral sources, phone calls, forms, portals or third parties.
  • Why the clinic collects and uses the information, including treatment, administration, billing, reminders and service improvement.
  • Who the clinic may disclose information to, and in what circumstances.
  • Whether any information is stored or processed overseas.
  • How the clinic protects information from loss, misuse or unauthorised access.
  • How patients can request access to or correction of their information.
  • Who to contact with privacy questions or complaints.

That may sound straightforward, but the wording matters. A vague statement like "we may share your information where necessary" can create more risk than clarity if it never explains the likely recipients or purposes.

When This Issue Comes Up

This issue usually appears well before a privacy complaint. Most clinics need a workable privacy policy at setup, during digital changes, and any time patient information starts flowing through a new process.

When opening a new clinic

Before you spend money on setup, founders often focus on premises, equipment, staffing and registration. Privacy needs attention at the same stage. If you are choosing a business structure, setting up a company, negotiating a lease, arranging software subscriptions and preparing intake forms, that is the right time to make sure the privacy policy matches the way the clinic will actually operate.

A new clinic may need privacy wording across several touchpoints, not just one document. For example:

  • website privacy policy
  • patient registration forms
  • consent or treatment forms
  • telehealth terms
  • staff confidentiality expectations
  • supplier agreements with software and IT providers

When adding online booking or telehealth

Clinics often underestimate how much extra data handling comes with digital tools. Online bookings can collect health details before a patient attends. Telehealth may involve video platforms, recordings, messaging tools, electronic prescriptions and follow-up communications.

Before you sign with a platform provider, check whether the provider stores data offshore, what security controls exist, and how patient data can be accessed or deleted. Your privacy policy should not say information is kept only in New Zealand if your systems do something different.

When working with third parties

Private clinics rarely handle everything in-house. They may share information with labs, radiology providers, specialists, insurers, debt collection agencies, accountants, IT contractors, cloud hosts or outsourced reception services. Each arrangement raises practical privacy questions.

This does not mean every service provider must be named individually in the policy. It does mean the categories of disclosure should be described clearly enough that patients understand the likely flow of their information.

When a patient asks for records or raises a complaint

Patients often first read your privacy policy when something has already gone wrong, or seems to have gone wrong. That might be a request for a copy of notes, a disagreement about a disclosure, or a concern about texts and reminders being sent to the wrong number.

If the policy is clear, current and easy to find, your clinic has a much better starting point for dealing with that issue calmly and consistently.

When buying or selling a clinic

Privacy issues also arise in business sales, acquisitions and restructures. A buyer may want access to patient records as part of due diligence, or patient data may need careful handling during ownership changes. Before you sign a contract for a sale or merger, check how patient information will be reviewed, transferred and secured, and whether additional notices or consents may be needed.

Practical Steps And Common Mistakes

The best clinic privacy policies are built from real workflows, not copied from another website. Start with what your team actually collects and does, then draft the policy around those facts.

Step 1: Map your patient information lifecycle

Write down how information enters, moves through and leaves the clinic. That means following the patient journey from first contact to file storage or deletion.

Your mapping exercise should usually cover:

  • website enquiries and booking forms
  • phone calls and reception notes
  • new patient registration
  • clinical consultations and records
  • referrals and test requests
  • payment processing and invoicing
  • follow-up reminders and marketing messages
  • storage, backups, archiving and disposal

This step often reveals hidden collection points, such as voicemail, shared inboxes or mobile devices used by practitioners.

Step 2: Separate necessary collection from convenience collection

Clinics should only collect information they genuinely need for their services or related lawful purposes. Asking for every possible detail "just in case" can create unnecessary risk.

For example, a specialist clinic may have strong reasons to request referral details and relevant medical history before an appointment. It may have much weaker reasons to request unrelated personal information through an online form. If you collect something sensitive, be ready to explain why.

Step 3: Explain disclosures in a patient-friendly way

Patients do not expect legal jargon. They do expect an honest explanation of where their information may go as part of their care and clinic operations.

Common disclosure categories for private healthcare clinics may include:

  • other treating practitioners or specialists
  • pathology, imaging or laboratory providers
  • pharmacies or prescription services
  • ACC, insurers or funders where relevant
  • payment processors and practice management software providers
  • IT support, cloud storage or document management providers
  • regulators or other parties where disclosure is required or authorised by law

If your clinic sends newsletters, promotions or health updates, deal with that separately and clearly. Treatment communications and marketing communications should not be blurred together.

Step 4: Match the policy to your website and forms

A polished privacy policy will not help if your forms, pop-ups and staff scripts say something different. Check whether your collection notices at the point of sign-up or booking line up with the policy language.

Review the wording on:

  • website contact forms
  • booking confirmations
  • patient registration packs
  • telehealth onboarding
  • email footers and SMS reminders
  • hard copy forms used at reception

This is especially important for clinics that offer services online or combine in-person treatment with digital follow-up. If you are selling health products online as well as providing services, make sure the consumer-facing website wording, customer terms and privacy statements all fit together.

Step 5: Check overseas storage and service providers

Many clinics use cloud-based systems, and some store or process data outside New Zealand. That does not automatically mean the setup is unlawful, but it does mean you need to understand what happens to patient information and describe your practices accurately.

Before you sign a vendor contract, ask practical questions about:

  • where data is hosted
  • who can access it
  • whether subcontractors are involved
  • how security incidents are handled
  • how long data is retained
  • what happens when the contract ends

The privacy policy should then reflect the arrangement at a sensible level of detail. Do not promise local-only handling if the clinic uses international platforms.

Step 6: Build an access and correction process

Patients should be able to ask for access to their information and request corrections. A privacy policy should tell them how to do that, but the clinic also needs an internal process so staff know what happens next.

That process might cover who receives requests, how identity is checked, what records are searched, how responses are tracked, and when clinical or legal review is needed. Without this, requests can be delayed, mishandled or answered inconsistently.

Step 7: Train staff and review regularly

Reception staff, nurses, clinicians and managers all handle privacy in different ways. The policy should not sit untouched in a website footer while everyday practice drifts away from it.

Review your policy when:

  • you introduce new software
  • you add telehealth or online services
  • you change clinic ownership or structure
  • you start a new marketing channel
  • you begin sharing data with a new provider
  • patients raise repeated privacy questions or complaints

Common mistakes clinics make

Most privacy problems in private healthcare settings are practical failures, not obscure legal technicalities. The common mistakes are predictable.

  • Using a generic policy that does not mention health information.
  • Listing broad collection purposes without linking them to real clinic functions.
  • Failing to cover referrals, test providers, insurers or software vendors.
  • Ignoring online bookings, telehealth tools or patient portals.
  • Collecting information through forms that ask for more than the clinic needs.
  • Not having a clear process for access or correction requests.
  • Leaving privacy wording unchanged after a change in software, ownership or services.
  • Assuming staff know what the policy means without training.

The safest approach is simple. Say what your clinic really does, only collect what you need, and make sure your forms, systems and contracts back that up.

FAQs

Does every private healthcare clinic in New Zealand need a privacy policy?

Most clinics that collect personal and health information should have a clear privacy policy. If you have a website, online booking, patient files or digital communications, a written policy is a practical minimum.

Is a website privacy policy enough on its own?

No. A website policy is important, but clinics also need privacy wording and processes across registration forms, staff practices, software arrangements and patient communications. The public policy needs to match what happens behind the scenes.

What laws are most relevant for clinic privacy in New Zealand?

The main framework usually includes the Privacy Act 2020 and the Health Information Privacy Code. The exact application can depend on the clinic's services, systems and how information is collected and disclosed.

Can a clinic use overseas cloud software?

Often yes, but the clinic needs to understand how patient information is handled and make sure its privacy statements are accurate. It is also wise to review the vendor contract, security controls and any cross-border data issues before you sign.

What if our clinic already has a privacy policy from a template?

A template can be a starting point, but it should be reviewed against your actual patient journey, disclosures, forms, software and internal processes. Health information handling is usually too specific for a copy-and-paste approach.

Key Takeaways

  • A privacy policy for a New Zealand private healthcare clinic should be tailored to the clinic's real collection, use, storage and disclosure of health information.
  • The policy should align with the Privacy Act 2020, the Health Information Privacy Code and the clinic's day-to-day systems and staff practices.
  • Common risk areas include generic templates, unexplained data sharing, telehealth tools, online bookings, overseas software providers and poor access request processes.
  • Founders should sort privacy out early, especially before you sign supplier agreements, launch digital services, or change ownership arrangements.
  • Privacy compliance works best when the policy, patient forms, staff training, software contracts and internal procedures all say the same thing.

If your business is dealing with privacy policy private healthcare clinics and wants help with privacy policy drafting, patient consent wording, software and supplier contract review, compliance checks, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

When should you formalise this?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.