Privacy policy

How we handle your information

This policy explains how SurgiHub handles personal information, including health information. It covers the patient app, the app used by surgical teams, the browser interface used by practice staff, and this website.

Surgihub Pty Ltd · ABN 51 701 392 770 · ACN 701 392 770
Effective 13 September 2026 · Version 1.0

1. Who we are, and what this covers

SurgiHub is a platform that surgical practices use to run an operation from end to end: the booking, the coordination of the surgical team, and the guided journey a patient follows from the first consultation through to recovery. It is operated in Australia by Surgihub Pty Ltd.

We hold ourselves to the Australian Privacy Principles.

If you are a patient, the practice treating you chose SurgiHub and invited you to it. Your relationship is with that practice and they hold your medical record. We hold that information on their behalf and on their instructions, and we also have obligations to you in our own right. For anything about your care, your practice is the right place to start. Section 10 tells you how to come to us instead if you would rather.

If you are a practice, section 9 sets out what happens to your data and your patients' data when your subscription ends.

2. What we hold

About patients

Name, date of birth, mobile number and email address, all of which are required in order to use SurgiHub. A photograph of your face, which is also required, and which section 6 explains. The details of the operation: the procedure, the date, the hospital, the surgical team, and the equipment and implants involved. Answers to medical history forms, pre-operative questionnaires and outcome questionnaires. The consent form and the record of it being signed. Fee estimates and their acknowledgment. Messages exchanged with the practice, including any photograph sent, such as a photograph of a healing wound. Notifications sent, and whether items in the journey have been opened.

Billing details, including identifiers

So that your practice can bill your operation and claim from whoever is paying for it, we hold your Medicare number, your private health fund membership number, and where they apply your WorkCover claim number and your Department of Veterans' Affairs number. Section 5 sets out how we treat these, because the law treats some of them differently from ordinary personal information.

About a nominated next of kin

Their name, their relationship to the patient and their mobile number, so that they can be invited and can follow the journey. They can see it and change nothing.

About practice staff and clinical teams

Name, role, work contact details and login credentials, and a photograph where the person chooses to provide one. A photograph is not required of staff.

About suppliers and external team members

Name, contact details, and the case information their role requires. A supplier is given what is needed to get the right equipment to the right hospital for the right patient, which includes the patient's name, and no more than that.

About everyone who uses the apps

Device and notification identifiers so that alerts reach the right phone, and technical logs.

3. Why we hold it, and how we collect it

Almost everything we hold about a patient comes either from the practice, entered when the operation is booked, or from the patient, on setting up the app, completing a form or sending a message.

We hold it in order to do the thing the practice is using SurgiHub for: to book and coordinate the operation, to confirm that the person in front of the surgical team is the right person, to give the patient the right information at the right stage, to collect consent and forms, to let the patient and the practice talk to each other, to keep a nominated relative informed, to allow the practice to bill the operation and claim from the payer, and to record how the patient got on afterwards.

Health information is sensitive information under Australian privacy law and attracts stronger protection. We hold it because it is necessary for the practice to provide surgical care, and with the patient's consent.

We do not collect information about a patient from anyone other than the practice, the patient, and a next of kin the patient has nominated.

4. What we do not do

We do not sell personal information. We do not disclose it for marketing. We do not use it to advertise. We do not use patient information to train artificial intelligence models.

We acquire no right to reuse or redistribute the templates, pathways or education content a practice builds. That material belongs to the practice.

5. Medicare numbers and other identifiers

Your Medicare number, and your Department of Veterans' Affairs number if you have one, are what Australian privacy law calls government related identifiers. So, on our reading, is a WorkCover claim number, which is assigned by a statutory insurer. The law places specific limits on what an organisation may do with them, stricter than for ordinary personal information. Three things follow, and we state them rather than leave them to be inferred.

We hold them for billing and claiming, and for nothing else. They exist in your record so that your practice can invoice your operation and claim from Medicare, from your health fund, from WorkCover or from Veterans' Affairs, as the case may be.

We do not use any of them to identify you within SurgiHub. Your record is identified by an identifier of our own. The law restricts an organisation from adopting a government related identifier as its own way of identifying a person, and we have not done so. Your Medicare number is a number we hold about you, not the number by which we know you.

SurgiHub cannot send them anywhere. The platform has no connection to Medicare, to any health fund, to WorkCover or to Veterans' Affairs, and it cannot lodge a claim or transmit a membership number to any of them. Your identifiers sit in your record so that your practice can bill and claim on its own systems, and that is the only route by which they reach a payer.

Your private health fund membership number is not a government identifier, but we treat it the same way.

6. Your photograph

Every patient using SurgiHub provides a photograph of their face, and we ask you to understand why before you decide how you feel about it.

It exists so that the right operation happens to the right person. A surgeon may meet you once in a consulting room and next see you on an operating list among several patients on the same morning, sometimes for the same procedure. Your photograph is how the surgeon and the team confirm that the person in front of them is the person whose record they are reading. It is a patient safety measure, not a convenience.

Who can see it. The clinical team at the practice treating you, and nobody else. It is not visible to other patients, it is not visible to another practice, and it is not given to suppliers or to the hospital.

What we do not do with it. Your photograph is not used for facial recognition, for automated matching of any kind, or to create a biometric template. No system compares it to anything. It is looked at by a person, in the way a photograph on a file has always been looked at by a person.

It is held in Australia, with the rest of your record, and it is covered by everything in section 9.

Staff and clinical team members may add a photograph if they wish. They are not required to.

7. Who else handles it

Running the platform requires a small number of service providers. Each is bound to handle information only as we instruct.

We also disclose information to the practice's own team and to the people an operation requires, being the hospital and the suppliers of the equipment and implants the surgeon has specified.

Beyond these, we disclose information only where the law requires it or where you ask us to.

8. Chat messages are held in the United States

This is the one part of SurgiHub where information leaves Australia, and we would rather you read it here than discover it later.

Everything else in the SurgiHub database, being the booking, the documents, the consent, the forms, your photograph and your billing details, is held in Australia. Messages are different. Chat is provided by CometChat, and CometChat holds its data in the United States. Its standard regions are the United States, Europe and India; Australia is not one of them.

That matters because chat in SurgiHub is not small talk. It carries clinical questions, symptom reports and photographs of healing wounds, and it forms part of the medical record.

What we do about it. CometChat holds ISO 27001 certification and SOC 2 certification across security, availability, privacy, confidentiality and processing integrity. Messages are encrypted in transit and stored encrypted. Each practice has its own private conversation with each patient, so a patient treated by two practices has two separate conversations rather than one shared thread, and membership of a conversation is set by SurgiHub rather than by anyone joining it. Messages are retained permanently, as a medical record requires, and no message can be deleted by a patient, a staff member or an administrator.

Sending information overseas does not transfer our responsibility for it. We remain accountable for how it is handled there.

9. How we protect it, and how long we keep it

Data is held in Australia on Amazon Web Services. Every patient record carries the practice it belongs to, and that separation is applied automatically to every request rather than left to each individual screen: a request that arrives without saying which practice is asking is refused rather than answered with another practice's data.

Information is encrypted in transit, and encrypted at rest to the AES-256 standard. Backups are taken automatically, are held in Australia, and are encrypted the same way. Restoration is tested rather than assumed.

Access is limited by role, so each member of staff sees what their role requires, and patients' personal details are hidden from those who do not need them.

Nothing in a clinical record can be deleted by any user. Where an item must be removed from view, the original is retained.

We hold no security certification of our own and do not claim one. Our infrastructure providers hold theirs.

How long we keep it

While a practice's subscription is active, its records are kept in full. If the subscription ends, the data is not deleted, because these are health records. Access closes, the data stays intact, and for twelve months at no charge the practice may ask us for a complete export: patients, procedures, consents, files, conversations and templates. At the end of that period we provide a final export, the practice acknowledges that the record-keeping obligation now rests with it, and our copy is destroyed. A practice may instead pay an annual fee for us to keep the archive.

Our twelve months is a handover window and not a substitute for a practice's own retention obligations, which are set by law and measured in years.

If a surgeon leaves a group practice, we are the repository and not the arbiter, and we do not adjudicate between practitioners. A practice owner may ask us for an export confined to one surgeon's patients and may choose whether to provide it. Separately, any patient may direct that their own record be sent wherever they choose.

10. Seeing your information, and correcting it

You may ask to see what we hold about you, and you may ask us to correct it. Those are rights under Australian privacy law, not favours.

For anything about your care, your appointments or your medical record, ask your practice first. They hold your record, they know you, and they can act immediately.

You may also come to us at admin@surgihub.com.au. We will ask you to verify who you are, and we will respond within 30 days. If we cannot give you what you have asked for, we will tell you why in writing.

You can change your own contact details, your photograph, and your name and date of birth, under Profile in the app. Please tell your practice as well if your name or date of birth changes, because the hospital matches your booking against those details. Your Medicare, fund, WorkCover and Veterans' Affairs details are changed by your practice, since they are used for billing.

You may direct us to send your record elsewhere, including to a surgeon who has moved to a different practice. That right is yours regardless of what any practice would prefer.

11. If something goes wrong

If we suspect a data breach we assess it promptly, and we notify every affected practice without undue delay and with enough detail for them to meet their own obligations to their patients. Where a breach is likely to result in serious harm, we notify the Office of the Australian Information Commissioner and the affected individuals, as the Notifiable Data Breaches scheme requires. We tell practices even where that threshold is not met, on the view that a practice would rather hear it from us than not at all.

12. Complaints

If you believe we have mishandled your information, tell us at admin@surgihub.com.au. We will acknowledge your complaint and respond within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

13. Anonymity

Because SurgiHub exists to coordinate an operation on a specific person, we cannot deal with patients anonymously or under a pseudonym. The surgical team and the hospital have to know who you are, and the photograph described in section 6 is part of that.

14. Changes to this policy

We will publish any change here and update the version and date above. Where a change materially affects how we handle your information, we will tell practices, and patients will be told in the app.