BabyPortal Privacy Policy
Last updated: 2026-06-11
This policy explains how BabyPortal handles personal and health information under the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). It is written in plain English. If anything is unclear, email privacy@babyportal.au and we'll explain.
1. Who we are
BabyPortal is a clinical record system operated by Dr Jubal John (FRACP), trading as NeoPaeds, the APP entity responsible for the information described in this policy. We are a single neonatal paediatric practice based in Western Australia.
- ABN: [TBD: ABN to be inserted before publication]
- Contact: privacy@babyportal.au
- Practice phone: [TBD: practice phone number]
2. What information we collect
We collect only what we need to provide neonatal clinical care and to bill for it. This includes:
- About your baby (the patient): name, date of birth, sex, MRN, gestation at birth, birth and subsequent weights, head circumference, length, feeding history, clinical observations, medications, diagnoses, and any documents the doctor uploads (e.g. discharge summary).
- About you (the parent): name, mobile phone number, email address, relationship to the baby, and your Medicare or private health fund details if used for billing.
- Account + activity: sign-in events, IP address, and an audit log of who viewed or changed each record (FHIR AuditEvent — see section 7).
3. How we collect it
Most information comes directly from you when you register or use the parent app, or from the doctor during consultations. Some information is imported from our practice management system (Genie PMS), which is the source of truth for clinical records created during in-person visits. Billing data flows to Tyro Health when a claim is submitted.
4. Why we collect it
We collect health information for the primary purpose of providing clinical care to your baby. We use it to:
- Run consultations and document the clinical encounter.
- Send GP letters and discharge summaries to your nominated GP.
- Submit Medicare, DVA, and private health claims via Tyro on your behalf.
- Send you appointment reminders, invitations to the parent app, and clinically relevant follow-up.
We do not use your data for research, advertising, marketing, or sale to third parties. If we ever want to use de-identified data for service improvement or audit, that's an internal use and your identifiable information stays inside the system.
5. Who we disclose information to
We share the minimum amount of information needed with each of the following recipients. The HL7 / FHIR / SMS channels mentioned below are how data physically moves between systems.
- Your nominated GP and referring clinicians: via HL7 messages or PDF letters. This is the clinical handover that follows every consultation, and is the main reason the record exists.
- Medicare, DVA, and private health insurers: via Tyro Health (Australian gateway) when a claim is submitted on your behalf.
- AWS (Amazon Web Services), Sydney: our database and file storage run in AWS's Sydney (ap-southeast-2) region. AWS does not access your data; they only host the infrastructure.
- AWS Bedrock (Sydney): we use Bedrock to help draft clinical notes and parent summaries from dictation. Content sent to Bedrock has personal identifiers scrubbed where possible, and Bedrock runs in the Sydney region. No data leaves Australia for this.
- AWS SES (Sydney): we use SES to send email one-time codes and notifications. Same region as above.
- Twilio (United States): we use Twilio to send SMS. SMS is not encrypted in transit, so our SMS templates deliberately omit your baby's name and any clinical detail. Twilio's infrastructure is based in the USA, so message metadata (your phone number, time sent, status) transits US systems. This is an overseas disclosure under APP 8 and you consent to it by using the parent app.
- Google (United States): if you choose to sign in with a Google account, Google handles the OAuth handshake only. No clinical information is sent to Google.
- NeWT — Newborn Weight Tool (United States): in the first weeks of life your doctor may open NeWT (run by Penn State Health) to plot your baby's early weight loss against a published reference. When they do, your baby's birth date/time and weight measurements (no name or record number) are sent to NeWT's US service. This is a clinician-initiated, non-routine overseas disclosure under APP 8.
6. Data residency
Your clinical record, including all of your baby's health information, is stored in Australia in the AWS Sydney (ap-southeast-2) region. AI processing and email delivery also run in Sydney. The only routine overseas disclosure is the SMS channel via Twilio, described above.
7. Security
We protect your information using industry-standard measures appropriate for clinical data:
- Encryption in transit (TLS) and at rest (AWS-managed encryption on the database and file storage).
- Role-based access — only your care team and authorised parents can read your baby's record.
- A full audit trail (FHIR AuditEvent) of who viewed, created, updated, or exported each record. Audit logs are retained for the life of the clinical record.
- Multi-factor authentication for staff accounts.
- Regular review of third-party security advisories and dependency updates.
8. Your right to access and correct your information (APP 12 + APP 13)
You have the right under APP 12 to ask for a copy of the personal information we hold about you and your baby, and under APP 13 to ask us to correct anything that is wrong, out of date, or incomplete.
To make a request, email privacy@babyportal.au with your name, your baby's name and date of birth, and what you'd like. We'll respond within 30 days. There is no fee for a standard request. If the request is unusually complex we may discuss a reasonable cost with you first.
Some clinical records must be retained under Australian medical record-keeping rules even if you ask us to delete them. We'll always explain what can and can't be deleted.
9. Complaints
If you think we've mishandled your information, please tell us first — email privacy@babyportal.au. We aim to acknowledge within 2 business days and resolve within 30 days.
If you're not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Online form: search “OAIC privacy complaint form”
10. Notifiable data breaches
We follow the Notifiable Data Breach (NDB) scheme under Part IIIC of the Privacy Act. If a data breach is likely to result in serious harm to you or your baby, we will notify you and the OAIC as soon as practicable, and within the 30-day assessment window required by the scheme. We have a written data breach response plan and review it after any incident.
11. Children
BabyPortal exists to record care for babies and young children. Your child cannot create an account or consent to use of their information themselves — you, as the parent or guardian, give consent on their behalf.
We treat paediatric records with extra care: access is restricted to the doctors involved in care and to the parent(s) you authorise. We retain the clinical record until the child turns 25 years of age, which is the standard retention period for paediatric medical records in Australia. After that, records are de-identified or securely destroyed in accordance with the relevant state health-records legislation.
12. Updates to this policy
We may update this policy from time to time. The “Last updated” date at the top of the page reflects the most recent change. If we make a material change (e.g. a new overseas disclosure, a change to how data is used), we will notify you by email and in-app before the change takes effect.
Older versions of this policy are preserved in our source code history and available on request.
Related
See also the data-sharing policy shown when you register, which is the per-Consent record of what you agreed to at sign-up.