Privacy Policy & AI Use
Dr Allen GP — Dr Robert Allen, General Practitioner ABN 42 531 360 958 · Ahpra registration MED0002137140
Effective: 29/07/2026
In short
I consult as an independent GP at two practices. Almost everything about your information is handled by the practice where you are seen, under that practice's privacy policy — your medical record, appointments, billing, results, referrals and correspondence.
Two things I handle myself: the ADHD clinic, and insurance and injury reports.
This page is my privacy policy for the purposes of the Australian Privacy Principles. Plainer answers to common questions are on the FAQs page.
1. Your medical record
The definitive clinical record of your care — consultation notes, results, referrals, correspondence, assessment reports — is created and held in the clinical software of the practice where the consultation took place. So are your contact details, appointments and billing.
I do not maintain a separate medical record, patient database or mailing list.
Each practice is a separate business with its own privacy policy and its own process for access and correction requests:
Key Largo Medical Centre, 1/61 Ocean Keys Blvd, Clarkson WA 6030 — (08) 6401 7444 · [klmc.net.au]
St John Joondalup, 21 Joondalup Drive, Edgewater WA 6027 — (08) 9400 7000 · [stjohnhealth.com.au]
For a copy of your record, a correction, or a privacy concern about how your information has been handled, contact the practice directly. They hold it and can action it.
2. Exception one: the ADHD clinic
Assessment and treatment happen at St John Joondalup and are recorded in St John's clinical software. Three things sit outside that.
1. The enquiry form on this website. Collects your name, date of birth, mobile, email and which practice you attend. Emailed to me and also stored by Squarespace, outside Australia. If you are a Key Largo patient, St John holds nothing about you, so these details are what allows them to register you.
2. NovoPsych, used to send and score the standardised rating scales. Holds your name and email address alongside your responses. Data is stored on Australian servers with backups in Australia.
3. A coded prescribing and review register, held in Notion. Because I consult across two practices with separate clinical systems, I keep a single list of the patients I am the primary ADHD prescriber for, so that reviews, prescribing intervals and outcomes can be tracked safely in one place. Notion stores data outside Australia, including in the United States.
How I limit the risk
The register contains no name, date of birth, address or contact details. Patients are identified by a code, and the code-to-patient link is recorded only in the practice's clinical system.
Enquiry form details are deleted from my email and from the website's stored submissions once passed to St John. I do not maintain a waiting list.
NovoPsych assessments are identified by code, and I have not opted in to its optional research data sharing.
No clinical notes, correspondence or assessment reports are held outside the practice's clinical software.
All accounts use strong passwords and multi-factor authentication.
Collateral history. Informant questionnaires form part of your clinical record at the practice. Informants should not assume their responses will remain confidential from the patient.
3. Exception two: insurance and injury reports
For workers compensation and motor vehicle injury claims, information about your injury and capacity is provided to your employer, insurer or rehabilitation provider — where you have consented, or where disclosure is otherwise required or authorised by law. Clinical information unrelated to the claim is not ordinarily included.
Certificates and reports are produced at the practice and form part of your record there.
One thing sits outside that: a list of pending report requests, held in the same Notion register, so I know what has been requested, what needs quoting, and what has been paid and is ready to complete.
How I limit the risk
The list holds the requesting party, the date and the status of each request. Patients are identified by a code.
It contains no clinical detail — the report itself is written at the practice, into your record.
Entries are removed once the report is completed and invoiced.
4. AI clinical documentation
I use Heidi, an AI documentation assistant, to help produce consultation notes. It transcribes the consultation and generates a draft, which I review and correct before it enters your record at the practice.
I seek your consent each time Heidi is used. After it has been explained at the first consultation, this may simply be a brief check that you remain comfortable. You may decline at any time without any effect on your care, and consent is documented in the clinical record.
Heidi states that for Australian users, Scribe information is hosted in Australia, audio is not retained, identifiers are removed during processing, and patient data is not used to train its models. Once the final note is in the practice record, I delete the session from Heidi.
The final note is my responsibility, not the software's.
5. This website and my email
Squarespace hosts this website. It processes technical and usage information such as IP address and pages viewed, and stores this outside Australia. On a healthcare website, the pages someone visits may allow inferences about their health interests. This site carries no advertising pixels, retargeting or third-party marketing trackers.
Google Workspace is used for my email. Identifiable patient information does sometimes arrive there — a referral, or an enquiry form submission. When it does, I transfer it to the practice record and delete it from my mailbox. Google may store or process this information outside Australia.
Patients should not use this website, email or social media to send clinical information, report symptoms, request results, or raise anything urgent. These channels are not monitored continuously. Book an appointment or phone the practice. This does not apply to referrals sent between practitioners through established professional channels.
If you need urgent help, call 000. For mental health crisis support, call Lifeline on 13 11 14.
6. Security and complaints
Access to the systems I administer is protected by strong passwords and multi-factor authentication. I minimise what is placed in them and use coded information wherever practical. I am covered by the Notifiable Data Breaches scheme and will notify you and the OAIC of any eligible breach likely to result in serious harm.
For anything held by the practices — your record, appointments, billing, results — contact the practice where you were seen.
For anything described in sections 2 to 5, contact me at privacy@drallengp.com. I aim to acknowledge within 7 days and respond within 30 days. Access rights are subject to limited exceptions under privacy law; if access is refused I will explain why.
If you are not satisfied with my response:
Office of the Australian Information Commissioner — privacy handling. Online complaint form; enquiries 1300 363 992 · oaic.gov.au Health and Disability Services Complaints Office (WA) — complaints about a health service. 1800 813 583 Ahpra — concerns about a practitioner's professional conduct. 1300 419 495
7. Changes
This policy is reviewed at least annually, and next in December 2026 to account for changes to the Privacy Act taking effect that month.
Contact: Dr Robert Allen · privacy@drallengp.com