Most Australian small businesses with turnover under $3 million are exempt from the Privacy Act 1988. Health practices are not: any organisation that provides a health service and holds health information is covered, whatever its size. So every psychologist, counsellor, GP or allied health practice using an AI scribe needs to know how that tool handles the Australian Privacy Principles.
This article explains how Twofold, an AI scribe for clinicians, approaches Australian privacy law: its status under the Act, what happens when information goes overseas, how data breaches are handled, and which obligations stay with your practice. It is written for clinicians evaluating Twofold and for the practice managers and privacy officers who review it. If you are still comparing tools, see the best AI scribes for Australian psychologists.
Is Twofold covered by the Privacy Act 1988?
Yes. Where the Privacy Act applies, Twofold is an APP entity. That means the Australian Privacy Principles bind Twofold directly — it is accountable to the Office of the Australian Information Commissioner (OAIC) for how it handles personal information, not only to your practice through a contract.
The Act reaches organisations outside Australia that carry on business in Australia, and it covers health service providers regardless of turnover.
Which APPs matter most for an AI scribe, and how does Twofold meet them?

- APP 1 — open and transparent management. Twofold's privacy policy states what it collects, why, and that personal information, including health information, is likely to be disclosed to recipients in the United States.
- APP 3 and APP 6 — collection, use and disclosure. Health information is sensitive information under the Act. It's collected by your clinician with the client's consent, and Twofold uses it only to provide the documentation service and directly related purposes. It is never used for marketing, and never used to train or fine-tune models.
- APP 8 — cross-border disclosure. Twofold processes information in the United States, on Microsoft Azure and Google Cloud. See the next section for what that means for your practice.
- APP 11 — security. Twofold protects information with administrative, technical and physical safeguards, including encryption, access controls and a documented security program.
- APP 12 and APP 13 — access and correction. You can ask Twofold for access to, or correction of, information it holds about you. Requests about a client's clinical record go to the treating clinician.
What does overseas disclosure mean for my practice?
When your practice sends client information to Twofold, it is disclosing that information to an overseas recipient, because Twofold processes it in the United States. The Privacy Act allows this. Under APP 8, your practice must first take reasonable steps to ensure the recipient won't breach the APPs — usually by relying on the vendor's terms — and your own privacy policy should say that client information is likely to be disclosed overseas and to which countries.
Because Twofold is itself an APP entity, the APPs apply to it directly. Your practice still keeps its own APP 8 obligation to take reasonable steps before disclosing.
Twofold does not offer Australian hosting. If your practice's policy requires information to stay in Australia, Twofold is not the right fit.
Do state health records laws apply?
They can. Two states have health privacy laws that cover private health service providers and restrict transfers out of the state:
- Victoria — Health Records Act 2001 (HPP 9). Health information may be transferred outside Victoria only on specified grounds, including that the recipient is bound by a law, scheme or contract substantially similar to the Health Privacy Principles, or that the individual consents.
- New South Wales — Health Records and Information Privacy Act 2002 (HPP 14). A similar rule applies to transfers outside NSW.
Twofold being bound by the APPs is relevant to those grounds. Check which ground your practice relies on.
How are data breaches handled?
Under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act), an eligible data breach is one likely to result in serious harm. The entity must assess a suspected breach within 30 days and notify the OAIC and affected individuals.
Where an eligible data breach occurs, Twofold notifies the OAIC and, where the scheme requires it of Twofold, the affected individuals.

What stays your practice's responsibility?
Twofold's obligations don't replace your practice's. Your practice still:
- Obtains the client's informed consent to record the session and documents it. AHPRA notes that consent is particularly important for AI tools that record private conversations, and recording without consent can breach state surveillance device laws.
- Keeps its own privacy policy current, including that client information is likely to be disclosed overseas.
- Takes reasonable steps under APP 8 before disclosing information overseas.
- Handles client requests to access or correct their clinical record.
- Reviews every AI draft before it becomes part of the record.
This article explains how Twofold approaches Australian privacy law as of September 2026. It is general information, not legal advice. Your obligations depend on your state, profession and practice; confirm them with your professional body or a privacy adviser.

