Privacy Policy
Last updated: 31 August 2026
Cardia Heart Specialists (“Cardia”, “we”, “our” or “us”) respects your privacy and is committed to protecting the personal and health information entrusted to us.
We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Health Records and Information Privacy Act 2002 (NSW) and other applicable privacy and health-records legislation.
Information we may collect
The personal information we collect depends on your interaction with Cardia and may include:
your name, date of birth, address and contact details;
Medicare, Department of Veterans’ Affairs and private health insurance information;
emergency-contact and next-of-kin details;
referral information and details of your referring or treating healthcare providers;
current and previous medical conditions, symptoms, medications, allergies and family medical history;
consultation notes, correspondence, test results, medical images, reports and treatment information;
appointment, billing and payment information;
information supplied through our website, telephone enquiries, email correspondence and online forms; and
technical website information, such as your IP address, browser type, device information and website activity.
Health information is sensitive information under Australian privacy law. We will collect it only where reasonably necessary to provide healthcare or related services and where collection is permitted by law.
How we collect information
We generally collect personal information directly from you or from a parent, guardian or authorised representative.
Where appropriate, we may also receive information from your referring doctor, general practitioner, another specialist, hospital, pathology or diagnostic-imaging provider, allied health professional, Medicare, health insurer or another person involved in your care.
When you communicate with Cardia by email, telephone, through our website or through an online booking or enquiry service, information may also be collected through those channels.
Where lawful and practicable, you may interact with us anonymously or using a pseudonym. However, Cardia will ordinarily need accurate identifying and health information to provide safe and effective medical care.
Why we collect and use your information
Cardia may collect, hold, use and disclose personal information to:
arrange and manage appointments;
assess, diagnose and manage your health;
provide medical consultations, cardiac testing, treatment and ongoing care;
communicate with you, your referring doctor and other healthcare providers involved in your care;
obtain, review and share relevant test results, medical records and reports;
process Medicare, Department of Veterans’ Affairs, insurance and billing matters;
manage clinical, administrative and legal records;
respond to enquiries, feedback or complaints;
maintain and improve our services, systems and website;
meet accreditation, insurance, reporting and regulatory requirements;
undertake quality assurance, clinical audit, education or approved research where permitted by law; and
comply with our professional, ethical and legal obligations.
We will generally use your information for the purpose for which it was collected or for a directly related purpose that you would reasonably expect. We may use it for another purpose with your consent or where permitted or required by law.
When information may be disclosed
To support your care and operate the practice, Cardia may disclose relevant information to:
medical practitioners and staff working within Cardia;
your referring doctor, general practitioner and other members of your treating team;
hospitals, pathology providers, diagnostic-imaging providers, pharmacies and allied health professionals;
Medicare, the Department of Veterans’ Affairs and private health insurers;
service providers supporting our practice-management, medical-record, appointment, billing, communications, IT and document-storage systems;
professional advisers, insurers, auditors and accreditation bodies; and
government agencies, regulators, courts or law-enforcement bodies where disclosure is authorised or required by law.
We do not sell patients’ personal or health information.
Website enquiries and email
Information submitted through our website or by email is not intended for urgent medical matters. Please do not use a general website enquiry form to send extensive or highly sensitive medical information unless Cardia has specifically asked you to do so.
Although Cardia takes reasonable steps to protect electronic communications, ordinary email and internet transmissions may not always be completely secure.
Submitting an online enquiry does not create a doctor–patient relationship. If you are experiencing a medical emergency, call Triple Zero (000) or attend your nearest hospital emergency department.
Cookies and website information
Our website may use cookies and similar technologies to support website functionality, understand how visitors use the site and improve the online experience.
This may involve collecting information such as your IP address, browser type, device, pages visited and the date and time of your visit. This information does not usually identify you directly, although it may be treated as personal information when linked with other identifying information.
You may be able to limit or disable cookies through your browser settings. Some parts of the website may not function correctly if cookies are disabled.
Storage and security
Cardia takes reasonable physical, administrative and technical steps to protect personal information against loss, misuse, interference and unauthorised access, modification or disclosure.
These measures may include secure clinical and practice-management systems, access controls, staff confidentiality requirements, password protection, secure storage and appropriate information-handling procedures.
No electronic system can be guaranteed to be completely secure. If Cardia becomes aware of a data breach, we will assess and respond to it in accordance with applicable privacy and data-breach notification requirements.
We retain medical and administrative records for the periods required by law and professional standards. When personal information is no longer required to be retained, we take reasonable steps to securely destroy it or permanently de-identify it.
Overseas service providers
Some technology, website-hosting, email, data-storage or support providers used by Cardia may process or store limited personal information outside Australia, including in the United States or other countries in which those providers operate.
Where overseas processing or disclosure occurs, Cardia will take reasonable steps to ensure that personal information is handled consistently with applicable Australian privacy requirements. Cardia aims to keep clinical medical records within secure systems appropriate for Australian healthcare services.
Accessing or correcting your information
You may request access to personal or health information Cardia holds about you or ask us to correct information that is inaccurate, incomplete, out of date or misleading.
Requests should be made in writing and should include sufficient information to allow us to verify your identity and locate the relevant records. We will respond within a reasonable period and in accordance with applicable law.
In some circumstances, access may be limited or refused where permitted by law. If this occurs, we will generally provide written reasons and explain the available options. A reasonable administrative fee may apply to providing access or copies where permitted by law, but you will not be charged simply for making a request.
Direct communications
Cardia may occasionally send practice-related information or communications where permitted by law. You may ask not to receive non-essential or promotional communications at any time by using the unsubscribe option provided or contacting the practice.
This will not prevent us from sending communications required for your appointments, treatment, billing or ongoing care.
Privacy enquiries and complaints
If you have a question, concern or complaint about how Cardia has handled your personal or health information, please contact us using the contact details published on this website.
Please provide sufficient details about your concern so that we can investigate it. Cardia will acknowledge and respond to privacy complaints within a reasonable period.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or the Information and Privacy Commission NSW.
Changes to this policy
Cardia may update this Privacy Policy from time to time to reflect changes to our services, information-handling practices, technology or legal obligations. The current version will be published on this website with the date of the latest update.

