Overview
In Australia, the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) govern how organizations handle personal information, with stricter conditions applying to health information because it is classified as sensitive information. This guide explains how Dermi Atlas Professional acts as a technical tool designed to support the privacy obligations of Australian dermatology and aesthetic practices.
Which Practices the Privacy Act Covers
An organization bound by the APPs is an APP entity. Most small businesses with an annual turnover of AUD 3 million or less fall outside the Privacy Act, but private-sector health service providers are an explicit exception: a practice that provides a health service and holds health information is covered regardless of turnover. Clinical photographs and the notes recorded alongside them are health information, so an Australian dermatology or aesthetic practice is an APP entity for the records it holds in Dermi Atlas Professional.
Dermi's Role: Dermi develops and licenses the Dermi Atlas Professional software. Because Dermi Atlas Professional is deployed on the practice's own infrastructure and stores health information locally, Dermi Inc. does not access that information as part of normal operations. The full description of Dermi's role and the data Dermi processes is set out in the Dermi Privacy Policy, the Dermi Atlas Professional EULA, and the Dermi Sub-Processors document. Practices should consult their privacy officer or legal counsel for the resulting determination under the Privacy Act and any applicable state or territory legislation.
Mapping Features to the Australian Privacy Principles
The following sections outline how Dermi Atlas Professional features align with the Australian Privacy Principles that bear most directly on clinical imaging.
APP 3 and APP 5: Collection, Consent, and Notification
APP 3 permits the collection of health information where the individual consents and the collection is reasonably necessary for the provider's functions. APP 5 requires that the individual be notified of the collection and the purposes it serves.
Feature: Consent Management
Dermi Atlas Professional includes a configurable consent workflow, described in full in Clinical Image Consent. The Patient Consent for Clinical Photography preference can be set to Disabled, Advisory, or Required.
- Enforcement: Required blocks image uploads until documented authorization is recorded for the patient; Advisory displays consent reminders without blocking capture.
- Digital Consent: The patient reviews a consent description covering the purpose of image collection, how images may be used, the privacy and security measures applied, and patient rights including withdrawal, then enters a full name as the digital signature. The description text supports the notification expected under APP 5.
- External Verification: A clinician records that verbal, written, or other consent was obtained outside the application, with an optional notes field.
- Revocation: Consent is revoked from the patient details page by typing the confirmation phrase REVOKE CAPTURE CONSENT, and, under Comprehensive logging, the revocation is recorded in the activity logs.
Feature: Minimal Patient Records
The unique patient identifier is the only required field on a patient record. Every demographic and contact field is optional, so a practice can limit collection to the information it actually needs for the service it provides.
APP 6: Use and Disclosure
APP 6 restricts the use and disclosure of health information to the purpose for which it was collected, subject to the exceptions set out in the principle.
- Data Isolation: Every patient and image record is associated with its owning account, and users cannot view patient records belonging to other accounts within the same deployment.
- Disclosure Trail: Under Comprehensive logging, PDF generation and image downloads are recorded, so the occasions on which health information left the system are visible in the audit trail.
- No Vendor Access: Patient data is not synced to Dermi servers, and Dermi support staff cannot access the local instance or its data remotely.
APP 8: Cross-Border Disclosure
APP 8 keeps an entity accountable for personal information it discloses to an overseas recipient, which makes the storage location of clinical photographs a material question for Australian practices.
- Local Residency: All patient photographs, clinical notes, demographic records, and audit logs are stored on the host computer operated by the practice. Routine clinical use therefore involves no overseas disclosure of health information through the software.
- What Reaches Dermi: Account verification actions transmit account identifiers and technical metadata (username, first name, account email address, request type, the verification link, IP addresses, user agent, and timezone). License verification transmits the signed installer and license tokens together with a device fingerprint identifying the host machine. No patient data is included in either. The processing locations for that metadata are listed in the Dermi Sub-Processors document.
- Practice-Initiated Transfers: Exported reports, downloaded images, and system backups are copies of health information that leave the software. Whether a copy is placed with an overseas recipient, such as an offshore cloud storage provider, is a decision made by the practice and remains its responsibility under APP 8.
APP 11: Security of Personal Information
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, and unauthorized access, modification, or disclosure, and to destroy or de-identify it once it is no longer needed.
- Encryption in Transit: TLS encrypts traffic between the host computer and tablets or laptops on the local network. Dermi Atlas Manager supplies the certificate configuration and the Network Gateway container generates the self-signed certificate at startup.
- Authentication: Passwords are salted and hashed before storage and must meet enforced complexity requirements. Two-Factor Authentication using time-based one-time passwords is optional and recommended, and all active sessions can be ended across devices from Options => Account.
- Audit Logging: Comprehensive logging is the shipped default. Each entry records the timestamp, the acting account, the operation, the affected resource, and the before and after states where applicable; authentication and account events additionally record IP address, user agent, and timezone.
- Deletion and Retention: The Data Deletion Policy configured in Dermi Atlas Manager determines whether deletion is reversible (Recoverable or Standard) or immediate and permanent (Permanent). The retention period for soft-deleted records is configurable from 1 to 600 months, defaults to 120 months, and a daily cleanup process removes records once they expire, which supports the destruction obligation in APP 11.
- Host Controls: Full-disk encryption, host firewall rules, and secure backup storage are configured by the practice and form part of the reasonable steps expected of it.
APP 12 and APP 13: Access and Correction
APP 12 gives an individual the right to access the personal information held about them, and APP 13 requires the entity to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Record Access: The patient details page presents every recorded demographic and contact field, and the Patient Activity Logs card shows the activity recorded against that record.
- Export: Complete Patient Reports can be exported as PDFs and original images can be downloaded at full resolution, which allows an access request to be answered with the images themselves rather than a summary.
- Correction: All demographic and contact fields are editable, changes are tracked per field with a per-field undo, a save is written only when a value has changed, and every modification is recorded in the audit trail with its timestamp, acting account, and the before and after state of the record. That record demonstrates when a correction was made and by whom.
State and Territory Health Records Laws
Victoria, New South Wales, and the Australian Capital Territory each have separate health records legislation that applies alongside the Privacy Act and sets out its own handling, security, access, and correction obligations. Those obligations run parallel to APP 11, APP 12, and APP 13, and the same local storage model, audit trail, and export tools described above support them. Retention minimums differ by jurisdiction, so the Data Retention Period configured in Dermi Atlas Manager should be confirmed against the rule that applies to the practice before it is reduced.
Breach Response and the Notifiable Data Breaches Scheme
The Notifiable Data Breaches scheme requires an APP entity to assess a suspected eligible data breach and, where the breach is likely to result in serious harm and the risk cannot be remediated, to notify the affected individuals and the Office of the Australian Information Commissioner. The assessment is expected to be completed within 30 days of the entity becoming aware of the suspected breach.
How Dermi Atlas Supports Response:
If a tablet is lost or a user account is compromised, the Dermi Atlas Professional audit logs supply the evidence the assessment depends on:
- Which patient records the affected account opened, and when.
- Whether images were downloaded or PDF reports generated from those records.
- The IP address, user agent, and timezone recorded against the authentication events, which help separate authorized sessions from unauthorized ones.
Bounding the exposure by account and time window is what allows the practice to reach the serious-harm determination inside the assessment window. Note that under the default Standard deletion policy the historical logs for a deleted record are removed at the time of deletion; the Recoverable policy retains them for the full retention period instead.
Checklist for Administrators
To support Privacy Act obligations when using Dermi Atlas Professional:
- Confirm Comprehensive Logging: Audit Logging ships set to Comprehensive; confirm it has not been changed to Essential in Dermi Atlas Manager under Options => Advanced.
- Set the Consent Level: Align the Patient Consent for Clinical Photography preference with the practice's own consent forms and collection notice.
- Review the Retention Period: Check the Data Retention Period in Dermi Atlas Manager against the retention minimum that applies in the practice's state or territory before reducing it, because a reduction is applied retroactively to existing deleted records.
- Secure the Host: Enable full-disk encryption (BitLocker or FileVault) on the computer running the software, and restrict physical access to it.
- Control Backup Destinations: Backups and exported reports are copies of health information; store them encrypted and confirm the location of any cloud destination before it is used, since an overseas recipient engages APP 8.
- Prepare a Breach Procedure: Name the person who reviews the audit logs and the person who prepares any notification, so the 30-day assessment window can be met.
- Publish a Privacy Policy: APP 1 requires a clearly expressed and current privacy policy describing how the practice manages personal information; the deployment details in this guide inform that document.
Disclaimer: This guide describes software features and is not legal advice. Compliance with the Privacy Act 1988 (Cth) and any applicable state or territory health records legislation is the responsibility of the practice, which should consult a privacy officer or legal counsel regarding its specific obligations.
Related Resources
- Security and Compliance Fundamentals for a broader overview of the platform's security posture.
- Data Security Architecture for the technical detail behind local storage, encryption, and authentication.
- Audit Logging Configuration for configuring and reviewing activity logs.
- Configuring Data Retention for Deleted Records for deletion policies and retention period configuration.
- HIPAA Compliance Guide for United States regulatory guidance.
- PIPEDA Compliance Guide for Canadian privacy regulation guidance.