NZ Health Privacy Compliance
HIPC & Privacy Act 2020 Compliance
How Quikly supports the Health Information Privacy Code 2020 and NZ Privacy Act 2020 for practitioners across Aotearoa New Zealand.
Compliance at a glance
Health Information Privacy Code 2020
Built to support HIPC rules for health agencies handling health information. All 13 principles are addressed below.
NZ Privacy Act 2020
Designed around the 13 Information Privacy Principles for collection, storage, use, and disclosure of personal information.
Australian data hosting
Primary data hosted in Sydney. Australia's Privacy Act 1988 provides comparable safeguards for IPP 12 cross-border requirements.
Encryption at rest
Passwords and third-party API credentials (including Stripe, POLi, Windcave, and Verifone) are encrypted before storage, with TLS 1.2+ in transit.
Access controls
Role and partner-based access so client data is only visible to authorised staff. Session management and permission checks throughout the product.
No third-party data selling
Client data is never sold to advertisers or data brokers. Results and records stay within your practice and necessary processors.
The 13 Information Privacy Principles
The NZ Privacy Act 2020 establishes 13 Information Privacy Principles (IPPs). Here is how Quikly addresses each one for practices using our platform.
- 1
IPP 1: Purpose of collection
Health and booking information is collected only for lawful purposes connected to providing appointments, care coordination, and practice operations. You define the purpose; clients are informed through your workflows and our Privacy Policy.
- 2
IPP 2: Source of information
Information is collected directly from the individual (or their parent/guardian for children) through bookings, patient forms, and account details they provide, not from unrelated third-party sources without consent.
- 3
IPP 3: Collection of information
Clients can see what is being collected and why when they book or complete forms. Staff accounts and correspondence explain how data is used in the practice.
- 4
IPP 4: Manner of collection
Information is collected lawfully and fairly through secure, encrypted connections. No deceptive tracking on intake or booking flows.
- 5
IPP 5: Storage and security
Data is protected with TLS 1.2+ in transit and encryption at rest for confidential information (passwords, payment gateway API credentials for Stripe, POLi, Windcave, and Verifone, and other integration secrets), hosted in Sydney, Australia, with partner-scoped access controls and continuous infrastructure monitoring.
- 6
IPP 6: Access to personal information
Practitioners access their own client data through the secure staff dashboard. Individuals may request access to their information through their practitioner or by contacting us.
- 7
IPP 7: Correction of information
Staff can correct client contact and profile details in the dashboard. Individuals may request corrections to their personal information at any time.
- 8
IPP 8: Accuracy of information
Structured booking and form capture reduce transcription errors. Practitioners can review and update records as part of normal clinical and admin workflows.
- 9
IPP 9: Retention of information
Clinical and health-related information is retained in line with professional and HIPC expectations (typically a minimum of 10 years from last entry for NZ health records). Account deletion and export options remain available subject to those obligations.
- 10
IPP 10: Use of information
Health and booking information is used only for the purpose for which it was collected: appointments, care, billing, and practice operations. We do not sell data or use client information for unrelated marketing.
- 11
IPP 11: Disclosure of information
Client data is not disclosed to third parties for advertising. Assessment and booking details are visible only to authorised staff in your practice, plus processors needed to run the platform (payments, hosting, email/SMS).
- 12
IPP 12: Cross-border disclosure
Primary clinical and booking data is hosted in Australia (Sydney). Under IPP 12, Australia provides comparable privacy safeguards via the Privacy Act 1988. Ancillary processors (e.g. authentication or payments) are held to equivalent protections.
- 13
IPP 13: Unique identifiers
Quikly generates its own internal identifiers. Government identifiers such as NHI numbers are never adopted as account or system primary identifiers.
Data hosting & cross-border transfer
Under IPP 12, health information can only be transferred to jurisdictions with comparable privacy safeguards. Australia meets this requirement.
Why Australia?
- Privacy Act 1988 provides comparable protections to NZ
- Australian Privacy Principles mirror NZ IPPs in key areas
- OAIC provides regulatory oversight
- Sydney data centres meet enterprise security standards
- Low-latency access from New Zealand
Security infrastructure
- At rest: passwords and API credentials for payment gateways (Stripe, POLi, Windcave, Verifone) and other integrations are encrypted before storage
- In transit: TLS 1.2+ between browsers, app, and database
- Auth: Secure staff and customer authentication with session expiry
- Isolation: Partner-scoped queries so practices cannot see each other's data
Your obligations as a NZ practitioner
Quikly provides technical safeguards. As a health practitioner, you also have responsibilities under the HIPC 2020.
- 1
Inform your clients
Let clients know you use Quikly to collect and store booking and health-related information. Explain the purpose and how data supports their care.
- 2
Maintain your own security
Use a strong password, do not share login credentials, and log out of shared or public computers.
- 3
Respect client rights
Clients have the right to access and correct their health information under the Privacy Act 2020. Facilitate access requests promptly.
- 4
Follow your professional code
Handle clinical data in line with your professional body's code of ethics and any sector-specific retention rules.
Compliance FAQ
Is Quikly HIPC compliant?
Quikly is built to support compliance with the Health Information Privacy Code 2020 (HIPC). We address the 13 health information privacy principles through technical safeguards including encryption at rest for confidential credentials, Australian data hosting (IPP 12), access controls, and data minimisation. See the IPP breakdown on this page for details.
Where is my patient data stored?
Booking and client records are stored on enterprise-grade infrastructure in Sydney, Australia. Australia provides comparable privacy safeguards to NZ under Information Privacy Principle 12.
What encryption does Quikly use?
TLS 1.2+ for data in transit between browsers, the application, and the database. Confidential information is encrypted at rest before storage, including account passwords and API credentials for third-party connections such as Stripe, POLi, Windcave, Verifone, and other integration secrets.
What happens if there is a data breach?
Quikly follows a breach notification approach aligned with the Privacy Act 2020 mandatory breach reporting requirements. In the event of a notifiable privacy breach, affected practitioners and the Privacy Commissioner would be notified as required by law.
NZ privacy resources
- Privacy Commissioner: HIPC 2020 - official Health Information Privacy Code
- Privacy Act 2020 - full text from Parliamentary Counsel Office
- privacy.org.nz - guidance for organisations handling personal information
Start with HIPC-aligned booking software
Free trial available. Built in NZ, hosted in Australia, designed for beauty, wellness, and allied health practices.