NZ Health Privacy Compliance

HIPC & Privacy Act 2020 Compliance

How Quikly supports the Health Information Privacy Code 2020 and NZ Privacy Act 2020 for practitioners across Aotearoa New Zealand.

Privacy Act 2020HIPC 2020Encryption at RestAustralian Data HostingIPP 12 Compliant

Compliance at a glance

Health Information Privacy Code 2020

Built to support HIPC rules for health agencies handling health information. All 13 principles are addressed below.

NZ Privacy Act 2020

Designed around the 13 Information Privacy Principles for collection, storage, use, and disclosure of personal information.

Australian data hosting

Primary data hosted in Sydney. Australia's Privacy Act 1988 provides comparable safeguards for IPP 12 cross-border requirements.

Encryption at rest

Passwords and third-party API credentials (including Stripe, POLi, Windcave, and Verifone) are encrypted before storage, with TLS 1.2+ in transit.

Access controls

Role and partner-based access so client data is only visible to authorised staff. Session management and permission checks throughout the product.

No third-party data selling

Client data is never sold to advertisers or data brokers. Results and records stay within your practice and necessary processors.

The 13 Information Privacy Principles

The NZ Privacy Act 2020 establishes 13 Information Privacy Principles (IPPs). Here is how Quikly addresses each one for practices using our platform.

  1. 1

    IPP 1: Purpose of collection

    Health and booking information is collected only for lawful purposes connected to providing appointments, care coordination, and practice operations. You define the purpose; clients are informed through your workflows and our Privacy Policy.

  2. 2

    IPP 2: Source of information

    Information is collected directly from the individual (or their parent/guardian for children) through bookings, patient forms, and account details they provide, not from unrelated third-party sources without consent.

  3. 3

    IPP 3: Collection of information

    Clients can see what is being collected and why when they book or complete forms. Staff accounts and correspondence explain how data is used in the practice.

  4. 4

    IPP 4: Manner of collection

    Information is collected lawfully and fairly through secure, encrypted connections. No deceptive tracking on intake or booking flows.

  5. 5

    IPP 5: Storage and security

    Data is protected with TLS 1.2+ in transit and encryption at rest for confidential information (passwords, payment gateway API credentials for Stripe, POLi, Windcave, and Verifone, and other integration secrets), hosted in Sydney, Australia, with partner-scoped access controls and continuous infrastructure monitoring.

  6. 6

    IPP 6: Access to personal information

    Practitioners access their own client data through the secure staff dashboard. Individuals may request access to their information through their practitioner or by contacting us.

  7. 7

    IPP 7: Correction of information

    Staff can correct client contact and profile details in the dashboard. Individuals may request corrections to their personal information at any time.

  8. 8

    IPP 8: Accuracy of information

    Structured booking and form capture reduce transcription errors. Practitioners can review and update records as part of normal clinical and admin workflows.

  9. 9

    IPP 9: Retention of information

    Clinical and health-related information is retained in line with professional and HIPC expectations (typically a minimum of 10 years from last entry for NZ health records). Account deletion and export options remain available subject to those obligations.

  10. 10

    IPP 10: Use of information

    Health and booking information is used only for the purpose for which it was collected: appointments, care, billing, and practice operations. We do not sell data or use client information for unrelated marketing.

  11. 11

    IPP 11: Disclosure of information

    Client data is not disclosed to third parties for advertising. Assessment and booking details are visible only to authorised staff in your practice, plus processors needed to run the platform (payments, hosting, email/SMS).

  12. 12

    IPP 12: Cross-border disclosure

    Primary clinical and booking data is hosted in Australia (Sydney). Under IPP 12, Australia provides comparable privacy safeguards via the Privacy Act 1988. Ancillary processors (e.g. authentication or payments) are held to equivalent protections.

  13. 13

    IPP 13: Unique identifiers

    Quikly generates its own internal identifiers. Government identifiers such as NHI numbers are never adopted as account or system primary identifiers.

Data hosting & cross-border transfer

Under IPP 12, health information can only be transferred to jurisdictions with comparable privacy safeguards. Australia meets this requirement.

Why Australia?

  • Privacy Act 1988 provides comparable protections to NZ
  • Australian Privacy Principles mirror NZ IPPs in key areas
  • OAIC provides regulatory oversight
  • Sydney data centres meet enterprise security standards
  • Low-latency access from New Zealand

Security infrastructure

  • At rest: passwords and API credentials for payment gateways (Stripe, POLi, Windcave, Verifone) and other integrations are encrypted before storage
  • In transit: TLS 1.2+ between browsers, app, and database
  • Auth: Secure staff and customer authentication with session expiry
  • Isolation: Partner-scoped queries so practices cannot see each other's data
View full security documentation →

Your obligations as a NZ practitioner

Quikly provides technical safeguards. As a health practitioner, you also have responsibilities under the HIPC 2020.

  1. 1

    Inform your clients

    Let clients know you use Quikly to collect and store booking and health-related information. Explain the purpose and how data supports their care.

  2. 2

    Maintain your own security

    Use a strong password, do not share login credentials, and log out of shared or public computers.

  3. 3

    Respect client rights

    Clients have the right to access and correct their health information under the Privacy Act 2020. Facilitate access requests promptly.

  4. 4

    Follow your professional code

    Handle clinical data in line with your professional body's code of ethics and any sector-specific retention rules.

Compliance FAQ

Is Quikly HIPC compliant?

Quikly is built to support compliance with the Health Information Privacy Code 2020 (HIPC). We address the 13 health information privacy principles through technical safeguards including encryption at rest for confidential credentials, Australian data hosting (IPP 12), access controls, and data minimisation. See the IPP breakdown on this page for details.

Where is my patient data stored?

Booking and client records are stored on enterprise-grade infrastructure in Sydney, Australia. Australia provides comparable privacy safeguards to NZ under Information Privacy Principle 12.

What encryption does Quikly use?

TLS 1.2+ for data in transit between browsers, the application, and the database. Confidential information is encrypted at rest before storage, including account passwords and API credentials for third-party connections such as Stripe, POLi, Windcave, Verifone, and other integration secrets.

What happens if there is a data breach?

Quikly follows a breach notification approach aligned with the Privacy Act 2020 mandatory breach reporting requirements. In the event of a notifiable privacy breach, affected practitioners and the Privacy Commissioner would be notified as required by law.

NZ privacy resources

Start with HIPC-aligned booking software

Free trial available. Built in NZ, hosted in Australia, designed for beauty, wellness, and allied health practices.