Version 1.0
Privacy Policy | Interface Med Legal
Interface Med Legal (ABN 20071188773) is committed to the responsible and lawful handling of personal information, including sensitive health information. This Policy explains how we collect, hold, use and disclose personal information as independent medicolegal and occupational therapy consultants.
Who We Are and How We Operate
Interface operates in the medicolegal and forensic expert services space. Unlike a traditional health provider, we do not provide clinical treatment and we typically do not have a direct relationship with the individuals whose information we hold.
We act as independent experts and service providers, receiving personal and health information from third parties such as law firms, insurers, government compensation bodies, and courts, for the purpose of providing expert assessments, reports, and opinions.
This context shapes how we collect and handle information, as described in this Policy.
Categories of Information We Handle
We handle personal information that is reasonably necessary for the provision of our services. This includes:
Personal Information
- Full name, date of birth, and contact details
- Claim, matter, or reference numbers
- Employment and occupational history
Sensitive Health Information
- Medical histories, clinical notes, and diagnostic results
- Medical and psychiatric records, where relevant
Legal and Procedural Information
- Details of legal claims, proceedings, or decisions
- Witness statements and litigation-related documents
- Court-mandated disclosures and discovery materials
Website Information
Our website does not use automated decision-making or AI-driven tools to collect or process your information. We may collect limited technical data (such as browser type and pages visited) for website performance purposes only.
How We Receive and Handle Information
We receive information through two distinct streams, both integral to the provision of our expert services.
3.1 Information Collected During Assessment
Where an individual participates in an independent assessment, we collect information directly in the course of that assessment, including clinical interview responses, consented photographs, clinical observations, and standardised assessment results.
3.2 Information Received from Third Parties
Personal and health information is provided to Interface by the instructing party prior to or alongside an assessment, including briefs of evidence, medical records, and court-provided documentation, in accordance with APP 3.6.
Use, Disclosure, and Confidentiality
Primary Purpose
Information we hold is used strictly for the purpose for which it was provided, typically preparing expert reports, responding to instructing-party queries, or complying with court orders.
Confidentiality and the Implied Undertaking to the Court
Information provided by way of legal discovery, subpoena, or court instruction is held subject to an implied undertaking owed to the relevant court and is not used for unrelated purposes.
Secondary Disclosure
We will not disclose personal information to a third party for a secondary purpose without consent, unless required or authorised by law.
Data Security and Storage
Given the highly sensitive nature of the information we hold, we apply rigorous security standards:
- All case-related data is stored on secure, encrypted servers located within Australia.
- Access to case files is restricted on a need-to-know basis, protected by multi-factor authentication.
- Website infrastructure is maintained separately from internal case management systems.
- We conduct regular reviews of our security practices.
Notifiable Data Breaches
In the event of a data breach likely to result in serious harm, we respond under the Notifiable Data Breaches scheme, including containing the breach, notifying the OAIC, and notifying affected individuals or instructing parties.
Retention and Destruction
We retain personal information for a minimum of seven (7) years from the date of the relevant report, with longer periods where latent injury, extended limitation periods, professional indemnity standards, or court orders apply. Information is securely destroyed or de-identified once no longer required.
Access and Correction
Individuals have the right under APP 12 to request access to information we hold about them, and to request correction under APP 13. As we typically act on instructions from a third party, requests may need to be directed to the instructing party; we acknowledge direct requests within five (5) business days.
Cross-Jurisdictional Operations
We provide services across multiple Australian states and territories. Where state-based health privacy legislation applies in addition to the federal APPs, we comply with the more protective standard. We do not currently transfer personal information outside of Australia.
10. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or applicable law. The current version is always available at interface.com.au/privacy.
Version 1.0 — April 2026 — Initial publication
11. Contact and Complaints
If you have a question, concern, or complaint about how Interface handles personal information, please contact our Privacy Officer:
Privacy Officer — Interface Med Legal
Suite 601, 26–30 Spring Street, Bondi Junction NSW 2022
[email protected] · 1300 852 072
We will acknowledge your complaint within five (5) business days and aim to resolve it within 30 days. If unsatisfied, you may contact:
Office of the Australian Information Commissioner (OAIC)
www.oaic.gov.au · 1300 363 992
