Episap provides a case-first multidisciplinary team (MDT) workflow for clinical teams. This privacy policy explains how Episap handles personal information, sensitive information and health information when authorised users prepare, run and document MDT meetings, invite participants, request patient consent and manage patient-case records.
About this privacy policy
We are bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). This policy explains how and why we collect, use, hold and disclose your personal information.
"We", "us" and "our" means Episap, the operator of the Episap clinical MDT service.
Meaning of personal information and sensitive information
Personal information is any information or an opinion about an identified individual, or an individual who can be reasonably identified from the information or opinion. Information or an opinion may be personal information regardless of whether it is true.
Sensitive information means:
Information or an opinion (that is also personal information) about an individual's:
racial or ethnic origin;
political opinions;
membership of a political association;
religious beliefs or affiliations;
philosophical beliefs;
membership of a professional or trade association;
membership of a trade union;
sexual orientation or practices;
criminal record;
health information about an individual;
Health information about an individual.
Genetic information about an individual that is not otherwise health information.
Biometric information that is to be used for the purpose of automated biometric verification or biometric identification.
Biometric templates.
Kinds of personal information we collect and hold
The kinds of personal information we collect and hold about you are:
account and profile details of clinicians, coordinators and other authorised users, including name, email address, role, discipline and authentication metadata; meeting metadata, attendance records, invitations, participant notes and follow-up information; patient identity and contact details entered by authorised users for consent and case administration; de-identified or partially de-identified clinical case content, MDT questions, recommendations, notes, files and audit records; consent responses and communication records; support requests; and technical logs needed to operate, secure and improve the service.
We also collect and hold the following kinds of sensitive information where authorised users enter it into Episap or where it is necessary to operate an MDT workflow:
health information, patient case information, diagnosis and treatment context, MDT recommendations, consent records and information about clinician participation in care-team discussions.
We also collect information about how you access, use and interact with our website, app and other digital channels. This information includes:
device and browser information, IP address, session and authentication events, usage logs, security logs, communication delivery records, page and feature interactions, error diagnostics and cookie or similar technology data where used.
Why we collect, hold, use and disclose your personal information
We collect, hold and use your personal information so that we can provide our goods and/or services, administer our organisation and comply with the law. The specific purposes for which we handle your personal information are to:
create and administer user accounts; prepare, schedule, run and record MDT meetings; manage patient consent requests and consent status; maintain patient-case records and meeting summaries; send invitations, reminders, consent links and service communications; provide support; secure the service, investigate incidents and maintain audit logs; comply with legal, clinical governance, privacy, security and record-keeping obligations; and improve the reliability and usability of Episap.
We also disclose your personal information to third parties for different purposes as follows:
authorised clinicians, coordinators and workspace members involved in the relevant MDT workflow; service providers who host, secure, send communications for, or otherwise support Episap, including Supabase, LiveKit, Resend and Twilio where configured; professional advisers; regulators, courts, law enforcement or government agencies where required or permitted by law; and other persons where the relevant individual, patient, customer or authorised user has consented or directed us to disclose the information.
How we collect your personal information
We generally collect your personal information directly from you whenever you interact with us, including when you create an account, use Episap, join or schedule an MDT meeting, respond to a consent request, contact support or visit our website.
We also collect your personal information as follows:
We may collect personal information indirectly from the organisation that subscribes to or administers Episap, clinicians and coordinators who enter patient or meeting information, invited participants, authentication and communication providers, and technical service providers that generate security, delivery and usage logs.
We collect sensitive information only where it is entered or authorised by a care team member, patient, customer or other person with authority to provide it, or where it is generated as part of the MDT workflow:
through patient profiles, case forms, meeting agendas, meeting notes, uploaded supporting information, consent links, meeting summaries and audit events. Episap is designed to separate patient identity information from clinical case content where practical and to use access controls, encryption and audit logging to reduce privacy risk.
How we store and hold personal information
We store most information about you in computer systems and databases operated by either us or our external service providers. Some information about you is recorded in paper files that we store securely.
We implement and maintain processes and security measures to protect personal information, which we hold from misuse, interference or loss, and from unauthorised access, modification or disclosure.
These processes and systems include the following:
identity and access management controls, including authenticated sessions, role-based access patterns and restricted administrative access;
policies and procedures requiring personnel and contractors to keep information secure and handle patient and clinical information appropriately;
security and privacy training for personnel with access to production systems or support workflows;
monitoring and review of security practices, audit logs, access patterns and incident response processes;
client-side encryption for patient identifying information where implemented, de-identification controls for clinical case content, tamper-evident audit records, secure communications configuration, backups and incident response processes.
We will also take reasonable steps to destroy or de-identify personal information once we no longer require it for the purposes for which it was collected or for any secondary purpose permitted under the APPs.
Disclosure of personal information to overseas recipients
We may disclose personal information to recipients located outside Australia where our service providers, communications infrastructure, support personnel or other authorised recipients process information outside Australia.
Those recipients are likely to be located in Australia, the United States and other countries where our infrastructure, communications, security, support or professional service providers operate. Episap is intended to use Australian-hosted infrastructure for patient and clinical information where practical.
Access to and correction of your personal information
You have a right to request access to, or correction of, the personal information that we hold about you by contacting us. Our contact details are set out below at paragraph 10.
There are some circumstances where we may refuse your request to access or correct your personal information. If we refuse your request, we will notify you in writing of the reasons for the refusal. If you disagree with our decision, you may make a privacy complaint using the complaints procedure set out below at paragraph 9.
If we are unable to correct your personal information, you may ask us to include a statement that you believe your personal information is inaccurate, out of date, irrelevant or misleading.
There is no charge for requesting access to, or correction of, your personal information, but we may require you to meet our reasonable costs in providing you with access (such as photocopying costs or costs for time spent on collating large amounts of material).
We will respond to your requests to access or correct personal information within a reasonable period, which is generally within 30 days of receiving your request.
Privacy complaints
If you have a complaint about the way in which we have handled your personal information, including in relation to your request for access or correction of your personal information, you should contact us first using the details set out below at paragraph 10.
We will consider your complaint and determine whether it requires further investigation. We will notify you of the outcome of this investigation.
If you remain dissatisfied with the way in which we have handled a privacy issue, you may make a complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Contact details
If you have any questions, comments, requests or concerns, please contact us at:
Episap Email: matthewjduff@icloud.com Website: https://episapient.com
Changes to this policy
From time to time, we may update this privacy policy to reflect changes to how we handle personal information or the types of personal information that we hold. Any changes to this policy will be published on our website.
You may obtain a copy of the current policy from our website or by contacting us at the contact details above set out in paragraph 10.