Skip to main content

Privacy

Privacy policy

How Juno Speech Pathology handles your personal and health information.

Draft for Juno’s review

This policy is a draft prepared on 27 September 2026 to reflect how the practice’s systems actually work. It is awaiting review by Juno and has not yet been formally adopted. It is not legal advice.

About this policy

Juno Speech Pathology (“Juno”, “I”, “me”) is a speech pathology practice run by Mengmeng "Juno" Zhang, MSPA-CPSP, as a sole trader (ABN 87 274 043 179). As a health service provider, I am bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what information I collect, why, how it is stored and protected, who it may be shared with, and how you can access or correct it or make a complaint.

What information I collect

I collect only the information I need to provide speech pathology services. This may include:

  • Identity and contact details of the client and of parents, guardians, carers and other contacts — such as names, date of birth, phone, email and address (for home visits or invoices).
  • Relationship details — for example who is a guardian, who is authorised to receive information, and any relevant custody arrangements.
  • Health information — developmental, medical, educational and communication history, assessment results, session notes, goals, reports, referral letters and other documents you or others provide.
  • Funding and billing details — for example NDIS participant number, plan dates and plan manager, GP referral details for Medicare, private health fund name, and invoice and payment records. I never store card numbers.
  • Consent records — what you have agreed to, and when.

Health information is “sensitive information” under the Privacy Act. I collect it with your consent, or where the law otherwise allows.

How I collect it

  • Directly from you — by phone, email, in sessions, and through online intake and consent forms sent to you by secure, single-use link.
  • From others with your consent — for example your GP, paediatrician, school, early childhood service, other therapists or plan manager.

You can make a general enquiry without giving your name. It is usually not practicable to provide a speech pathology service anonymously or under a pseudonym.

Why I collect, use and disclose it

  • To assess, plan and provide speech pathology services, and keep accurate clinical records.
  • To communicate with you, including appointment reminders.
  • To issue invoices and receipts, and to support claims with the NDIS, Medicare or your health fund where relevant.
  • To liaise with schools, doctors and other professionals involved in the client’s care — only with consent.
  • To meet legal and professional obligations.

I do not sell personal information, use it for marketing, or share it with anyone for purposes unrelated to your care. I may disclose information without consent only where the law requires or permits it — for example to lessen or prevent a serious threat to someone’s life, health or safety, or when required by a court order.

How information is stored and protected

  • Practice system in Australia. Client records, notes, documents, invoices and forms are held in the practice’s own management system, hosted on Amazon Web Services (AWS) in the Sydney region (ap-southeast-2).
  • Encryption. Stored data is encrypted using keys managed in AWS Key Management Service, and all data is sent over encrypted (HTTPS/TLS) connections.
  • Restricted access. Only Juno can sign in to the system, and sign-in requires multi-factor authentication. There are no client or public logins. Technical administration of the underlying AWS account is limited to Juno and any technical support person she authorises.
  • Audit trail. The system keeps a record of changes to client records and of document downloads, including who made them and when. The audit trail itself does not contain clinical details. Finalised clinical notes are not overwritten; corrections are added as dated addenda.
  • Documents are kept in private storage that cannot be reached from the internet directly, and can only be opened through short-lived links (a few minutes) created for Juno.
  • Backups. The database has continuous backups that can restore data from any point in the previous 35 days.
  • Emails sent by the system (for example appointment reminders or form links) are sent from AWS in Sydney and do not contain clinical details.

Disclosure outside Australia

Client records are stored in Australia. Some limited information may be handled outside Australia:

  • Email. The practice email address (juno.speechtherapy@gmail.com) is provided by Google (Gmail), which may store email on servers outside Australia. For this reason, please don’t send detailed health information by email.
  • Website delivery and security. This website and the practice system are delivered through the AWS CloudFront network, and protected by a web application firewall. These services process technical information such as IP addresses and the pages requested, and some of it may be processed outside Australia (for example in the United States).
  • Telehealth. Video calls use a third-party video-conferencing service, which may process call data outside Australia. You’ll be told which service is used before your first telehealth session.

This website

This website has no contact forms, no cookies, no analytics and no advertising trackers. If you email or call, that information is handled as described in this policy.

How long records are kept

Health records are kept for as long as needed for your care and to meet legal and professional obligations, and are then securely destroyed or de-identified. As a guide, records are kept for at least 7 years after the last service, or for a client who was under 18, until they turn 25 — whichever is later. Financial records are kept for at least 5 years. Deleted information may remain in backups for up to 35 days.

Accessing and correcting your information

You can ask to see the information I hold about you (or your child), and ask for it to be corrected if it is inaccurate, out of date or incomplete. Please contact me using the details below. I will respond within a reasonable time, usually within 30 days. There is no charge to make a request.

For requests about a child, I will check that the person asking has the authority to access that information. In limited situations the law allows access to be refused; if so, I will explain why in writing. Corrections to finalised clinical notes are made as dated addenda, so the original record is kept.

Data breaches

If a data breach is likely to result in serious harm, I will notify affected people and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.

Questions and complaints

If you have a question or concern about privacy, please contact me first — I will look into it and respond in writing, usually within 30 days.

If you are not satisfied with my response, you can complain to the Office of the Australian Information Commissioner (1300 363 992). You can also raise concerns about a health service with the Office of the Health Ombudsman (Queensland). See also feedback and complaints.

Changes to this policy

This policy may be updated when practices or systems change. The current version will always be on this page.

Draft prepared 27 September 2026. Not yet adopted.