Privacy Policy

How we handle your information.

This policy is written in two columns: plain language on the left, legal detail on the right. Read whichever suits you — or both.

Last updated: April 2026

In plain language The legal detail
01 — Who We Are

Who We Are

Sohma House is a healthcare clinic in Cairns, Queensland. We provide medicinal cannabis consultations, integrative health services, and allied health care.

If you have questions about your privacy, contact Cameron Rosin (Practice Manager) at cam@sohma.house or visit us at 17 Anderson St, Manunda QLD 4870.

02 — What We Collect

What Information We Collect

We collect what we need to provide you with safe, informed healthcare. Nothing more.

Your details: name, date of birth, address, phone, email, Medicare number, emergency contact.

Your health information: medical history, current conditions, medications, allergies, cannabis treatment history, clinical notes from your consultations, intake questionnaire responses, and vitals.

Government identifiers: Medicare number, DVA number, or concession card details — for billing and prescribing purposes only.

When you use our website: your IP address is processed by our security provider (Cloudflare) to protect the site. If you book an appointment, fill in a contact form, register for a class, book a studio, or submit an application, we collect the information you enter. We use Google Maps to help you autocomplete your address — Google receives the text you type in the address field.

What we don't collect

No analytics. No tracking pixels. No third-party cookies. No data sold to anyone, ever.

Our website does not use Google Analytics, Facebook pixels, or any behavioural tracking. We don't build advertising profiles. We don't share your browsing activity with data brokers. The only reason we collect your information is to look after your health.

03 — Cannabis Confidentiality

Your Cannabis Treatment Is Confidential

Your decision to use medicinal cannabis is private. We will never tell your employer, your insurer, your family, or even your regular GP without your explicit permission.

We understand the stigma. Many of our patients don't want people in their lives to know they use cannabis medicine — and that is entirely your right. Your treatment details stay within the Sohma House care team unless you tell us otherwise.

Your regular GP: If your GP contacts us requesting your records, we will confirm with you first. We will not send anything without your explicit consent. Some patients specifically don't want their regular GP to know they attend our clinic, and we respect that completely.

Insurance and employers: We do not share your treatment information with insurers, employers, or any other third party. If you have concerns about how a cannabis prescription might affect your insurance, we recommend speaking with your insurer or a financial adviser directly.

One thing we must do: If your doctor prescribes cannabis through the TGA's Special Access Scheme (SAS-B), your name, condition, and proposed treatment are submitted to the Therapeutic Goods Administration. This is a legal requirement of the prescribing pathway — not our choice. Your prescriber will explain this to you and obtain your consent before any application is submitted.

Workplace drug testing: If you use THC-containing products, you may test positive on a workplace drug screen. This is an important clinical consideration that your prescribing doctor will discuss with you.

You don't need to tell us why you're concerned about privacy. Many of our patients have specific reasons — work, family, insurance — and we don't ask. We just protect your information as if everyone has a reason.

04 — Why We Collect It

Why We Collect It

We collect your information for one primary reason: to provide you with safe, informed healthcare.

Your health history helps your doctor make safe prescribing decisions. Your contact details let us send appointment reminders and follow-up communications. Your Medicare details allow us to process billing. And some information is collected because the law requires it — particularly for cannabis prescribing through the TGA.

05 — How We Use It

How We Use Your Information

Your information is used to:

  • Provide your clinical care — consultations, prescribing, treatment plans
  • Coordinate between practitioners on your care team (e.g., your GP and nurse share relevant clinical information to provide joined-up care)
  • Send you appointment reminders and clinical follow-ups
  • Process billing, Medicare claims, and invoices
  • Send prescriptions to your chosen pharmacy
  • Fulfil legal requirements (TGA reporting, record-keeping obligations)

We don't use your information for marketing or sell it to anyone.

06 — Who We Share With

Who We Share It With

We share your information only when necessary for your care or required by law:

  • Your Sohma House care team — practitioners involved in your treatment share relevant clinical information
  • Your pharmacy — so they can dispense your prescriptions
  • The TGA — if you're prescribed cannabis via the SAS-B pathway (legally required)
  • Medicare or DVA — for billing purposes
  • Other doctors or specialists — only with your explicit consent
  • Legal authorities — only when compelled by law (court orders, mandatory reporting)

We never share your information with employers, insurers, data brokers, advertisers, or any commercial third party.

07 — Where Your Data Lives

Where Your Data Lives

Your data is stored on secure Australian servers. We use industry-leading infrastructure providers who meet strict security standards. Your clinical records are stored in Australia.

Our scheduling system (Halaxy) is an Australian healthcare platform. Our clinical records database runs on Australian servers in Sydney. Every access to your records is logged in an immutable audit trail that cannot be altered or deleted.

The one exception: when you visit our website, the connection is protected by Cloudflare, which operates servers worldwide. Cloudflare handles website security only — it does not store your health information. See the next section for details.

08 — Cross-Border Data

Cross-Border Data

Your clinical records, health information, and patient data are stored in Australia on servers located in Sydney.

When you visit our website, your connection is secured by Cloudflare, which operates servers worldwide including in the United States. Cloudflare handles the website security layer only — it does not store your health data.

When we send you emails — appointment confirmations, reminders, or intake form links — these are delivered through a transactional email service (Postmark) that operates from the United States. The emails contain your name and appointment details but not your clinical records.

09 — Security

How We Protect Your Information

We take the security of your information seriously. Our platform uses multiple layers of protection:

  • Encryption: Your data is encrypted when it's sent to us (in transit) and when it's stored (at rest). Sensitive fields like SMS messages and clinical handover notes are individually encrypted.
  • Access controls: Staff can only see the information their role requires. A receptionist sees different information than a clinician.
  • Authentication: Staff access requires multiple verification steps — not just a password.
  • Audit trail: Every time someone accesses your records, it's logged permanently in a tamper-proof ledger. We know who accessed what, and when.
  • Screen protection: Sensitive information is masked on-screen and requires deliberate action to reveal. Workstations lock automatically after inactivity.
10 — Retention

How Long We Keep Your Records

We keep your health records for at least 7 years — that's the law for health records in Australia. If you were treated as a minor, we keep your records until you turn 25.

If your records are involved in a complaint or legal matter, we keep them until the matter is fully resolved.

If you stop being a patient, we still keep your records for the required period. We can't delete them early even if you ask — the law requires us to keep them. We dispose of records securely when the retention period ends.

11 — Consent & Withdrawal

Consent and Withdrawal

When you register with us, you consent to how we handle your information. Here's what that covers — and what you can change your mind about:

You can withdraw at any time:

  • Appointment reminders by email or SMS
  • Information sharing across the care team (though this may limit the quality of coordinated care we can provide — your doctor will explain)

You cannot withdraw while receiving SAS-B treatment:

  • TGA reporting — this is a legal requirement of the prescribing pathway. If your cannabis is prescribed through SAS-B, your application must be submitted to the TGA. You can discontinue treatment if you don't want this disclosure, but you cannot receive SAS-B treatment without it.

To withdraw consent for any optional use, contact us at cam@sohma.house. Withdrawal is always prospective — it applies from the date you tell us, not retrospectively.

12 — Your Rights

Your Rights

Under Australian privacy law, you have the right to:

  • See your records. You can request access to the personal and health information we hold about you. We'll respond within 30 days.
  • Fix mistakes. If something in your record is factually wrong — a wrong date of birth, an incorrect medication, a misspelled name — you can ask us to correct it. Clinical judgments (your doctor's assessment) are not subject to patient-directed correction, but factual errors are.
  • Complain. If you believe we've mishandled your information, raise it with us first — we'd prefer that, because we want to fix it. If you raise a privacy concern, our Practice Manager will investigate and respond within 30 days. We take every concern seriously — it's how we improve. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner.

To exercise any of these rights, contact Cameron Rosin (Practice Manager) at cam@sohma.house.

13 — Data Breaches

What Happens If Something Goes Wrong

If we ever experience a data breach that could seriously affect you, we'll tell you directly and we'll tell the Office of the Australian Information Commissioner. We have a detailed data breach response plan, and our staff are trained to report any suspected breach immediately.

We don't wait to be certain before acting. If there's a reasonable suspicion that your information may have been compromised, we investigate immediately and notify you as soon as we know the facts.

14 — Changes

Changes to This Policy

We may update this policy from time to time — for example, if the law changes, if we add new services, or if we change how we handle information. When we do, we'll update the date at the top of this page.

For significant changes that affect how we use your health information, we'll notify you directly and give you the opportunity to discuss any concerns with your treating practitioner before the changes take effect.

15 — Contact

Contact Us

If you have any questions about this policy, want to access or correct your information, or have a privacy concern, contact our Practice Manager:

Cameron Rosin — Practice Manager

Sohma House

17 Anderson St, Manunda QLD 4870

Email: cam@sohma.house