Privacy Policy

Sewry Holdings Pty Ltd trading as Precision Surgical Billing

Last updated: 19 August 2026

 

1. Who we are

Precision Surgical Billing is operated by Sewry Holdings Pty Ltd. We provide medical and surgical billing, aged debtor recovery and related administrative support services to specialist medical practices and medical practitioners. In providing these services, we may handle personal information and sensitive health information on behalf of our clients.

We are committed to managing personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and other privacy obligations that apply to our activities.

 

2. The information we collect and hold

The information we collect or hold depends on the services being provided and may include:

• Patient full name, date of birth, residential or postal address and contact details

• Medicare number and Individual Reference Number (IRN)

• Private health fund membership details

• Department of Veterans' Affairs (DVA) details where relevant

• Workers' compensation, insurer or third-party payer details where relevant

• Billing, account and payment information required to process or reconcile accounts

• Information about procedures, services, item numbers, service dates, referrals or other information required for billing and claims processing

• Correspondence and information relating to rejected, adjusted, unpaid or outstanding claims and aged debtors

• Contact details for medical practitioners, practice managers and other authorised practice representatives

• Name, phone number and email address submitted through our website or other business enquiry channels.

Health information is sensitive information under Australian privacy law and is handled with additional care.

 

3. How we collect information

Patient information is generally provided to us by the medical practitioners and practices that engage us, rather than collected directly from patients. Information may be provided through:

• secure access to a client's practice management or billing system, including approved remote-access arrangements

• Halaxy or another practice management system authorised by the client

• secure Microsoft 365 or SharePoint file-sharing arrangements

• secure email or other authorised communication channels where required

• communications with Medicare, private health funds, DVA, insurers and other authorised parties in connection with billing or claims.

We do not require or encourage sensitive patient information to be sent through unsecured channels. Where we collect personal information indirectly, we and our clients will take reasonable steps, where required, to ensure individuals are appropriately informed about how their information is handled.

 

4. Why we collect, hold, use and disclose information

We collect, hold, use and disclose personal and health information only where reasonably necessary for our functions and services, including:

• preparing, submitting and managing medical and surgical billing

• submitting, following up and reconciling Medicare, private health fund, DVA, insurer and private billing claims

• managing claim rejections, adjustments, resubmissions and payment discrepancies

• following up outstanding accounts and providing aged debtor recovery services

• communicating with medical practitioners, practices, patients and authorised payers about billing matters

• maintaining business records and meeting legal, regulatory, insurance and accounting obligations

• responding to enquiries about our services.

We do not sell patient information or use patient health information for unrelated marketing purposes.

 

5. Disclosure of information

Where necessary to provide our services, personal or health information may be disclosed to authorised recipients such as:

• Medicare Australia

• private health funds

• the Department of Veterans' Affairs

• workers' compensation, motor accident or other insurers where relevant

• the medical practitioner or practice responsible for the patient's account

• patients or their authorised representatives where appropriate

• technology or service providers used to support billing, secure communication, file storage or claims processing

• government agencies, regulators, courts or other bodies where required or authorised by law.

We take reasonable steps to limit disclosure to authorised recipients and to the information reasonably necessary for the relevant purpose.

 

6. Third-party platforms and service providers

We use third-party technology providers to support our services. These may include:

• Halaxy - used for practice management, billing and claims processing where selected for a client. Halaxy states that Australian practice data is stored in Australia.

• Microsoft 365, including Outlook and SharePoint - used for business email, secure document collaboration and file sharing.

• Xero - used for our own business accounting and invoicing. Xero may contain business contact and financial information relating to our clients. Patient personal or health information is not entered into or stored in Xero.

We may change service providers from time to time. We take reasonable steps to select providers with appropriate privacy and security safeguards and will update this policy where a material change affects how personal information is handled.

 

7. Overseas disclosure and processing

We aim to keep patient health information within systems and arrangements appropriate for Australian healthcare billing. Halaxy states that Australian practice data is stored in Australia. Some technology providers we use may operate globally or use overseas personnel or subprocessors for support, infrastructure or ancillary services.

Where our use of a service provider results in a disclosure of personal information to an overseas recipient, we take reasonable steps as required by APP 8 to ensure the information is handled consistently with applicable Australian privacy requirements. Depending on the provider and service used, business contact or account information may be processed in countries including Australia, New Zealand and the United States. We do not intentionally send patient health information overseas unless this is necessary, authorised and appropriately protected.

 

8. How information is held and stored

Our approach is to minimise unnecessary storage and duplication of personal information. In most cases, patient information is accessed directly through a client's system or an authorised secure platform. Where information is entered into Halaxy or another authorised system, it is stored within that system in accordance with the relevant client arrangement and provider controls.

Where information is temporarily received in a document or email, we transfer it to the appropriate system where required and securely delete unnecessary local copies when they are no longer needed, subject to legal, contractual and record-keeping requirements.

 

9. Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include:

• multi-factor authentication (MFA) for systems and accounts where available

• password-protected, encrypted and access-controlled devices

• restricting access to authorised personnel only

• automatic device locking and other endpoint security controls

• anti-malware and security software

• regular software and security updates

• secure remote-access methods approved by the relevant client or technology provider

• secure file-sharing and communication methods

• regular backup of critical business data and appropriate recovery arrangements.

 

10. Retention and destruction

We retain personal information only for as long as reasonably necessary to provide our services, manage accounts, resolve disputes and meet legal, contractual, insurance or record-keeping obligations. When information is no longer required and we are permitted to do so, we take reasonable steps to securely delete, destroy or de-identify it.

Where records remain within a client's practice management system, the client generally controls the retention period for those records.

 

11. Email and communications

In some circumstances, personal or health information may need to be communicated by email or other electronic means for billing, claims processing or account follow-up. Where this occurs, we take reasonable steps to verify recipients, limit the information shared to what is necessary, and use appropriate security safeguards.

 

12. Data breaches

If we become aware of an actual or suspected data breach involving personal information, we will promptly assess and contain the incident, take reasonable steps to reduce harm, notify the relevant client and other affected parties where appropriate, and comply with the Notifiable Data Breaches scheme and other applicable legal obligations where required.

 

13. Access and correction

Individuals may request access to, or correction of, personal information held about them. Because we generally act on behalf of medical practitioners and practices, requests relating to patient records should usually be directed first to the relevant medical practitioner or practice. We will cooperate with our clients and respond to requests as required by applicable privacy law.

If you believe personal information we hold directly about you is inaccurate, incomplete or out of date, you may contact us using the details at the end of this policy.

 

14. Privacy complaints

If you believe we have mishandled personal information or breached the Australian Privacy Principles, please contact us in writing using the details below and provide enough information for us to understand and investigate your concern.

We will acknowledge and assess privacy complaints and aim to provide a substantive response within 30 days where reasonably practicable. If you are not satisfied with our response, you may be able to make a complaint to the Office of the Australian Information Commissioner (OAIC).

 

15. Anonymity and pseudonyms

Where practicable and lawful, individuals may interact with us without identifying themselves or by using a pseudonym. However, identification will usually be required where it is necessary to process medical billing, claims, payments, account recovery or respond to a matter relating to a particular patient or account.

 

16. Website enquiries

Our website may collect limited personal information through contact or enquiry forms, including name, email address, phone number, practice details and information voluntarily included in an enquiry. We use this information to respond to enquiries and manage prospective client communications. We do not use patient health information submitted through general website enquiry forms and ask users not to include sensitive patient information in those forms.

 

17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology providers, business practices or legal obligations. The current version will be published on our website with the date of the latest update.

 

18. Contact

For questions, access or correction requests, or privacy complaints, please contact:

Precision Surgical Billing

Sewry Holdings Pty Ltd

Phone: 1300 269 820

Email: info@precisionsurgicalbilling.com.au

ABN: 12 683 662 991