Since 2020, telehealth has evolved from an emergency stopgap during the pandemic into a permanent, mainstream channel for delivering healthcare across Australia. What began as phone and video calls to reduce viral transmission has matured into sophisticated, multi-disciplinary virtual care models. By early 2025, clinicians report that up to 35–40% of routine consultations now occur via telehealth platforms.
In response to this rapid expansion, online provider Eucalyptus has published an initial proposal to support a discussion about industry-wide standards in a post about Telehealth 2025 Best Practice Principles. These principles set out comprehensive requirements for clinical safety, patient care and data protection in these settings.
We wanted to highlight the 2025 Principles, unpack their three core categories and provide guidance for Australian clinics and practitioners to align with these benchmarks—ensuring safe, effective and trusted telehealth services.
Key Summary
- Posted in May 2025.
- Principles organised into three categories: Clinical Safety, Quality & Governance; Good Patient Care; Data Protection & Security.
- Key focus areas include real-time consult requirements, credentialling, consent, EHR integration, auditing and encryption.
- Other resources about telehealth: Essential Tools for Successful Telehealth OT Sessions, Virtual Collaboration in Healthcare, How to Set Up Telehealth in Medical Centres
The 2025 Principles
In May 2025, Eucalyptus released its Best Practice Principles for Australian Online Telehealth Providers. Published by The Medical Republic and discussed by Founder Tim Doyle on LinkedIn, it fills a regulatory gap in Australia’s telehealth landscape.
Lyndon Goddard, Head of Public Policy at Eucalyptus, explained that the Australian Commission on Safety and Quality in Health Care (ACSQHC) has yet to finalise a virtual care standard. After more than two years of anticipation and no formal progress, Eucalyptus decided to lead the initiative from an industry perspective. Clinical Director Dr Matt Vickers emphasised that telehealth presents a unique risk profile compared to in-person care—everything from identity verification to continuity and interoperability demands bespoke guidance.
The proposal addresses four overarching domains:
- Clinical Safety, Quality & Governance: Protocols for safe prescribing, real-time consultation requirements, incident management, credentialling and remuneration safeguards.
- Continuity of Care & Patient Outcomes: Consent to contact regular GPs, clinical handovers, My Health Record integration and outcome benchmarking.
- Data Protection & Security: Access controls, vulnerability and penetration testing, system monitoring and encryption standards.
- Governance Framework: Self-regulatory code with external evaluation, leading to formal accreditation and regulatory oversight.
Notably, the document highlights the absence of telehealth-specific accreditation and regulation at a company level in Australia. While Medicare billing rules apply to bulk-billed services, many online-only clinics operate entirely on private billing, escaping standard Commonwealth oversight. Late in 2024, AHPRA launched a rapid-response oversight group to monitor high-risk telehealth prescribing of medicinal cannabis and weight-loss drugs—but a comprehensive governance mechanism remains an industry priority.
The ACSQHC has indicated its intention to extend the upcoming third edition of the National Safety and Quality Health Service (NSQHS) Standards to address digital-tool risks, and its existing NSQDMH Standards provide a framework for digital mental health services. However, Eucalyptus’s principles aim to cover the full spectrum of telehealth modalities, from telephone and videoconferencing to remote monitoring and mobile apps.

The Three Categories of Principles
The Telehealth 2025 Best Practice Principles are structured into three interlocking categories. Together, they provide a complete framework for designing, delivering and governing virtual care services:
- Clinical Safety, Quality & Governance
- Good Patient Care
- Data Protection & Security
Clinical Safety, Quality & Governance ensures every telehealth service has robust protocols: from requiring a synchronous (video or phone) consultation at least annually, to verifying patient identity via IHI or photo ID, to defining internal clinical indicators for error benchmarking. It mandates formal credentialling processes—aligned with AHPRA and NSQHS standards—and clear accountability structures, such as a dedicated Clinical Governance Committee.
Good Patient Care emphasises evidence-based models: treatment options must reflect current clinical guidelines, outcomes data should be measured against national benchmarks, and patients must receive ongoing support, including side-effect guidance and referrals to in-person practitioners when needed. Informed consent is recorded via multiple media, and clear clinical handovers maintain continuity of care—particularly through My Health Record uploads.
Data Protection & Security covers compliance with the Privacy Act 1988 and My Health Records Act 2012, requiring end-to-end encryption, strict access controls (unique accounts, 2FA), regular vulnerability assessments and annual penetration tests. It also includes system-event logging, phishing simulations for staff, and tested backup/restoration procedures to ensure data integrity and availability.
As Tim Doyle notes on LinkedIn, these three pillars interconnect to form a dynamic standard, enabling telehealth providers to benchmark performance and adapt to emerging risks over time.
Key Details Within Each Category
A. Clinical Safety, Quality & Governance
- Clinical Protocols: Standardise risk assessments and prescribing processes in line with ARTG listings; include synchronous consultation mandates (phone or video) and escalate to in-person care when needed.
- Verification Processes: Verify identity via Individual Healthcare Identifier (IHI), photo ID or GP confirmation; cross-verify medical history through additional consultations or external records (pharmacist, My Health Record).
- Credentialling & Scope: Align with AHPRA and NSQHS credentialling requirements: confirm qualifications, registrations and scope of practice; for non-GP practitioners, assess experience and supervision plans.
- Clinical Indicators & Audits: Define metrics for consultation comprehensiveness, note accuracy, treatment understanding and clinician conduct; audit high-risk consults, new-practitioner sessions and random samples quarterly.
- Incident & Safety Reporting: Maintain RCA processes for incidents; report prescribing errors, adverse events, duplicate-account attempts and technical outages; review findings quarterly with governance committee.
- Remuneration Integrity: Design payment models that safeguard prescribing autonomy and avoid per-script incentives that could bias clinical decisions.
B. Good Patient Care
- Evidence-Based Model of Care: Base treatment pathways on current clinical evidence; update protocols as guidelines evolve; measure outcomes against national and international benchmarks.
- Consent & Handover: Obtain explicit, documented telehealth consent; prepare handover summaries when care transitions back to regular GPs; upload relevant notes to My Health Record.
- Ongoing Support & Feedback: Provide side-effect guidance, medication instructions and referrals to pharmacies or allied health when appropriate; solicit patient feedback through surveys and review complaints promptly.
- Record Consistency: Ensure internal records use standardised clinical terminology and are clear, comprehensive and interoperable with other health systems.
C. Data Protection & Security
- Regulatory Compliance: Adhere to Privacy Act 1988, My Health Records Act 2012 and state health privacy laws; maintain clear privacy notices and patient rights documentation.
- External Evaluation: Secure accreditation against ISO/IEC 27001 and AICPA SOC 2 frameworks; review certificates annually.
- Access Control: Issue unique user accounts, enforce strong passwords and 2FA; conduct quarterly reviews to remove stale or unnecessary access rights.
- Vulnerability Management & Testing: Implement policies to detect, prioritise and remediate software/hardware vulnerabilities; perform annual penetration tests and regular vulnerability scans.
- Security Awareness & Monitoring: Deliver onboarding and ongoing cybersecurity training, including simulated phishing; configure system logs and alerts for unauthorised access attempts or anomalies.
- Backups & Incident Recovery: Back up all systems and databases daily; test restoration procedures quarterly to ensure rapid recovery and data integrity.

Conclusion
The Telehealth 2025 Best Practice Principles represent a milestone for virtual care in Australia. By embedding these standards—across clinical safety, patient-centred care and rigorous data protection—your practice can deliver telehealth that is safe, compliant and respected by patients and regulators alike. Start by mapping your current processes to the three categories, engaging staff in targeted training and partnering with accredited vendors to close any gaps.
Disclaimer: This blog is intended as a general overview of the topic and should not be construed as professional legal or medical advice.
Sources
- Medical Republic (May 2025), “Telehealth giant releases best practice principles”
- Tim Doyle LinkedIn post (2025), “Telehealth Best Practice Principles for Australian Online Providers”

