Our practice is committed to best practice in relation to the management of information we collect. This practice has developed a policy to protect patient privacy in compliance with the Privacy Act 1988 (Cth) (‘the Privacy Act’). Our policy is to inform you of:
- the kinds of information that we collect and hold, which, as a medical practice, is likely to be ‘health information’ for the purposes of the Privacy Act;
- how we collect and hold personal information;
- the purposes for which we collect, hold, use and disclose personal information;
- how you may access your personal information and seek the correction of that information;
- how you may complain about a breach of the Australian Privacy Principles and how we will deal with such a complaint;
- whether we are likely to disclose personal information to overseas recipients;
The type of information we may collect and hold includes:
- Your name, address, date of birth, email and contact details
- Medicare number, DVA number and other government identifiers, although we will not use
these for the purposes of identifying you in our practice
Other health information about you, including:
- notes of your symptoms or diagnosis and the treatment given to you
- your specialist reports and test results
- your appointment and billing details
- your prescriptions
- your genetic information
- your healthcare identifier
We will generally collect personal information:
- from you directly when you provide your details to us. This might be via a face to face discussion, telephone conversation, registration form or online form
- from a person responsible for you
- from third parties where the Privacy Act or other law allows it – this may include, but is not limited to: other members of your treating team, diagnostic centres, specialists, hospitals, the My Health Record system, electronic prescription services, Medicare, your health insurer, the Pharmaceutical Benefits Scheme
In general, we collect, hold, use and disclose your personal information for the following purposes:
- To provide health services to you
- To communicate with you in relation to the health service being provided to you
- To comply with our legal obligations, including, but not limited to, mandatory notification of communicable diseases or mandatory reporting under applicable child protection legislation.
- To help us manage our accounts and administrative services, including billing, arrangements with health funds, pursuing unpaid accounts, management of our ITC systems
- For consultations with other doctors and allied health professional involved in your healthcare;
- To obtain, analyse and discuss test results from diagnostic and pathology laboratories
- For identification and insurance claiming
- If you have a My Health Record, to upload your personal information to, and download your personal information from, the My Health Record system. As of the 31/12/2020 we do not currently participate in the My Health Record System
- To liaise with your health fund, government and regulatory bodies such as Medicare, the Department of Veteran’s Affairs and the Office of the Australian Information Commissioner (OAIC) (if you make a privacy complaint to the OAIC), as necessary.
You have a right to seek access to, and for correction of the personal information, which we hold about you. For details on how to access and correct your health record, please contact our practice as noted below under ‘Contact Details.’
We will normally respond to your request within 30 days.
Our staff are trained and required to respect and protect your privacy. We take reasonable steps to protect information held from misuse and loss and from unauthorised access, modification or disclosure.
Your personal information may be stored at our practice in various forms. The majority of our records are in electronic format. Any correspondence, received in an alternative method, are then scanned into your personal records and the paper document is then shredded. X-rays, CT scans and similar are not held by the practice and are the responsibility of the patient. Documented photos are stored in your electronic records.
Our practice stores all personal information securely. All electronic patient records, personal information and financial information are securely stored using individual passwords, confidentiality agreements for any staff and or contractors entering the premises. This system is maintained both within the practice, and via our IT consultants. Encrypted Back-ups of all data are performed daily and held securely in the event of a fire or similar.
If you have any questions about privacy-related issues or wish to complain about a breach of the Australian Privacy Principles or the handling of your personal information by us, you may lodge your complaint in writing to (see below for details). We will normally respond to your request within 30 days.
If you are dissatisfied with our response, you may refer the matter to the OAIC:
Phone:1300 363 992
Fax: +61 2 9284 9666
Post: GPO Box 5218
Sydney NSW 2001
The Privacy Act provides that individuals must have the option of not identifying themselves, or of using a pseudonym, when dealing with our practice, except in certain circumstances, such as where it is impracticable for us to deal with you if you have not identified yourself.
This Policy will be reviewed from time to time to take account of new laws and technology, changes to our operations and other necessary developments. Updates will be publicised on the practice’s website.