Current as of: 23rd October 2023
Why and when your consent is necessary
When you register as a patient of our practice, you provide consent for our GPs and practice staff to access and use your personal information so they can provide you with the best possible healthcare. Only staff who need to see your personal information will have access to it. If we need to use your information for anything else, we will seek additional consent from you to do this.
Why do we collect, use, hold and share your personal information?
Our practice will need to collect your personal information to provide healthcare services to you. Our main purpose for collecting, using, holding and sharing your personal information is to manage your health. We also use it for directly related business activities, such as financial claims and payments, practice audits and accreditation, and business processes (eg staff training).
What personal information do we collect?
The information we will collect about you includes:
- names, date of birth, addresses, contact details
- medical information including medical history, medications, allergies, adverse events, immunisations, social history, family history and risk factors
- Medicare number (where available) for identification and claiming purposes
- healthcare identifiers
- health fund details
- details associated with over the phone payments (MOTO) provided to administration for services rendered are not retained in any form, once payment has been completed.
- telephone and telehealth interactions are not recorded
Dealing with us anonymously
You have the right to deal with us anonymously or under a pseudonym unless it is impracticable for us to do so or unless we are required or authorised by law to only deal with identified individuals.
How do we collect your personal information?
Our practice will collect your personal information:
- When you make your first appointment our practice staff will collect your personal and demographic information via your registration.
- During the course of providing medical services, we may collect further personal information, such as through Electronic Transfer of prescriptions and My Health Record, via shared health summaries and event summaries.
- We may also collect your personal information when you visit our website, send us an email or SMS, telephone us, make an online appointment or communicate with us using social media.
- In some circumstances personal information may also be collected from other sources. Often this is because it is not practical or reasonable to collect it from you directly. This may include information from:
- your guardian or responsible person
- other involved healthcare providers, such as specialists, allied health professionals, hospitals, community health services and pathology and diagnostic imaging services
- your health fund, Medicare, or the Department of Veteran’s Affairs (as necessary).
Who do we share your personal information with?
We sometimes share your personal information:
- with third parties who work with our practice for business purposes, such as accreditation agencies or information technology providers – these third parties are required to comply with APPs and this policy, this includes but it is not limited to HotDoc Pty Ltd. Hot Doc provide services relating to on-line booking, follow-up of results, health promotion and payment systems. Best Practice Pty Ltd is our medical software provider, they may at times have access to limited information in order to support our IT systems, they are also required to comply with APP’s.
- with other healthcare providers
- approved clinical trial providers
- when it is required or authorised by law (eg court subpoenas)
- when it is necessary to lessen or prevent a serious threat to a patient’s life, health or safety or public health or safety, or it is impractical to obtain the patient’s consent
- to assist in locating a missing person
- to establish, exercise or defend an equitable claim
- for the purpose of confidential dispute resolution process
- when there is a statutory requirement to share certain personal information (eg some diseases require mandatory notification)
- during the course of providing medical services, through Electronic Transfer of Prescriptions (eTP), MyHealth Record/PCEHR system (eg via Shared Health Summary, Event Summary), electronic transmission of referrals.
Only people that need to access your information will be able to do so. Other than in the course of providing medical services or as otherwise described in this policy, our practice will not share personal information with any third party without your consent.
We will not share your personal information with anyone outside Australia (unless under exceptional circumstances that are permitted by law) without your consent.
Our practice will not use your personal information for marketing any of our goods or services directly to you without your express consent. If you do consent, you may opt-out of direct marketing at any time by notifying our practice in writing.
How do we store and protect your personal information?
We hold your personal information in a number of forms, including electronic or digital images, and hard copy paper based documents. We employ a range of physical and electronic security measures to ensure your personal information is adequately protected. These measures include:
- storing your personal information in a secure facility;
- using anti-virus software to protect electronic information; and
- limiting access to your personal information to those persons who are required to access it for the purpose of providing services to you or us. Our internet service provider may record details of visits to our website. This information will only be used by us internally for statistical and research purposes.
- referrals are generally created from electronic templates within our medical software, this ensures only information from your medical record is included in external referrals.
How can you access and correct your personal information at our practice?
We will take reasonable steps to ensure that the personal information held by us is accurate, up-to-date, complete, relevant and not misleading. You have a right to access your personal information. Such access may be granted or refused in accordance with the APPs. We are not obliged to provide access if:
- we reasonably believe that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety;
- giving access would have an unreasonable impact on the privacy of other individuals;
- the request for access is frivolous or vexatious;
- the information relates to existing or anticipated legal proceedings between you and us and would not ordinarily be accessible by the discovery process in such proceedings;
- giving access would reveal our intentions in relation to negotiations with you in a way that would prejudice those negotiations;
- giving access would be unlawful;
- denying access is required or authorised by or under an Australian law or a court/tribunal order;
- we have reason to suspect that unlawful activity, or misconduct of a serious nature relating to our functions or activities has been, is being or may be engaged in and giving access would be likely to prejudice the taking of appropriate action in relation to the matter;
- giving access would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or
- giving access would reveal internal evaluative information in connection with a commercially sensitive decision-making process.
To request access to personal information, please complete the Request to Access Medical Records form which is available from Mingara Medical. You may also request that your personal information be corrected if you believe it to be inaccurate, incorrect or incomplete.
If you make a request for access to or correction of personal information, we will:
- respond to your request within a reasonable period; and
- if reasonable and practicable, give access to or correct the information in the manner requested.
- If we refuse your request, we will provide you with written reasons for doing so.
Integrity Of Your Personal Information
We will take reasonable steps to:
- ensure that the personal information that we collect is accurate, up to date and complete;
- ensure that the personal information we hold, use or disclose is, with regard to the relevant purpose, accurate, up to date, complete and relevant; and
- secure your personal information.
We will take reasonable steps to protect personal information from misuse, interference and loss, unauthorised access, modification or disclosure. We will also take reasonable steps to destroy or de-identify personal information that we hold if we no longer need the information for the primary purpose for which the information was collected and we are not otherwise required by law to retain the information.
Your information is required to be retained by the practice by NSW legislation for:
- Adult: 7 years from the date of the last entry
- Child: Until the age of 25 years.
How can you lodge a privacy related complaint?
We take complaints and concerns regarding privacy seriously. You should express any privacy concerns you may have in writing to 2/7 Mingara Drive, Tumbi Umbi, NSW, 2261. We will then attempt to resolve it in accordance with our resolution procedure which dictates a response within 30 days.
You may also contact the OAIC. Generally the OAIC will require you to give them time to respond, before they will investigate. For further information visit www.oaic.gov.au or call the OAIC on 1300 363 992.
Policy review statement
This policy will be updated annually, and the new policy will be uploaded to our website.