Version: 1.0
Date: 20/09/2025
Author: Director
Status: Active
This policy explains how we collect, use, store and share your personal information, and the limited circumstances in which we may need to disclose it to others involved in your care.
A patient health record means all health information we hold about you in any form (electronic or paper), including clinical notes, history, medications, allergies, immunisations, referrals, correspondence from other providers, investigation requests/results, images, care plans, prescriptions, consents, communications (phone/SMS/email logs relevant to care), and Medicare/DVA claiming details kept by our practice.
When you register as a patient you give consent for our GPs and staff to access and use your personal information to deliver healthcare.
If we ever wish to use your information for a non-healthcare purpose (e.g. direct marketing) we will first obtain your additional, explicit consent.
Yes, where practical and lawful. For most clinical services we must confirm your identity to meet safety and Medicare requirements.
Note: We do not permit clinical photos to be taken on personal devices.
Where lawful and practicable, you may interact with us anonymously or using a pseudonym (e.g., general enquiries). Identification is required where mandated by law (e.g., prescriptions, Medicare claiming) or where anonymity is impracticable for safe clinical care.
For your ongoing care, we rely on implied consent to share relevant information with other treating providers (you can tell us not to share; we'll record and respect that unless required or authorised by law).
We may share information:
| Purpose | Typical recipient |
|---|---|
| Ongoing care | Other GPs, specialists, pathology & imaging providers |
| Business services | Accreditation bodies; IT vendors (bound by confidentiality and the Australian Privacy Principles) |
| Legal obligations | Court orders/subpoenas; mandatory disease notifications |
| Serious threat | To prevent or lessen a serious threat to life, health or safety |
| De-identified quality data | Primary Health Network (population-health reporting; de-identified only) |
We do not disclose identifiable patient information to overseas recipients. Our clinical software, secure messaging, hosting and backups are located in Australia, and our vendor contracts prohibit offshore access to identifiable patient data. If you ask us to send records to an overseas provider, we will obtain your explicit consent and handle it under APP 8. If this position changes, we will update this policy and, where practicable, list the relevant countries.
With your consent we may send targeted health-promotion messages (e.g. flu-clinic reminders) by SMS/email. You can opt out at any time. We do not sell or rent patient lists to third parties.
De-identified data are periodically supplied to the PHN and used internally for audit, research and staff education. Patients who do not wish their data to be included can advise reception.
We generate referrals, health-summaries and certificates through Best Practice (clinical software) and HealthLink secure messaging. Access is restricted by individual log-ins and role-based permissions.
We use Heidi AI to assist doctors with note-taking.
Patients may request that Heidi AI not be used during their consultation.
Submit a written request (email or letter) to [email protected] or mail to PO Box 44 Unanderra NSW 2526.
We will respond within 30 days. There is no fee for access or correction, though a reasonable charge may apply for large record compilations or transfers. Proof of identity (3 identifiers) is required.
How to request records:
See Requests for Medical Information policy for full process, fees, and timeframes.
Write to the Privacy Officer using the contact details in Section 2. We aim to resolve all complaints within 30 days.
If you are not satisfied, you may contact:
If you are in NSW and believe your health information privacy has been breached, you may also complain to the NSW Information and Privacy Commission (IPC) under the Health Records and Information Privacy Act 2002. Time limits and process are explained by the IPC: https://www.ipc.nsw.gov.au/resources/fact-sheet-privacy-related-complaints-under-hrip-act
See Health Information Management policy for full retention procedures.
Our public website does not collect personal information via contact forms. We use Google Analytics cookies to collect aggregated, anonymous usage statistics.
This policy is reviewed at least annually or whenever we change how we operate or when legislation changes. The latest version is always available on our website; significant changes will be communicated directly to patients.
Next review date: 20/09/2026