On Point Family Practice understands the importance to our patients of maintaining privacy in relation to the personal information we collect, use, disclose, hold or otherwise handle in connection with managing our patients. This Privacy Policy sets out how we comply with our obligations under the Privacy Act 1988 and other relevant State and Territory legislation in handling your personal information. By attending our practice, you consent to your personal information being collected, used, disclosed, stored, and otherwise handled in accordance with this Policy and other relevant arrangements between us. We may change our Privacy Policy from time to time by publishing changes to it on our website. You should check our website periodically to ensure you are aware of our current Privacy Policy.
Personal information is information or an opinion about an identified or reasonably identifiable person, whether or not true and whether recorded in a material form or not. Within this Privacy Policy unless indicated otherwise, references to personal information also include sensitive information such as information or an opinion about your health, or health services provided to you. We will only collect personal information from you where reasonably necessary for purposes directly related to our functions or activities. We will only collect as much personal information as we and medical practitioners operating from our medical centre need to provide you with services (including medical services) and to allow us to obtain payment for those services.
The types of personal information we may collect and hold about you include:
We may also collect personal information from you when you use and access our websites (including any information contained in an online enquiry or a request for an appointment, device type and ID, IP address, pages you visited, time and date of visit and geo-location information).
If you do not provide us with all the personal information we request, medical practitioners operating from our medical centre may not be able to provide medical services to you. We collect personal information about you in several ways, including from:
When you attend our practice to obtain services from the medical practitioners operating from the practice, we create a unique digital medical record for you. When you visit our websites, a small data file called a “cookie” is stored on your computer or mobile device by our server. We use cookies to maintain user sessions and to generate statistics about the number of people that visit our websites. Generally, this information will not identify you and we do not link it back to your identity or other information that you have provided to us.
We collect, use, disclose and handle personal information about you for the purpose of delivering, or facilitating the delivery of medical and health services, including to:
We use and handle your personal information as is reasonably incidental to our ordinary course operations, including where necessary to manage our administration, store data, conduct systems maintenance and penetration testing, and manage accounts and payment for the services provided to you. Subject to compliance with applicable Australian law, these incidental operations shall include our use and, where necessary, disclosure of your personal information:
Where you attend the medical centre you will be taken to have consented to the receipt of such materials (including by SMS and email), and to the use and disclosure of your personal information for this purpose. You may opt-out of receiving such materials by contacting the Privacy Officer below or following the unsubscribe process described in the relevant material.
We may share your information if:
We may use de-identified information (derived from your personal information) for internal teaching purposes or to monitor, evaluate, plan and improve the services provided at our practice. We may use your personal information to provide third parties (such as universities, government organisations and pharmaceutical companies) with aggregated, de-identified health information about our patients. These third parties may use the bulk de-identified information they receive from us for their business purposes. Should you, at any time, wish to withdraw your consent for your personal information to be part of a de-identified information database, please notify our Privacy Officer using the contact details below providing your full name, date of birth and address. Withdrawing this consent will not affect the relationship between you and your medical practitioner, nor will it hinder your ability to access services at a Centre. If third parties undertaking research request identified data (ie. personal information) from our medical records, we will only provide such identified data if:
We may also access, use or disclose your personal information:
We will use best endeavours to ensure your personal information is only stored and accessible from within Australia. However, we may disclose your personal information, or enable it to be accessed by:
We may hold your personal information in either electronic or hard copy form. We take reasonable steps, and implement reasonable safeguards, to protect your personal information that we hold from misuse, interference and loss, as well as unauthorised access, modification and disclosure. We ensure that we and the medical practitioners handle all patient information securely and in accordance with this Privacy Policy and professional duties of confidentiality. We and medical practitioners operating in our practice are subject to a range of obligations relating to the periods for which health information and records must be retained.
We must generally retain health information about an individual until at least an individual turns 25 – if we collected the information before the individual was 18, or 7 years from the last occasion on which that health information was altered, or a health service was provided to that individual from the practice. Following such retention periods, if we no longer require personal information for a purpose permitted by Australian law, we will take reasonable steps to securely destroy or de-identify such personal information.
You (or your parent, guardian, attorney, authorised representative or responsible person) may request (i) details of what personal information we hold about you; or (ii) access to, or that corrections be made to, the personal information we hold about you, by contacting the Privacy Officer (details below). Following such retention periods, if we no longer require personal information for a purpose permitted by Australian law, we will take reasonable steps to securely destroy or de-identify such personal information.
You (or your parent, guardian, attorney, authorised representative or responsible person) may request (i) details of what personal information we hold about you; or (ii) access to, or that corrections be made to, the personal information we hold about you, by contacting the Privacy Officer (details below). Please include your name, email address and/or telephone number and clearly describe your concerns or complaint. We will endeavour to respond to your complaint within a reasonable time after it is made. If you are unhappy with our response, we will provide you with information about further steps you can take.
Privacy Officer – Principal GP
Dr Alexander Baggott