Mernda GP Clinic Privacy Policy

Introduction

This privacy policy is to provide information to you, our patient, on how your personal information (which includes your health information) is collected and used within our practice, and the circumstances in which we may share it with third parties.

Why and when your consent is necessary?

Upon registering as a patient at our practice, you provide consent for our medical practitioners and practice staff to access and use your personal information, ensuring the best delivery of healthcare services. Your personal information is only accessible by authorised staff members when it is necessary to deliver care. Should we require your information for other purposes, we will always obtain further consent from you.


Why do we collect, use, hold and share your personal information?

Our practice will need to collect your personal information to provide healthcare services to you. Our main purpose for collecting, using, holding and sharing your personal information is the effective management of your health. Additionally, this data is utilized for directly related business activities such as financial claims and transactions,
practice audits, accreditation, and operational processes, including staff training.


What personal information do we collect?

The information we will collect about you includes:

  •  Names, date of birth, addresses, contact details.
  • Medical information including medical history, medications, allergies, adverse events, immunisations, social history, family history and risk factors.
  • Medicare number (when available) for identification and claim-related purposes.
  •  Healthcare identifiers
  • Health fund details.
 

Dealing with us anonymously

You have the right to deal with us anonymously or under a pseudonym unless it is impracticable for us to do so or unless we are required or authorised by law to only deal with identified individuals.

How do we collect your personal information?

Our practice will collect your personal information through the following channels:

  • Prior to your initial appointment, our staff gathers personal and demographic data through your
    registration.
  • Subsequent medical services, further personal information may be collected.
  •  Through Electronic Transfer of Prescriptions (eTP) and MyHealth Records, including Shared Health Summaries and Event Summaries.
  • Personal information might be obtained when you visit our website, correspond via email or SMS, place a telephone call, or schedule an online appointment.
  • In certain cases, personal data may be obtained from alternative sources due to practical limitations in directly acquiring it from you. This could involve:
    o Your guardian or responsible person.
    o Other involved healthcare providers, such as specialists, allied health professionals, hospitals, community health services, and diagnostic facilities.
    o Health insurance providers, Medicare, or the Department of Veteran’s Affairs.

Who do we share your personal information with?

We sometimes share your personal information:

  • With third parties that collaborate with our practice for business purposes, such as accreditation agencies or information technology providers, subject to adherence to APPs and this policy.
  • With other healthcare providers.
  • When legally obligated (e.g., court subpoenas, the Victorian Coroner).
  • When necessary to prevent a serious threat to a patient’s life, health, safety or acquiring patient consent is impractical.
  • Indispensable to mitigate a grave threat to a patient’s life, health, safety, public health, or safety, and acquiring patient consent is impractical.
  • To assist in locating a missing person.
  • To establish, exercise or defend an equitable claim.
  • For a confidential dispute resolution process.
  • In accordance with statutory obligations to share particular personal information (e.g., mandatory reporting of certain diseases like Covid-19).D
  • During medical services, through Electronic Transfer of Prescriptions (eTP), MyHealth Record (e.g. via Shared Health Summary, Event Summary).
Access to your information is restricted to relevant staff. Excluding medical services or circumstances outlined in this policy, personal information will not be disclosed to any third party without your explicit consent. Personal information will not be shared with entities outside Australia, except in exceptional circumstances permitted by law
and with your consent.
Our practice will not use your personal information for marketing any of our goods or services without your express consent. Should you consent, you retain the right to opt out of direct marketing by notifying our practice in writing.
 
How do we store and protect your personal information?

Your personal information may exist in various formats within our practice and is always stored securely. Electronic records are secured through password-protected clinical software. Paper records are stored in dedicated locked cabinets. Video recording of patient consults for Registrar training purposes may also be kept, additional consent from you is required for video recording of any consult and is to be obtained prior to consultation.
 
How can you access and correct your personal information at our practice?
You have the right to request access to, and correction of, your personal information. Our practice accommodates requests for medical record access, which must be made in writing to the patient’s primary general practitioner. We aim to provide records within 30 days and a nominal fee of $35.00 is applicable. We actively seek to maintain
accurate and updated personal information. Requests for correction or updates should be communicated in writing to the Practice Manager.
 
Security – CCTV
 
Internal and external cameras are installed at the clinic. Access to footage adheres to the provisions of the Privacy Act 1988 as amended.
 
How can you lodge a privacy-related complaint, and how will the complaint be handled at our practice?
 
Privacy concerns and grievances are treated with utmost seriousness. Such matters should be conveyed in writing to the Practice Manager at 108 Galloway Drive, Mernda. Initial contact can be made by calling 03 5176 1933 to connect with the Practice Manager. We are committed to resolving these matters in line with our established resolution procedure. Alternatively, you may contact the Office of the Australian Information Commissioner (OAIC) on 1300 336 002 or the Health Services Commissioner on 1800 136 066 for further assistance.
 
Privacy and our website
 
Information submitted via our website is provided at the patient’s discretion. Web-based online bookings require a user login and password for access.
 
Privacy and Email Communication
Ordinarily, clinical information is not dispatched via unencrypted email. In urgent scenarios, clinical information may be sent via password-protected email, or with the patient’s explicit consent through standard email.
 
Policy review statement
 
Our policy will be reviewed annually or at other times if legislative changes occur.