Privacy, Internet, Social Media, Email and Data Breach policies
9.11. Internet, social media and email
9.11. Internet, social media and email
9.11. Internet, social media and email
The DWMC recognises the usefulness of the internet, email, mobile devices and computer equipment as research, communication and work tools. This policy sets out the appropriate standards of behaviour for users of the DWMC’s information technology resources.
At all times when accessing or using the DWMC’s information technology resources, users must ensure that they comply with this policy. It is the user’s responsibility to ensure that they use the DWMC’s information technology resources in a lawful and professional manner.
This policy outlines the expectations in the use of the DWMC’s:
- Information technology resources.
- Internet.
- Social media.
- Email facilities.
- Mobile phones and mobile devices.
If a user is unsure about any matter covered by this policy, they should seek the assistance of their manager.
This policy applies to all staff members of DWMC, and contractors (including sub-contractors and temporary contractors) referred to as users. This policy applies to the use of all internet, social media, email and computer facilities, both during and outside of business working hours. This policy applies to the use of internet, social media, email and computer facilities inside the workplace, as well as use from remote locations and after hours use of personal computers. Use of computer facilities includes use of laptops, mobile phones and similar products, and any other equipment that provides a means of accessing the DWMC’s email and internet facilities. For example, this policy extends to the use of a personal computer which has access to the DWMC’s IT systems.
The DWMC’s information technology resources (“IT resources”) are provided to support the business and administrative activities of the DWMC. These resources include:
• The DWMC’s network.
• Computer systems and software including personal computers, notebooks and servers.
• Mobile phones, smart phones and wireless data cards.
• Access to the internet.
• Email, telephones and related services.
If users produce, collect and/or process DWMC related information in the course of their work, that information remains the property of the DWMC. This includes information stored on third party websites.
Extent of personal use
Users are permitted to use the DWMC’s IT resources for limited, incidental personal purposes, provided that such use does not:
• Interfere with the efficient business operations of the DWMC.
• Violate this policy or any other policy of the DWMC.
• Negatively impact upon the user’s work performance.
• Hinder the work of other users.
• Damage the reputation, image or operations of the DWMC.
• Such use must not cause noticeable additional cost to the DWMC.
- The DWMC accepts no responsibility for:
- Loss or damage or consequential loss or damage, arising from personal use of its IT resources.
- Loss of data or interference with personal files arising from the efforts to maintain the IT resources.
Guidelines for use of IT resources
Users must comply with the following guidelines when using the DWMC’s IT resources:
• Users must use their own username/login code and/or password when accessing the DWMC’s computer systems.
• Users should protect their username/login code and password information at all times and not divulge such information to any other person, unless it is necessary to do so for legitimate business reasons.
• Username/login codes and passwords are not to be recorded on or near computer equipment/mobile devices.
• Users should ensure that they log off from their account, and lock their computer/mobile device or shut down their computer/mobile device when leaving such equipment unattended to ensure that others do not have access to the DWMC’s computer systems.
• Users in possession of the DWMC’s computer equipment or mobile devices (including laptops, mobile phones, pagers, personal data assistants, wireless data cards, etc) must at all times ensure that such equipment is stored or placed in areas with a minimal possibility of theft or damage.
• IT resources must not be used for private commercial purposes except where the paid work is conducted in accordance with the DWMC’s practice, or the work is for the benefit of an entity in which the DWMC holds an interest.
• Use of proprietary software is subject to terms of license agreements between the DWMC and the software owner or licensor, and may be restricted in its use.
• The DWMC name or logo may only be used with prior approval from the Principal.
All use must be in accordance with the prior approval of the Principal.
Prohibited conduct
Certain behaviour is considered to be inappropriate use of the DWMC’s IT resources and is strictly prohibited. Examples of such prohibited conduct are, but are not limited to:
Users must not send (or cause to be sent), upload, download, use, retrieve, or access any file, email or internet material that:
- Is obscene, offensive or inappropriate. This includes text, images, sound or any other material, sent either in an email or in an attachment to an email, or through a link to an internet site (URL). For example, material of a sexual nature, hateful, indecent or pornographic material.
- Causes insult, offence, intimidation or humiliation by reason of unlawful harassment or discrimination.
- Is defamatory or incurs liability or adversely impacts on the image of the DWMC. A defamatory message or material is a message or material that is insulting or lowers the reputation of a person or group of people.
- Is otherwise illegal, unlawful or inappropriate.
- Affects or may affect the performance of, or cause damage to or overload the DWMC’s computer systems or internal or external communications in any way.
- Gives the impression of or is representing, giving opinions or making statements of on behalf of the DWMC without the express authority of the DWMC.
- They don’t solicit socially harmful activities including arms, carbon pollution, gambling, tobacco, pornography, low-cost labour/slave labour, human rights violations and animal cruelty.
Users must not use IT resources to:
- Violate copyright or other intellectual property rights. Computer software that is protected by copyright is not to be copied from, or into, or by using the DWMC’s computing facilities, except as permitted by law or by contract with the owner of the copyright. Similarly, users should not copy or access copyright protected music or videos on the DWMC’s IT resources.
- Breach an individual’s privacy, including patients under the care of a Fellow or trainee;
- Create any legal or contractual obligations on behalf of the DMC unless expressly authorised by the Principal.
- Disclose any confidential information of the DWMC or any employee, Fellow, trainee, client or supplier of the DWMC unless expressly authorised by the DWMC.
- Install software or run unknown or unapproved programs on the DWMC’s computers. Under no circumstances should users modify the software or hardware environments on the DWMC’s computer systems (this includes installing software purchased by users for personal private use) without prior approval from the general manager, IT.
- Gain unauthorised access (hacking) into any other computer within the DWMC or outside the DWMC or attempt to deprive other users of access to or use of any DWMC computing system.
- Plagiarise another person’s work.
- Deliberately send or cause to be sent chain or spam emails in any format.
- Obtain personal gain. For example, running a personal business using the DWMC’s computers.
- Gamble.
- Stream content for personal use.
- Use peer to peer file sharing software such as VUZE, BitTorrent, etc.
- Download, install or use instant messaging software.
- Perpetrate any form of fraud or software, film or music piracy.
Users must not use another user’s computer or internet access or email facilities (including passwords and usernames/login codes) for any reason without the express permission of the user.
Internet
The DWMC’s IT resources should only be connected to the internet using means authorised by the Principal, IT.
Users are not permitted to publish personal web pages on computers connected to the DWMC network.
9.12Using social media in our practice
- Policy
‘Social media’ is defined as online social networks used to disseminate information through online interaction.
Regardless of whether social media is used for business related activity or for personal reasons, the following standards apply to members of our practice team, including general practitioners. Practitioners and team members are legally responsible for their postings online. Practitioners and team members may be subject to liability and disciplinary action including termination of employment or contract if their posts are found to be in breach of this policy.
- Personal and professional use of social media by DWMC staff and contractors must not bring the DWMC into disrepute, compromise effectiveness at work, imply DWMC endorsement of personal views or disclose, without authorisation, confidential information.
- Workers are responsible for the content they post on their personal social media accounts. Where a Worker’s personal use of social media contravenes our policy, then it may be appropriate for the DWMC to respond, either in work time or after hours.
- Think about consequences, please remember: Using your public voice to trash or embarrass your employer, your patients, your co-workers or even yourself is not okay – and not very smart.
For the sake of clarity, social media includes, but is not limited to:
• Social networks (such as Facebook and MySpace).
• Blogs.
• Wikis (such as Wikipedia).
• Podcasts.
• Forums.
• Content communities (such as YouTube and Flickr).
• Microblogs (such as Twitter).
- Procedure
Our practice has appointed Practice Manager Tanya Barrett as our social media officer with designated responsibility to manage and monitor the practice’s social media accounts. All posts on the practice’s social media websites must be approved by this person.
When using the practice’s social media, all members of our practice team will not:
- Post any material that:
- Is unlawful, threatening, defamatory, pornographic, inflammatory, menacing, or offensive
- Infringes or breaches another person’s rights (including intellectual property rights) or privacy, or misuses the practice’s or another person’s confidential information (e.g. do not submit confidential information relating to our patients, personal information of staff, or information concerning the practice’s business operations that have not been made public)
- Is materially damaging or could be materially damaging to the practice’s reputation or image, or another individual
- Is in breach of any of the practice’s policies or procedures
- Use social media to send unsolicited commercial electronic messages, or solicit other users to buy or sell products or services or donate money
- Impersonate another person or entity (for example, by pretending to be someone else or another practice employee or other participant when you submit a contribution to social media) or by using another’s registration identifier without permission
- Tamper with, hinder the operation of, or make unauthorised changes to the social media sites
- Knowingly transmit any virus or other disabling feature to or via the practice’s social media account, or use in any email to a third party, or the social media site
- Attempt to do or permit another person to do any of these things:
- Claim or imply that you are speaking on the practice’s behalf, unless you are authorised to do so
- Disclose any information that is confidential or proprietary to the practice, or to any third party that has disclosed information to the practice
- Be defamatory, harassing, or in violation of any other applicable law
- Include confidential or copyrighted information (e.g. music, videos, text belonging to third parties), and
- Violate any other applicable policy of the practice.
All members of our practice team must obtain the relevant approval from our social media officer prior to posting any public representation of the practice on social media websites. The practice reserves the right to remove any content at its own discretion.
Any social media must be monitored in accordance with the practice’s current polices on the use of internet, email and computers.
Our practice complies with the Australian Health Practitioner Regulation Agency (AHPRA) national law, and takes reasonable steps to remove testimonials that advertise our services (which may include comments about the practitioners themselves). Our practice is not responsible for removing (or trying to have removed) unsolicited testimonials published on a website or in social media over which we do not have control.
Any social media posts by members of our practice team on their personal social media platforms should:
- Users must take a common sense approach to the content that they publish online. Because of the public nature of the internet and social media, this common sense approach also applies to use of social networking sites outside of business hours or on equipment other than DWMC equipment.
- If a user is holding themselves out as a representative of the DWMC, any material published online must:
- Be relevant to the user’s area of expertise.
- Not be anonymous.
- Maintain professionalism, honesty and respect. Statements of fact about the DWMC and its products and services, publicly available information and information already published on the DWMC’s website ( when available) are all examples of appropriate online content.
- Users must not publish any material online that contains the DWMC’s confidential information (including financial information and information about organisational matters), the personal information of another (without that individual’s consent), information about the DWMC’s customers or clients, or content that may offend, intimidate, defame or humiliate a Fellow, trainee, staff member, volunteer or contractor of the DWMC. Further, if a user becomes aware of the publication of material that is linked to the DWMC, its workers or its clients which would be deemed distasteful or inappropriate, the user should report such conduct to the DWMC’s Human Resources Department.
If a user is unsure about whether they should publish material on the internet, they should seek guidance from the Computer Security officer, IT.
- Include the following disclaimer example in a reasonably prominent place if they are identifying themselves as an employee of the practice on any posting: ‘The views expressed in this post are mine and do not reflect the views of the practice/business/committees/boards that I am a member of’, and
- Respect copyright, privacy, fair use, financial disclosure and other applicable laws when publishing on social media platforms.
Social media activities internally and externally of the practice must be in line with this policy.
Email/Message
Appropriate standards of civility should be used when using email and other messaging services to communicate with other staff members or any other message recipients. When using the email or messaging system users must not send:
• Angry or antagonistic messages – these can be perceived as bullying or threatening and may give rise to formal complaints under grievance procedures or discrimination/sexual harassment procedures.
• Offensive, intimidating or humiliating emails – the DWMC’s IT resources must not be used to humiliate, intimidate or offend another person/s on the basis of their race, gender, or any other attribute prescribed under anti-discrimination legislation.
Guidelines for use of the DWMC’s email system
A user must comply with the following guidelines when using the DWMC’s email system:
• Any disclaimer which is automatically included in the DWMC’s emails must not be removed.
• If a user receives an email which they suspect contains a virus, they should not open the email or any attachment to the email and should immediately contact the IT service desk for assistance.
• If a user receives an email the content of which (including an image, text, materials or software) is in breach of this policy or any the DWMC’s other policies, the user should immediately delete the email and report the matter to the Computer security officer, IT. The user must not forward the email to any other person.
• Users must not publish the DWMC email address on a private business card.
• Users must not forward or copy emails that contain personal information about an individual without the prior permission of that individual. They must be sent by return email to address provided. Patient must be advised not secure and noted in their clinical notes.
• Endeavor to answer emails within 2 working days or have an auto respond message.268
• Users must adhere to the guidelines and prohibitions set out in this policy at all times.
• Messaging and email must not be used for private commercial purposes except where the work is for the purposes of a corporate entity in which the DWMC holds an interest.
Mobile phones and mobile devices
Mobile phones and/or mobile devices may be provided by the DWMC to staff members, Fellows or trainees for the purposes of carrying out DWMC business. Mobile phones, mobile devices, accessories and associated telephone numbers remain the property of the DWMC at all times.
Mobile phones and mobile devices are considered IT resources and, as such, their use is governed by this policy. If mobile devices are provided the users are responsible for understanding the costs associated with using the DWMC’s mobile phones and mobile devices and should ensure that this equipment is used in the most cost effective manner. All costs associated with the use of mobile phones and mobile devices will be included in the appropriate management budget reports. Periodic checks and trend analysis will be undertaken by the IT Department on all costs associated with the use of mobile phones and mobile devices. An investigation may be undertaken where it is identified that a user is exceeding reasonable personal use of the equipment provided.
Guidelines for use of the DWMC’s mobile phone and mobile devices
Users must comply with the following guidelines when using the DWMC’s mobile phones and mobile devices:
• Users must maintain the operational effectiveness of the mobile phone or mobile device (i.e. keeping the batteries charged when required to be contacted).
• Mobile phones and mobile devices that have the ability to be password protected and encrypted must have this security feature activated at all times. Users are not to remove or modify such security features as configured by the IT Department.
• International and premium number call facilities will not be available without prior agreement for both business and private use and must be approved by the budget holder for the phone. Requests to allow international use should be made through the ITcoordinator.
• Users are prohibited from using mobile phones or devices while operating a motor vehicle in the conduct of business for the DWMC.
• Users must report any loss, theft, damage or security breach of any mobile phone or mobile device immediately to the IT coordinator to ensure appropriate measures are taken to secure and disable the device. If such loss, theft or damage is due to the negligence of the user, the user may be responsible for the cost of replacing or repairing the mobile device.
MONITORING – EMAIL, FILES, INTERNET DOWNLOADS OR DATA STORAGE
DWMC does not generally monitor email, files, internet downloads or data stored on its IT resources. However, the DWMC reserves the right to access and monitor any computer or other electronic device connected to the DWMC’s network. This includes equipment owned by DWMC and personal computing equipment (for example, laptops) that are connected to the network.
Access to and monitoring of equipment is permitted for any reason, including but not limited to, suspected breaches of this policy by a user or unlawful activities. Access to and monitoring includes, but is not limited to, email, web sites, server logs and electronic files.
DWMC may keep a record of any monitoring or investigations.
DELORAINE & WESTBURY MEDICAL CENTRE Privacy statement
Your privacy is our business statement
Current as of: 7/10/2025
Introduction
This privacy policy is to provide information to you, our patient, on how your personal information (which includes your health information) is collected and used within our practice, and the circumstances in which we may share it with third parties.
Why and when your consent is necessary
When you register as a patient of our practice, you provide consent for our GPs and practice staff to access and use your personal information so they can provide you with the best possible healthcare. Only staff who need to see your personal information will have access to it. If we need to use your information for anything else, we will seek additional consent from you to do this.
Why do we collect, use, hold and share your personal information?
Our practice will need to collect your personal information to provide healthcare services to you. Our main purpose for collecting, using, holding and sharing your personal information is to manage your health. We also use it for directly related business activities, such as financial claims and payments, practice audits and accreditation, and business processes (eg staff training).
What personal information do we collect?
The information we will collect about you includes your:
- names, date of birth, addresses, contact details
- medical information including medical history, medications, allergies, adverse events, immunisations, social history, family history and risk factors
- Medicare number (where available) for identification and claiming purposes
- healthcare identifiers
- health fund details.
Dealing with us anonymously
You have the right to deal with us anonymously or under a pseudonym unless it is impracticable for us to do so or unless we are required or authorised by law to only deal with identified individuals.
How do we collect your personal information?
Our practice may collect your personal information in several different ways.
- When you make your first appointment our practice staff will collect your personal and demographic information via your registration.
- During the course of providing medical services, we may collect further personal information.
[Information can also be collected through electronic transfer of prescriptions (eTP), My Health Record, eg via Shared Health Summary, Event Summary.]
- We may also collect your personal information when you visit our website, send us an email or SMS, telephone us, make an online appointment or communicate with us using social media.
- In some circumstances personal information may also be collected from other sources. Often this is because it is not practical or reasonable to collect it from you directly. This may include information from:
- your guardian or responsible person
- other involved healthcare providers, such as specialists, allied health professionals, hospitals, community health services and pathology and diagnostic imaging services
- your health fund, Medicare, or the Department of Veterans’ Affairs (as necessary).
When, why and with whom do we share your personal information?
We sometimes share your personal information:
- with third parties who work with our practice for business purposes, such as accreditation agencies or information technology providers – these third parties are required to comply with APPs and this policy
- with other healthcare providers
- when it is required or authorised by law (eg court subpoenas)
- when it is necessary to lessen or prevent a serious threat to a patient’s life, health or safety or public health or safety, or it is impractical to obtain the patient’s consent
- to assist in locating a missing person
- to establish, exercise or defend an equitable claim
- for the purpose of confidential dispute resolution process
- when there is a statutory requirement to share certain personal information (eg some diseases require mandatory notification)
- during the course of providing medical services, through eTP, My Health Record (eg via Shared Health Summary, Event Summary).
Only people who need to access your information will be able to do so. Other than in the course of providing medical services or as otherwise described in this policy, our practice will not share personal information with any third party without your consent.
We will not share your personal information with anyone outside Australia (unless under exceptional circumstances that are permitted by law) without your consent.
Our practice will not use your personal information for marketing any of our goods or services directly to you without your express consent. If you do consent, you may opt out of direct marketing at any time by notifying our practice in writing.
Our practice may use your personal information to improve the quality of the services we offer to our patients through research and analysis of our patient data.
We may provide de-identified data to other organisations to improve population health outcomes. The information is secure, patients cannot be identified, and the information is stored within Australia. You can let our reception staff know if you do not want your information included.
Our practice routinely provides patient health information to other organisations for secondary use, health population and research. Your data is protected under the same collection procedure and is only used when de identified. Whilst patient consent for sharing de-identified practice data is not a legal requirement, we consider it a good practice to have a procedure for ensuring patients who do not consent to secondary use of data are removed from any data extraction process. Please advise the reception team if you do not want to participate in secondary use of your data.
How do we store and protect your personal information?
Your personal information may be stored at our practice in various forms.
[eg as paper records, electronic records, visual records (X-rays, CT scans, videos and photos), audio recordings.]
Our practice stores all personal information securely.
[ We securely store and protect personal information, eg electronic format, in protected information systems or in hard copy format in a secured environment. We use passwords, secure cabinets and confidentiality agreements for staff and contractors.
How can you access and correct your personal information at our practice?
You have the right to request access to, and correction of, your personal information.
Our practice acknowledges patients may request access to their medical records. We require you to put this request in writing and our practice will respond within a reasonable time. (30 days to reply and there is fee for the provision of electronic records.)
Our practice will take reasonable steps to correct your personal information where the information is not accurate or up to date. From time to time, we will ask you to verify that your personal information held by our practice is correct and current. You may also request that we correct or update your information, and you should make such requests in writing to Practice Manager on manager@delorainemedical.com
How can you lodge a privacy-related complaint, and how will the complaint be handled at our practice?
We take complaints and concerns regarding privacy seriously. You should express any privacy concerns you may have in writing. We will then attempt to resolve it in accordance with our resolution procedure. [Our complaint handling process is as follows, acknowledgment of complaint is sent upon receiving a complaint. We may take up to 30 days to reply with an outcome.
Practice Manager
C/0 PO Box 42
Deloraine Tas 7304
Or email to
manager@delorainemedical.com
You may also contact the OAIC. Generally, the OAIC will require you to give them time to respond before they will investigate. For further information visit www.oaic.gov.au or call the OAIC on 1300 363 992.
Health Complaints Commissioner Tasmania 1800001170
Privacy and our website
We do not collect information via our website/social media, but our policy is available on the website.
Policy as at 7/10/2025
Deloraine & Westbury Medical Privacy Policy statement
Current as of: 7/10/2025
The objective of this document is to provide you, our patient, with clear information on how your personal information is collected and used within the practice. Occasionally we also need to share your personal information to involve others in your healthcare and this policy outlines when, how, and why we share your information.
- Who can I contact about this policy?
For enquiries concerning this policy, you can contact manager@delorainemedcial.com
Or phone 63622266 and speak with the Privacy officer or Practice Manager
- When and why is your consent necessary?
When you register as a patient of this practice, you provide consent for the GPs and practice staff to access and use your personal information to facilitate the delivery of healthcare. Access to your personal information is restricted to practice team members who require it for your care. If we ever use your personal information for purposes other than outlined in this document, we will obtain additional consent from you.
It is important to us that as our patient, you understand why we collect and use your personal information.
By acknowledging this Privacy Policy you consent to us collecting, holding, using, retaining and disclosing your personal information in the manners described below.
- Why do we collect, use, store, and share your personal information?
The practice collects, uses, stores, and shares your personal information primarily to manage your health safely and effectively. This includes providing healthcare services, managing medical records, and ensuring accurate billing and payments. Additionally, we may utilise your information for internal quality and safety improvement processes such as practice audits, accreditation purposes, and staff training to maintain high-quality service standards.
- What personal information is collected?
The information we will collect about you includes your:
- names, date of birth, addresses, contact details
- medical information including medical history, medicines, allergies, and adverse reactions immunisations, social history, family history and risk factors
- Medicare number (where available) for identification and claiming purposes
- healthcare identifier numbers
- health fund details.
- Can you deal with us anonymously?
You can deal with us anonymously or under a pseudonym unless it is impracticable for us to do so or unless we are required or authorised by law to only deal with identified individuals.
Dealing with general practices anonymously
The Privacy Act requires patients to be provided with the option of not identifying themselves, or of using a pseudonym, when dealing with a practice unless it is impracticable to do so. Information about this should appear in the practice privacy policy.
The Privacy Act 1988 requires practices to consider whether it is practical to give patients the option of not identifying themselves, or using a pseudonym. However, practices do not have to deal with patients anonymously or pseudonymously. The OAIC website provides further information in this topic here.
- How is personal information collected?
The practice may collect your personal information in several different ways:
When you make your first appointment, the practice team will collect your personal and demographic information via your registration.
We may also collect your personal information when you send us an email or SMS, telephone us, make an online appointment.
In some circumstances, personal information may also be collected from other sources, including:
- Your guardian or responsible person.
- Other involved healthcare providers, such as specialists, allied health professionals, hospitals, community health services, and pathology and diagnostic imaging services.
- Your health fund, Medicare, or the Department of Veterans’ Affairs (if relevant).
- While providing medical services, further personal information may be collected via:
- electronic prescribing
- My Health Record
- online appointments.
Various types of images may be collected and used, including:
- CCTV footage: Collected from our premises for security and safety purpose ( not used at present)
- Phone calls are recorded for training purposes
- Photos and medical images: These can be taken using personal devices for medical purposes, following the guidelines outlined in our guide on using personal devices for medical images. ( emailed to manager@delorainemedical.com to be imported into your medical file and then deleted from the device, we use a device that is specially for the purpose and kept in the treatment rooms). If a clinician uses a personal device after emailing the image it must be deleted from the device within 30 minutes ( not recommended).
Compliance with privacy obligations
To comply with Australian privacy obligations when collecting personal information from third-party sources, we will aways understand and adhere to the Privacy Act 1988 and the Australian Privacy Principles (APPs) this includes:
– verifying third-party compliance
– ensuring informed consent
– collecting only necessary data
– maintaining data accuracy
– updating your privacy policy and notifying patients of these updates as required
– protecting data with strong security measures
– facilitating individuals’ rights to their data
– providing regular education and training for the practice team on privacy practices.
To ensure compliance, you can include the following line in the privacy policy:
“We will always comply with privacy obligations when collecting personal information from third-party sources. This includes ensuring transparency with patients, obtaining necessary consents, maintaining data accuracy, securing the information, and using it only for specified purposes.”
- When, why and with whom do we share your personal information?
We sometimes share your personal information:
- with third parties for business purposes, such as accreditation agencies or information technology providers – these third parties are required to comply with APPs and this policy
- with other healthcare providers (e.g. In referral letters)
- when it is required or authorised by law (e.g. court subpoenas)
- when it is necessary to lessen or prevent a serious threat to a patient’s life, health or safety or public health or safety, or it is impractical to obtain the patient’s consent
- to assist in locating a missing person
- to establish, exercise or defend an equitable claim
- for the purpose of confidential dispute resolution process
- When it is a statutory requirement to share certain personal information (e.g. some diseases require mandatory notification)
- When it is provision of medical services, through electronic prescribing, My Health Record (e.g. via Shared Health Summary, Event Summary).
- The right of children to privacy of their health information, based on the professional judgment of the doctor and consistent with the law, might at times restrict access to this information by parents or guardians.
Only people who need to access your personal information will be able to do so. Other than providing medical services or as otherwise described in this policy, the practice will not share personal information with any third party without your consent.
We do not share your personal information with anyone outside Australia (unless under exceptional circumstances that are permitted by law) without your consent.
- Will your information be used for marketing purposes?
The practice will not use your personal information for marketing any goods or services directly to you without your express consent. If you do consent, you may opt out of direct marketing at any time by notifying the practice in writing.
- How is your information used to improve services?
The practice may use your personal information to improve the quality of the services offered to patients through research, analysis of patient data for quality improvement and for training activities with the practice team
We may provide de-identified data to other organisations to improve population health outcomes. If we provide this information to other organisations patients cannot be identified from the information we share, the information is secure and is stored within Australia. You can let reception staff know if you do not want your de-identified information included.
At times, general practices are approached by research teams to recruit eligible patients into specific studies which require access to identifiable information. You may be approached by a member of our practice team to participate in research. Researchers will not approach you directly without your express consent having been provided to the practice. If you provide consent, you would then receive specific information on the research project and how your personal health information will be used, at which point you can decide to participate or not participate in the research project.
- How are document automation technologies used?
Document automation is where systems use existing data to generate electronic documents relating to medical conditions and healthcare.
The practice uses document automation technologies to create documents such as referrals, which are sent to other healthcare providers. These documents contain only your relevant medical information.
These document automation technologies are used through secure medical software Medical Director and Pracsoft.
All users of the medical software have their own unique user credentials and password and can only access information that is relevant to their role in the practice team.
The practice complies with the Australian privacy legislation and APPs to protect your information.
All data, both electronic and paper are stored and managed in accordance with the Royal Australian College of General Practitioners Privacy and managing health information guidance.
- How are Artificial Intelligence (AI) Scribes used?
The practice uses an AI scribe tool to support GPs take notes during their consultations with you. The AI scribe uses an audio recording of your consultation to generate a clinical note for your health record. The recommended practice AI scribe service is Heidi.
Heidi:
- does not share information outside of Australia
- destroys the audio file once the transcription is complete.
- removes sensitive, personal identifying information as part of the transcription
The practice will only use data from our digital scribe service to provide healthcare to you. If other scribes are used they must comply with our AI policy and the APP.
- How is your personal information stored and protected?
Your personal information may be stored in various forms.
[eg as paper records, electronic records, visual records (X-rays, CT scans, videos and photos), audio recordings.]
The practice stores all personal information securely.
[ We securely store and protect personal information, eg electronic format, in protected information systems or in hard copy format in a secured environment. We use passwords, secure cabinets and confidentiality agreements for staff and contractors.
We do not use CCTV at present but we do record phone calls for training purposes, if you do not want your call recorded please advise the reception staff. They are kept for 3 days then deleted.
- How can you access and correct your personal information at the practice?
You have the right to request access to, and correction of, your personal information.
The practice acknowledges patients may request access to their medical records.
You have the right to request access to, and correction of, your personal information.
Our practice acknowledges patients may request access to their medical records. We require you to put this request in writing and our practice will respond within a reasonable time. (30 days to reply and there is fee for the provision of electronic records.)
Our practice will take reasonable steps to correct your personal information where the information is not accurate or up to date. From time to time, we will ask you to verify that your personal information held by our practice is correct and current. You may also request that we correct or update your information, and you should make such requests in writing to Practice Manager on manager@delorainemedical.com
- How can you lodge a privacy-related complaint, and how will the complaint be handled at the practice?
We take complaints and concerns regarding privacy seriously. You should express any privacy concerns you may have. We will then attempt to resolve it in accordance with the resolution procedure.
If you do not feel we have resolved your issue You may also contact the Office of the Australian Information Commissioner. The Office of the Australian Information Commissioner will require you to give them time to respond before they investigate. For further information visit www.oaic.gov.au or call the OAIC (Office of the Australian Information Commissioner) on 1300 363 992. Or Health Complaints Commissioner Tasmania 1800001170
- How is privacy on the website maintained?
At Deloraine & Westbury Medical , any personal information you share with us through website, email, and social media, is handled securely and confidentially. This practice uses analytics and cookies. At present we do not collect information from our website or social media platforms.
- Policy review statement
Our privacy policy is regularly reviewed to ensure compliance with current obligations.
If any changes are made:
- They will be reflected on the website.
- Significant changes may be communicated directly to patients via email or other means.
Please check the policy periodically for updates. If you have any questions, feel free to contact us.
Data Breach:
Practice Data Breach Response Plan
Procedure
- This Data Breach Response Plan (Response Plan) sets out the procedure to be followed by Deloraine & Westbury Medical Pty Ltd staff in the event that the practice experiences a data breach, or suspects that a data breach has occurred.
- A data breach occurs when personal information (defined in section 6 of the Privacy Act 1988 (Cth) is lost or subjected to unauthorized access, modification, use or disclosure or other misuse. Personal information refers to information that identifies or reasonably identifies an individual.
- A data breach will also occur where protected practice information is unlawfully used or disclosed. ‘Protected D & WMC information’ includes a broader range of information than “personal information” as it includes information about all entities, not just medical notes.
Examples of a data breach include when:
- A data base containing medical records is hacked
- Health information is mistakenly provided to the wrong person
- A device containing patients‘ medical records is lost or stolen
- Whilst the process outlined in this Response Plan applies to all data breaches it is important to note that in some instance, the privacy provision may impose stricter standards on the Practice than those contained in this Response Plan. Thus, where a breach involves ‘protected Practice information’ both the Response Plan and the legislation must be considered collectively.
- It is also important to note that Office of the Australian Information Commissioner (OAIC) is only concerned with breaches that involve personal information. Data breaches that involve ‘protected Practice information’ that is not ‘personal information’ do not need to be reported to the OAIC.
- Adherence with the Response Plan will ensure that the Practice can contain, assess and respond to data breaches in a timely fashion in order to mitigate potential harm to affected persons.
- This plan:
- Sets out the roles and responsibilities of staff;
- Sets out the contact details of appropriate staff in the event of a data breach; and
- Outlines the procedure to be followed in the event of a data breach.
The Practice Staff member to notify the practice manager
- Immediately notify the practice manager of the suspected data breach.
- Record and advise the practice manager of the time and date the suspected breach was discovered, the type of information involved, the cause and extent of the breach, and the context of the affected information and the breach.
Practice Manager to assess the breach
- The practice manager must assess and determine whether a data breach has occurred.
- If the practice manager has any suspicion that a breach has occurred, the practice manager must immediately notify the CEO and Medical Director of the Practice.
Practice Manager and CEO/Medical Director to assess the seriousness of the breach
- In some instances, a minor breach may be able to be dealt with at the practice level. Where a minor breach is dealt with at the director level, the following details must be recorded:
- Description of the breach or suspected breach;
- Action taken by the practice manager to address the breach or suspected breach;
- Outcome of that action
- Sign off from the CEO/Medical Director that no further action is required; and
- Confirmation that the incident has been recorded in the practice Data breach incident log.
- The record must be saved in the folder below:
- Data breach register in office
- Practice mangers C:\ drive
- If the breach is serious, it must immediately be escalated to the practice Manager and the CEO/Medical Director who will then determine whether the directors of the Practice are involved.
The Team will then investigate and follow the full procedure for investigation and notifications.