Patient Privacy Policy

1. Introduction

In summary, we collect information needed to provide safe care and operate our practice. We use and share it only for your care, practice administration, legal obligations and other purposes permitted by law. We protect it through technical and organisational safeguards, and you may ask to access or correct it or make a privacy complaint. Contact our Privacy Officer using the details in Schedule 1 if you have questions or wish to exercise these rights. Elwood Village Medical is operated by Elwood Medical Group Pty Ltd (ACN 651 971 087; ABN 54 651 971 087) (we, us or our). We are a general practice146 Ormond Rd, Elwood VIC 3184, providing general medical, nursing and preventive health services to patients of all ages. Protecting patient privacy and the integrity of health information is a fundamental obligation of our practice. This Privacy Policy explains how we collect, hold, use, disclose and protect your personal information, including sensitive health information, in the course of providing our services (Services). It applies to all patients, and to parents, guardians, carers, substitute decision-makers, referrers and other individuals whose personal information we handle in the ordinary course of our practice. We are bound by:
  • the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs) contained in Schedule 1 to that Act;
  • the Health Records Act 2001 (Vic) (Health Records Act) and the Health Privacy Principles (HPPs) contained in Schedule 1 to that Act; and
  • the My Health Records Act 2012 (Cth), to the extent that we participate in the My Health Record system.
Where the Privacy Act and the Health Records Act each apply to the same information and impose differing requirements, we comply with the more protective obligation. Unless the context otherwise requires, words importing the singular include the plural and vice versa. Details of our practice, our Privacy Officer, and the information systems and service providers we use are set out in Schedule 1 and Schedule 2 respectively.

2. What is personal information and health information?

Personal information is information or an opinion, whether true or not, about an identified individual or an individual who is reasonably identifiable from that information, either alone or in combination with other information to which we have, or are likely to have, access. Sensitive information is a subset of personal information that is afforded a higher degree of protection under the Privacy Act. Health information is a form of sensitive information and includes information or an opinion about the health or disability of an individual, information collected in the course of providing a health service, and information that is predictive of an individual’s health. Under Victorian law, health information is defined in section 3 of the Health Records Act in correspondingly broad terms, and extends to information or an opinion about your physical, mental or psychological health or disability, your expressed wishes about the future provision of health services to you, and any personal information collected in the course of providing a health service to you. Given the nature of general practice, the substantial majority of the information we collect and hold about you is health information. We apply the highest standard of care to its protection.

3. What personal information do we collect?

3.1 Personal and demographic information

We collect the following categories of personal information:
  • your full name (including any former or preferred name), residential and postal address, telephone number(s) and email address;
  • your date of birth and gender and, where you choose to provide it, your gender identity and pronouns;
  • your Medicare number and card details, and your Individual Healthcare Identifier (IHI);
  • your Department of Veterans’ Affairs (DVA) file number and entitlement details, where applicable;
  • your National Disability Insurance Scheme (NDIS) participant number, where applicable;
  • your private health insurance, pensioner concession or health care card details;
  • financial and billing information, including payment card details processed through our secure payment terminal and account information required to facilitate invoicing, Medicare and DVA claiming, and health fund claiming;
  • your emergency contact and next of kin details, and the details of any nominated carer, guardian, attorney, medical treatment decision maker or other substitute decision-maker;
  • the name and contact details of your usual general practitioner, preferred pharmacy and other treating health practitioners; and
  • your preferred language and any interpreter, communication or accessibility requirements.

3.2 Health information

As a general practice, we collect and hold a comprehensive range of sensitive health information, including:
  • your medical history, including presenting complaints, past illnesses, past surgical and other procedures and prior diagnoses;
  • your current and previous diagnoses;
  • your current and past medications, including dosages and prescribing practitioners;
  • your known allergies and adverse drug reactions;
  • your immunisation history, including information recorded on and obtained from the Australian Immunisation Register;
  • your family history, including familial and genetic risk factors relevant to your care;
  • your social history, including occupation, living arrangements, relationship circumstances and the use of alcohol, tobacco and other substances, where clinically relevant;
  • disability-related information, where relevant to your assessment and management;
  • mental health information, including assessments, mental health treatment plans and related correspondence;
  • treatment plans, chronic disease and care plans, care recommendations, referrals and post-treatment instructions;
  • clinical assessments and examination findings recorded during consultations, including nursing assessments and vital signs;
  • clinical photographs, including wound and skin photographs, taken for the purposes of clinical documentation, diagnosis and monitoring;
  • pathology, diagnostic imaging and other investigation results; and
  • referral letters, discharge summaries and clinical correspondence received from general practitioners, specialists, hospitals, pharmacies, pathology and radiology services, allied health practitioners, insurers and legal representatives.

3.3 Aboriginal and Torres Strait Islander status and other voluntary demographic information

We invite, but do not require, patients to identify whether they are of Aboriginal or Torres Strait Islander origin. We collect this information so that we may offer clinically appropriate services and Commonwealth programs for which Aboriginal and Torres Strait Islander patients are eligible, including annual health assessments and the Closing the Gap PBS Co-payment Program, and to support quality improvement and service planning. Information about racial or ethnic origin is sensitive information under the Privacy Act, and we apply the same heightened standard of protection to it as we apply to health information. The provision of this information is entirely voluntary, and if you choose not to provide it this will have no effect whatsoever on the care you receive from our practice.

3.4Information we do not collect

We do not collect biometric identifiers or biometric templates, such as fingerprints, facial recognition data or voice prints, and we do not use facial recognition or voice identification technology of any kind. Clinical photographs taken at our practice are taken solely for clinical purposes and are not used as, or converted into, biometric identifiers. We do not collect information about your political opinions, membership of political associations, professional or trade associations or trade unions, religious or philosophical beliefs, sexual orientation or practices, or criminal record, except to the extent that such information is volunteered by you and is directly relevant to the health service being provided.

4. How do we collect your personal information?

We collect personal information by a number of means. Wherever it is reasonable and practicable to do so, we collect information about you directly from you, as required by HPP 1.3. We also receive information from third parties involved in your healthcare, as described below.

4.1 Direct collection

We collect information directly from you when you:
  • complete our new patient registration and intake forms, whether in hard copy at our practice or electronically;
  • attend a consultation, during which clinical observations, history and examination findings are recorded;
  • participate in a telehealth or telephone consultation;
  • contact our practice by telephone, email, our website or other means, including to make, change or cancel an appointment; or
  • otherwise provide information in the course of receiving, or enquiring about, our Services.
Your consent to the collection of personal information may be express (for example, by signing a consent form or completing a registration form which acknowledges this Privacy Policy) or implied by your conduct in seeking and receiving our Services.

4.2 Collection from third parties

We frequently receive personal and health information about you from third parties who are involved in your care or who have a legitimate role in your health management. Such third parties include:
  • other general practitioners and medical practices, which provide referral letters, medical histories, health summaries and clinical records on transfer of care;
  • specialist medical practitioners, who provide diagnostic reports, procedural records and treatment recommendations;
  • hospitals and day procedure facilities, which provide discharge summaries, operation reports and results;
  • pharmacies, which may provide dispensing histories relevant to your medication management;
  • pathology and diagnostic imaging services, which provide investigation results, generally by secure electronic messaging;
  • allied health practitioners and community health services involved in your care;
  • NDIS support coordinators and disability support providers, and aged care assessment teams;
  • government agencies, including Services Australia, the Department of Veterans’ Affairs, the Australian Immunisation Register and the Australian Digital Health Agency;
  • insurance companies, including workers compensation and transport accident insurers, where you are a claimant or insured person;
  • legal representatives, where your care is the subject of legal or compensation proceedings; and
  • your family members, carers and substitute decision-makers, where appropriate.
We collect information from these third parties with your express or implied consent, or in circumstances where collection without consent is permitted, being where the information is reasonably necessary for one or more of our functions or activities and the collection is permitted under APP 3.4 and HPP 1.1. Where we collect information about you from someone other than you, we take such steps as are reasonable in the circumstances to ensure that you are, or have been, made aware of the matters set out in APP 5 and HPP 1.4, unless doing so would pose a serious threat to the life or health of any individual or would involve the disclosure of information given to us in confidence.

4.3 Unsolicited information

If we receive personal information about you that we did not solicit, we will determine within a reasonable period whether we could have collected that information had we solicited it. If we could not have done so, and the information is not contained in a Commonwealth record and we are not required by law or a court or tribunal order to retain it, we will destroy or de-identify the information as soon as practicable, provided it is lawful and reasonable to do so. We note, however, that HPP 4.2 prohibits a health service provider from deleting health information other than in accordance with that principle. Where we are prohibited from deleting unsolicited health information, we will instead restrict access to it and will not use or disclose it except as permitted by law.

5. Why do we collect, hold and use your personal information?

5.1 Primary purposes

We collect, hold and use your personal information for the following primary purposes:
  • to provide general practice and nursing services to you, including assessment, diagnosis, treatment, prescribing, procedures, referral and ongoing management;
  • to develop, implement, review and monitor treatment plans, chronic disease management plans and preventive health activities tailored to your clinical needs;
  • to issue and manage clinical recalls, reminders and results follow-up, including reminders for tests, immunisations, reviews and preventive health activities;
  • to communicate with your other treating health practitioners, including specialists, pharmacists, allied health practitioners and hospitals, so as to ensure coordinated and continuous care;
  • to make and manage appointments and to communicate with you about your care, including by SMS and email;
  • to process billing and invoicing, and to make Medicare, DVA and private health fund claims and to facilitate payment;
  • to maintain accurate, complete and contemporaneous clinical records as required by law and professional standards; and
  • to meet our obligations under applicable laws, accreditation standards and our professional indemnity arrangements.

5.2 Secondary purposes

We may also use your information, in de-identified form wherever practicable, for the following secondary purposes, each of which is either directly related to the primary purpose and within your reasonable expectations, or otherwise permitted by APP 6 and HPP 2:
  • quality improvement activities, including clinical audit, review of patient outcomes, and accreditation against the RACGP Standards;
  • the funding, management, planning, monitoring, improvement and evaluation of our health services, in accordance with HPP 2.2(f);
  • the education and training of our clinical and administrative staff, medical students and general practice registrars;
  • research, case studies and the compilation or analysis of statistics, in each case only where the information is de-identified, or where you have given your separate consent, or where the use or disclosure is conducted in accordance with guidelines issued under section 95A of the Privacy Act or section 22 of the Health Records Act; and
  • the establishment, exercise or defence of a legal or equitable claim, including in connection with a complaint, investigation or claim concerning our practice.

5.3 Direct marketing

We do not use or disclose your personal information for direct marketing purposes, and we do not provide your personal information to any third party for that purpose. Communications we send you about your care, including appointment reminders, clinical recalls and preventive health reminders, are sent for the purposes described in section 5.1 and are not direct marketing. If we were in future to introduce any general practice communication that constitutes direct marketing, we would do so only on an opt-in basis and with a simple means of opting out in each communication, consistent with APP 7.

5.4 No sale or commercial transfer of information

We do not sell, rent, exchange or otherwise transfer your personal information to any person for any commercial benefit, service or advantage. We do not permit any of our service providers to use information about our patients for their own commercial purposes, or for the purpose of training artificial intelligence models, save where such training is conducted on data that has been irreversibly de-identified and is expressly permitted by our contractual arrangements with that provider.

6. Technology, artificial intelligence and automated processes

Our practice uses a number of software platforms, and certain automated and artificial intelligence (AI) assisted tools, to support practice administration and clinical documentation. We are transparent about the use of these technologies and about the safeguards that govern them. The systems we use, the providers who operate them and the location at which data is held are set out in Schedule 2.

6.1 Practice management and clinical software

Our clinical records are created and held within our clinical and practice management system. That system, together with our payment, telephony, accounting, practice analytics and policy management platforms, is used for scheduling, clinical documentation, prescribing, secure messaging, appointment reminders, invoicing, payment processing and claiming. Our systems are hosted and supported by our contracted information technology provider, which is bound by confidentiality and privacy obligations under its agreement with us.

6.2 Automated administrative communications

We use automated functions within our practice management system to generate appointment confirmations, appointment reminders, clinical recalls and reminders, and account and payment communications. These communications are generated from information held in our clinical system and are subject to the same security and privacy protections as all other personal information we hold. You may elect the channel by which you receive these communications, and you may opt out of non-essential automated communications by notifying our Privacy Officer. We will nonetheless continue to contact you where a clinically significant result or recall requires us to do so.

6.3 AI-assisted clinical documentation

Our practitioners use an AI-assisted clinical documentation tool (an “AI scribe”) to support the recording, transcription and summarisation of consultation notes. The tool listens to the consultation and generates a draft clinical note, which is then reviewed, corrected and approved by the treating practitioner before it is saved to your record. The practitioner remains responsible at all times for the accuracy and content of your clinical record. You will be informed before an AI scribe is used in your consultation and your consent will be sought. You may decline the use of the tool, or withdraw your consent at any time, without any effect whatsoever on your access to our Services or on the care you receive. Consistent with the RACGP Standards, no audio or audio-visual recording of a consultation is made without your consent. In respect of the AI scribe presently in use at our practice, we are informed by the provider:
  • that all transcription and language-model processing is performed on servers located in Australia;
  • that the audio of the consultation is not retained and is destroyed immediately following transcription;
  • that transcripts are redacted of personally identifying information before further processing; that data is encrypted in transit and at rest; and
  • that documents are retained on the provider’s Australian servers for a short, configurable period before being permanently deleted.
Further information about the specific tool in use is available from our Privacy Officer on request.

6.4 Practice analytics

We use a practice analytics platform to monitor the performance, efficiency and clinical quality of our practice. That platform draws data from our clinical system and presents it in aggregated form for practice management, quality improvement and business planning purposes, which is a use permitted by HPP 2.2(f). We do not use practice analytics to make decisions about individual patients.

6.5 No automated clinical decision-making

We do not use automated systems or artificial intelligence for clinical decision-making, diagnosis or the formulation of treatment recommendations. All clinical judgements, diagnoses, prescribing decisions and treatment decisions at our practice are made by registered health practitioners exercising independent professional clinical judgement.

6.6 Automated decisions affecting your rights or interests

We do not use any computer program to make, or to substantially and directly assist in making, any decision of that kind. Decisions that affect your rights or interests, including decisions about your clinical care, your eligibility for particular services, and the fees payable by you, are made by our practitioners and staff. Should our practice adopt any technology to which APP 1.7 applies, we will amend this Privacy Policy before doing so to disclose the kinds of personal information used, the kinds of decisions made, and the kinds of decisions for which the program is used to substantially and directly assist a human decision-maker.

7. Our website and online services

Our website is located at the address set out in Schedule 1. You may visit our website without identifying yourself. Our web server and the analytics tools we use may automatically record limited technical information about your visit, including your internet protocol address, browser type, the pages you view and the date and time of your visit. This information is used in aggregate to administer and improve our website and is not used to identify you. Our website may use cookies, being small text files placed on your device, to enable the website to function correctly and to collect anonymous usage statistics. You may configure your browser to refuse cookies, although some functions of our website may not then operate as intended. If you submit an enquiry, appointment request or registration form through our website, the information you provide will be collected and handled in accordance with this Privacy Policy. Where we use a third-party online appointment booking platform, that provider will also handle your information in accordance with its own privacy policy, and we encourage you to review it.

8. When and how do we disclose your personal information?

We handle your health information with the utmost discretion. As a general principle, we do not disclose your personal information to any person outside our practice without your consent, save in the limited circumstances described below, each of which is required or authorised by law.

8.1 Disclosure with your consent

Where we share information with third parties in the course of coordinating your care, we do so with your consent, which is documented in your patient record. Consent may be given expressly, in writing or verbally, in which case it is noted in your clinical record, or may be implied by your conduct in seeking a referral or in requesting that we liaise with another practitioner. Disclosures made with your consent may be to:
  • specialists, allied health practitioners, hospitals, day procedure centres and other members of your treating team;
  • pathology and diagnostic imaging providers requested to carry out investigations;
  • pharmacies, in connection with the dispensing of prescriptions;
  • another general practice or health service provider to whom you transfer your care;
  • NDIS support coordinators, plan managers and disability service providers, and aged care providers and assessment services;
  • insurers, case managers and legal representatives acting in connection with a workers compensation, transport accident, personal injury, income protection or other claim, to the extent authorised by you; and
  • any other person specifically authorised by you in writing.

8.2 Our service providers and contractors

We disclose personal information to service providers who assist us to operate the practice, including our information technology and cloud hosting provider, our clinical software, secure messaging, telephony, payment processing, practice analytics, accounting and secure document destruction providers. Each of these providers is engaged under arrangements that require it to protect the information it handles on our behalf, to use that information only for the purposes for which it was provided to it, and to comply with applicable privacy laws. We remain accountable to you for the information we entrust to them.

8.3 Disclosure required or authorised by law

We may be required or authorised by or under an Australian law, or by a court or tribunal order, to disclose your personal information without your consent. Circumstances in which this may occur include:
  • in response to a subpoena, summons, warrant, court order or other compulsory legal process;
  • in response to a lawful request or audit by Services Australia, the Department of Veterans’ Affairs, the Professional Services Review or the Department of Health, Disability and Ageing in connection with Medicare or DVA claiming;
  • in response to a lawful request by the Australian Health Practitioner Regulation Agency, a National Board, the Health Complaints Commissioner, or a coroner; and
  • where disclosure is necessary for the establishment, exercise or defence of a legal or equitable claim.

8.4 Mandatory reporting and public protection obligations

As a general practice operating in Victoria, we and our practitioners are subject to a number of statutory reporting obligations which may require us to disclose information about you without your consent. These include:
  • the reporting of notifiable conditions and infectious diseases to the Chief Health Officer under the Public Health and Wellbeing Act 2008 (Vic) and the regulations made under that Act;
  • the mandatory reporting by registered medical practitioners and registered nurses of a belief on reasonable grounds that a child has suffered, or is likely to suffer, significant harm as a result of physical injury or sexual abuse, under section 182 of the Children, Youth and Families Act 2005 (Vic);
  • the obligation to disclose to Victoria Police information giving rise to a reasonable belief that a sexual offence has been committed against a child under 16, under section 327 of the Crimes Act 1958 (Vic);
  • the mandatory notification to the Australian Health Practitioner Regulation Agency of notifiable conduct by a registered health practitioner or student, under section 141 of the Health Practitioner Regulation National Law (Victoria);
  • the reporting of reportable deaths to the Coroner under the Coroners Act 2008 (Vic);
  • the reporting of vaccinations administered to the Australian Immunisation Register under the Australian Immunisation Register Act 2015 (Cth); and
  • the reporting to the Department of Transport and Planning of a condition that may render a person unfit to hold a driver licence, where that reporting is permitted or required under the Road Safety Act 1986 (Vic).
Where it is lawful, practicable and safe to do so, we will inform you before making a disclosure of this kind.

8.5 Victorian information sharing schemes

General practitioners and general practice nurses are prescribed information sharing entities under the Child Information Sharing Scheme established by Part 6A of the Child Wellbeing and Safety Act 2005 (Vic) and under the Family Violence Information Sharing Scheme established by Part 5A of the Family Violence Protection Act 2008 (Vic). This means that, in defined circumstances and subject to the Ministerial Guidelines made under each scheme, we may share information with, and are obliged to respond to requests for information from, other prescribed entities for the purpose of promoting the wellbeing or safety of a child, or for the purpose of assessing or managing a risk of family violence. Where these schemes apply, information may be shared without your consent, and the schemes prevail over the consent requirements that would otherwise apply under the Health Records Act. Certain categories of information are excluded from sharing under the schemes, and we will not share excluded information. We will seek and take into account the views of the child, and of the affected person in a family violence context, wherever it is safe, appropriate and reasonable to do so.

8.6 Serious threat to life, health, safety or welfare

We may use or disclose your personal information without your consent where we reasonably believe that the use or disclosure is necessary to lessen or prevent a serious threat to the life, health, safety or welfare of any individual, or a serious threat to public health, public safety or public welfare, in accordance with APP 6.2(c) and HPP 2.2(h). It is not necessary that the threat be imminent. Any disclosure of this kind is recorded in writing.

8.7 Disclosure to family members and carers

Where you are incapable of giving consent, we may disclose health information about you to an immediate family member where the disclosure is necessary to provide appropriate health services to you or to your care, or is made for compassionate reasons, in each case limited to the extent reasonable and necessary and provided the disclosure is not contrary to any wish you expressed before becoming incapable of consenting. This reflects HPP 2.4. If you are known or suspected to be deceased or missing, or have been involved in an accident and are incapable of consenting, we may use or disclose information to the extent reasonably necessary to identify you or to locate an immediate family member or other relative, in accordance with HPP 2.5. Outside these circumstances, we will not discuss your care with a family member, partner or carer, or confirm that you are a patient of our practice, without your consent. If you wish a particular person to be able to speak with us about your care, please advise our reception staff so that we may record that authority on your file.

8.8 My Health Record

Where you have a My Health Record and have not withdrawn your consent, we may upload documents to, and view documents in, your My Health Record for the purposes of your healthcare. The My Health Record system is administered by the Australian Digital Health Agency under the My Health Records Act 2012 (Cth), which imposes its own controls, access settings and penalties for unauthorised collection, use or disclosure. You may set your own access controls, request that particular documents not be uploaded, or cancel your record at any time by contacting the Australian Digital Health Agency. Please tell your practitioner if you do not wish a particular document to be uploaded.

9. How do we store and protect your personal information?

We are committed to ensuring that your personal information is stored securely and protected against misuse, interference and loss, and against unauthorised access, modification or disclosure, as required by APP 11 and HPP 4.1. We implement a comprehensive suite of technical and organisational security measures.

9.1 Where your information is held

Our clinical and practice management records are held electronically in a cloud environment hosted and managed by our contracted information technology provider in Australian data centres. Limited paper records, including hard copy forms and correspondence received by post or facsimile, are held at the practice and are scanned into the clinical record.

9.2 Technical security measures

Our technical security framework includes:
  • password protection and encryption for all digital systems, and Secure Sockets Layer (SSL) or equivalent protocols for all data transmission;
  • multi-factor authentication for access to our practice management and clinical systems;
  • encryption of sensitive information both in transit and at rest;
  • secure server infrastructure provided through certified cloud service providers with Australian data sovereignty protections;
  • firewall protection, endpoint protection software, regular security monitoring, software updates and threat assessments;
  • the exchange of clinical correspondence and results by encrypted secure messaging in preference to unencrypted email; and
  • automated backup systems with encrypted data recovery capabilities, tested periodically.

9.3 Organisational security measures

Our organisational security measures include:
  • role-based access controls, ensuring that each member of our team may access only the information necessary for the performance of their duties, with full clinical record access confined to treating clinical staff and administrative access confined to the information required for reception, billing and practice management functions;
  • individual user accounts and audit logging, so that access to and amendment of clinical records is attributable to an identified user;
  • immediate account deactivation and access removal upon the departure of any member of our team;
  • written confidentiality undertakings from all employees, contractors and students, which survive the end of their engagement;
  • induction and ongoing training for all staff on privacy obligations, confidentiality, information handling and cyber security awareness;
  • a documented incident response and data breach notification procedure, maintained in our practice policy management system; and
  • ongoing evaluation of our technology platforms and third-party service providers to ensure continued compliance with applicable privacy and security standards.

9.4 Paper records and physical security

Where personal information is held in paper form, it is stored in secure areas of the practice to which access is restricted, and is not left unattended in areas accessible to patients or visitors. Consultation and treatment rooms are configured so that computer screens displaying patient information are not visible to other patients. Paper records containing personal information are securely destroyed when no longer required, in the manner described in section 11.

9.5 Limitations

Whilst we take all reasonable precautions to protect your personal information, no method of data transmission or electronic storage is completely secure. We cannot guarantee the absolute security of information transmitted over the internet, and any such transmission occurs at your own risk. If you send us personal or health information by ordinary email, please be aware that ordinary email is not a secure means of communication.

9.6 Data breaches

We maintain a documented data breach response plan. If we suspect that a data breach may have occurred, we will contain the breach immediately and will carry out an assessment, expeditiously and in any event within 30 days, to determine whether the breach is an eligible data breach. Where we have reasonable grounds to believe that an eligible data breach has occurred, being a breach that is likely to result in serious harm to any affected individual, we will notify the Office of the Australian Information Commissioner (OAIC) and each affected individual as soon as practicable, as required by Part IIIC of the Privacy Act. That notification will set out the nature of the breach, the kinds of information concerned, and the steps we recommend that you take in response. We will also notify the Health Complaints Commissioner and any other regulator where required or appropriate, and will report the incident to our professional indemnity insurer and, where applicable, our cyber insurer.

10. Overseas and interstate disclosure

Our clinical records, and the information held in our clinical and practice management system, are stored in Australian data centres. Our AI-assisted clinical documentation tool processes and stores data exclusively within Australia. We do not transfer your health information overseas for the purpose of providing health services to you. Certain administrative and accounting platforms used by our practice are operated by providers who host data in data centres located outside Australia. Where this occurs, the information involved is limited to that necessary for the administration of the practice, such as a patient name and the amount and date of an account, and does not include your clinical record. Before disclosing personal information to an overseas recipient, we take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs in relation to that information, as required by APP 8.1, and we remain accountable under section 16C of the Privacy Act for acts and practices of that recipient that would breach the APPs. You should be aware that HPP 9 regulates the transfer of health information to any recipient located outside Victoria, and not merely outside Australia. Where we transfer health information to a recipient outside Victoria, whether elsewhere in Australia or overseas, we do so only where the recipient is subject to a law, binding scheme or contract that effectively upholds principles for the fair handling of information substantially similar to the HPPs, or where we have taken reasonable steps to ensure that the recipient will not handle the information inconsistently with the HPPs, or where another basis set out in HPP 9.1 applies. The location at which each of our providers holds data is identified in Schedule 2.

11. How long do we keep your personal information?

We are prohibited by HPP 4.2 from deleting health information about you before the later of:
  • where the information was collected while you were a child, the date on which you attain the age of 25 years; and
  • the date seven years after the last occasion on which we provided a health service to you.
Our practice retains clinical records for at least that period. In practice we generally retain records for longer, because the limitation periods applicable to claims arising out of the provision of health services, particularly claims by or on behalf of children and persons under a disability, may extend well beyond seven years, and because our professional indemnity insurer requires records to remain available. At the expiry of the applicable retention period, personal information is securely destroyed. Electronic records are permanently and irreversibly deleted from our live systems and from backup media by our information technology provider, and we obtain confirmation that this has occurred. Paper records are destroyed by cross-cut shredding, or are destroyed by a contracted secure destruction provider that issues a certificate of destruction. Where health information is deleted, we make and retain a written note of the name of the individual to whom the information related, the period covered by it and the date on which it was deleted, as required by HPP 4.3. Where information cannot practicably be destroyed at the expiry of the retention period, for example because it forms part of records that are the subject of ongoing legal proceedings, a complaint or an investigation, it will be retained only for so long as necessary for that purpose and will then be destroyed. We may retain de-identified information beyond the standard retention period for quality improvement, training or research purposes. If our practice is sold, transferred or closed, we will comply with HPP 10, which requires us to publish a notice in a newspaper circulating in the locality of the practice stating how we propose to deal with the health information we hold, to take such other steps to notify patients as the Health Complaints Commissioner’s guidelines require, and, not earlier than 21 days after that notice, to elect either to retain that information or to transfer it to the provider taking over the practice or to you or a provider nominated by you.

12. Your rights in relation to your personal information

12.1 Right of access

You have the right, under APP 12 and under HPP 6.1 and Part 5 of the Health Records Act, to request access to the personal and health information we hold about you. Requests for access should be made in writing to our Privacy Officer, whose contact details appear in Schedule 1. We may require you to provide evidence of your identity, and, where a request is made on your behalf, evidence of that person’s authority to act for you. We will respond to a request for access as soon as practicable, and in any event no later than 45 days after we receive it. You may ask to inspect your information at the practice, to be given a copy of it, or to be given an accurate summary of it, and we will ordinarily provide access in the form you request. We may charge a fee for providing access, which will not exceed the maximum fee prescribed by the Health Records Regulations 2023 (Vic) and which we will tell you about before we incur it. We do not charge for making a request. We may refuse access in the limited circumstances permitted by the Privacy Act and the Health Records Act, including where providing access would pose a serious threat to the life or health of any person, would have an unreasonable impact on the privacy of other individuals, would be unlawful, or where the information relates to existing legal proceedings between you and us. If we refuse access, we will give you written reasons and will tell you how you may complain about that decision. Where access is refused on the ground that it would pose a serious threat to your life or health, you may nominate a health service provider to whom the information will be given so that they may assess and, if appropriate, explain it to you, in accordance with Division 3 of Part 5 of the Health Records Act.

12.2 Right to correction

Under APP 13 and HPP 6.5, you have the right to request the correction of personal information we hold that is inaccurate, out of date, incomplete, irrelevant or misleading. Requests for correction should be made in writing to our Privacy Officer. We will notify you of our decision on your request as soon as practicable, and in any event no later than 30 days after we receive it, and we will record the name of the person who made the correction and the date on which it was made. For medico-legal reasons, we do not delete or overwrite an original clinical entry. Where a correction is made, the corrected information is recorded in a manner that preserves the integrity and audit trail of the record. If we are not willing to make a correction you have requested, you may give us a written statement setting out your position, and we will take reasonable steps to associate that statement with the relevant information so that it is apparent to anyone reading the record. We will also take reasonable steps to notify any health service provider to whom we previously disclosed the information and who may reasonably be expected to rely on it.

12.3 Requests for deletion or restriction of use

You may ask us to delete your personal information, or to restrict its use. We will comply with such a request to the extent that we are permitted by law to do so. You should be aware, however, that HPP 4.2 prohibits us, as a health service provider, from deleting health information about you before the period described in section 11 has expired, and that we are required by law and by professional standards to maintain complete clinical records. Where we are unable to comply with a request for deletion, we will tell you in writing why that is so, and we will consider whether the use of the information can instead appropriately be restricted.

12.4 Transfer of your information to another provider

If you ask us to make your health information available to another health service provider, or authorise another provider to request it from us, we must provide a copy or an accurate written summary of that information to that provider as soon as practicable, on payment of a fee not exceeding the prescribed maximum. This right, conferred by HPP 11, exists independently of your right of access under section 12.1.

12.5 Anonymity and pseudonymity

You may deal with our practice anonymously or under a pseudonym when making a general enquiry that does not require us to identify you, and you are not obliged to identify yourself in order to visit our website. It is not, however, practicable for us to provide clinical services anonymously or under a pseudonym. Accurate identification is essential to safe clinical care, including the correct correlation of investigation results, the safe prescribing of medicines, the accurate recording of allergies and adverse reactions, and the prevention of clinical error. It is also required by law in order to claim Medicare and DVA benefits, to prescribe under the Pharmaceutical Benefits Scheme, and to record vaccinations on the Australian Immunisation Register. If you have concerns about being identified, including for reasons of personal safety, please raise them with our Privacy Officer so that we can discuss what protective measures may be available to you.

12.6 Communications and format

We provide communications in both electronic and hard copy format. You may tell us your preferred method of contact, including whether you wish to receive reminders by SMS or by email, and you may change that preference at any time. Where you have safety concerns, we can record restrictions on the methods and addresses we use to contact you.

13. Children, young people and patients who cannot consent

13.1 Children and young people

Where a patient is a young child, we ordinarily collect information from, and provide information to, a parent or other person with parental responsibility for the child. There is no fixed age in Victoria at which a young person becomes able to make their own decisions about their health care and their health information. A young person under the age of 18 who is assessed by their treating practitioner as having sufficient maturity and understanding to comprehend the nature and consequences of the health service in question may consent to that service and may control the collection, use and disclosure of the health information arising from it. Where a young person is assessed as having that capacity, we will not disclose their health information to a parent or guardian without the young person’s consent, unless disclosure is required or authorised by law or is necessary to lessen or prevent a serious threat to any person’s life, health, safety or welfare. Health information collected while a patient was a child must not be deleted before that patient attains the age of 25 years, as described in section 11.

13.2 Patients who lack decision-making capacity

Where a patient is incapable of giving consent within the meaning of section 85(3) of the Health Records Act, we will deal with that patient’s authorised representative. Depending on the circumstances, an authorised representative may be a guardian appointed under the Guardianship and Administration Act 2019 (Vic), an attorney appointed under an enduring power of attorney, a medical treatment decision maker or support person under the Medical Treatment Planning and Decisions Act 2016 (Vic), a parent or person with parental responsibility in the case of a child, or another person appointed by the Victorian Civil and Administrative Tribunal. We will take reasonable steps to verify the authority of any person purporting to act as an authorised representative or substitute decision-maker before relying upon their consent or providing information to them, and we may ask to see the relevant appointment document, order or advance care directive so that a copy may be placed on the patient’s file. Where a patient is incapable of consenting and it is not reasonably practicable to obtain the consent of an authorised representative, or the patient has no authorised representative, we may collect, use or disclose health information to the extent reasonably necessary to provide a health service to the patient, in accordance with HPP 1.1(c) and HPP 2.2(d).

13.3 Family violence and patient safety

We recognise that the handling of personal information can carry particular risks for patients experiencing or at risk of family violence. Where you tell us that you have safety concerns, we can apply restrictions to your record, including confidential contact details, restrictions on the persons with whom we will communicate, and restrictions on the correspondence we send to a residential address. Please raise any such concerns with your practitioner or with our Privacy Officer.

13.4 Deceased patients

We continue to protect the health information of deceased patients. A legal representative of a deceased patient has a right of access under the Health Records Act to the health information we hold about that patient, and may make decisions about that information. Requests of this kind should be made in writing to our Privacy Officer, accompanied by evidence of the applicant’s authority.

13.5 NDIS participants, DVA clients and aged care

Where you are an NDIS participant, we may, with your consent, collect information from and disclose information to your support coordinator, plan manager or supported independent living provider for the purpose of coordinating your care. Where you hold DVA entitlements, your DVA file number and entitlement information are collected and held for the purposes of facilitating claims and ensuring appropriate care coordination, and we handle that information in accordance with the applicable DVA provider requirements. Where we provide services to you in a residential aged care facility or other shared living environment, we take particular care to ensure that consultations are conducted, and information communicated, in a manner that preserves your privacy so far as the environment permits.

14. Complaints, enquiries and contact

14.1 Our complaint handling process

If you have any concern about the manner in which we have handled your personal information, or you believe that we have breached the APPs, the HPPs or any other applicable privacy obligation, you are entitled to make a complaint to our Privacy Officer. You may do so in writing, by email, or by asking to speak with our Privacy Officer at the practice. We take all privacy complaints seriously and will investigate them promptly and impartially. Making a complaint will not affect the care you receive from our practice. Our complaint handling process is as follows:
  • we will acknowledge your complaint within 7 business days of receiving it;
  • we will investigate the matter with the relevant personnel and, where necessary, with our external privacy advisers;
  • we will provide you with a substantive written response, including our findings and any corrective action taken, within 30 days of receiving your complaint; and
  • if further time is required because of the complexity of the matter, we will notify you of the expected timeframe and keep you informed of our progress.

14.2 Health Complaints Commissioner (Victoria)

If you are not satisfied with our response, or you would prefer to raise your concern directly with the Victorian regulator, you may complain to the Health Complaints Commissioner, which is the body responsible for complaints about the handling of health information under the Health Records Act. A complaint to the Health Complaints Commissioner must generally be made within 12 months after you became aware of the matter complained of, and the Commissioner will ordinarily expect that you have first raised the matter with us.
Health Complaints Commissioner (Victoria)
Telephone 1300 582 113
Postal address Level 26, 570 Bourke Street, Melbourne VIC 3000
Website www.hcc.vic.gov.au

14.3 Office of the Australian Information Commissioner

You may alternatively make a complaint about our handling of your personal information to the Office of the Australian Information Commissioner, which is responsible for complaints under the Privacy Act. The OAIC will ordinarily expect that you have first complained to us and allowed us 30 days to respond.
Office of the Australian Information Commissioner
Telephone 1300 363 992
Email enquiries@oaic.gov.au
Postal address GPO Box 5218, Sydney NSW 2001
Website www.oaic.gov.au

14.4 Complaints about a practitioner

A complaint about the professional conduct of a registered health practitioner may be made to the Australian Health Practitioner Regulation Agency at www.ahpra.gov.au. A complaint about the health service you have received, as distinct from the handling of your information, may also be made to the Health Complaints Commissioner.

15. Third party services and websites

This Privacy Policy does not apply to third party websites, services or platforms to which we may link or refer, including online appointment booking platforms, payment processors, health information websites and the websites of other health service providers involved in your care. We are not responsible for the privacy practices of any third party, and we encourage you to review the privacy policy of any third party service with which you interact.

16. Changes to this Privacy Policy

We will review this Privacy Policy at least once every two years, and in any event whenever there is a material change to our practice, to the systems or service providers we use, or to the law. This document satisfies our obligation under HPP 5.1 to set out in a document our clearly expressed policies on the management of health information and the steps an individual must take to obtain access to their health information, and our obligation under APP 1.3 to maintain a clearly expressed and up to date policy about our management of personal information. The current version of this Privacy Policy is maintained on our website and is available free of charge in hard copy from our reception on request. When material changes are made, we will update the version details recorded in Schedule 3, publish the updated policy on our website, and display a notice at our reception. Where a change requires your consent as a matter of law, we will seek that consent separately.

17. How to contact us

For all privacy-related enquiries, access requests, correction requests, complaints or concerns, please contact our Privacy Officer using the details set out in Schedule 1. Schedule 1 – Practice details and Privacy Officer
Item Detail
Practice (trading) name Elwood Village Medical
Operating entity Elwood Medical Group Pty Ltd
ACN 651 971 087
ABN 54 651 971 087
Practice address 146 Ormond Rd, Elwood VIC 3184
Postal address 146 Ormond Rd, Elwood VIC 3184
Telephone (03) 9828 757
Website www.elwoodvillagemedical.com.au
Privacy Officer Elizabeth Violette Bishara, Practice Manager
Privacy Officer email manager@elwoodvillagemedical.com.au
Services provided General practice and practice nursing services
Professional registration Our practitioners are registered with the Australian Health Practitioner Regulation Agency
Professional indemnity Professional indemnity insurance is maintained, and extends to privacy breaches
Schedule 2 – Systems and service providers The following table records the principal systems used by our practice, the purposes for which each is used, and the location at which data is held. It is maintained by our Privacy Officer and is updated as our systems change. A change to this Schedule does not of itself constitute a material change to this Privacy Policy.
System Provider Purpose Data location
Best Practice Best Practice Software Pty Ltd Clinical records, prescribing, recalls and reminders, practice management Australia
Cloud hosting and IT support GP Support IT Services Hosting, backup, security and support of practice systems Australia
Tyro Tyro Payments Limited Payment processing, Medicare and health fund claiming at the point of care Australia
Lyrebird Lyrebird Health Pty Ltd AI-assisted transcription and drafting of consultation notes Australia
Cubiko Cubiko Pty Ltd Practice analytics and quality improvement reporting Australia
PracticeHub Avant Mutual Group Practice policy, compliance and staff training management Australia
3CX 3CX/practice telephony provider Telephone system and telehealth consultations Australia
Xero Xero Australia Pty Ltd Accounting, invoicing and bookkeeping Outside Australia (United States)
Schedule 3 – Version control
Version Date of issue Approved by Next scheduled review
1.0 18 August 2026 Dr Shnedha Nagpal 18 August 2028