Australian Privacy Principles (app) Policy
Part A – Purpose and Context
- CardioVascular Clinics is committed to ensuring the privacy and confidentiality of all personal information affiliated with the CardioVascular Clinics business undertakings.
- CardioVascular Clinics follow the terms and conditions of privacy and confidentiality in accordance to the Australian Privacy Principles (APPs) as per schedule 1 of the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth), forming part of the Privacy Act 1988 (‘the Act’).
- The point of contact regarding any queries regarding this policy is Shelly, Manager CardioVAscular Clinics 1300 306 358 [email protected]
Part B – Australian Privacy Principles
- As a private sector CardioVascular Clinics provider and under permitted health situations, CardioVascular Clinics is required to comply with the APPs as prescribed under the
- The APPs regulate how CardioVascular Clinics may collect, use, disclose and store personal information and how individuals, including CardioVascular Clinics patients may:
- address breaches of the APPs by CardioVascular Clinics;
- access their own personal information; and,
- correct their own personal information.
- In order to provide patients with adequate health care services, CardioVascular Clinics will need to collect and use personal information. It is important to be aware that if the patient provides incomplete or inaccurate information or the patient withholds personal health information CardioVascular Clinics may not be able to provide the patient with the services they are requesting.
- “personal information” as defined by the Privacy Act 1988 (Cth). Meaning
“information or an opinion including information or an opinion forming part of a database, whether true or not, and whether recorded in a material format or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion”; and,
- “health information” as defined by the Privacy Act 1988 (Cth). This is a particular subset of “personal information” and means:
- Information or opinion about the health or disability (at any time i.e. past, present or future) of an individual that can be classified as personal information;
- Information or opinion about an individual’s expressed wishes about the future provision of health services that can be classified as personal information;
- Information or opinion about CardioVascular Clinics provided, or to be provided, to an individual, that can be classified as personal information;
- Other personal information collected to provide, or in providing, a health service;
- Other personal information about an individual collected in connection with the donation, or intended donation, by the individual of his or her body parts, organs or body substances; or
- Genetic information about an individual in a form that is, or could be, predictive of the health of the individual or a genetic relative of the individual.
- Personal information also includes ‘sensitive information’ which is information including, but not limited to a patient’s:
- political opinions;
- sexual preferences; and or,
- health information.
- Information deemed ‘sensitive information’ attracts a higher privacy standard under the Act and is subject to additional mechanisms for the patient’s protection.
- “personal information” as defined by the Privacy Act 1988 (Cth). Meaning
Part C – Types of personal information
- CardioVascular Clinics collects information from each individual patient that is necessary to provide the patient with adequate health care services.
- This may include collecting information about a patient’s health history, family history, ethnic background or current lifestyle to assist the health care team in diagnosing and treating a patient’s condition.
Part D – collection & Retention
- This information will in most circumstances be collected directly from the patient through but not limited to the following mediums:
- CardioVascular Clinics patient consent form;
- medical treatment form; and or,
- face to face consultation.
- In other instances, CardioVascular Clinics may need to collect personal information about a patient from a third party source. This may include:
- relatives; or,
- other CardioVascular Clinics providers.
- This will only be conducted if the patient has provided consent for CardioVascular Clinics to collect his/her information from a third party source; or, where it is not reasonable or practical for CardioVascular Clinics to collect this information directly from the patient. This may include where:
- the patient’s health is potentially at risk and his/her personal information is needed to provide them with emergency medical treatment.
- CardioVascular Clinics endeavours to store and retain a patient’s personal & health information in [hard copy on site, transferred electronically onto a domestic server etc].
Part E – Purpose of collection, Use & Disclosure
- CardioVascular Clinics only uses a patient’s personal information for the purpose(s) they have provided the information for unless one of the following applies:
- the patient has consented for CardioVascular Clinics to use his/her information for an alternative or additional purpose;
- the disclosure of the patient’s information by CardioVascular Clinics is reasonably necessary for the enforcement of criminal law or a law imposing a penalty or sanction, or for the protection of public revenue;
- the disclosure of the patient’s information by CardioVascular Clinics will prevent or lessen a serious and imminent threat to somebody’s life or health; or,
- CardioVascular Clinics is required or authorised by law to disclose the patient’s information for another purpose.
Health Professionals to provide treatment
- During the patient’s treatment at CardioVascular Clinics he/she may be referred to alternative medical treatment/services (i.e. pathology or radiology) where CardioVascular Clinics staff may consult with senior medical experts when determining a patient’s diagnosis or treatment.
- CardioVascular Clinics staff may also refer the patient to other CardioVascular Clinics providers for further treatment during and following the patient’s admission. These services include, but are not limited to:
- Physiotherapy; or,
- Outpatient or community health services
- These health professionals will be designated CardioVascular Clinics providers appointed to use the patient’s health information as part of the process of providing treatment. Please note that this process will be conducted whilst maintaining the confidentiality and privacy of the patient’s personal information.
Alternative Health services
- At any point a patient wishes to be treated by an alternative medical practitioner or health care service that requires access to his/her personal/health information CardioVascular Clinics requires written authorisation. This written authorisation is to state that the patient will be utilising alternative health services and that these health services have consented for a transfer of personal/health information.
Other Third Parties
- CardioVascular Clinics may provide the patient’s personal information regarding a patient’s treatment or condition to additional third parties. These third parties may include:
- other relatives;
- close personal friends;
- guardians; or,
- a person exercising a patient’s power of attorney under an enduring power of attorney.
- Where information is relevant or reasonable to be provided to third parties, written consent from the patient is required.
- Additionally, the patient may at any time wish to disclose that no third parties as stated are to access or be informed about his/her personal information or circumstances.
Other Uses of Personal Information
- In order to provide the best possible environment to treat patients, CardioVascular Clinics may also use personal/health information where necessary for:
- activities such as quality assurance processes, accreditation, audits, risk and claims management, patient satisfaction surveys and staff education and training;
- invoicing, billing and account management;
- to liaise with a patient’s health fund, Medicare or the Department of Veteran’s Affairs, as necessary; and,
- the purpose of complying with any applicable laws – i.e. in response to a subpoena or compulsory reporting to State or Federal authorities.
- If at any point or for any of the aforementioned reasons CardioVascular Clinics uses or discloses personal/ health information in accordance with the APPs, CardioVascular Clinics will provide written notice for the patient’s consent for the use and/or disclosure.
Part F – Access and changes to personal information
- If an individual patient reasonably requests access to their personal information for the purposes of changing the information he/she must engage with the relevant practice manager.
- The point of contact for patient access to personal information is:
Shelly Shaw [Manager]
1300 306 358
Monday to Friday
- Once an individual patient requests access to his/her personal information CardioVascular Clinics will respond within a reasonable period of time to provide the information.
- All personal information will be updated in accordance to any changes to a patient’s personal circumstances brought to CardioVascular Clinics attention. All changes to personal information will be subject to patient’s consent and acknowledgement.
- If an individual requests access to his/her personal information CardioVascular Clinics will charge $50. Please note that this fee is associated with administrative costs only.
Part G – Complaints handling
- How an individual patient may complain about a breach of the Australian Privacy Principles, or a registered APP code (if any) that binds the entity, and how the entity will deal with such a complaint.
Part H – Personal Information and overseas recipients
- Use of Overseas Parties:
- CardioVascular Clinics does not engage with any overseas entities, with which personal or health information would be transferred, appointed or disclosed.
- CardioVascular Clinics does not engage with overseas entities, with which personal or health information would be transferred, appointed or disclosed.
Part i – Disposal of personal/health information
- If CardioVascular Clinics receives any unsolicited personal information that is not deemed appropriate for the permitted health situation, CardioVascular Clinics will reasonably de-identify and dispose of the information accordingly.
- If CardioVascular Clinics holds any personal or health information that is no longer deemed relevant or appropriate for the permitted health situation, CardioVascular Clinics will reasonably de-identify and dispose of the information accordingly.
Part J – Access to policy
Part K – Review of Policy
- CardioVascular Clinics in accordance with any legislative change will review the terms and conditions of this policy to ensure all content is both accurate and up to date.