Clinical governance standard

CG2 – Patient identification


      1. CG2 – Patient identification

CG2 | Patient identification


Consumer expectation statement: I expect I am correctly identified by this practice. 

 

CG2.A The practice uses a minimum of three approved patient identifiers to correctly match each patient to their patient health record. 

The practice:

  • uses a minimum of three of the following approved patient identifiers to confirm a patient’s identity each time they engage with the practice:
    • name (family and given names together are one identifier)
    • date of birth
    • address
    • Medicare or DVA number
    • individual phone number.


Verifying a patient’s identity helps to maintain patient safety and confidentiality. Failure to correctly identify a patient can have serious, potentially life-threatening consequences for the patient.

Correctly identifying patients using a minimum of three identifiers confirms that practitioners have the correct patient health record for each consultation. For example, a parent and child could have the same first name, family name, and address, but will have different dates of birth.


Correct patient identification is necessary when:

  • a patient makes an appointment
  • a patient presents to the practice for their appointment
  • the practice communicates with a patient over the telephone or electronically
  • a patient telephones asking for a repeat of a prescription
  • a patient sees more than one member of the clinical team during a visit
  • a patient record is accessed
  • the practice collects and manages information about a patient (for example, scanned documents, X-rays).


When conducting telehealth consultations over the phone or via video, members of the clinical team also need to confirm the patient’s identity using a minimum of three identifiers. It is recommended that confirmation of a patient’s identity be documented in the medical record for each telehealth encounter.


When matching patients to their health record, members of the practice team need to:

  • be mindful of privacy and confidentiality
  • not compromise the safety of the patient
  • ensure the correct patient is matched to their health record, particularly if they have a common or duplicated name
  • seek identifying information from patients rather than providing the information to the patient and asking them to confirm that it is correct.

The practice could develop a process to remind reception staff to ask patients to identify themselves. 

To protect patient privacy, especially for patients who may be at risk, the practice could:

  • direct patients to a private area and use written prompts
  • use discreet verification methods
  • use privacy sensitive check-in processes.

For example, the practice could:

  • identify patients via official documents such as a driver’s licence or passport. Medicare cards cannot be used as a stand-alone patient identifier, as they do not include a photo of the patient and may share numbers across family members. However, a current Medicare card could be used as a secondary identifier alongside an approved patient identifier that has photo identification, such as a current driver’s licence or passport
  • if using an online check-in system to identify patients presenting for an appointment (for example, a tablet or kiosk in the waiting room, or via the patient’s mobile phone), use multi-factor authentication
  • provide patients with writing materials on which they can write details of their approved identifiers
  • ascertain the correct spelling of the patient’s name from their physical or digital Medicare card (if they have one) and ask the patient to confirm other approved identifiers in a way that is sensitive to their needs.

To confirm the currency and accuracy of patient information, reception staff may view an official government-issued photo identification document (for example, a current driver’s licence or passport) that displays the patient’s name and date of birth. Visual inspection of such documentation is sufficient, and copies must not be stored in the patient health record.


It is not advisable to retain photos of patient identification documents in patient health records, particularly if the practice’s clinical information system does not allow information to be permanently deleted. This is a data security risk and could result in identity theft if there is a cyber security incident at the practice. The practice’s privacy policy could address this issue.


The practice could develop internal procedures or prompts to support consistent use of three approved patient identifiers at relevant points of contact, helping to reduce the risk of patient mismatching and support patient safety, accuracy and continuity of care.


In line with the Australian Privacy Principles, wherever it is lawful and practicable, patients need to be able to remain anonymous when receiving care from the practice and when practicable to do so(23). Patients may choose to receive services anonymously if, for example, sensitive issues arise or they feel they may be at risk, such as in situations of family, domestic and sexual violence (FDSV) or difficult relationships. In these circumstances, the use of an alias or ‘disguised identity’ may be the most appropriate approach.
 
The Office of the Australian Information Commissioner (OAIC) provides information about:

  • the differences between anonymity and pseudonymity (the use of a fictitious name or identifier)
  • situations where it may be legally required to identify patients (eg when prescribing medications, referring to diagnostic services, or accessing benefits such as Medicare).

The practice could:

  • obtain legal advice about situations where it is lawful for patients to maintain anonymity or pseudonymity
  • use functions in the clinical information system to enhance patient privacy in sensitive situations (for example, by restricting access to the patient’s health record to the patient’s regular GP).
In high‑risk situations, such as where there are safety concerns, the practice may support patients to use a preferred name or pseudonym in accordance with Australian Privacy Principle 2 (APP2), provided this does not conflict with legal requirements for prescriptions, referrals or benefits claims.


Following the death of an Aboriginal or Torres Strait Islander person, some communities have cultural protocols to avoid naming deceased people, and this may influence the ways the practice identifies patients. As protocols differ throughout the country, the practice could ask the local Aboriginal or Torres Strait Islander community about correct procedures relating to avoidance of names, time periods for avoidance, and the use of images of deceased people. The RACGP’s resource, An introduction to Aboriginal and Torres Strait Islander health cultural protocols and perspectives may provide useful information, however, it is always important to discuss protocols with local Aboriginal and Torres Strait Islander community members, or where possible, family members(24).

Advertising