The practice needs to collect personal health information and then safeguard its confidentiality and privacy in accordance with:
- the Australian Privacy Principles (APPs) contained in the Privacy Act 1988
- legal and ethical confidentiality obligations
- other relevant state or territory laws (which may or may not be specific to health).
The practice is subject to stringent privacy obligations because it holds health information, which is a subset of what is referred to as personal information. Sensitive personal information, which includes any health information, requires more rigorous protection than non-sensitive information. Personal information can include any information collected to provide a health service, including a person’s:
- name and address
- bank account details
- Medicare number
- health information
- demographic and identity-related details.
Even when there is no name attached, some details about a person’s medical history or other information could identify them (for example, details of an appointment). Therefore, this information is considered health information and must be protected in accordance with the Privacy Act 1988.
There may be specific circumstances that allow or require the practice to share or disclose sensitive health-related information. This can only be done in accordance with the APPs, and in the interests of a patient’s health and wellbeing, as described by the Office of the Australian Information Commissioner and relevant legislation.
The RACGP’s Privacy and managing health information in general practice explains the safeguards and procedures that general practices need to implement to meet legal and ethical standards relating to privacy and security. The practice’s medical defence organisation can also provide information and advice about developing relevant strategies.