Foundations of general practice standard

F9 – Confidentiality and privacy of health and other information


      1. F9 – Confidentiality and privacy of health and other information

F9 | Confidentiality and privacy of health and other information


Consumer expectation statement: I expect that my health information held by this practice is secure and confidential, and I am promptly notified if a data breach occurs.

F9.A The practice manages health information securely and confidentially.

The practice:

  • informs patients how their personal health information is managed, including security, confidentiality and access
  • has at least one member of the practice team who has primary responsibility for privacy related matters
  • maintains a privacy policy consistent with the Australian Privacy Principles and communicate it to patients
  • confirms that the practice team understands and implements its privacy policy
  • protects patient privacy when communicating electronically with or about patients by using a secure message system or other method of encryption, unless the patient has provided informed consent to their information being sent without such protection
  • informs patients of its data breach protocols.

F9.B The practice has a policy and procedure so that only authorised members of the practice team can access its clinical information system, prescription forms, and other official documents.

The practice:

  • only allows authorised members of the practice team to access its clinical information system via unique individual identification and according to the person’s level of authorisation
  • describes in its privacy policy how members of the practice team access patient information, including how access levels are determined and allocated
  • securely stores all official documents, including prescription forms, administrative records, templates and letterhead.


Protecting the security and confidentiality of health and other information is critical for consumer privacy and safety.


The practice needs to collect personal health information and then safeguard its confidentiality and privacy in accordance with:

  • the Australian Privacy Principles (APPs) contained in the Privacy Act 1988
  • legal and ethical confidentiality obligations
  • other relevant state or territory laws (which may or may not be specific to health).

The practice is subject to stringent privacy obligations because it holds health information, which is a subset of what is referred to as personal information. Sensitive personal information, which includes any health information, requires more rigorous protection than non-sensitive information. Personal information can include any information collected to provide a health service, including a person’s:

  • name and address
  • bank account details
  • Medicare number
  • health information
  • demographic and identity-related details.

Even when there is no name attached, some details about a person’s medical history or other information could identify them (for example, details of an appointment). Therefore, this information is considered health information and must be protected in accordance with the Privacy Act 1988.

There may be specific circumstances that allow or require the practice to share or disclose sensitive health-related information. This can only be done in accordance with the APPs, and in the interests of a patient’s health and wellbeing, as described by the Office of the Australian Information Commissioner and relevant legislation.

The RACGP’s Privacy and managing health information in general practice explains the safeguards and procedures that general practices need to implement to meet legal and ethical standards relating to privacy and security. The practice’s medical defence organisation can also provide information and advice about developing relevant strategies.


The practice’s documented privacy policy needs to address the management of patient health information, and the practice needs to inform patients of the policy. The privacy policy needs to be in plain English, specify a review date, and address certain legal requirements, including:

  • information about how members of the practice team collect and access patient information, that includes:
    • the definition of a patient health record
    • the kinds of personal information the practice collects and holds
    • how and why the practice collects, stores, uses, protects, and discloses personal information (including remote access if applicable)
    • how patients can communicate with the practice anonymously
  • patients’ interactions about their privacy and health information
    • how patients can access and correct personal information held by the practice
    • how a patient can complain about a breach of the APPs or of a registered APP code, and how the practice will deal with such a complaint
  • the disclosure of patients’ health information to a third party
    • obtaining informed patient consent when disclosing health information
    • to whom health information might be disclosed
    • whether health information is likely to be disclosed overseas and, if so, where and how
    • how the practice uses document automation technologies, particularly so that only the relevant medical information is included in referral letters.

Refer to the RACGP’s privacy policy template available at the resources page on the RACGP website.

For further information about privacy, visit the Office of the Australian Information Commissioner’s (OAIC’s) website.

Consumers need to have access to the practice’s privacy policy. This could be on the practice’s website or reception staff could provide a copy when a consumer asks for one (for example, via a QR code or hard copy).
See PP1 – Information about the practice for more information on making information such as this accessible to patients.


The Privacy Act 1988 permits an organisation to disclose necessary health information to an individual’s responsible person (such as a carer), if:

  • it is reasonably necessary, in the context of providing a health service to that individual
  • the individual is physically or legally incapable of consenting or communicating that consent.

If a carer is seeking access to a patient’s health information, it is recommended that the practice seeks advice from its medical defence organisation before deciding whether to give the carer access to the information or not.


The practice needs to confirm that members of the practice team understand and implement its privacy policy.

 As well as being familiar with the APPs, members of the practice team could:

  • familiarise themselves with the relevant state/territory laws about privacy and health records (for more information about privacy laws in each jurisdiction, visit the OAIC website)
  • undertake regular privacy training to maintain familiarity with privacy requirements.


Members of the practice team require access only to the systems, platforms and information they need to undertake their roles. Members of the practice team have a responsibility to use patient information only for its intended purpose and for the benefit of the patients. Different roles will require different levels of access, and the practice needs to allocate system permissions accordingly. Access could include, but is not limited to:

  • the practice’s clinical information system/s
  • online identity verification and authentication systems (for example, for secure access to government online services including Medicare and Health Connect Australia)
  • digital health record platforms, including My Health Record
  • correspondence (letters and emails) from consumers or external clinicians.


Keep health information concealed from unauthorised sight and prevent unauthorised access, by adopting practical measures such as:

  • positioning computer screens so they can’t be viewed by unauthorised people
  • using automated privacy tools, such as screensavers, when devices are unattended
  • installing security measures on devices (for example, mobile phones, tablets, laptops, and other portable devices) that are of the same standard as the practice’s desktop computers.

Advertising