Privacy Policy
Introduction
At Jindabyne Medical Practice, we are committed to safeguarding the privacy and confidentiality of patients’ personal information. This Privacy Policy outlines how the business manages, uses, stores, and protects your personal and health information in accordance with Australian legislation and professional standards. It applies to all patients and staff, and covers all personal information collected by our practice.
Purpose
The purpose of this policy is to provide a clear explanation of how the business complies with its privacy obligations, what information is collected, how it is used and disclosed, and how patients can exercise their rights regarding their information.
Scope
This policy applies to all personal and health information held by the business, whether in paper or electronic form, and covers all interactions with patients, staff, contractors, and third parties.
Our Commitment to Privacy
We are dedicated to protecting your personal information and adhering to the highest standards of privacy and confidentiality in all aspects of the business.
Legal Framework
The business complies with the following laws and standards:
- Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
- Relevant State and Territory health records legislation
- The Royal Australian College of General Practitioners (RACGP) 5th Standards of General Practice Accreditation Guidelines
The business regularly reviews its policies to ensure ongoing compliance with all applicable legal and professional obligations.
Collection of Personal Information
Types of Information Collected
The business collects the following types of information, as necessary for your care and business operations:
- Name, address, date of birth, contact details
- Medicare number, concession card and health fund details
- Medical history, current health needs, medications, allergies
- Family medical history (where relevant)
- Appointment and billing records
- Other information relevant to your care or required by law
Methods of Collection
The business collects personal information directly from you, your authorised representative, or, where necessary, from other healthcare providers with your consent. Information is gathered via:
- Patient registration forms
- Direct conversations and consultations
- Electronic communications (e.g. email, online bookings)
- Referrals and correspondence from other health professionals
- Test results and imaging reports
Where possible, the business will collect information directly from you. If the business needs to collect information from a third party, your consent will be sort, unless otherwise permitted or required by law.
Use and Disclosure of Personal Information
How Information is Used
Your personal and health information is used to:
- Provide you with medical care and treatment
- Communicate with you about your appointments and care
- Manage practice operations, billing, and administration
- Comply with legal obligations and reporting requirements
- Conduct quality assurance, staff training, and accreditation processes
Circumstances for Disclosure
The business may disclose your information:
- To other healthcare providers involved in your care (e.g. specialists, hospitals, pathology, imaging services)
- To third parties with your consent (e.g. family members, carers)
- When required or authorised by law (e.g. public health reporting, court orders)
The business will always seek your consent before sharing your information, unless the disclosure is required or permitted by law.
Data Security and Storage
Safeguards
The business takes all reasonable steps to protect your personal information from misuse, loss, unauthorised access, modification, or disclosure. Security measures include:
- Secure electronic record systems with password protection
- Physical security for paper records (locked filing cabinets, restricted access areas)
- Staff training in privacy and confidentiality
- Regular review of data security practices
Retention and Disposal
The business will retain health information for as long as required by law and professional guidelines. When no longer needed, records are securely destroyed or de-identified according to established procedures.
Access and Correction of Personal Information
Patient Rights
You have the right to access your personal information held by the business, and to request corrections if you believe the information is inaccurate, incomplete, or outdated.
Procedures for Access and Correction
To request access or correction, please contact The Practice Manager in writing via pm@jindabynemedical.com.au. We will respond to your request within a reasonable timeframe, usually within 30 days. Access may be denied in certain circumstances (e.g. where required by law), but we will inform you of the reason in such cases.
Complaints and Enquiries
How to Raise Concerns
If you have any questions, concerns, or complaints about how your information is managed, please contact the Practice Manager via pm@jindabynemedical.com.au. We take all privacy concerns seriously and will respond promptly and fairly.
Contact Details
Practice Manager
Jindabyne Medical Practice
PO Box 545 JINDABYNE. NSW. 2627
Phone: 02 6457 1221
Email: pm@jindabynemedical.com.au
Policy Review
Frequency and Process for Updates
This Privacy Policy is reviewed at least every 2 years, or sooner if there are changes to relevant laws, guidelines, or our practice procedures. Updates will be communicated to patients and staff via our website, at reception, or by direct notice as appropriate. For further information about privacy in healthcare, you may contact the Office of the Australian Information Commissioner or your relevant State or Territory health complaints authority.
