Skip to main content

Privacy Policy

Introduction

At Jindabyne Medical Practice, we are committed to safeguarding the privacy and confidentiality of patients’ personal information. This Privacy Policy outlines how the business manages, uses, stores, and protects your personal and health information in accordance with Australian legislation and professional standards. It applies to all patients and staff, and covers all personal information collected by our practice.

Purpose

The purpose of this policy is to provide a clear explanation of how the business complies with its privacy obligations, what information is collected, how it is used and disclosed, and how patients can exercise their rights regarding their information.

Scope

This policy applies to all personal and health information held by the business, whether in paper or electronic form, and covers all interactions with patients, staff, contractors, and third parties.

Our Commitment to Privacy

We are dedicated to protecting your personal information and adhering to the highest standards of privacy and confidentiality in all aspects of the business.

Legal Framework

The business complies with the following laws and standards:

  • Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
  • Relevant State and Territory health records legislation
  • The Royal Australian College of General Practitioners (RACGP) 5th Standards of General Practice Accreditation Guidelines

The business regularly reviews its policies to ensure ongoing compliance with all applicable legal and professional obligations.

Collection of Personal Information

Types of Information Collected

The business collects the following types of information, as necessary for your care and business operations:

  • Name, address, date of birth, contact details
  • Medicare number, concession card and health fund details
  • Medical history, current health needs, medications, allergies
  • Family medical history (where relevant)
  • Appointment and billing records
  • Other information relevant to your care or required by law

Methods of Collection

The business collects personal information directly from you, your authorised representative, or, where necessary, from other healthcare providers with your consent. Information is gathered via:

  • Patient registration forms
  • Direct conversations and consultations
  • Electronic communications (e.g. email, online bookings)
  • Referrals and correspondence from other health professionals
  • Test results and imaging reports

Where possible, the business will collect information directly from you. If the business needs to collect information from a third party, your consent will be sort, unless otherwise permitted or required by law.

Use and Disclosure of Personal Information

How Information is Used

Your personal and health information is used to:

  • Provide you with medical care and treatment
  • Communicate with you about your appointments and care
  • Manage practice operations, billing, and administration
  • Comply with legal obligations and reporting requirements
  • Conduct quality assurance, staff training, and accreditation processes

Circumstances for Disclosure

The business may disclose your information:

  • To other healthcare providers involved in your care (e.g. specialists, hospitals, pathology, imaging services)
  • To third parties with your consent (e.g. family members, carers)
  • When required or authorised by law (e.g. public health reporting, court orders)

The business will always seek your consent before sharing your information, unless the disclosure is required or permitted by law.

Data Security and Storage

Safeguards

The business takes all reasonable steps to protect your personal information from misuse, loss, unauthorised access, modification, or disclosure. Security measures include:

  • Secure electronic record systems with password protection
  • Physical security for paper records (locked filing cabinets, restricted access areas)
  • Staff training in privacy and confidentiality
  • Regular review of data security practices

Retention and Disposal

The business will retain health information for as long as required by law and professional guidelines. When no longer needed, records are securely destroyed or de-identified according to established procedures.

Access and Correction of Personal Information

Patient Rights

You have the right to access your personal information held by the business, and to request corrections if you believe the information is inaccurate, incomplete, or outdated.

Procedures for Access and Correction

To request access or correction, please contact The Practice Manager in writing via pm@jindabynemedical.com.au. We will respond to your request within a reasonable timeframe, usually within 30 days. Access may be denied in certain circumstances (e.g. where required by law), but we will inform you of the reason in such cases.

Complaints and Enquiries

How to Raise Concerns

If you have any questions, concerns, or complaints about how your information is managed, please contact the Practice Manager via pm@jindabynemedical.com.au. We take all privacy concerns seriously and will respond promptly and fairly.

Contact Details

Practice Manager
Jindabyne Medical Practice
PO Box 545 JINDABYNE. NSW. 2627
Phone: 02 6457 1221
Email: pm@jindabynemedical.com.au

Policy Review

Frequency and Process for Updates

This Privacy Policy is reviewed at least every 2 years, or sooner if there are changes to relevant laws, guidelines, or our practice procedures. Updates will be communicated to patients and staff via our website, at reception, or by direct notice as appropriate. For further information about privacy in healthcare, you may contact the Office of the Australian Information Commissioner or your relevant State or Territory health complaints authority.