Privacy Policy

Privacy & Electronic Communication Policy

Safe, lawful and respectful handling of patient information across every communication channel

Document control Details
Policy owner Practice Manager / Privacy Officer
Approved by Michele Newman
Original effective date February 2026
Last updated 3 September 2026
Review date September 2027, or earlier following a significant incident or change
Version 2.0
Applies to All doctors, nurses, allied health professionals, reception and administration staff, contractors, students and locums

Purpose

Milsons Point Medical Centre is committed to protecting patient privacy and maintaining accurate, complete and secure health records. This policy explains how the practice collects, records, accesses, uses, discloses, stores, transfers, retains and securely destroys personal and health information.

It also sets the practice rules for communicating electronically with patients, healthcare providers and authorised third parties. These rules support safe care, patient choice, confidentiality and compliance with privacy and accreditation requirements.

Practice contact: Suite 3, 80 Alfred Street, Milsons Point NSW 2061 | Phone: 02 9023 9999 | Email: reception@milsonspointmedical.com.au

Scope

This policy applies to information in every format, including Best Practice clinical software, the appointment system, secure messaging, practice Outlook email, SMS, My Health Record, telehealth platforms, scanned documents, paper records, photographs, billing information, pathology and imaging results, recalls, referrals and archived records.

It applies whenever a team member creates, views, discusses, prints, copies, downloads, sends, receives, stores or disposes of patient information, whether working at the practice or through approved remote access.

Legal and professional framework

The practice manages patient information in accordance with applicable requirements, including:

  1. Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
  2. Health Records and Information Privacy Act 2002 (NSW) and the NSW Health Privacy Principles.
  3. My Health Records Act 2012 (Cth), where My Health Record is used.
  4. RACGP Standards for general practices and relevant professional obligations.
  5. Applicable record-retention, public health, child protection, subpoena and other legal requirements.

Where authority or the correct course of action is unclear, the information must not be released until the Practice Manager or treating practitioner has reviewed the request and, if needed, obtained professional advice.

Responsibilities

Role Responsibility
Practice Principal Provides governance and approves this policy.
Practice Manager Oversees access, staff training, privacy requests, complaints, electronic communication controls and suspected breaches.
Clinical team Makes timely and accurate records; authorises clinical disclosures; reviews incoming clinical communication; and shares information only when permitted.
Reception and administration Verifies identity and contact details, records consent, protects front-desk privacy, and follows approved sending, receiving and escalation procedures.
All team members Uses an individual login, accesses only what is required, protects passwords and immediately reports errors, misdirection, suspicious access or possible breaches.
IT and other contractors Meets confidentiality, access, backup, security and breach-reporting requirements in their contracts.

 

Collection and consent

The practice collects only information reasonably necessary to provide healthcare and manage related practice activities. This may include identity and contact details, Medicare and billing information, medical and family history, medications, allergies, examination findings, diagnoses, care plans, referrals, results, correspondence, consent, cultural or communication needs and emergency contacts.

Where practical, information is collected directly from the patient. It may also be received from a parent, guardian, carer, treating practitioner, hospital, pathology or imaging provider, My Health Record, Medicare or another authorised source.

Information may be collected when a patient registers or attends the practice, telephones, sends an email or SMS, uses the practice website or online appointment system, participates in telehealth, or communicates through another approved channel. Information may also be exchanged through Electronic Transfer of Prescriptions (eTP) and My Health Record, where applicable.

Patients are told why information is needed and how it may be used or disclosed. Consent may be written, verbal or implied by the circumstances where lawful and appropriate. Consent for electronic communication is recorded in Best Practice and may be withdrawn or changed by the patient at any time.

Patients may use a pseudonym or remain anonymous where lawful and practicable; however, this may limit the services the practice can safely provide or claim through Medicare.

Accurate and complete patient records

  • Records are made at the time of the event or as soon as possible afterwards and are clear enough for another practitioner to understand the care provided.
  • At least three approved patient identifiers are checked before information is opened, changed, discussed, sent, scanned or filed.
  • Patients are regularly asked to confirm their contact details, emergency contact, Medicare details, allergies and other important information.
  • Information is checked before it is copied, scanned or imported into a record. Duplicate or wrong-patient records are reported immediately.
  • Original clinical entries are not deleted or overwritten. Corrections are made through an auditable amendment that preserves the original entry, author, date and reason.
  • Important telephone, email, SMS, secure-message and telehealth communications, including contact attempts and outcomes, are recorded in Best Practice.

Access controls and confidentiality

  • Access is role-based and limited to the minimum information required for the person’s work.
  • Every user must use their own account and keep passwords confidential. Shared logins are not permitted.
  • Multi-factor authentication is used where available and screens are locked whenever left unattended.
  • Staff must not access their own record, or the record of family, friends, colleagues or well-known people, unless formally involved in the person’s care or specifically authorised under practice procedure.
  • Access is reviewed when duties change and removed promptly when employment or engagement ends. Audit logs may be reviewed routinely or where inappropriate access is suspected.
  • Patient information is not stored on personal devices, personal email accounts, unapproved cloud services or unencrypted removable media.
  • Confidentiality obligations continue after a team member leaves the practice.

Use and disclosure

Patient information is used or disclosed for the primary purpose of providing healthcare and for directly related purposes the patient would reasonably expect, including referrals, pathology, imaging, billing, recalls, accreditation, quality improvement and practice administration, where permitted by law.

Information may also be disclosed with patient consent, where required or authorised by law, to prevent or lessen a serious threat, for mandatory reporting, under a valid court order or subpoena, or in another permitted situation. Only the minimum necessary information is released and the disclosure is documented.

Information is not sold and is not used for direct marketing without appropriate consent. Overseas disclosure is not made unless required, permitted and appropriate privacy safeguards have been considered.

The practice may share information with other healthcare providers; Medicare, the Department of Veterans’ Affairs or health funds where necessary; service providers supporting the practice, including approved IT and accreditation providers; and other persons or bodies where the patient has consented or disclosure is required or authorised by law. Contracted service providers must protect information and comply with applicable privacy requirements.

If a patient has expressly consented to receive direct marketing, they may withdraw that consent at any time by contacting the practice in writing.

Communicating electronically

Electronic communication is convenient but can be misdirected, intercepted, forwarded, viewed on a shared device or accessed by someone other than the intended recipient. The practice therefore uses secure messaging as the preferred method for clinical information and applies additional safeguards whenever Outlook email is required.

General rules

  1. Use only practice-approved systems, accounts and devices. Personal email, personal messaging apps and personal cloud storage must not be used for patient information.
  2. Verify the patient or recipient using at least three approved identifiers and confirm their authority to receive the information.
  3. Check the destination carefully, including the complete email address, secure-messaging recipient or mobile number. Do not rely only on autocomplete.
  4. Send only the minimum information needed. Avoid clinical details in email subject lines, SMS text or calendar invitations.
  5. Obtain and record patient consent where required, including informed consent for patient-directed email. Explain that email carries privacy risks even when safeguards are used.
  6. Document significant incoming and outgoing electronic communications in Best Practice, including the date, recipient, consent, information sent or received, method used and any follow-up required.
  7. Electronic communication is not continuously monitored and must not be used for emergencies. Patients requiring urgent medical assistance are directed to call 000 or attend an emergency department.

Best Practice and secure messaging

Best Practice is the practice’s clinical information system and the primary record of patient care. Referrals, reports, clinical letters and transfers should be sent through the approved secure, encrypted messaging functionality integrated with Best Practice wherever the recipient can receive them.

  • The staff member confirms the correct patient, document and receiving practitioner or organisation before sending.
  • Only approved secure-messaging directories and verified recipient details are used.
  • Sent items, delivery information and clinically relevant replies are retained or recorded in the patient’s Best Practice record.
  • A failed, rejected or undelivered message is followed up promptly using another approved method and the action is documented.

Sending patient information through Outlook

Outlook may be used only from the practice’s approved account when secure messaging is unavailable or the patient specifically requests email. All patient health information sent through Outlook must be contained in a password-protected attachment. Sensitive information must not be placed in the subject line or email body.

Before sending, the staff member must complete the following steps:

  1. Confirm the request and consent. Confirm that the patient wants the specific document sent by email, explain the remaining privacy risks, and record the patient’s consent in Best Practice.
  2. Verify the patient. Use at least three approved identifiers before discussing or releasing information.
  3. Confirm the address. Ask the patient to state or spell the full email address, read it back, and confirm whether it is a personal rather than shared or workplace inbox.
  4. Confirm the document and authority. Check that the correct document has been authorised for release and that only the necessary pages or information are included.
  5. Protect the attachment. Convert the document to an appropriate format where needed and apply a strong, unique password. Do not use easily guessed information such as the patient’s name, date of birth, Medicare number or address.
  6. Send the password separately. Provide the password by a different channel, such as by telephone or SMS after the patient’s mobile number has been verified. Never include the password in the same email.
  7. Complete a final check. Recheck the patient, recipient address, attachment and message immediately before selecting Send. Remove unintended recipients and do not use Reply All unless every recipient is authorised.
  8. Record the communication. Document the date, recipient, patient confirmation and consent, information sent, password-protection method and any required follow-up in Best Practice.

If the patient does not consent to email, the practice offers another appropriate method, such as collection in person, post following identity checks, or secure transfer to an authorised healthcare provider.

SMS and appointment messaging

  • Approved uses. SMS may be used for appointment reminders, recalls, brief administrative messages, electronic prescription links and other approved purposes.
  • Minimum information. Messages do not include detailed or highly sensitive clinical information.
  • Verified number. The mobile number is checked regularly and before sensitive links or information are sent.
  • Patient preference. Consent choices or withdrawal are recorded, and an alternative contact method is arranged when needed for safe follow-up.
  • Clinical replies. Clinically significant SMS replies are transferred to Best Practice and allocated to the appropriate clinician. Administrative staff do not interpret results or provide clinical advice.

Receiving emails, secure messages and electronic documents

  • Practice inboxes and secure-message queues are monitored during opening hours by authorised staff. They are not emergency channels.
  • Incoming clinical information is matched to the correct patient, saved or imported into Best Practice, and allocated promptly to the responsible practitioner.
  • Requests requiring clinical judgement, prescriptions, referrals, results interpretation or urgent advice are escalated to a clinician. Reception staff do not provide clinical advice.
  • Unexpected links or attachments are not opened until the sender is verified. Suspected phishing or malicious content is reported immediately.
  • If an electronic message cannot be confidently matched to the correct patient or sender, staff pause processing and seek clarification before filing or acting on it.

9.6 Time-critical and highly sensitive information

Email or SMS must not be relied on as the only method for urgent, time-critical or high-risk clinical information. The responsible clinician determines the appropriate method, which may include direct telephone contact, documented clinical handover or emergency escalation. Contact attempts and outcomes are recorded in Best Practice.

Where the sensitivity or potential harm from misdirection is high, the Practice Manager / Privacy Officer or treating practitioner must approve the communication method. Secure messaging, direct clinician-to-clinician contact or in-person collection is preferred.

AI scribing and document automation

AI-assisted scribing

With the patient’s informed consent, an authorised clinician may use an approved scribing service to assist with consultation notes or clinical correspondence. A patient may decline its use without affecting their care. The clinician must review, correct and approve the content before saving it to the correct Best Practice record.

  • Consent. The clinician explains the proposed use of the scribing service and obtains consent before it is activated.
  • Approved service. Only a practice-approved service with appropriate privacy and security controls may be used.
  • Clinical review. Generated content is treated as a draft and is not part of the final health record until reviewed and approved by the clinician.
  • Incident reporting. Any error, unexpected disclosure or security concern is reported immediately to the Practice Manager / Privacy Officer.

Document automation

The practice may use approved document automation technology to prepare referrals, letters and other clinical documents. The treating clinician must review every document to confirm that it is accurate, addressed to the correct recipient and contains only information relevant to the patient’s care before it is sent.

Results, recalls and follow-up

Clinical results and correspondence are received into Best Practice and allocated to the responsible practitioner. The practitioner reviews and actions them within the required timeframe. Urgent or clinically significant results are escalated immediately in accordance with the practice recall and escalation procedure.

Before giving information, staff confirm the patient’s identity and follow the practitioner’s instructions. Contact attempts, messages, advice and outcomes are recorded. Administrative staff do not interpret results or provide clinical advice.

My Health Record

Only authorised healthcare providers may access My Health Record for a permitted healthcare purpose. Access must comply with patient access controls, the practice procedure and applicable law. Information downloaded into Best Practice becomes part of the practice record and is protected accordingly. Suspected unauthorised access or disclosure is reported immediately to the Practice Manager / Privacy Officer for assessment and notification.

Electronic records, security, backup and business continuity

The practice uses electronic patient records. Best Practice is the principal clinical record system, and electronic backups are completed daily. Further operational detail is contained in the practice Computer System Manual.

  • Clinical systems, devices and networks are protected through current security software, firewalls, supported software, encryption where appropriate and controlled administrator access.
  • Electronic records are securely backed up. Backups are monitored, protected from unauthorised access and periodically tested for restoration.
  • Paper records and removable media are secured and are not left unattended in public or shared areas.
  • Remote access is approved, secure and limited to authorised users.
  • The business continuity and information recovery plan is maintained and tested so essential patient information can be restored after an outage or disaster.

Privacy within the practice

Conversations are kept as private as reasonably possible. Staff use a low voice, avoid discussing patients where others can hear, position screens away from public view and keep documents face down or securely filed. A private area is offered for sensitive discussions. Whiteboards, diaries and appointment screens visible to patients must not display unnecessary health information.

15. Patient access, correction and record transfer

Patients may request access to, or correction of, their health information verbally or in writing. Requests are referred to the Practice Manager / Privacy Officer and identity and authority are verified before information is released.

The practice responds within a reasonable period, generally within 30 calendar days. Access is provided in the requested form where reasonable and practicable. A reasonable fee may apply to the cost of providing access, but no fee is charged simply for making a request. Access may be limited or refused only where permitted by law, with reasons and complaint options provided.

Corrections are made transparently without erasing the original clinical entry. If the practice does not agree to a correction, the patient may ask for a statement of the requested correction to be associated with the record.

A patient who wishes to transfer their medical record to another practice must provide a completed transfer authority, usually supplied by the new practice. The practice verifies the request before securely forwarding the record. A file-transfer fee may apply and will be explained before processing.

Requests to access, correct or update information may be made in writing to the Practice Manager at reception@milsonspointmedical.com.au or by using the practice Update My Details form.

Children, capacity and authorised representatives

Requests involving children, guardians, enduring guardians, attorneys, substitute decision-makers, carers or deceased patients are assessed individually. Staff confirm identity, authority, the patient’s capacity, the young person’s maturity and any risk to the patient or another person. Family relationship alone does not automatically permit access. Clinical or legal advice is obtained when authority is unclear.

Anonymity and pseudonyms

Where practical and lawful, patients may communicate with the practice anonymously or using a pseudonym. This may not be possible when accurate identification is required to provide safe healthcare or process Medicare, pharmacy, pathology or other health-related services.

Quality improvement and research

Patient information may be used for practice accreditation, audits and quality-improvement activities. Wherever practical, information used for these purposes is de-identified. Identifiable information is not used for research without patient consent unless otherwise permitted by law.

Record retention and secure destruction

The practice retains health records for at least the minimum period required by applicable NSW law: generally seven years from the last entry for an adult, and for a person who was under 18 when the record was made, until the person turns 25. Longer retention may be appropriate because of ongoing care, a legal hold, a complaint, a claim or another requirement.

Inactive and archived records remain secure and retrievable. When lawful retention periods have passed and records are no longer needed, destruction is authorised and documented. Paper is securely shredded or destroyed by an approved provider; electronic data and media are securely erased or physically destroyed so the information cannot be reconstructed.

Privacy incidents and data breaches

Any actual or suspected loss, wrong-recipient message, unauthorised access, cyber incident, inappropriate discussion, wrong-patient entry or disclosure must be reported immediately to the Practice Manager / Privacy Officer. Staff must not conceal an incident or independently contact affected people unless directed or urgent safety action is required.

Step Required action
1. Contain Stop further access or disclosure; recall or recover the message if safe; preserve evidence; and isolate affected equipment where directed.
2. Assess Record what occurred, whose information is affected, the sensitivity of the information, likely harm, remedial action and whether My Health Record is involved.
3. Notify Obtain advice and notify affected individuals, the OAIC, the My Health Record System Operator or other bodies where legally required.
4. Improve Fix the cause, document decisions, review the incident at the appropriate meeting, update controls or procedures and provide further staff education.

 

An eligible data breach is assessed promptly under the Notifiable Data Breaches scheme. My Health Record incidents are assessed under their separate mandatory notification requirements.

Privacy enquiries and complaints

Patients may raise a privacy concern or complaint in writing to the Practice Manager at reception@milsonspointmedical.com.au, by post to Suite 3, 80 Alfred Street, Milsons Point NSW 2061, or by calling 02 9023 9999. The practice will acknowledge and investigate the concern fairly and aims to respond within 14 days. Complaints are recorded in the complaints register and used to improve systems.

If dissatisfied, a patient may contact the Office of the Australian Information Commissioner on 1300 363 992 or at www.oaic.gov.au, or the Health Care Complaints Commission on 1800 043 159.

Training, monitoring and review

  1. All team members sign a confidentiality agreement and complete privacy and information-security training at induction and at least annually.
  2. Training includes phishing awareness, secure messaging, Outlook safeguards, password protection, three-identifier checks, documenting consent and breach reporting.
  3. Compliance may be checked through access reviews, audit logs, backup logs, incident reviews, record audits and staff competency checks.
  4. This policy is reviewed annually and after a significant incident, legislative change, accreditation finding or major system change.

A free copy of this policy is available at reception or on the practice website. Material changes will also be reflected in the Practice Information Booklet where relevant.

Related practice documents

  • Patient Health Record Policy
  • Three-Step Patient Identification Procedure
  • Results, Recalls and Follow-up Procedure
  • Data Breach Response Plan and Incident Register
  • Business Continuity and Information Recovery Plan
  • My Health Record Security and Access Procedure
  • Records Transfer, Retention and Destruction Procedure
  • Complaints Management Policy

References

  • Office of the Australian Information Commissioner. Australian Privacy Principles guidelines. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines
  • Office of the Australian Information Commissioner. Chapter 11: APP 11 – Security of personal information, version 1.3, October 2025. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information
  • Office of the Australian Information Commissioner. Quick reference guide for responding to data breaches, 29 June 2026. https://www.oaic.gov.au/privacy/notifiable-data-breaches/quick-reference-guide-for-responding-to-data-breaches
  • Royal Australian College of General Practitioners. Standards for general practices, 5th edition – Criterion C6.4 Information security. https://www.racgp.org.au/running-a-practice/practice-standards/standards-5th-edition
  • Royal Australian College of General Practitioners. Using email in general practice, updated 24 March 2026. https://www.racgp.org.au/running-a-practice/technology/business-technology/using-email-in-general-practice

Contact Us

If you have any questions about this Privacy Policy, please contact us.

Opening Hours

Mon   8am - 6pm

Tue   8am - 6pm

Wed   8am - 6pm

Thu   8am - 6pm

Fri   8am - 6pm

Sat   9am - 2pm

Sun   9am - 1pm