Skip to content

Privacy and health records

Privacy policy

Last reviewed

This policy sets out what the practice does with your personal and health information: what is collected, why it is held, who it can be given to, and what you can ask us to do about it.

About this policy

Chapel Street Medical Centre is a private health service provider in Victoria. Two laws govern how we handle information about you, and both apply at once.

Commonwealth
Privacy Act 1988 and the Australian Privacy Principles.
Victoria
Health Records Act 2001 and the Health Privacy Principles.

The policy covers everyone the practice holds information about, whether you are a current patient, a former patient, or someone who has contacted us without becoming one.

Health information is treated as sensitive information under both laws. We collect it where it is reasonably necessary to provide or manage your care, or where a law requires or permits us to.

What we collect

What we hold depends on the care you have received. It may include:

  • Your name, date of birth, address and contact details
  • Medicare, Department of Veterans' Affairs, concession or other healthcare identifiers
  • Appointments you have made, attended or missed
  • Medical history, symptoms, diagnoses, allergies, medicines and treatment
  • Clinical notes, referrals, specialist letters, pathology and imaging results
  • Family and social history where it is relevant to your care
  • Billing, payment and rebate records
  • Emergency contact, next of kin or an authorised representative

We do not collect more than the care or the administration of it requires.

How we collect it

Wherever it is reasonable and practical, we collect information from you directly: when you book, when you speak to reception, when you fill in a form, and during the consultation itself.

Some information reaches us from elsewhere, where that is lawful and appropriate:

  • Another doctor, specialist, allied health practitioner or hospital
  • A pathology or diagnostic imaging provider
  • A parent, guardian, carer or authorised representative
  • HealthEngine, when you book through it
  • Medicare, the Department of Veterans' Affairs or another government service
  • An insurer, compensation scheme or legal representative, where you have authorised it

Why we hold it

The primary purpose is your care. In practice that means:

  • Assessing, treating and managing your health
  • Keeping a medical record that is complete enough to be clinically useful
  • Arranging appointments, referrals, tests and follow-up
  • Contacting you about your care and about the practice
  • Processing accounts, Medicare rebates and other authorised claims
  • Running recalls and reminders, where you have agreed to them
  • Meeting our professional, legal, regulatory and public health obligations
  • Managing the practice itself, including safety, complaints and security

We may also use information for a closely related purpose you would reasonably expect, or where a law requires or permits it.

Who we share it with

Information is disclosed where your care or the administration of it needs it, and where privacy law permits. Depending on the situation that can mean:

  • Practitioners involved in treating you, and in your continuity of care
  • Specialists, allied health providers, hospitals, pathology and imaging services
  • Medicare, the Department of Veterans' Affairs and other government agencies
  • Insurers, compensation schemes or legal advisers, where you have authorised it or a law permits it
  • Service providers that support the practice, including our clinical software, records, communications and billing providers, each of which is required to handle information appropriately
  • Courts, tribunals, regulators and law enforcement, where a law requires or authorises it

We disclose the least that will do the job.

Your record, and how long we keep it

Records are held electronically and, for older material, on paper. They include clinical notes, correspondence, results, referrals, prescriptions and billing records.

Victorian law sets a minimum period before health information may be destroyed. Unless another law requires something different, we must keep it until the later of these two points:

  • Seven years after the last occasion we provided you with a health service
  • Your twenty-fifth birthday, where the information was collected while you were a child

The word that matters there is later. For a child seen at eight, the twenty-fifth birthday is the operative date, not the seven years. When records are eventually destroyed or transferred, that is done in a way that protects confidentiality.

This website and online booking

The website

This website gives information about the practice. It does not collect health information, and it does not set advertising or tracking cookies. There is no contact form, and nothing on it asks you to send us anything about your health.

Email is not a secure way to send health information. If you email the practice, keep it to practical matters like appointments and administration, and raise anything clinical by phone or at your appointment.

Website statistics

We use Umami, a privacy-focused statistics service, to see how the website is used: which pages are read, and how often someone taps to call us, to book, or to get directions. We use it to improve the website, and for no other purpose.

It sets no cookies, it does not follow you to other websites, and it does not build a profile of you. What it records is the page you are on, the site or search engine you arrived from, your browser and device type, and an approximate location worked out from your internet connection. Umami states that it does not collect information that identifies you.

None of this is connected to your medical record, your appointments, or anything you tell the practice. Umami processes it for us on servers in the European Union. If your browser is set to send a Do Not Track signal, the website records nothing at all.

Booking through HealthEngine

Online booking is operated by HealthEngine, not by this practice. When you open the booking screen and enter your details, HealthEngine collects that information under its own privacy policy and passes the booking to us.

HealthEngine is a separate organisation making its own decisions about your information, including whether any of it is handled outside Australia. If that matters to you, its policy is the document to read, and you can always book by calling the practice instead.

Keeping it secure

We take reasonable steps to protect information against loss, misuse, interference and unauthorised access. That includes access controls on our systems, physical security at the practice, confidentiality obligations on everyone who works here, and limiting access to the people whose job requires it.

No system removes every risk. If we suspect a data breach we are required to assess it, and where it is likely to cause serious harm we must notify the people affected and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.

Seeing and correcting your record

You can ask to see the information we hold about you, ask us to correct anything inaccurate, out of date, incomplete or misleading, or ask us to send your record to another health service provider.

Ask reception, or write to the Practice Manager. We may need to confirm your identity first, or the authority of anyone acting for you.

Access
We must respond within 45 days. Where a fee applies, we tell you in writing first, and access follows within 7 days of payment.
Correction
We must respond within 30 days.

A reasonable charge may apply to providing access, within the limits Victorian law sets. Asking for a correction is free, and so is making one.

Access can be refused in the circumstances the law allows, and a correction can be declined. If that happens we will explain why in writing, and you can ask us to attach a statement to the record setting out that you disagree with it.

If you have a privacy concern

Raise it with the Practice Manager first. Tell us what happened and what you would like done about it, so that we can look into the right thing.

The Privacy Act expects you to give us an adequate opportunity to respond, generally 30 days, before taking a privacy complaint to the Information Commissioner. If you are not satisfied with our answer, or we do not give you one in that time, two bodies can take it further.

The practice's feedback and complaints page sets out the process in full, including what to include and what happens after you raise something.

Changes to this policy

We update this policy when what we do with information changes, when we change a provider, or when the law changes. The current version is always the one on this page, and the date it was last reviewed is at the top.

If this website is not a convenient way for you to read it, ask at reception or call (03) 9534 5151 and we will provide it another way.