Privacy policy

Dr Ebad Medical Centre is committed to protecting the privacy, confidentiality, and security of patient health information, in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and RACGP Standards for General Practices.

 


The practice collects personal information necessary to provide safe and effective healthcare, including name, contact details, date of birth, Medicare details, medical history, medications, allergies, test results, and billing information. This may be collected directly from the patient, authorised representatives, or other healthcare providers.

 


The practice obtains consent (written, verbal and documented, or implied where appropriate) before collecting, using, or disclosing personal information. Patients may withdraw consent at any time, subject to legal and clinical requirements.

 


Patient information may be used or disclosed for healthcare purposes (e.g. referrals, communication with hospitals), with patient consent (e.g. insurance or legal requests), or where required or permitted by law (e.g. mandatory reporting, court orders). Only information necessary and relevant to the purpose requested is released.

 


Requests from insurers, employers, lawyers, government bodies, or family members are only processed after verifying the requester’s identity, authority, and patient consent where required. Unauthorised requests will be declined.

 


The practice protects patient information through secure clinical software, restricted and individually logged access, secure passwords, protected paper records, and secure disposal of confidential documents.

 


Patients have the right to request access to their health information, and to request correction of inaccurate or incomplete information. Access may be limited where permitted by law.

 


A privacy breach may include sending information to the wrong person, unauthorised access, loss of confidential documents, or unauthorised discussion of patient information. All suspected breaches must be reported to the Practice Manager. The practice will investigate, assess potential harm, take corrective action, and notify affected individuals where required.

 


Patients may raise privacy concerns with the Practice’s Privacy Officer. The practice will acknowledge, investigate, and respond to complaints, and implement improvements where required. Patients may also contact the Office of the Australian Information Commissioner (OAIC) if they remain dissatisfied.

 


This policy is reviewed annually, following legislative changes, and following significant privacy incidents.