Privacy Policy – Patients

Template Privacy Policy – Practices to have all patients sign this policy

The Practice must ensure that each patient reviews and signs the below policy.

All practices must have a Privacy Policy in place to be compliant with the Privacy Act 1988. This policy needs to set out how and what type of personal and health information is collected, stored, accessed and managed.


Part A – Purpose and Context

Rosslea Medical Centre is committed to ensuring the privacy and confidentiality of all personal information affiliated with Rosslea Medical Centre business undertakings.

Rosslea Medical Centre follows the terms and conditions of privacy and confidentiality in accordance to the Australian Privacy Principles (APPs) as per schedule 1 of the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth), forming part of the Privacy Act 1988 (‘the Act’).

The purpose of this Privacy Policy is to clearly communicate how Rosslea Medical Centre collects and manages personal information.

The point of contact regarding any queries regarding this policy is Sue Sigmund, Practice Manager:     Phone 07 4758 0500 Email:

Part B – Australian Privacy Principles

As a private sector health service provider and under permitted health situations, Rosslea Medical Centre is required to comply with the APPs as prescribed under the Act.

The APPs regulate how Rosslea Medical Centre may collect, use, disclose and store personal information and how individuals, including Rosslea Medical Centre’s patients may:

  1. address breaches of the APPs by Rosslea Medical Centre
  2. access their own personal information; and,
  • correct their own personal information.

In order to provide patients with adequate health care services, Rosslea Medical Centre will need to collect and use personal information. It is important to be aware that if the patient provides incomplete or inaccurate information or the patient withholds personal health information Rosslea Medical Centre may not be able to provide the patient with the services they are requesting.

In this Privacy Policy, common terms and definitions include:

“personal information” as defined by the Privacy Act 1988 (Cth). Meaning “information or an opinion including information or an opinion forming part of a database, whether true or not, and whether recorded in a material format or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion”; and,

“health information” as defined by the Privacy Act 1988 (Cth).  This is a particular subset of “personal information” and means:

  • Information or opinion about the health or disability (at any time i.e. past, present or future) of an individual that can be classified as personal information;
  1. Information or opinion about an individual’s expressed wishes about the future provision of health services that can be classified as personal information;
  2. Information or opinion about health service provided, or to be provided, to an individual, that can be classified as personal information;
  • Other personal information collected to provide, or in providing, a health service;
  1. Other personal information about an individual collected in connection with the donation, or intended donation, by the individual of his or her body parts, organs or body substances; or,
  2. Genetic information about an individual in a form that is, or could be, predictive of the health of the individual or a genetic relative of the individual.

Personal information also includes ‘sensitive information’ which is information including, but not limited to a patient’s:

  • race;
  1. religion;
  2. political opinions;
  • sexual preferences; and or,
  1. health information.

Information deemed ‘sensitive information’ attracts a higher privacy standard under the Act and is subject to additional mechanisms for the patient’s protection.

Part C – Types of Personal Information

Rosslea Medical Centre collects information from each individual patient that is necessary to provide the patient with adequate health care services.

This may include collecting information about a patient’s health history, family history, ethnic background or current lifestyle to assist the health care team in diagnosing and treating a patient’s condition.

Part D – Collection & Retention

This information will in most circumstances be collected directly from the patient through but not limited to the following mediums:

  • Health Care Service patient consent form;
  1. medical treatment form; and or,
  2. face to face consultation.

In other instances, Rosslea Medical Centre may need to collect personal information about a patient from a third-party source. This may include:

  • relatives; or
  • other health service providers.

This will only be conducted if the patient has provided consent for Rosslea Medical Centre to collect his/her information from a third-party source; or, where it is not reasonable or practical for Rosslea Medical Centre to collect this information directly from the patient. This may include where the patient’s health is potentially at risk and his/her personal information is needed to provide them with emergency medical treatment.

Part E – Purpose of Collection, Use & Disclosure

Rosslea Medical Centre only uses a patient’s personal information for the purpose(s) they have provided the information for unless one of the following applies:

  • the patient has consented for Rosslea Medical Centre to use his/her information for an alternative or additional purpose;
  1. the disclosure of the patient’s information by Rosslea Medical Centre is reasonably necessary for the enforcement of criminal law or a law imposing a penalty or sanction, or for the protection of public revenue;
  2. the disclosure of the patient’s information by Rosslea Medical Centre will prevent or lessen a serious and imminent threat to somebody’s life or health; or,
  • Rosslea Medical Centre is required or authorised by law to disclose the patient’s information for another purpose.

Health Professionals to provide treatment

During the patient’s treatment at Rosslea Medical Centre he/she may be referred to alternative medical treatment/services (i.e. pathology or radiology) where Rosslea Medical Centre staff may consult with senior medical experts when determining a patient’s diagnosis or treatment.

Rosslea Medical Centre staff may also refer the patient to other health service providers for further treatment during and following the patient’s admission.  These services include, but are not limited to:

  • Allied Health e.g.: Physiotherapy; or,
  • Outpatient or community health services.

These health professionals will be designated health service providers appointed to use the patient’s health information as part of the process of providing treatment. Please note that this process will be conducted whilst maintaining the confidentiality and privacy of the patient’s personal information.

Alternative Health services

At any point a patient wishes to be treated by an alternative medical practitioner or health care service that requires access to his/her personal/health information Rosslea Medical Centre requires written authorisation. This written authorisation is to state that the patient will be utilising alternative health services and that these health services have consented for a transfer of personal/health information.

Other Third Parties

Rosslea Medical Centre may provide the patient’s personal information regarding a patient’s treatment or condition to additional third parties. These third parties may include:

  • parent(s);
  • child/ren;
  • other relatives;
  • close personal friends;
  • guardians; or
  • a person exercising a patient’s power of attorney under an enduring power of attorney.

Where information is relevant or reasonable to be provided to third parties, written consent from the patient is required.

Additionally, the patient may at any time wish to disclose that no third parties as stated are to access or be informed about his/her personal information or circumstances.

Other Uses of Personal Information

In order to provide the best possible environment to treat patients, Rosslea Medical Centre may also use personal/health information where necessary for:

  • activities such as quality assurance processes, accreditation, audits, risk and claims management, patient satisfaction surveys and staff education and training;
  • invoicing, billing and account management;
  • to liaise with a patient’s health fund, Medicare or the Department of Veteran’s Affairs, as necessary; and,
  • the purpose of complying with any applicable laws – i.e. in response to a subpoena or compulsory reporting to State or Federal authorities.

If at any point or for any of the aforementioned reasons Rosslea Medical Centre uses or discloses personal/ health information in accordance with the APPs, Rosslea Medical Centre will provide written notice for the patient’s consent for the use and/or disclosure.

Part F – Access and Changes to Personal Information

If an individual patient reasonably requests access to their personal information for the purposes of changing the information, he/she must engage with the practice manager.

Once an individual patient requests access to his/her personal information, Rosslea Medical Centre will respond within a reasonable period of time to provide the information.

All personal information will be updated in accordance to any changes to a patient’s personal circumstances brought to Rosslea Medical Centre attention. All changes to personal information will be subject to patient’s consent and acknowledgement.

If an individual requests access to his/her personal information Rosslea Medical Centre will charge a fee calculated based on the administrative or other reasonable costs incurred in providing the access. Please note that this fee is associated with administrative costs only.

Part G – Complaints Handling

How an individual patient may complain about a breach of the Australian Privacy Principles, or a registered APP code (if any) that binds the entity, and how the entity will deal with such a complaint. APPs is available online at: or Phone 1300 363 992

Patients should feel free to discuss any concerns,

If you have any comments, complaints, or criticisms or just a good idea, please fill in a suggestion form or feedback form located near the front reception counter. These can be anonymously or you may add your contact details for the Practice Manager to discuss with you. Alternatively, please ask to speak to the Practice Manager who is available at all times or feel free to call and speak to her on the Practice number 07 4758 0500

Questions or complaints about any issues related to the privacy of their personal information with their doctor.  If a patient remains dissatisfied, you can contact the Office of the Health Ombudsman on 133646 or email

Part H – Personal Information and Overseas Recipients 

Use of Overseas Parties: Rosslea Medical Centre does not engage with any overseas entities, with which personal or health information would be transferred, appointed or disclosed.

The aforementioned entities engaged overseas are subject to the legislative requirements as stipulated by the APPs.

Part I – Disposal of Personal/Health Information

If Rosslea Medical Centre receives any unsolicited personal information that is not deemed appropriate for the permitted health situation, Rosslea Medical Centre will reasonably de-identify and dispose of the information accordingly.

If Rosslea Medical Centre holds any personal or health information that is no longer deemed relevant or appropriate for the permitted health situation, Rosslea Medical Centre will reasonably de-identify and dispose of the information accordingly.

Part J – Access to Policy

Rosslea Medical Centre provides free copies of this Privacy Policy for patients and staff to access.

Part K – Review of Policy

Rosslea Medical Centre in accordance with any legislative change, will review the terms and conditions of this policy to ensure all content is both accurate and up to date.

Part L – Patient Acknowledgement

I [Patient Name],                         acknowledge that I have read the aforementioned Privacy and Confidentiality Policy and understand the requirements of Rosslea Medical Centre and myself in how to manage my personal information whilst attending Rosslea Medical Centre.

Signed ……………………………………………                          Date: ………………………………………………