Health Zone Barwell Medical Centre Privacy Policy
Current as of 26 August 2026
Purpose |
1. Our privacy obligations
Health Zone Barwell Medical Centre is committed to protecting the privacy, confidentiality and security of patient information. We manage personal information in accordance with applicable Australian and New South Wales privacy laws, including:
- Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
- Health Records and Information Privacy Act 2002 (NSW) (HRIP Act) and the 15 Health Privacy Principles (HPPs)
- My Health Records Act 2012 (Cth), where the My Health Record system is used
- other laws that authorise or require the collection, use or disclosure of health information.
This policy applies to GPs, nurses, employees, contractors and other authorised persons who handle information on behalf of the practice.
2. Why and when consent is necessary
When you register with the practice and receive healthcare, we collect and use information that is reasonably necessary to provide and manage your healthcare. Your consent may be express or implied, depending on the circumstances and the purpose for which the information is being handled.
Only people who need access to your information for an authorised purpose should access it. If we want to use or disclose your information for a purpose that is not directly related to your care or otherwise permitted by law, we will seek additional consent where required.
All staff and relevant contractors are required to maintain confidentiality and comply with the practice’s privacy and information-security requirements.
3. Why we collect, use, hold and share personal information
Our main purpose for collecting, using, holding and sharing personal information is to provide safe and effective healthcare and to manage your relationship with the practice. We may also use information for directly related practice activities, including:
- appointments, recalls, reminders and follow-up care
- clinical communication and referrals to other healthcare providers
- Medicare, Department of Veterans’ Affairs, private health insurance and other billing or payment activities
- quality improvement, clinical audit, accreditation and service management
- staff education and training, where permitted and appropriately managed
- responding to complaints, legal claims, subpoenas, investigations and regulatory requirements
- information technology, cybersecurity, system support, secure backups and business continuity.
4. What personal information we collect
Depending on the services you receive, we may collect and hold information such as:
- name, date of birth, address, telephone number, email address and other contact details
- identity and demographic information
- medical history, diagnoses, medications, allergies, adverse events, immunisations, pathology and imaging results, family and social history, occupation, risk factors and other clinical information
- Medicare number, Individual Healthcare Identifier and other healthcare identifiers
- private health fund and Department of Veterans’ Affairs details, where relevant
- next of kin, emergency contact, parent, guardian or authorised representative details
- billing and payment information
- communications with the practice, including telephone, email, SMS and online messages
- images, photographs, audio or video recordings where clinically required, consented to, or otherwise permitted by law.
5. Dealing with us anonymously or using a pseudonym
You may deal with us anonymously or by using a pseudonym where this is lawful and practicable. In many healthcare situations, however, it may not be practicable or safe to provide care without correctly identifying you, and some services or claims may require us to verify your identity.
6. How we collect personal information
We usually collect information directly from you, including when you register, make an appointment, attend a consultation, use telehealth, contact us by telephone, email or SMS, complete a form, use our website or use an online booking service such as HotDoc.
Where it is not reasonable or practicable to collect information directly from you, or where you have authorised us to do so, we may collect information from:
- a parent, guardian, carer, responsible person or authorised representative
- GPs, specialists, allied health professionals, hospitals, community health services and other healthcare providers
- pathology and diagnostic imaging providers
- Medicare, the Department of Veterans’ Affairs, private health insurers and other relevant agencies
- My Health Record and secure clinical messaging systems, where applicable.
Where required, we will take reasonable steps to make you aware that information has been collected from another source and the circumstances of that collection.
7. Children and young people
We recognise that children and young people have privacy and confidentiality rights. When handling a child or young person’s health information, the practice will consider their age, maturity, capacity to understand the proposed handling of their information, the nature of the healthcare being provided, any relevant parental or guardian responsibility, and any safety or legal concerns.
A parent or guardian does not automatically have unrestricted access to every part of a young person’s health record in all circumstances. Requests for access or disclosure will be assessed in accordance with privacy law, consent and capacity principles, professional obligations, court orders where relevant, and the best interests and safety of the child or young person.
Information may be disclosed without consent where required or authorised by law, including where mandatory child-protection reporting or another legal obligation applies.
8. When, why and with whom we share personal information
We may disclose personal information where necessary for your healthcare, where you have consented, or where the disclosure is otherwise required or authorised by law. This may include disclosure:
- to other healthcare providers involved in your care
- to pathology, diagnostic imaging, pharmacy and other clinical service providers
- through electronic transfer of prescriptions, secure messaging and My Health Record, where used
- to Medicare, the Department of Veterans’ Affairs, insurers or other organisations for billing and claiming purposes
- to service providers that support the practice, such as information technology, secure cloud or backup providers, appointment and recall providers, payment providers, auditors and accreditation organisations
- where required by legislation, court order, subpoena, warrant or another lawful authority
- where necessary to lessen or prevent a serious threat to life, health or safety, where permitted by law
- for mandatory notification of certain diseases or other reportable matters
- for confidential dispute resolution, legal advice or the establishment, exercise or defence of a legal or equitable claim.
We do not sell patient information. Where third-party service providers handle information on our behalf, we take reasonable steps appropriate to the circumstances to ensure suitable privacy, confidentiality and security protections are in place.
9. Overseas disclosure and storage
The practice does not intentionally disclose personal information overseas unless the disclosure is necessary for an authorised purpose, you have consented, or the disclosure is otherwise permitted by law. Some technology or service providers may store, process or support information using infrastructure located outside Australia. Where this occurs, we take reasonable steps to assess and manage privacy and security risks and to meet applicable Australian privacy obligations.
You may contact the Practice Manager if you would like further information about overseas handling by a particular service used by the practice.
10. Direct marketing
We will not use sensitive health information for direct marketing unless this is permitted by law and the required consent has been obtained. Where you have consented to receive marketing communications from the practice, you may withdraw that consent or opt out at any time.
Clinical recalls, reminders, appointment messages and information sent as part of your healthcare are not treated as direct marketing merely because they are sent by SMS or email.
11. How we store and protect personal information
Personal information may be stored in electronic systems and, where necessary, in paper records, clinical images, photographs, audio or video files and other approved formats. The practice takes reasonable administrative, physical and technical steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure.
Safeguards may include, as appropriate:
- individual user accounts and role-based access controls
- passwords and other authentication controls
- system audit trails and monitoring of access where supported by the system
- secure networks, backups, software maintenance, cybersecurity controls and malware protection
- secure storage and disposal of paper records
- confidentiality obligations and privacy/security training for staff and contractors
- procedures for secure transfer of medical records and sensitive information.
Staff must not access a patient record unless access is required for their role and an authorised purpose.
12. Retention and secure destruction of health information
Health records are retained in accordance with NSW law and any other applicable professional or legal requirements. As a general rule for private health service providers in NSW:
- where health information was collected when the patient was an adult, it must generally be retained for at least 7 years from the last occasion on which a health service was provided to that patient
- where health information was collected when the patient was under 18 years of age, it must generally be retained until the patient reaches 25 years of age.
When information is no longer required and may lawfully be destroyed, it will be securely destroyed or permanently de-identified. The practice will keep any record of disposal or transfer required by NSW law.
13. Telehealth, email, SMS and electronic communications
The practice may communicate with patients and healthcare providers by telephone, telehealth, SMS, email, secure messaging and other approved electronic systems. Electronic communications can carry privacy and security risks, including messages being sent to an incorrect address or accessed by another person with access to the recipient’s device or account.
We take reasonable steps to use appropriate communication methods for the sensitivity of the information. We may verify your identity or contact details before releasing sensitive information and may use secure or password-protected methods where appropriate. Patients should tell us if they do not want particular communication channels used for routine messages.
14. My Health Record
Health Zone Barwell Medical Centre uses My Health Record where appropriate. Authorised healthcare providers may access or upload information in accordance with the My Health Records Act 2012 and applicable practice procedures. Patients can manage access controls within My Health Record and can obtain further information from the Australian Digital Health Agency.
Suspected privacy or security incidents involving My Health Record will be handled in accordance with applicable My Health Record breach-notification requirements as well as any other applicable data-breach obligations.
15. Artificial intelligence, transcription and automated tools
The practice uses approved digital tools that contain artificial intelligence, transcription or automated functions. Patient information must not be entered into unapproved public AI services by staff.
Where an approved tool processes patient information, the practice will consider privacy, security, contractual safeguards, data location, access controls, clinical safety and consent requirements before use. The practice will update this policy where required if personal information is used in automated decision-making that must be specifically described under the Privacy Act.
16. Data breaches and privacy incidents
A privacy incident or data breach may occur where personal information is lost or is accessed, used, altered or disclosed without authorisation. Examples include an email sent to the wrong recipient, unauthorised access to a patient record, loss of a device or paper file, credential compromise, malware or ransomware, or inappropriate disclosure of information.
The practice maintains processes for responding to suspected privacy and data breaches. We will take reasonable steps to contain the incident, protect affected information, assess the circumstances and reduce the risk of harm. Where the Notifiable Data Breaches (NDB) scheme applies and an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law. Other notification obligations, including those relating to My Health Record, will also be followed where applicable.
Suspected privacy incidents should be reported promptly to the Practice Manager.
17. Accessing your personal information
You have a right to request access to personal information and health information held about you, subject to limited exceptions under applicable law. You may contact the practice to make a request. We may ask you to put a request in writing where this is reasonably necessary to understand the request, verify your identity or authority, or manage the release securely.
Before releasing information, we may require appropriate proof of identity and, where a person is acting for someone else, evidence of their authority. We aim to respond within a reasonable period and without unreasonable delay. If a fee is permitted for providing access or copies, we will advise you before proceeding.
If access is refused or restricted, we will explain the reason where required and advise you of available complaint or review options.
18. Correcting your personal information
We take reasonable steps to keep personal information accurate, complete and up to date. You may ask us to correct or update your information at any time. Requests can be made to reception or the Practice Manager. We may ask for supporting information where necessary to assess the requested correction.
Contact: office@hzmc.com.au or 02 8865 0650.
19. Privacy complaints
We take privacy complaints seriously. If you have a concern about how your personal information has been handled, please contact the Practice Manager so that we can investigate and respond.
Privacy complaints can be made by email, telephone or in writing to:
- Practice Manager
- Health Zone Barwell Medical Centre, Suite 16, 7-9 Barwell Avenue, Castle Hill NSW 2154
- Email: office@hzmc.com.au
- Telephone: 02 8865 0650
We will acknowledge and address complaints as promptly as practicable. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) or, in relation to NSW health privacy matters, the Information and Privacy Commission NSW (IPC NSW). Those bodies may require you to first give the practice an opportunity to respond.
- OAIC: www.oaic.gov.au | 1300 363 992
- IPC NSW: www.ipc.nsw.gov.au
20. Privacy and our website
Our website may contain links to external websites and may use cookies, analytics or third-party functionality to support website operation, understand website usage or enable online services. The privacy practices of external sites are governed by their own privacy policies, and we are not responsible for their content or privacy practices.
Where website tools collect personal information, the practice will take reasonable steps to ensure that the collection is appropriate, transparent and consistent with applicable privacy requirements. We will not knowingly use health information collected through our website for unrelated advertising or tracking purposes without the required consent and lawful basis.
Online appointment and communication services provided by third parties, including HotDoc where used, may also have their own privacy notices. Patients should review those notices for information about how the third-party provider handles information in connection with its service.
21. Changes to this policy
We may update this privacy policy from time to time to reflect changes in law, technology, practice systems or the way we handle personal information. The current version will show its effective or review date and will be made available through the practice and, where applicable, on our website.
22. Policy governance
Policy owner | Practice Manager Katrina Barnett |
Effective date | 26 August 2026 |
Review cycle | At least every 12 months, or earlier if privacy law, systems or practice processes materially change |
Next scheduled review | August 2027 |