Menu Close

Privacy Policy

1. About this Privacy Policy

At Arana Hills Medical Centre, we respect your privacy and are committed to protecting the confidentiality and security of your personal information, including your health information.

This Privacy Policy explains how we collect, hold, use, disclose and protect your personal information, how you can access and correct information we hold about you, and how you can make a privacy complaint.

We manage personal information in accordance with the Privacy Act 1988, the Australian Privacy Principles (APPs), applicable health privacy and confidentiality obligations, and relevant professional and regulatory requirements.

This policy is also intended to reflect the privacy, confidentiality, information security and digital health expectations of the RACGP Standards for general practices (6th edition).

This policy applies to information collected by the practice in person, by telephone, electronically, through our website and online services, and from other sources as described below.

2. Who can I contact about privacy?

If you have questions about this Privacy Policy, how we handle your personal information, or wish to make a privacy-related request or complaint, please contact:

Privacy Officer / Practice Manager
Arana Hills Medical Centre
14b/5-11 Patricks Road
Arana Hills, QLD, 4054
Phone: 07 3351 6444 | Email: practice_manager@aranamed.com.au

Our Privacy Officer is responsible for overseeing privacy matters within the practice and supporting the practice team to understand and implement our privacy policies and procedures.

3. Why and when is your consent necessary?

When you become a patient of our practice, we will ask for your consent to collect, hold, use and disclose your personal information for purposes connected with providing healthcare to you.

This includes allowing authorised members of the practice team to access the information they need to perform their role in providing and managing your healthcare.

Access to personal information is limited to authorised members of the practice team and other authorised persons who require access for legitimate purposes.

Where we intend to use or disclose your personal information for a purpose that is not reasonably expected in connection with your healthcare or another permitted purpose, we will seek your consent where required.

Some uses or disclosures of personal information may be permitted or required by law without your consent. These circumstances are described in this policy.

Where a particular technology is used in your care, such as an AI-supported clinical tool or other digital health technology, we will provide appropriate information about how it is used and obtain informed consent where required.

You may withdraw consent where consent is the basis for a particular use or disclosure, although there may be circumstances where we are required or authorised by law to continue to hold or use information.

4. Why do we collect, hold, use and disclose your personal information?

Our primary purpose for collecting and holding your personal information is to provide safe, appropriate and effective healthcare.

We may collect, hold, use and disclose your information for purposes including:

  • Providing and managing your healthcare
  • Maintaining an accurate and comprehensive health record
  • Communicating with you about your healthcare
  • Arranging appointments, recalls, referrals and follow-up care
  • Coordinating care with other healthcare providers
  • Prescribing and managing medicines
  • Electronic prescribing and other digital health services
  • Accessing or contributing information to my health record, where applicable
  • Processing Medicare, department of veterans’ affairs and private health fund claims
  • Billing, payments and financial administration
  • Complying with legal, regulatory and professional obligations
  • Responding to subpoenas, court orders and other lawful requests
  • Managing risks, incidents and complaints
  • Quality improvement, clinical audit and accreditation activities
  • Practice administration and business operations
  • Staff education and training
  • Research, where permitted and appropriately governed
  • Using de-identified information for secondary purposes such as population health analysis and service improvement
  • Protecting the health, safety and wellbeing of patients, the practice team and others.

We will only collect, use and disclose information for purposes that are permitted by law and consistent with this Privacy Policy.

5. What personal information do we collect?

Depending on your circumstances and the services we provide, we may collect and hold:

Identity and contact information

 

  • Name
  • Date of birth
  • Preferred name
  • Gender or sex where clinically or administratively relevant
  • Residential and postal address
  • Telephone numbers
  • Email address
  • Emergency contact and next-of-kin details
  • Other demographic information relevant to your care.

 

 

Health information

 

  • Medical history
  • Current and previous health conditions
  • Medicines and treatments
  • Allergies and adverse reactions
  • Immunisation history
  • Pathology and diagnostic imaging results
  • Specialist and hospital correspondence
  • Family history
  • Social history
  • Lifestyle information
  • Risk factors
  • Mental health information
  • Information relevant to preventive and chronic disease care
  • Information about your healthcare preferences where relevant
  • Other information necessary to provide safe and appropriate healthcare.

 

 

Administrative and healthcare identifiers

 

  • Medicare number
  • Department of Veterans’ Affairs details, where relevant
  • Healthcare identifiers
  • Private health fund details
  • Billing and payment information
  • Information required to process claims.

 

 

Digital and communication information

Depending on the services you use, we may also collect:

 

  • Online appointment information
  • Patient portal information
  • Electronic correspondence
  • SMS and email communications
  • Information provided through online forms
  • Information associated with telehealth consultations
  • Information generated through electronic prescribing
  • Information accessed through or contributed to my health record
  • Technical information generated when you interact with our website or online services.

 

 

Images, audio and visual information

Where clinically or operationally necessary and appropriately authorised, we may collect:

  • Clinical photographs
  • Medical images such as x-rays, scans or other diagnostic images
  • Photographs or videos used for clinical or operational purposes
  • Audio recordings, where applicable and with appropriate consent or other lawful basis.

6. Can I deal with the practice anonymously or using a pseudonym?

You may have the option to deal with us anonymously or using a pseudonym where this is lawful and practicable.

However, anonymity or pseudonymity may not be practicable where we need to identify you to provide healthcare safely, maintain an accurate medical record, process a Medicare or health fund claim, comply with a legal requirement, or otherwise perform an activity that requires identification.

If you wish to enquire about dealing with the practice anonymously or using a pseudonym, please speak with our reception team or Privacy Officer.

7. How do we collect your personal information?

We may collect personal information directly from you in several ways, including when you:

  • Register as a patient
  • Make or attend an appointment
  • Complete a paper or electronic registration or medical history form
  • Communicate with us in person, by telephone, SMS or email
  • Use our website
  • Use our online appointment or patient portal services
  • Participate in a telehealth consultation
  • Provide information during a consultation
  • Provide information through a feedback or complaint process
  • Communicate with us through social media or other digital channels.

 

We may also collect information from other sources where permitted or required by law and where it is necessary or appropriate for your healthcare or practice operations.

These sources may include:

 

  • Your parent, guardian, carer or responsible person
  • Another person authorised to act on your behalf
  • Your usual GP or previous healthcare providers
  • Specialists
  • Allied health professionals
  • Hospitals
  • Community health services
  • Pathology providers
  • Diagnostic imaging providers
  • Pharmacies and other healthcare providers
  • Medicare
  • The department of veterans’ affairs
  • Your private health fund
  • My Health Record
  • Other relevant government or healthcare services.

 

 

Where we collect personal information from third parties, we take reasonable steps to ensure that the information is collected, used, held and disclosed in accordance with applicable privacy obligations.

8. Digital health technologies

We use digital health technologies to support the delivery, coordination and administration of healthcare.

Depending on the services offered by the practice, these may include:

 

  • Electronic medical records
  • Electronic prescribing
  • My Health Record
  • Secure messaging
  • Telehealth
  • Online appointment systems
  • Patient portals
  • Electronic forms
  • SMS and email communication systems
  • Digital recall and reminder systems
  • Diagnostic and clinical software
  • Other approved digital health technologies.

 

 

The practice currently uses the following digital health technologies:

Best Practice (Bp Premier) – Practice management and clinical software used for patient records, clinical documentation, prescribing, referrals, results, recalls and billing.

Lyrebird – AI-powered clinical documentation/medical scribe technology that can assist GPs by converting consultations into structured clinical notes, reducing documentation workload.

Heidi Health – AI medical scribe that listens to consultations and generates clinical documentation, letters and summaries for review by the clinician.

My Health Record – Australia’s national digital health record system, allowing authorised healthcare providers to access and contribute information such as shared health summaries, pathology results, specialist letters and prescription information.

ePrescribing / electronic prescriptions – Enables GPs to send prescriptions electronically, including through prescription tokens and Active Script Lists.

HPOS (Health Professional Online Services) – Australian Government platform used by healthcare professionals to access services including Medicare, PBS and other health-related administrative systems.

PRODA – Digital identity and authentication system used by Australian healthcare providers to securely access government health services.

Healthlink / secure messaging systems – Used to securely exchange clinical information, referrals, specialist correspondence and discharge summaries between healthcare providers.

Telehealth platforms – Video and telephone consultation technologies used by GPs to provide remote consultations where clinically appropriate.

SmartReferrals / electronic referral systems – Digital forms and referral solutions that allow GPs to electronically submit referrals and other clinical information to hospitals and specialists.

Medicare Online / electronic claiming – Digital systems that enable practices to process Medicare claims and related administrative transactions electronically.

HotDoc – Online appointment booking, patient reminders, digital forms, telehealth and patient communication platform widely used by Australian GP practices.

Clinical decision-support tools – Digital resources such as medication interaction checkers, clinical guidelines and risk calculators that support GPs in diagnosis, prescribing and treatment decisions.

Before introducing or materially changing digital health technologies, the practice considers relevant issues including patient safety, privacy, information security, clinical suitability, accessibility, workflow, costs, support arrangements and the management of information.

Where informed consent is required for the use of a digital health technology in your care, the treating clinician will discuss this with you and document your consent.

Where appropriate, we will provide reasonable alternatives if you do not wish to use a particular digital health technology.

9. Artificial intelligence (AI)

Arana Hills Medical Centre uses the following AI technology/services:

Lyrebird – AI-powered clinical documentation/medical scribe technology that can assist GPs by converting consultations into structured clinical notes, reducing documentation workload.

Heidi Health – AI medical scribe that listens to consultations and generates clinical documentation, letters and summaries for review by the clinician.

Where an AI system is used in your care, we will explain its use to you and obtain and document informed consent where required.

The practice remains responsible for the safe and appropriate use of AI. Clinicians remain accountable for clinical decisions and patient care, including reviewing information generated or supported by AI before it is relied upon for your healthcare.

For each AI service used by the practice, we will assess and manage relevant privacy and security matters, including:

  • What information is provided to the AI system
  • How the information is used
  • Whether information is de-identified or anonymised
  • Where information is stored or processed
  • Whether information is disclosed outside Australia
  • Whether consultation audio or other source material is retained
  • How long information is retained
  • Whether information is used by the provider for purposes other than providing the service
  • Appropriate security and access controls
  • How the service is reviewed and monitored.

 

AI service details:
Lyrebird

Question

Answer

Provider/product

Lyrebird Health — provided by Subsidio Pty Ltd (Australia). 

Purpose

AI clinical scribe: listens to the consultation, transcribes it in real time and generates clinical documentation/notes for the clinician to review and transfer into the medical record. 

Information processed

Consultation audio/voice, real-time transcript, patient health information contained in the consultation, and generated clinical notes/documents. Audio is converted to text in real time.

Data location(s)

Australia for Australian deployments. Lyrebird states that Australian patient data is processed and stored in Australia, on regional cloud infrastructure. 

Overseas disclosure/processing

No, for Australian patient data according to Lyrebird’s current published information. Lyrebird states that Australian data is not transferred offshore and that transcription/AI processing occurs within Australia. 

Audio retained

No. Audio is transcribed in real time and discarded once transcription is complete; it is not stored. 

Data used for provider training

No. Lyrebird states that customer/patient data is never used to train or fine-tune its AI models. 

Patient consent required

Yes. Lyrebird states that patient consent is required before recording/using Lyrebird for a consultation. It prompts the clinician to obtain consent and records the time consent was obtained. 

help.lyrebirdhealth.com

 

Heidi

Question

Answer

Provider/product

Heidi Health — Heidi Scribe, an AI medical documentation/scribing platform.

Purpose

AI clinical scribe that listens to consultations, transcribes them in real time and generates clinical documentation for the clinician to review and finalise.

Information processed

Consultation voice/audio during the session, real-time transcription, patient health information contained in the consultation, and AI-generated clinical notes. Heidi also processes account/device information associated with use of the platform.

Data location(s)

Australia for Australian users. Heidi states that it has localised infrastructure and that Australian customers’ personal information is stored in Australia/local jurisdiction.

Overseas disclosure/processing

Generally, no for sensitive/identifiable Australian health information, but this should be qualified. Heidi states that some platform functionality relies on third-party services whose servers may be internationally located. Its published privacy information says localised storage is used and that sensitive/identifiable health information is not included in such overseas third-party processing.

Audio retained

No for normal real-time Heidi Scribe sessions. Heidi states that audio is not stored and is transcribed in real time. Exception: users can upload consultation voice recordings for transcription, which is a separate workflow and may involve storage of the resulting transcript.

Data used for provider training

No for patient/consultation data. Heidi states that consultation data, session transcripts and generated notes are not used to train its AI models, and that sensitive health information is not used for model training.

Patient consent required

Heidi recommends obtaining consent but does not itself mandate a particular consent process. Heidi says that consent requirements vary by jurisdiction and that the treating clinician/practice is responsible for obtaining and recording consent in accordance with its policies and applicable law. For an Australian GP practice, I would therefore treat patient consent as required by the practice’s privacy/clinical governance policy before using the scribe, rather than relying on Heidi’s statement that it is not universally mandatory.

support.heidihealth.com

 

You may ask your treating clinician or our Privacy Officer for further information about an AI technology used in your care.

10. When, why and with whom do we disclose your personal information?

We may disclose your personal information where it is necessary and permitted for your healthcare, practice operations or another lawful purpose.

This may include disclosure to:

Other healthcare providers

We may share relevant information with healthcare professionals involved in your care, including:

 

  • GPs and other doctors
  • Specialists
  • Nurses
  • Allied health professionals
  • Hospitals
  • Pathology providers
  • Diagnostic imaging providers
  • Pharmacists
  • Community health services
  • Other healthcare providers involved in your treatment.

 

 

Examples include referrals, clinical handover, treatment planning, results and correspondence.

Service providers

We may use external organisations to provide services to the practice, such as:

 

  • Clinical software providers
  • Secure messaging providers
  • Information technology and cybersecurity providers
  • Electronic prescribing providers
  • Online appointment providers
  • Patient portal providers
  • Medical transcription or documentation providers
  • Cloud storage or hosting providers
  • Document management services
  • Payment and billing providers
  • Accreditation organisations
  • Professional advisers
  • Website hosting, analytics or security providers

 

 

We take reasonable steps to ensure that contracted service providers handle personal information appropriately and consistently with applicable privacy obligations.

Government and statutory bodies

Information may be disclosed where required or authorised by law, including to:

 

  • Medicare
  • The Department of Veterans’ Affairs
  • Public health authorities
  • Regulatory authorities
  • Courts and tribunals
  • Law enforcement agencies where legally authorised
  • Other government bodies where disclosure is required or authorised.

 

 

Circumstances permitted by law

We may disclose information without your consent where permitted or required by law, including where

 

disclosure is necessary to:

  • Lessen or prevent a serious threat to a person’s life, health or safety
  • Lessen or prevent a serious threat to public health or safety
  • Comply with mandatory disease notification requirements
  • Comply with a court order, subpoena or other lawful requirement
  • Assist in locating a missing person
  • Establish, exercise or defend a legal or equitable claim
  • Participate in a confidential dispute resolution process
  • Otherwise comply with applicable legislation.

 

 

My Health Record and electronic health services

The practice participates in and uses approved electronic health services to support the safe, efficient and coordinated delivery of healthcare. Electronic health services are used in accordance with applicable Australian privacy, health information, cybersecurity and digital health requirements.

Where applicable, information may be uploaded to, accessed from or exchanged through My Health Record and other approved digital health services as part of providing healthcare.

The practice’s participation in My Health Record

The practice participates in the My Health Record system and may access, upload, view and exchange relevant health information through My Health Record as part of providing healthcare.

This may include, where appropriate:

  • Shared health summaries and other clinical information;
  • Event summaries and discharge information;
  • Prescription and dispensing information;
  • Pathology and diagnostic imaging reports; and
  • Other health information available through the patient’s My Health Record.

Access to My Health Record is limited to authorised practice staff and is undertaken for legitimate healthcare and related purposes. Staff are required to comply with applicable privacy, security and access requirements. Information will only be accessed or used where authorised and relevant to the patient’s care.

Patients may ask the practice about how their information is accessed and shared through My Health Record and may exercise the controls available to them under the My Health Record system.

The practice’s use of electronic prescribing

The practice uses electronic prescribing (ePrescribing) to issue prescriptions electronically where clinically appropriate and where supported by the patient’s circumstances and the relevant prescribing system.

Electronic prescriptions may be transmitted to the patient through an approved electronic prescription service, such as an SMS or email token, or may be made available through an appropriate prescription management application.

Electronic prescribing is used to improve the security, accuracy and convenience of prescribing and dispensing. Prescribers remain responsible for ensuring that prescriptions are clinically appropriate, accurately issued and authorised in accordance with applicable legislation and professional requirements.

Where electronic prescribing is not suitable or available, an alternative approved prescription method may be used.

The practice’s use of online appointment technology

The practice uses approved online appointment technology to provide patients with a convenient option for booking and managing appointments.

The practice’s primary online appointment provider is HotDoc. The practice also uses HealthEngine for appointment bookings only.

Online appointment services may collect information necessary to facilitate and manage an appointment, such as the patient’s name, contact details, appointment type, preferred practitioner and appointment time. The information collected will depend on the booking service and the information required to arrange the appointment.

HotDoc and HealthEngine are third-party service providers. The practice takes reasonable steps to ensure that third-party providers used to facilitate online appointments have appropriate privacy and security arrangements in place and that personal information is handled in accordance with applicable privacy requirements.

Online booking services are used for appointment management and are not a substitute for direct communication with the practice where a patient requires urgent medical attention or needs to discuss confidential or clinically significant information.

Patients may contact the practice directly by telephone or other approved methods if they do not wish to use, or are unable to access, the online appointment services.

The practice may change or add approved online appointment providers from time to time as required to support the delivery of healthcare services.

11. Overseas disclosure of personal information

We will take reasonable steps to determine whether personal information is likely to be disclosed to or accessed by overseas recipients.

The practice’s current position regarding overseas disclosure:

  • No overseas disclosure: We do not currently disclose personal information to overseas recipients or use service providers that are known to store or process personal information overseas.

 

Where overseas disclosure or access occurs, we will manage it in accordance with applicable privacy laws and our contractual, security and governance requirements.

Patients may contact our Privacy Officer for further information about overseas handling of their personal information.

You may also contact the OAIC. Generally, the OAIC will require you to give them time to respond before they will investigate. For further information visit www.oaic.gov.au or call the OAIC on 1300 363 992.

12. Use of personal information for marketing

We will not use your personal information for direct marketing of our goods or services without your consent where consent is required.

If you have consented to receive direct marketing communications, you may withdraw your consent or opt out at any time by contacting the practice.

We will not use your health information for direct marketing purposes without a lawful basis and appropriate consent where required.

13. Quality improvement, research and secondary use of data

We use information held by the practice to support the quality and safety of healthcare.

This may include:

 

  • Clinical audits
  • Quality improvement activities
  • Accreditation
  • Monitoring practice systems
  • Analysing patient and practice data
  • Staff education and training
  • Improving clinical and administrative processes.

 

 

Where possible and appropriate, data used for these purposes will be de-identified.

De-identified information

De-identified information is information from which identifying information has been removed or altered so that an individual is not reasonably identifiable.

Where information has been appropriately de-identified, it may be used or disclosed for purposes permitted by law, including population health analysis, research, quality improvement and service planning.

The practice may provide de-identified information to:
Brisbane North PHN in line with participation in the Practice Incentives Quality Improvement Program

The practice’s position on patient opt-out from secondary use of de-identified data:
Patients may choose to opt out of the secondary use of their de-identified health information, where such an opt-out is available.

Choosing to opt out will not adversely affect the patient’s access to healthcare, treatment, services or the quality of care provided by the practice. Patients will not be disadvantaged or treated differently because they have chosen to opt out.

Where a patient requests to opt out, the practice will record and manage the request in accordance with applicable privacy requirements and the arrangements of the relevant data-use program or service.

The patient’s decision to opt out will be respected without prejudice to the patient’s ongoing relationship with the practice or their right to receive appropriate healthcare.

 

Research involving identifiable information

From time to time, the practice may participate in research projects or be approached by researchers seeking to recruit eligible patients.

Where a research project requires identifiable patient information or patient participation, the practice will follow applicable legal, ethical and governance requirements.

Where your specific consent is required, you will be provided with information about the research before deciding whether to participate.

You are free to decline participation in research, and your decision will not affect your healthcare.

14. How do we store and protect your personal information?

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

Information may be held in different formats, including:

 

  • Electronic medical records
  • Electronic documents
  • Paper records
  • Pathology and diagnostic imaging reports
  • Photographs and other medical images
  • Audio or video recordings, where applicable
  • Correspondence
  • Electronic communications
  • Information held within approved digital health systems.

 

 

Security measures may include appropriate:

 

  • Access controls
  • Individual user accounts and permissions
  • Passwords and authentication
  • Secure systems and networks
  • Encryption or secure messaging where appropriate
  • Physical security
  • Secure storage of paper records
  • Backups and recovery arrangements
  • Staff confidentiality obligations
  • Privacy and security training
  • Procedures for managing privacy and security incidents

 

 

 

Access to clinical systems is restricted according to a person’s role and responsibilities. Members of the practice team are expected to access only the information they need to perform their authorised duties.

We do not publish detailed security controls where doing so could reduce their effectiveness.

15. Confidentiality and access by the practice team

All members of the practice team have obligations to maintain patient confidentiality.

Authorised members of the practice team may access patient information where necessary for their role, including clinical care, administration, billing, recalls, quality improvement, practice management and other authorised activities.

We use individual user accounts and role-based access controls where supported by our systems.

Practice team members receive appropriate privacy and confidentiality education and training.

We may use contractors or external service providers where necessary. Their access to personal information is limited to what is reasonably required to perform their authorised functions.

16. Data breaches and privacy incidents

The practice maintains procedures for identifying, containing, assessing and responding to privacy and information security incidents.

If a data breach occurs, we will assess the incident and take appropriate action in accordance with applicable law, including the Notifiable Data Breaches scheme where applicable.

Where we are required to notify affected individuals or the Office of the Australian Information Commissioner, we will do so in accordance with the applicable requirements.

If you have concerns that your personal information may have been accessed, disclosed or handled inappropriately, please contact our Privacy Officer.

17. CCTV, photographs and medical images

CCTV

The practice does not currently operate CCTV

Clinical photographs and medical images

Photographs or other images may be taken where clinically necessary to assist in diagnosis, treatment or monitoring.

Where personal devices are used for clinical images, the practice requires appropriate privacy, security, consent, storage and transfer processes to be followed.

 

Clinical images are treated as health information and are protected accordingly.

18. Document automation and electronic records

The practice may use secure software to assist with document creation, referrals, correspondence and other clinical or administrative processes.

Where document automation is used, only information relevant to the purpose of the document should be included.

The practice will take reasonable steps to ensure that automated or electronically generated documents are reviewed appropriately and that information is accurate and suitable before being relied upon or sent to another party.

19. Website privacy

Our website may collect limited information when you interact with it. The types of information collected depend on the website functions and technologies currently in use.

The practice operates the Arana Hills Medical Centre website (https://aranamed.com.au/) using WordPress as its website content management system.

Website forms

The website does not currently provide patient enquiry or contact forms or a facility for patients to submit clinical or other sensitive health information directly to the practice.

Cookies

Our website may use cookies or similar technologies that are necessary for website functionality, security and technical operation. These may include cookies associated with WordPress and website security or technical functions.

The practice does not currently use Google Analytics or other website analytics services to track or analyse website visitors.

Where technically possible, website visitors can adjust cookie settings through their browser.

Embedded content and third-party websites

Our website may contain links or embedded content from third-party websites or services. When you interact with third-party content, the relevant third party may collect information about you in accordance with its own privacy policy.

We recommend reviewing the privacy policies of third-party websites and services before providing them with personal information.

Online appointments and patient portals

The website provides access to HotDoc for online appointment bookings.

Information entered into HotDoc may include information required to facilitate and manage an appointment and is collected and handled by HotDoc in accordance with its privacy policy and terms.

Online appointment provider: HotDoc

Patient portal provider: Not applicable via the practice website.

The practice periodically reviews the website, WordPress configuration, cookies and third-party services to ensure that the information provided in this Privacy Policy remains accurate and that appropriate privacy and security measures are maintained.

20. Email, SMS, telephone and electronic communication

We may communicate with you by telephone, SMS, email, secure messaging or other electronic means where appropriate.

Electronic communication can involve privacy and security risks. We will use appropriate safeguards and consider the sensitivity of the information before sending it electronically.

Where correspondence is sent from the patient’s Bp Premier clinical record, staff will check the patient’s recorded communication preferences and consent, verify the email address, and use available security features appropriate to the information being sent. Electronic correspondence sent from Bp Premier is recorded in the patient’s clinical record.

As a safety measure, the practice may respond to an email initiated by a patient using the same email address from which the patient contacted the practice. Staff will take reasonable steps to confirm the address and consider the sensitivity of the information before responding. A patient-initiated email does not automatically constitute consent for all future electronic communications.

If you request a particular communication method, we may use it where appropriate and lawful. Please notify us if your contact details or communication preferences change.

Please do not use ordinary email, SMS or website contact forms to send urgent medical information or information requiring immediate attention.

21. Social media and online reviews

If you contact or interact with the practice through social media, information you provide may be collected by the relevant social media provider as well as by the practice.

We will protect your privacy when responding to public comments, questions or reviews.

We will not disclose your confidential health information in response to an online review or public comment.

Where a matter involves personal or health information, we may ask you to contact the practice privately.

22. Accessing your personal information

You have the right to request access to personal information we hold about you, subject to applicable legal exceptions.

This includes access to your health information and medical records.

To request access, contact:

Privacy Officer / Practice Manager
Arana Hills Medical Centre
Arana Hills Plaza, 14b/5-11 Patricks Road, Arana Hills QLD 4054
Phone: 07 3351 6444 | Email: practice_manager@aranamed.com.au

We may need to verify your identity before providing access to personal information.

We will generally respond to an access request within a reasonable period and aim to respond within 30 days, where practicable.

There may be circumstances in which access is refused or limited where permitted by law. If this occurs, we will explain the reasons where appropriate and advise you of available complaint mechanisms.

We will not charge you for making an access request. A reasonable fee may apply for providing access in some circumstances, but any applicable fee will not be excessive and will reflect the reasonable costs of providing access.

23. Correcting your personal information

We take reasonable steps to ensure personal information is accurate, complete, up to date, relevant and not misleading for the purpose for which it is held.

You may ask us to correct information that you believe is inaccurate, incomplete, out of date, irrelevant or misleading.

Requests can be made by contacting:

Privacy Officer / Practice Manager
Arana Hills Medical Centre
Arana Hills Plaza, 14b/5-11 Patricks Road, Arana Hills QLD 4054
Phone: 07 3351 6444 | Email: practice_manager@aranamed.com.au

We will generally respond to correction requests within a reasonable period and aim to respond within 30 days, where practicable.

There is no charge for requesting correction or for correcting your personal information.

If we do not agree that information should be corrected, we will explain the reasons where appropriate and advise you of available complaint mechanisms.

Where appropriate, you may ask us to associate a statement with the information recording your disagreement.

24. How can I make a privacy complaint?

We take privacy complaints seriously.

If you believe that we have handled your personal information inappropriately or breached our privacy obligations, please contact our Privacy Officer.

Making a complaint to the practice

Please provide your complaint in writing where possible, including:

  • Your name and contact details
  • A description of your concern
  • Relevant dates or information
  • Any supporting documents
  • The outcome you are seeking.

You may send your complaint to:

Privacy Officer / Practice Manager
Arana Hills Medical Centre
Arana Hills Plaza, 14b/5-11 Patricks Road, Arana Hills QLD 4054
Phone: 07 3351 6444 | Email: practice_manager@aranamed.com.au

We will acknowledge and investigate your complaint in accordance with our complaints procedure.

We aim to provide a response within 30 days, where practicable. Some complaints may require additional time depending on their complexity.

We will not disadvantage you or compromise your healthcare because you have made a privacy complaint.

External complaints

If you are not satisfied with our response, or your complaint has not been resolved, you may contact the Office of the Australian Information Commissioner (OAIC).

Office of the Australian Information Commissioner
Website: https://www.oaic.gov.au/
Telephone: 1300 363 992

The OAIC generally expects individuals to raise their concern with the organisation first and allow a reasonable opportunity for the organisation to respond.

25. Your privacy choices and responsibilities

You can help us maintain accurate and secure health information by:

  • Providing accurate information
  • Telling us when your contact details change
  • Informing us of changes to your Medicare or health fund details
  • Telling us your communication preferences
  • Asking questions about how your information will be used
  • Telling us if you have concerns about a particular digital technology
  • Informing us if you believe your information has been accessed or disclosed inappropriately.

You should also take reasonable care when communicating sensitive information through unsecured channels such as ordinary email, SMS or third-party online services.

26. Children and people who require a representative

Where appropriate, personal information may be collected from or disclosed to a parent, guardian, carer or other authorised representative.

The practice will consider the legal authority of a person requesting access to or information about another person’s health information.

Where a patient can make their own decisions about their health information, the practice will generally respect the patient’s privacy and confidentiality in accordance with applicable law.

27. Transferring or obtaining medical records

Where you transfer to another healthcare provider, you may request that relevant health information be transferred to your new provider.

We will take reasonable steps to transfer relevant information securely and in a timely manner, subject to applicable consent, legal and professional requirements.

 

We may also receive health information from other healthcare providers where this is necessary and lawful for your healthcare.

28. How long do we keep personal information?

We retain personal information for as long as required for healthcare, legal, regulatory, professional, insurance, administrative or other lawful purposes.

Health records are retained in accordance with applicable legislation, professional requirements and the practice’s records management procedures.

When information is no longer required and there is no legal or other requirement to retain it, we will take reasonable steps to securely destroy it or ensure that it is de-identified.

29. Changes to this Privacy Policy

We regularly review this Privacy Policy and will update it when necessary, including when:

  • Privacy legislation changes
  • Relevant professional or regulatory requirements change
  • The practice introduces or changes digital health technologies
  • The practice introduces or changes ai technologies
  • Our information handling practices change
  • Significant changes occur to our website or online services
  • A privacy or security review identifies a need for change.

 

The current version of this policy will be made available on our website.

Where there are significant changes that affect how we handle your personal information, we may notify patients directly where appropriate.

This policy will be reviewed at least annually and sooner where there are significant operational, technological, legislative or regulatory changes.

30. Related legislation, standards and guidance

This Privacy Policy should be read together with applicable:

  • Privacy act 1988
  • Australian privacy principles
  • My health records act 2012, where applicable
  • Relevant Queensland privacy, health and confidentiality requirements
  • Applicable mandatory reporting and public health legislation
  • Professional confidentiality obligations
  • RACGP standards for general practices (6th edition)
  • Relevant RACGP privacy, information security, digital health and AI guidance.

This Privacy Policy document will be reviewed when deemed necessary by practice staff.

Last updated: 18/09/2026