Simulated workplaceCAQA Lakeside Health is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
HLTCAQA LakesideSimulated workplace
Back to library
CAQA Lakeside Health · Simulated workplace

Privacy and Health Records Policy

PolicyControlled document
LAK-POL-002
v3.1
Document ownerPractice Manager
Version3.1
Approved18 March 2026
Next review18 March 2027
StatusCurrent

Purpose. This policy describes how Lakeside Health collects, uses, stores, shares and protects patient health information in line with the Australian Privacy Principles and the state health records legislation.

1.Purpose and scope

Patients trust Lakeside with sensitive information. This policy applies to every record about a patient, whether in the electronic health record, a paper form, a pathology request, a dental chart, a radiograph or a dispensing record, and to every worker and student.

2.Collection

Staff must collect only the information needed to provide care, manage the practice and meet legal obligations, and must tell patients why it is collected and who it will be shared with. New patients must be given the privacy collection statement at registration and their consent recorded in the patient record.

3.Use and disclosure

Health information must be used only for the patient's care, for related administration and quality activities, or where the law requires it. Information must be shared with another provider only with the patient's consent or where the disclosure is permitted, and every disclosure must be recorded. Staff must not access a record unless they need it for their role.

  • Verify the identity of anyone requesting information
  • Confirm consent before sending records to a third party
  • Record every disclosure in the patient record
  • Refer requests from lawyers, insurers and employers to the Practice Manager

4.Security

The electronic health record uses individual logins with role-based access and automatic log-out. Staff must not share passwords, leave screens unlocked or discuss patients where they can be overheard. Paper records must be stored in locked areas and scanned to the electronic record within two working days.

5.Access and correction

Patients have the right to access their record and to request a correction. Requests must be logged with the Practice Manager and answered within 30 days. The treating practitioner will review any request where access might cause harm.

6.Retention and breaches

Adult records must be kept for at least seven years from the last entry and children's records until the child turns 25. Any suspected privacy breach must be reported to the Practice Manager on the day it is discovered and assessed under the notifiable data breach scheme.

7.Review

This policy will be reviewed every year and when privacy law or the accreditation standards change. The Practice Manager will report privacy requests and breaches to the clinical governance committee.

LAK-POL-002 v3.1 · CAQA Lakeside HealthUncontrolled when printed. Simulated document created by CAQA for training and assessment.