Privacy and Health Records Policy
v3.1
Purpose. This policy describes how Lakeside Health collects, uses, stores, shares and protects patient health information in line with the Australian Privacy Principles and the state health records legislation.
1.Purpose and scope
Patients trust Lakeside with sensitive information. This policy applies to every record about a patient, whether in the electronic health record, a paper form, a pathology request, a dental chart, a radiograph or a dispensing record, and to every worker and student.
2.Collection
Staff must collect only the information needed to provide care, manage the practice and meet legal obligations, and must tell patients why it is collected and who it will be shared with. New patients must be given the privacy collection statement at registration and their consent recorded in the patient record.
3.Use and disclosure
Health information must be used only for the patient's care, for related administration and quality activities, or where the law requires it. Information must be shared with another provider only with the patient's consent or where the disclosure is permitted, and every disclosure must be recorded. Staff must not access a record unless they need it for their role.
- Verify the identity of anyone requesting information
- Confirm consent before sending records to a third party
- Record every disclosure in the patient record
- Refer requests from lawyers, insurers and employers to the Practice Manager
4.Security
The electronic health record uses individual logins with role-based access and automatic log-out. Staff must not share passwords, leave screens unlocked or discuss patients where they can be overheard. Paper records must be stored in locked areas and scanned to the electronic record within two working days.
5.Access and correction
Patients have the right to access their record and to request a correction. Requests must be logged with the Practice Manager and answered within 30 days. The treating practitioner will review any request where access might cause harm.
6.Retention and breaches
Adult records must be kept for at least seven years from the last entry and children's records until the child turns 25. Any suspected privacy breach must be reported to the Practice Manager on the day it is discovered and assessed under the notifiable data breach scheme.
7.Review
This policy will be reviewed every year and when privacy law or the accreditation standards change. The Practice Manager will report privacy requests and breaches to the clinical governance committee.