Current as of: 1st July 2026
Introduction
This Privacy Policy explains how our practice collects, uses, stores, protects and discloses your personal information, including your health information.
We are committed to protecting your privacy and complying with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and all applicable health records legislation.
This policy applies to all personal information collected by our practice in the course of providing healthcare services.
Why and when your consent is necessary
When you register as a patient of our practice, you consent to our doctors, nurses and authorised practice staff collecting, using and disclosing your personal information for the primary purpose of providing healthcare to you.
Where we wish to use or disclose your information for any purpose not directly related to your healthcare, we will seek your consent unless otherwise authorised or required by law.
Only authorised personnel who require access to your information to perform their duties will be permitted to access your records.
Why do we collect, use and hold your personal information?
Our primary purpose for collecting your personal information is to provide safe, high-quality healthcare.
We also collect, use and hold your information for purposes directly related to the operation of our practice, including:
- maintaining your medical record
- arranging referrals and communicating with other healthcare providers
- prescribing medications and managing prescriptions
- requesting and receiving pathology and diagnostic imaging results
- appointment scheduling and reminders
- billing, Medicare, DVA and health fund claims
- quality improvement activities
- accreditation requirements
- clinical governance and risk management
- staff education and training
- complying with legal and regulatory obligations
- operating and securing our clinical information systems.
What personal information do we collect?
The information we collect may include:
- your name, date of birth and gender
- address and contact details
- emergency contact and next of kin details
- Medicare number
- Department of Veterans’ Affairs details
- healthcare identifiers
- private health insurance information
- occupation
- medical history
- medications
- allergies
- immunisations
- family and social history
- pathology and imaging reports
- specialist correspondence
- clinical notes
- investigation results
- payment information
- any other information relevant to your healthcare.
Dealing with us anonymously
Where lawful and practicable, you may interact with our practice anonymously or using a pseudonym.
However, in most situations this is not possible because accurate identification is necessary to provide safe healthcare and meet our legal obligations.
How do we collect your personal information?
We collect information in several ways, including:
- when you register with the practice
- during consultations
- from forms completed by you
- telephone calls
- emails
- SMS communications
- our website
- online booking systems
- My Health Record (where authorised)
- electronic prescriptions
- pathology providers
- radiology providers
- specialists
- hospitals
- allied health providers
- community health services
- Medicare
- Department of Veterans’ Affairs
- your guardian or authorised representative
- other healthcare providers involved in your care.
Use of technology, cloud services and AI-assisted systems
To assist in providing efficient and accurate healthcare services, our practice uses secure electronic systems, including cloud-based technologies and appropriately governed artificial intelligence (AI)-assisted software.
These technologies may assist with functions such as:
- processing and indexing clinical documents
- optical character recognition (OCR)
- document allocation
- appointment management
- clinical administration
- cybersecurity
- practice operations.
Where third-party technology providers process personal information on our behalf:
- they act only under our instructions
- they are required to maintain strict confidentiality
- they must implement appropriate security controls
- they are not permitted to use your personal information to train publicly available AI models
- they must comply with applicable Australian privacy requirements and contractual obligations.
AI systems used by our practice are administrative support tools only and do not replace clinical judgement or decision-making by your healthcare practitioner.
When do we disclose your personal information?
We may disclose your information to:
- other healthcare providers involved in your care
- pathology and diagnostic imaging providers
- hospitals
- pharmacists
- My Health Record (where applicable)
- Medicare
- Department of Veterans’ Affairs
- your health fund
- government agencies where required by law
- courts and tribunals where legally compelled
- professional advisers
- our insurers
- accreditation agencies
- contracted service providers assisting us to operate our practice
- information technology providers, including secure cloud service providers.
We will only disclose information necessary for the relevant purpose.
Overseas disclosure
Where possible, your personal information is stored and processed within Australia.
If a service provider stores or processes information outside Australia, we will only do so where:
- you have consented; or
- the disclosure is permitted by Australian privacy legislation; or
- contractual safeguards are in place to ensure your information receives substantially similar protection.
Direct marketing
We will not use your personal information to market our services without your consent.
You may withdraw your consent at any time.
This does not apply to appointment reminders or communications relating to your ongoing healthcare.
How we protect your personal information
Protecting patient information is one of our highest priorities.
We use a range of administrative, technical and physical safeguards, including:
- secure electronic medical records
- user authentication
- role-based access controls
- audit logging
- encryption of sensitive information
- secure cloud infrastructure
- regular software updates
- cybersecurity monitoring
- staff confidentiality obligations
- ongoing privacy and security training
- secure destruction of records when no longer required.
Despite these safeguards, no information system can be guaranteed to be completely secure.
Data retention
We retain health records for the periods required under Australian law and professional standards.
When records are no longer required, they are securely destroyed or permanently de-identified.
Accessing and correcting your information
You may request access to your personal information or request corrections if you believe the information is inaccurate, incomplete or out of date.
Requests should be made in writing to:
Email: admin@denmarkmedicalcentre.com.au
or
Practice Manager
Denmark Medical Centre
3/3 Mount Shadforth Road
Denmark WA 6333
We will respond within a reasonable period and in accordance with applicable legislation.
Privacy complaints
If you have concerns about how your personal information has been handled, please contact our Practice Manager.
Email:
admin@denmarkmedicalcentre.com.au
Mail:
Practice Manager
Denmark Medical Centre
3/3 Mount Shadforth Road
Denmark WA 6333
We will investigate your complaint promptly and aim to resolve it fairly.
If you are not satisfied with our response, you may lodge a complaint with:
Office of the Australian Information Commissioner (OAIC)
1300 363 992
Changes to this Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes in legislation, technology, clinical practice or the way we manage personal information.
The current version will always be available on our website and upon request.