Privacy Policy

Privacy Policy

This privacy policy explains how Hill Street Medical Centre collects, uses, stores, and shares your personal information, including your health information.
Our objective is to ensure that patient clearly understand how their personal information is managed within our practice and the circumstances in which it may be shared with other healthcare providers or organizations involved in your care.
If you have any questions about this policy or wish to make a privacy enquiry, please contact:
Hill Street Medical Centre
Email: admin@hillstreetmedical.com.au
Phone: 02 6583 1272

Why and when your consent is necessary?

When you register as a patient of our practice, you provide consent for our GPs and practice staff to access and use your personal information so they can provide you with the best possible healthcare. Only staff who need to see your personal information will have access to it. If we need to use your information for anything else, we will seek additional consent from you to do this.

Why do we collect, use, hold and share your personal information?

Our practice will need to collect your personal information to provide healthcare services to you. Our main purpose for collecting, using, holding, and sharing your personal information is to manage your health. We also use it for directly related business activities, such as financial claims and payments, practice audits and accreditation, and business processes (e.g., staff training).

What personal information do we collect?

The information we will collect about you includes your:

  • names, date of birth, addresses, contact details.
  • medical information including medical history, medications, allergies, adverse events, immunisations, social history, family history and risk factors.
  • Medicare number (where available) for identification and claiming purposes, healthcare identifiers, health fund details.
Dealing with us anonymously

You have the right to deal with us anonymously or under a pseudonym unless it is impracticable for us to do so or unless we are required or authorised by law to only deal with identified individuals.

How do we collect your personal information?

Our practice may collect your personal information in several different ways.


When you make your first appointment our practice staff will collect your personal and demographic information via your registration.


During providing medical services, we may collect further personal information.


We may also collect your personal information when you visit our website, send us an email or SMS, telephone us, make an online appointment or communicate with us using social media.


In some circumstances personal information may also be collected from other sources. Often this is because it is not practical or reasonable to collect it from you directly.

This may include information from:

  • your guardian or responsible person
  • other involved healthcare providers, such as specialists, allied health professionals, hospitals, community health services and pathology and diagnostic imaging services
  • your health fund, Medicare, or the Department of Veterans’ Affairs (as necessary).
    While providing medical services, further personal information may be collected via electronic prescribing, My Health Record, online appointments.
  • Various types of images may be collected and used including CCTV Footage for security and safety purposes, photos and medical images for medical purposes using HSMC devices.
What Is Patient Health Record?

Ensuring the quality of patient health records at Hill Street Medical Centre is a crucial aspect of providing safe and effective healthcare to our patients. The primary purpose of our clinical health records is to hold all the necessary information about each patient, supporting our healthcare professionals in making appropriate clinical decisions. As we embrace changes in primary care delivery, such as shared care models and the implementation of the national eHealth record (My Health Record), the significance of maintaining high-quality patient information becomes more critical than ever before.

How do we use document automation technologies?

We use secure medical software Best Practice and Health Link to create and share documents like referrals with healthcare providers, including only relevant medical information. Access to this software is restricted to authorized team members based on their roles. Your data is protected under Australian privacy laws and managed according to RACGP guidelines for health information.

How are Artificial Intelligence (AI) Scribes used?

Some doctors at Hill Street Medical Centre use an AI scribe tool called Heidi to assist with clinical note-taking during consultations.
Heidi uses audio recordings of consultations to generate clinical notes, does not share patient information outside Australia, temporarily stores transcription text only, removes personally identifiable information during processing. Heidi complies with internation security standards including ISO 27001, SOC2 Type 2, HIPAA, GDPR, Australian Privacy Principles.


Patients may request not to have AI scribes used during their consultation.

When, why and with whom do we share your personal information?

We may share your personal information when necessary to provide healthcare services or when required by law.
This may include sharing information:
– With other healthcare providers (e.g., referrals to specialists)
-With accreditation bodies
-With IT service providers supporting our systems
-When required by law (such as court subpoenas)
-To prevent serious threats to health or safety
-To assist in locating a missing person
-To establish or defend legal claims
-For confidential dispute resolution
-For mandatory disease notification
-Through digital health services such as My Health Record (Shared Health Summary, Event Summary)


We will not share your information outside Australia without your consent unless legally required.

Marketing

Hill Street Medical Centre will not use your personal information for marketing without your express consent. If you provide consent for marketing communications, you may opt out at any time by notifying the practice in writing.

How is your information used to improve services?

We may use patient information to improve healthcare services through:
– Quality improvement activities
– Practice audits
– Training
– Research and data analysis

How do we store and protect your personal information?

Your information may be stored in several formats:
– Electronic records
– Paper records
– Medical imaging records (e.g., X-rays, CT scans)
– Clinical photos or videos


Hill Street Medical Centre stores all information securely using:
– Protected clinical software systems
-Secure servers
– Password-protected access
– Restricted staff access levels
– Secure storage areas for physical documents


This privacy policy prohibits the recording, storage, or duplication of any automation technologies for telehealth or video conferencing sessions. However, if there arises a situation where we must record a consultation, we will first seek your verbal consent, and this consent will be documented in your file by the practitioner.

How can you access and correct your personal information at our practice?

You have the right to request access to, and correction of, your personal information.
Our practice acknowledges patients may request access to their medical records. We require you to put this request in writing, you can email us, and our practice will respond within a reasonable time.
Our practice will take reasonable steps to correct your personal information where the information is not accurate or up to date. From time to time, we will ask you to verify that your personal information held by our practice is correct and current. You may also request that we correct or update your information, and you should make such requests in writing an email to admin@hillstreetmedical.com.au.

How can you lodge a privacy-related complaint, and how will the complaint be handled at our practice?

If you have a privacy concern or complaint, please contact us in writing.
Email: admin@hillstreetmedical.com.au
Phone: 02 6583 1272
We will investigate and attempt to resolve your complaint in accordance with our complaint handling procedure.
If you are not satisfied with our response, you may contact:
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992

Policy review statement

This privacy policy is reviewed regularly to ensure it complies with current legal requirements and practice operations.
If significant changes are made:
Updates will be published on the practice website
Patients may be notified via notices within the practice