Privacy Policy
1. Introduction
Dr Hamish Shilton's medical practice is committed to protecting your privacy and maintaining the confidentiality and security of your personal and health information.
We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), applicable Victorian health privacy and medical-record requirements, the My Health Records Act 2012 (Cth) where relevant, and other applicable laws.
This Privacy Policy explains how we collect, use, disclose, store and protect your personal and health information, and how you may access or correct that information or make a privacy complaint.
2. Personal Information We Collect
We collect personal information reasonably necessary to provide medical and surgical care and operate the practice. This may include:
your name, address, date of birth and contact details;
medical history, diagnoses, medications, test results, clinical notes and treatment information;
referrals and correspondence from other healthcare providers;
Medicare, private health insurance and other billing information;
Individual Healthcare Identifiers and other identifiers where permitted or required by law;
emergency contact and next-of-kin details; and
other information you provide to us in connection with your healthcare.
Health information is sensitive information under Australian privacy law and is handled accordingly.
3. How We Collect Personal Information
We usually collect information directly from you, including:
when you book an appointment;
when you complete registration or other practice forms;
during consultations and treatment;
through telephone or email communications; and
when you communicate with the practice through our website.
Where reasonably necessary for your healthcare, we may also collect information from other sources, including your referring doctor, other healthcare professionals, hospitals, pathology and diagnostic imaging providers, Medicare, private health insurers and other persons or organisations involved in your care.
We will collect sensitive information with your consent unless collection is otherwise permitted or required by law.
4. How We Use Your Personal Information
We may use your personal and health information to:
provide medical and surgical care;
communicate with you and other healthcare professionals involved in your care;
arrange investigations, referrals and treatment;
maintain your medical record;
manage appointments and correspondence;
process accounts, Medicare claims, private health insurance and other billing;
manage the administrative and business functions of the practice;
meet professional, legal, regulatory and medical-indemnity requirements; and
maintain and improve the quality and safety of the services we provide.
We will not use your health information for direct marketing without your consent.
5. Website Enquiries and Squarespace
Our website is hosted using Squarespace.
Information entered into forms on our website may therefore be collected, transmitted, processed or stored through Squarespace systems and is also subject to Squarespace's own privacy and data-handling arrangements.
Website enquiry forms are intended for general enquiries and should not be used to provide sensitive, urgent or detailed medical information.
If you wish to send personal or health information electronically to the practice, we recommend contacting the practice directly at admin@shilton.net.au rather than entering that information into the website enquiry form.
Information received directly by the practice is handled in accordance with this Privacy Policy and applicable Australian privacy and health-information laws.
The website and electronic communications should not be used for medical emergencies or urgent medical advice.
6. Electronic Medical Records – Gentu / Magentus
The practice uses Gentu, provided by Magentus, as its electronic practice-management and clinical-record system.
Personal and health information forming part of your clinical record may be stored and managed using Gentu. Magentus states that Gentu operates on Australian-based cloud infrastructure and uses security controls including encryption and multi-factor authentication.
Access to clinical information within the practice is restricted to authorised persons according to their role and need to access that information.
Under Magentus Practice Management's current privacy arrangements, participating customers may take part in 'Data Projects'. These may include the use of Patient Data to generate clinical decision-support messages, or the de-identification and aggregation of Patient Data before disclosure to trusted partners and project sponsors for research, analytics and the improvement of health outcomes. Magentus may also use trusted technology partners to host data and provide infrastructure for these projects.
The practice has not opted out of participation in these Data Projects. Magentus states that participating customers and their patients may opt out of the use and disclosure of relevant Patient Data for Data Projects at any time. Patients who wish to opt out may contact the practice, or may contact Magentus directly in accordance with Magentus' current privacy policy.
Further information about Gentu, Magentus' handling of information and its Data Projects is available through the Magentus Privacy Policy and Trust Centre.
7. Use of Artificial Intelligence – Heidi Scribe
The practice uses Heidi Scribe, an AI-assisted clinical documentation service provided by Heidi Health, to assist with the transcription and preparation of clinical notes and correspondence.
During a consultation, Heidi Scribe may process information discussed between you and your treating practitioner, which may include personal and sensitive health information.
Heidi Health states that sensitive health information processed through Heidi Scribe undergoes pseudonymisation, with personal identifiers removed, and that patient data is not used to train, develop or improve Heidi's AI models.
Heidi states that personal information for Australian users is stored in Australia. Some functionality may, however, depend on third-party service providers whose servers are located internationally, with data-processing arrangements used by Heidi for those services.
Information generated using Heidi Scribe is used to assist your treating practitioner with clinical documentation. AI-assisted documentation is reviewed by the treating practitioner as appropriate before being incorporated into the medical record.
The use of Heidi Scribe does not replace the clinical judgement or responsibility of your treating practitioner. Heidi's terms require practitioners to hold the necessary authorisations and current consents for patient personal and sensitive information disclosed to Heidi. You may ask your treating practitioner about the use of Heidi Scribe during your consultation and may raise any concerns about its use.
Further information about Heidi Health's handling of personal and health information is available in the Heidi Health Privacy Policy.
8. Email Communications – Tuta (formerly Tutanota)
The practice uses Tuta (formerly Tutanota) for its practice email service, including admin@shilton.net.au.
Tuta is an encrypted email service. Tuta states that mailbox data is stored encrypted on its own servers in ISO 27001-certified data centres in Germany.
Because the Tuta service is hosted outside Australia, information contained in practice email may therefore be stored overseas. The practice has selected an encrypted email provider as part of the reasonable steps it takes to protect the confidentiality and security of information transmitted to and held by the practice.
Email between Tuta users, and password-protected email sent through Tuta's secure process to external users, can be end-to-end encrypted. Ordinary email sent to or from external email providers may not be end-to-end encrypted during the entire transmission, although Tuta states that email stored in the Tuta mailbox is encrypted.
Patients should avoid including unnecessary sensitive information in ordinary email and should contact the practice if they are uncertain about the appropriate way to communicate confidential medical information.
9. Disclosure of Personal Information
Where reasonably necessary and permitted by law, we may disclose personal or health information to:
other healthcare professionals and organisations involved in your care;
hospitals and healthcare facilities;
pathology and diagnostic imaging services;
Medicare, private health insurers and other payment or claims organisations;
your authorised representatives;
medical indemnity providers, professional advisers and auditors where appropriate;
regulatory authorities or other organisations where disclosure is required or authorised by law; and
organisations that provide services necessary for the operation of the practice, including practice-management, information technology, secure communications, data storage, clinical documentation, accounting and administrative services.
As described above, Patient Data held through Gentu may also be used or disclosed in connection with Magentus Data Projects where applicable. Magentus states that relevant Patient Data may be used for clinical decision-support, or de-identified and aggregated before disclosure to trusted partners and project sponsors for research, analytics and better health outcomes. Patients may opt out of such Data Projects.
We do not sell patient information and will not disclose your personal or health information to third parties for direct marketing without your consent.
10. Overseas Storage and Processing
Core Gentu clinical information is hosted using Australian-based cloud infrastructure according to Magentus. Magentus' broader privacy policy also provides that it may disclose personal information overseas to service providers where required to provide its services.
Some other services used by the practice involve overseas storage or processing. In particular:
practice email stored using Tuta is hosted on encrypted servers in Germany;
while Heidi states that personal information for Australian users is stored in Australia, some functionality may involve third-party services whose servers are located internationally; and
information entered into the practice website may be processed through Squarespace infrastructure in accordance with Squarespace's privacy and data-handling arrangements.
Where the practice engages a service provider that may handle personal information outside Australia, we take reasonable steps appropriate to the circumstances to consider and manage the privacy and security implications of that arrangement in accordance with applicable Australian privacy law.
11. Storage and Security
We take reasonable steps to protect personal and health information from misuse, interference, loss and unauthorised access, modification or disclosure.
Measures used by the practice include, as appropriate:
secure electronic clinical records using Gentu;
encrypted practice email using Tuta;
controlled access to clinical information;
secure authentication and passwords;
appropriate physical security of practice premises and records;
encryption and security measures provided by our technology providers;
limiting access to information according to staff roles and clinical requirements;
maintaining appropriate computer and network security; and
staff awareness of privacy and confidentiality obligations.
No electronic system or internet transmission can be guaranteed to be completely secure. We nevertheless take reasonable precautions appropriate to the sensitivity of the health information we hold.
12. Retention of Medical Records
Medical and other personal information is retained for the periods required by applicable legal, professional and clinical record-keeping requirements.
When personal information is no longer required and there is no legal or professional requirement for it to be retained, it will be securely destroyed or de-identified where appropriate.
13. Access and Correction
You have the right to request access to personal information we hold about you and to ask us to correct information that is inaccurate, incomplete, out of date or misleading, subject to exceptions permitted by law.
Requests may be made by contacting the practice using the details below. We may need to verify your identity before providing access to health information.
We will respond to requests within a reasonable period and in accordance with applicable legal requirements.
14. My Health Record
Where clinically appropriate, the practice may access or contribute information to My Health Record in accordance with the My Health Records Act 2012, applicable My Health Record Rules and Regulations, and other relevant legislation.
Access to My Health Record by the practice is restricted to authorised persons and permitted purposes associated with the provision of healthcare and other purposes permitted by law.
You can control access to your My Health Record using the privacy and access settings provided through the My Health Record system. Depending upon the available settings, you may restrict access to your record or particular documents and review the access history associated with your record.
Access may also occur in emergency circumstances where permitted by law.
The practice maintains appropriate security and access controls for its participation in the My Health Record system. Information contained in My Health Record is managed under the My Health Record legislative framework. The practice does not control the retention or deletion of information held by the national My Health Record system.
15. Data Breaches
If the practice becomes aware of a suspected or actual data breach involving personal or health information, we will assess and manage the incident in accordance with applicable legal requirements.
Where a breach is likely to result in serious harm and notification is required under the Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.
Incidents involving My Health Record information will also be managed and reported in accordance with applicable My Health Record requirements.
16. Privacy Complaints
If you have a question or concern about how we have handled your personal information, or believe that your privacy has been breached, please contact the practice.
We will take your complaint seriously, investigate it and respond within a reasonable period.
If you are not satisfied with our response, you may make a complaint to the Office of the Australian Information Commissioner (OAIC).
17. Contact Us
Dr Hamish Shilton's Rooms
Suite 19, Cabrini Hospital
183 Wattletree Road
Malvern VIC 3144
Phone: (03) 9923 8066
Email: admin@shilton.net.au
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legislation, technology, our service providers, third-party data practices or the way the practice operates.
The current version will be made available on our website and may also be obtained from the practice.