We are committed to protecting the privacy of patient information we collect and to handling your personal information in a responsible manner in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, cyber securitylegislation and ACT privacy act.
This Privacy Policy explains how we collect, use and disclose your personal information, how you may access that information and how you may seek the correction of any information. It also explains how you may make a complaint if you are concerned there has been a breach of privacy legislation.
From time to time we may make changes to our policy, processes and systems relating to how we handle your personal information. We will update this Privacy Policy to reflect any changes. Those changes will be available on our website and in the practice.
This Privacy Policy also addresses the responsible use of Artificial Intelligence (AI) technologies within our practice
What kinds of personal information do we collect?
The type of information we may collect and hold includes personal information about: Your name, address, date of birth, contact details, your Medicare number, email address, next of kin, billing details, your health information and other sensitive information relevant to your consultation (including your communications with us by TeleHealth or telephone).
How do we collect and hold personal information?
We will generally collect personal information from you directly when you provide your details to us; or from a person responsible for you and from third parties where the Privacy Act or other law allow it.
It is necessary for us to keep patients’ information after their last attendance at this practice for as long as it is required by law or is prudent having regard to administrative requirements.
At NCMS it is our usual policy to keep only one medical record. If you see more than one doctor at NCMS, your NCMS record will be shared. This is to ensure that all relevant information is available at the time of consultation to facilitate good medical care. If you do not want this to occur, please tell us.
Personal information from the Australian Government My Health Record may also be collected in accordance with the Personally Controlled Electronic Health Records Act (2012). The Specialists in our practice may also access your My Health Record. www.myhealthrecord.gov.au
Why do we collect, hold, use and disclose personal information?
In general, we may collect, hold, use and disclose your personal information for the following purposes:
- To provide health services to you;
- to communicate with you;
- to comply with our legal obligations which may include mandatory notification of communicable diseases and to help us manage our accounts and administrative services.
Patient health information may also be disclosed to other health professionals in the course of a case review at a multi-disciplinary meeting. These meetings allow discussion of clinical management with a group of specialists with expertise in a particular condition, in order to ensure that all relevant treatment options are explored. Permission to discuss your case at such a meeting will be sought from you in advance.
How can you access and correct your personal information?
Subject to the exceptions set out in the Privacy Act, you may seek access to and correction of the personal information that we hold about you in accordance with our access policy. A charge may be payable where the practice incurs costs in providing access. This will depend on the nature of the access. Please contact our Privacy Officer Raelene Surtees on 02 6222 6607, [email protected] or PO Box 5008 Garran ACT 2605.
Parents/Guardians and Children
The right of children to privacy of their health information, based on the professional judgement of the doctor and consistent with the law, might at times restrict access to this information by parents or guardians.
Are we likely to disclose your personal information overseas?
We may disclose your personal information to the following overseas recipients:
- any practice or individual who assists us in providing services (such as where you have come from overseas and had your health record transferred from overseas or have treatment continuing from an overseas provider);
- anyone else to whom you authorise us to disclose it;
- and anyone else where obliged by law.
How do we use Artificial Intelligence (AI) in the pracitce ?
NCMS may use AI technologies to enhance clinical decision-making, streamline administrative processes, and improve patient engagement. Examples of AI applications include:
- automated transcription of clinical consultations
Governance of AI Use:
- We use AI tools in a manner consistent with the Australian Privacy Principles and relevant ethical standards.
- Personal information is not used to train AI models unless express consent has been obtained.
- All outputs generated by AI systems are subject to human review and clinical oversight.
- No automated decision-making tool is used in this practice.
Recording of consultations
Although the Zoom videoconferencing platform has the ability to record TeleHealth consultations this will not be implemented. If patients or their carers wish to record consultations this should be with the express permission of the consulting doctor.
Our practice uses Medow Health, a healthcare software platform that complies with all relevant Australian healthcare regulations, including the Australian Privacy Principles (APPs). Medow Health is designed specifically for healthcare environments, with all data stored and processed in accordance with local laws. Voice recordings during consultations are processed in real-time and automatically deleted within 7 days with only essential diagnostic and documentation data retained. Use of this platform is only after obtaining specific consent from you.
Patient and practice data is securely stored using HIPAA-compliant Microsoft Azure infrastructure, ensuring data sovereignty and protection under Australian privacy legislation. Access to this data is restricted to authorised personnel, and appropriate security measures are maintained to safeguard patient information at all times.
By using Medow Health, our practice ensures that patient information is handled securely and in line with the highest standards of privacy and data protection. Further information is on the Medow website here: https://www.medowhealth.ai/trust-safety
How can you make a privacy related complaint?
We will take reasonable steps to protect the security of your information and comply with our legal obligations. Please do not hesitate to discuss any concerns, questions or complaints about any issues related to the privacy of your personal information with your doctor. Our staff are trained and required to respect your privacy. We take reasonable steps to protect information held from misuse and loss and from unauthorised access, modification or disclosure.
If you have any questions about privacy-related issues or wish to complain about a breach of the Australian Privacy Principles or the handling of your personal information by us, please contact our Privacy Officer Raelene Surtees on 02 6222 6607 [email protected] or PO Box 5008 Garran ACT 2605.
You may lodge your complaint in writing. Any complaint will be investigated and you will be notified of the making of a decision in relation to your complaint as soon as is practicable after it has been made, usually within 30 days.
Further details of your rights are available here from the Office of the Australian Information Commissioner www.oaic.gov.au, [email protected] or 1300 363 992.

