m
Recent Posts
Connect with:
Monday / August 31.
HomemibusinessMaintaining Patient Confidentiality: A Practical Guide

Maintaining Patient Confidentiality: A Practical Guide

graphic representing patient confidentiality

Protecting patient information is a core obligation for optometrists in Australia. The Privacy Act 1988 (Cth) (Privacy Act) governs how patient information is handled and is supported by the Australian Privacy Principles (APPs), which set out detailed rules around the collection, use, and disclosure of personal data.

New Zealand-based practitioners are bound by the Health Information Privacy Code 2020, which applies specifically to health service providers, and the Information Privacy Principles.

Key Responsibilities for Optometric Practices

Collecting Patient Information

Optometrists should only collect patient information where the patient has given their consent; and the information is reasonably necessary to provide optometric services.

Where possible, information should be obtained directly from the patient. However, collection from third parties may be appropriate:

  • In emergencies,
  • Where the patient lacks decision-making capacity (such as minors or individuals with cognitive impairment), or
  • Where information is provided by another healthcare practitioner.

Information may only be collected without a patient’s consent if the proposed collection is required by law; necessary to prevent a serious threat to health or safety; or permitted for approved research purposes.

Patients should be informed (at or before the time of collection) why their information is being collected, so they can make an informed decision as to whether to disclose their health information.

Use and Disclosure of Information

Patient information should only be used or disclosed for the purpose for which it was collected (being the provision of clinical care).

Unless an exception applies, the patient’s consent must be obtained to use or share their information for a different purpose (such as specialist referrals, insurance matters or marketing). Some examples

of exceptions include:

  • Compliance with legal obligations (for example, a court order), or
  • Circumstances where disclosure is necessary to prevent serious harm to the patient.

The patient’s express consent must be obtained before using their personal information to send them advertising or marketing material. In doing so, patients must be given clear instructions on how to opt out of receiving such material in the future.

Where patient information is shared with overseas recipients, optometrists must take reasonable steps to ensure the recipient complies with APPs. In these circumstances, the Australian optometrist remains responsible for any breach of privacy by the overseas recipient.

Patient information should only be used or disclosed for the purpose for which it was collected

Patient Access

Patients are entitled to access their personal information. Optometrists should respond to any patient’s request for access within a reasonable time frame – ideally, within 30 days.

Before the information is released, the identity of the patient must be verified. If the optometrist cannot verify the requester’s identity, the request should be declined.

Special care is required where access is requested by someone other than the patient, including:

Parents of children. Practitioners should not provide information, unless, based on their own assessment, the patient child does not have capacity to request the information independently; and

Insurers or lawyers. Information should only be provided with clear patient consent.

Access may be refused in certain circumstances, including where disclosure would pose a serious risk to health or safety; it would unreasonably compromise another person’s privacy; or disclosure of the information would be unlawful.

Correction of Patient Information

Practitioners must take reasonable steps to ensure their records are accurate and complete.

If a patient requests that their information be corrected:

  • The request should be dealt with promptly, again, ideally within 30 days,
  • Amendments should be made where the information is inaccurate, incomplete or misleading, and
  • Supporting material may be requested if the accuracy of the information is disputed.

Where corrections are made, third parties (such as referring practitioners) should be notified if requested by the patient.

Practitioners should also proactively correct any errors they identify and inform the patient accordingly.

Artificial Intelligence in Practice

The use of artificial intelligence (AI) tools for administrative tasks is now widespread in optometry, including speech-to-text platforms such as i-scribe and Heidi, which are used to transcribe patient consultations and generate clinical notes.

While these tools can improve efficiency and reduce administrative burden, they can also create privacy and data security risks for patients.

Before implementing AI tools, practitioners should carefully consider:

  • How the AI tools collect and store patient data,
  • The nature of the data used to test the system,
  • The technology’s limitations,
  • Whether the system is cloud-based or locally hosted, and
  • Whether any third parties or overseas entities have access to the data.

It is also essential to review the provider’s privacy practices and ensure they align with the practice’s own obligations.

The patient’s consent must also be obtained before AI speech-to-text applications are used during a consultation.

Managing Data Breaches

Optometrists must take reasonable steps to safeguard patient information against misuse, interference, and unauthorised access.

If a data breach occurs, the practitioner must (within 30 days) assess and determine whether the affected person, and either the Office of the Australian Information Commissioner (OAIC) or the New Zealand Privacy Commissioner, should be notified. This will be required if:

  • Personal information has been accessed or disclosed without authorisation, and
  • The data breach is likely to result in serious harm.

Consequences of Non-Compliance

Failure to comply with privacy obligations can result in significant penalties.

For example, for companies in Australia, the maximum penalty is the greater of:

  • AU$50 million,
  • Three times the benefit obtained from the breach (if this can be quantified), or
  • If the benefit cannot be quantified, 30% of turnover during the relevant period.

Individuals may face penalties of up to AU$2.5 million.

Minimising Risk in Practice

Develop clear organisational policies. Practices should maintain a clear and accessible privacy policy explaining how patient information should be handled. Supporting IT and data security policies should also be in place.

Train and support staff. A strong culture of confidentiality starts with education. Practitioners should ensure that their staff understand their obligations under relevant legislation, codes, and privacy principles; the practice’s internal policies; and how to identify and respond to privacy risks.

Ongoing training is important to keep pace with regulatory changes and evolving technologies.

Secure recordkeeping. Both electronic and hard copy records must be adequately protected. Practical safeguards include:

  • Using secure practice management systems,
  • Implementing measures such as multi-factor authentication,
  • Restricting access to physical records, and
  • Maintaining accurate, up-to-date patient files.

Ryan Scott is a lawyer in the Commercial, Business and Private Client Services Division at Burke Lawyers, a law firm based in Melbourne, Victoria. He works closely with medical and health care professionals, helping them to achieve their business goals while effectively managing risk. His core practice areas are contract law, commercial and business advisory, corporate governance, dispute resolution, business succession planning, and asset protection.

This article does not constitute legal advice and is intended to provide general information only. Readers must seek independent legal advice in relation to their own specific circumstances. No action should be taken, nor reliance placed, on the contents of this article whatsoever as an alternative to obtaining independent legal advice. The author, Burke Lawyers, and mivision accept no responsibility or liability for any loss or damage that may arise from reliance on this article.