PRIVACY AND SECURITY POLICY
This practice takes patient privacy, confidentiality and computer security very seriously. We have a strict confidentiality and security code of conduct in place. All staff have signed a strict confidentiality agreement with breach of confidentiality being a dismissible offence.

At night, our building is locked, alarmed, and protected with infrared video camera surveillance. Backup of data occurs nightly and is stored off site. Our patient databanks are protected by firewalls and connect to the external environment for a few minutes per day only to download results and are password protected.

All information gathered on patients is for the purposes of providing holistic ongoing patient care. We do not release any patient information for any research or commercial purposes.

Our Health Care Team (doctors, nurses, receptionists) have password access to records for the purposes of scanning in specialist letters, downloading path results, inputting automated results, recording surgery test results, retrieving results, documenting patient recalls, attempts to contact patients and recording messages from/to patients and recording consultation notes.

This "Health Care Team" approach is essential to provide prompt holistic quality care for patients. It is impractical to restrict access to doctors only due to legal requirements to maintain contemporaneous medical records i.e. to record all contacts with patients, also doctors are required to have a recall system in place for which our nurses need access to files / receptionists need to record messages, download results & receptionists need to scan in specialist letters in patients' files. All these activities occur on a need to know basis. Doctors cannot be receptionists, nurses, and doctors all at the same time. However, you can minimise the need for access by staff by simply making appointments (rather than calling for results/discussions/leaving messages )

Other accepted use and disclosure of health information is where disclosure is required by law, informing radiologists, pathologists , specialists and allied health workers of relevant patient history, an organisations management , billing & debt recovery, service monitoring, complaint handling, quality assurance, clinical audit activities, accreditation activities, maintenance of practice disease registers and medicolegal reasons.

Under the new Privacy legislation, we are required to ascertain the identity of the individual requesting results, since it is impossible to do this reliably over the telephone we will no longer be giving results over the phone. The medicare number is not allowed to be used as an identifier under the privacy legislation and things such as date of birth, mothers maiden name, file number & passwords are often known by close family/ friends who are the greatest potential source of a breach of confidentiality.

There is also the issue of minimising non-doctor access to patient records. If you ring for a result, a receptionist must access your records to check for these. Accordingly, we will no longer provide results over the telephone. Thus to maintain your privacy it is better to make an appointment to see the doctor for results or ask your Doctor to use the phone in 24 hour access computerised results system for routine results at each consultation.

Our Surgery Email is not encrypted which means it could be intercepted and read by others external to the surgery thus so we will not discuss medical information via email, it is for general enquires only.

Please note, due to time constraints, patient privacy reasons and to minimise interruptions to patient consultations, it is not possible for doctors to take calls for routine results.

On occasion, if the doctor feels they can be sure of a patient's identity, a telephone consultation may be booked to discuss results. ($5.50/min , non refundable by medicare)
Copyright © 2006/2007 Brisbane City 6 Day Medical Centre. All Rights Reserved.