Participants' privacy and confidentiality
Using our peer support service
The Nurse Midwife Health Program Australia (NMHPA) will ensure that all personal information, no matter how or where it is obtained, is handled sensitively, securely and in accordance with relevant legislation and regulations.
NMHPA complies with the Australian Privacy Principles for the Fair Handling of Personal Information. The privacy principles set the minimum standards for collecting, storing, using, disclosing, managing, accessing, correcting and disposing of personal information.
We are committed to taking all appropriate measures to ensure that the personal information of participants is protected from unauthorised access, loss, misuse, disclosure or alteration.
The program is committed to protecting all participants' privacy, confidentiality and personal information. We comply with the:
- Privacy Act 1988 and the Privacy Amendment Act 2012 (C’wealth)
- Privacy and Data Protection Act 2014, which is detailed in the Australian Privacy Principles (C’wealth)
- various State and Territory privacy legislation and regulations.
Note: This policy only refers to the privacy of participants.
Staff access and responsibilities
Our staff must:
- seek or give only information about an individual that is relevant to the service provided or requested
- gain signed consent from a participant when personal information is being disclosed to others outside the program
- ensure all records are stored in a manner that maintains confidentiality
- respect the privacy of all participants, including both written and verbal information, except where legal or ethical issues deem otherwise.
Only staff with direct involvement in a matter will have access to a participant’s file. Staff must not access a participant's personal information that does not pertain directly to their position or hold relevance to their work.
Unauthorised disclosure of information and breaches of confidentiality by staff will result in disciplinary procedures and possible dismissal.
Collection and access to information
Information must be collected directly from participants or from their authorised representative. Representatives include guardians, lawyers under enduring powers of attorney, agents under the Medical Treatment Act 1988, administrators under the Guardianship and Administration Act 1986, and/or a person otherwise empowered to act or make decisions in the best interests of participants.
Information remains the property of participants, and the program will ensure they are aware of:
- details of what is being collected
- purpose for which the information is being collected
- access – rights and how to access
- correction – rights and how to amend incorrect information
Information about individuals will be treated as confidential except when:
- harm risk - there is significant cause to believe a participant is at risk of harming themselves or someone else
- health or safety issue is apparent
- legal process applies and there is a requirement under legislative obligations.
Participant experience survey
NMHPA may invite participants to complete a short participant experience survey to help us improve our services. Participation is voluntary and will not affect your access to care.
Responses are anonymous - please do not include your name or any identifying details. Survey findings are aggregated and de-identified. The findings help us improve our service. Some responses may be used for marketing purposes.
Storage and security of personal information
NMHPA will maintain control and be responsible for the security of personal information it holds. We will take reasonable steps to protect personal information from misuse, loss and from unauthorised access, modification and/or disclosure
We will mitigate risk by:
- storing or saving participant information only on NMHPA’s network systems, within a prescribed database or document management system
- never storing participant information on a staff’s personal device or document management system
- locking hard copy documents containing personal and sensitive information in cabinets when not in use
- password-protecting when sharing electronic documents containing personal or sensitive information.
Privacy breaches
NMHPA is required to notify participants when there are reasonable grounds to believe that an eligible data breach has occurred.
The NMHPA Privacy and Data Breach Policy outlines how to manage a privacy or data breach, which is available on request.
Complaints about privacy breaches
Participants can complain or raise a concern if they believe NMHPA has breached their privacy regarding their information. To make a complaint please use the NMHPA Feedback form.
NMHPA takes complaints about privacy seriously. We will ensure investigations are thorough and a response is given within an appropriate timeframe.
Requesting access to your information
Participants may request access to personal information held by NMHPA.
Requests for access must be made in writing and require confirmation of identity. Where a request is made on behalf of a participant, appropriate documentation confirming authority (for example, an Enduring Power of Attorney or participant consent) is required.
When making a request, please provide detail to help us identify the information you are seeking.
NMHPA will consider each request in accordance with privacy legislation and our confidentiality obligations. In some circumstances, we may not be able to provide access to certain information. If this occurs, NMHPA will provide written reasons for the decision.
Request access to your information
Request must be made in writing.
- Topics
- Policy