CINXE.COM
Communications with patients | OAIC
<!doctype html> <html lang="en"> <head> <title>Communications with patients | OAIC</title> <!-- Misc Metadata --> <meta charset="utf-8"> <meta name="mobile-web-app-capable" content="yes"> <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0"> <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"> <!-- Global Default Metadata --> <meta name="dcterms.title" content="Communications with patients"> <meta name="dcterms.creator" content="OAIC"> <meta name="dcterms.created" content="2022-08-04T16:56:25+10:00"> <meta name="dcterms.modified" content="2024-09-05T11:39:15+10:00"> <meta name="dcterms.issued" content="2023-03-10T16:31:20+11:00"> <meta name="dcterms.format" content="HTML"> <meta name="dcterms.identifier" content="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients"> <!-- Custom Metadata --> <!-- Page //--> <!-- SEO //--> <meta name="publishedDate" content="10 March 2023"> <meta name="publishedDate_ISO" content="2023-03-10T00:00:00+11:00"> <meta name="description" content="The OAIC has a flowchart that outlines the considerations in sending communications to patients, which must be read with the information on this page." /> <meta name="pdISO" content="2023-03-10T00:00:00+11:00" /> <meta name="robots" content="" /> <!-- Chapter navigation //--> <meta name="chapter-nav" content="no" /> <meta name="chapter-nav-prev" content="" /> <meta name="chapter-nav-next" content="" /> <meta name="chapter-nav-prev-btn-text" content="Previous chapter" /> <meta name="chapter-nav-next-btn-text" content="Next chapter" /> <meta name="background_color" content="chapter-navigation__wrapper--white" /> <!-- Media //--> <meta name="show-related-articles" content="no" /> <meta name="topic" content="Health; Privacy" /> <meta name="contentType" content="" /> <meta name="featuredNews" content="no" /> <meta name="author-name" content="" /> <meta name="author-title" content="" /> <meta name="author-image" content="" /> <!-- Search //--> <meta name="type" content="web" /> <!-- Feedback //--> <meta name="showFeedbackWidget" content="yes" /> <meta name="showShareWidget" content="yes" /> <!-- Google+ Schema.org Data | https://developers.google.com/+/web/snippet/article-rendering --> <meta itemprop="name" content="Communications with patients" /> <meta itemprop="description" content="The OAIC has a flowchart that outlines the considerations in sending communications to patients, which must be read with the information on this page." /> <meta itemprop="image" content="" /> <!-- Twitter Card Data | https://dev.twitter.com/cards/types/summary --> <meta name="twitter:card" content="summary" /> <meta name="twitter:site" content="@OAICgov" /> <meta name="twitter:title" content="Communications with patients" /> <meta name="twitter:description" content="The OAIC has a flowchart that outlines the considerations in sending communications to patients, which must be read with the information on this page." /> <meta name="twitter:image" content="" /> <!-- Schema.org --> <script type="application/ld+json"> { "@context": "https://schema.org", "@type": "WebPage", "name": "Communications with patients", "description": "The OAIC has a flowchart that outlines the considerations in sending communications to patients, which must be read with the information on this page.", "url": "https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients", "datePublished": "04pm31Australia/Sydney", "dateModified": "05am30Australia/Sydney", "publisher": { "@type": "Organization", "name": "OAIC", "logo": { "@type": "ImageObject", "url": "https://www.oaic.gov.au/__data/assets/image/0028/245845/OAIC-logo-inline-dark-1.png", "caption": "OAIC - Australian Government - Office of the Australian Information Commissioner" } }, "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients" } } </script> <!-- Open Graph Data | http://ogp.me/ --> <meta property="og:title" content="Communications with patients" /> <meta property="og:type" content="website" /> <meta property="og:url" content="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients" /> <meta property="og:image" content="" /> <meta property="og:description" content="The OAIC has a flowchart that outlines the considerations in sending communications to patients, which must be read with the information on this page." /> <meta property="og:site_name" content="OAIC" /> <meta property="article:published_time" content="2023-03-10T16:31:20+11:00" /> <meta property="article:modified_time" content="2024-09-05T11:39:15+10:00" /> <meta property="article:tag" content="" /> <meta name="theme-color" content="#fafafa"> <!-- Readspeaker --> <script src="//cdn-oc.readspeaker.com/script/9755/webReader/webReader.js?pids=wr" type="text/javascript" id="rs_req_Init"></script> <!-- Google Tag Manager --> <script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-PTH9SP3B');</script> <!-- End Google Tag Manager --> <!-- Google Site Verification --> <meta name="google-site-verification" content="sQVHBUKhjuCjBjithPialZYhGQ5SPKwjb1_rY8OqsjA" /> <script src="https://cdn.jsdelivr.net/npm/chart.js"></script> <link rel="stylesheet" href="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/main.css?h=06ed308"> <link rel="stylesheet" href="https://www.oaic.gov.au/__data/assets/css_file/0024/240585/custom.css?v=0.1.245"> <!-- Fonts --> <link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap-icons@1.11.3/font/bootstrap-icons.min.css"> <link rel="preconnect" href="https://fonts.googleapis.com"> <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin> <link href="https://fonts.googleapis.com/css2?family=Source+Code+Pro:ital,wght@0,200;0,300;0,400;0,500;0,600;0,700;0,800;0,900;1,200;1,300;1,400;1,500;1,600;1,700;1,800;1,900&display=swap" rel="stylesheet"> <!-- Favicons --> <link rel="shortcut icon" href="https://www.oaic.gov.au/__data/assets/image/0016/14182/favicon-32x32.png"> <link rel="apple-touch-icon" href="https://www.oaic.gov.au/__data/assets/image/0015/14181/apple-touch-icon.png"> <!-- Running Squiz Matrix Developed by Squiz - http://www.squiz.net Squiz, Squiz Matrix, MySource, MySource Matrix and Squiz.net are registered Trademarks of Squiz Pty Ltd Page generated: 17 February 2025 17:28:00 --> </head> <body class="inside"> <!-- Cookie banner start --> <section class="cookie-banner" aria-labelledby="cookie-heading"> <h2 class="visuallyhidden" id="cookie-heading">We use cookies on this site</h2> <div class="cookie-banner__content"> <div> <p>We use cookies to analyse traffic and to improve your browsing experience on our website. To find out more, read our <a href="https://www.oaic.gov.au/about-the-OAIC/our-corporate-information/plans-policies-and-procedures/privacy-policy">privacy policy</a>.</p> </div> <button class="cookie-banner__close primary-button" id="close-cookie-banner" aria-label="Close and accept cookie policy">Close</button> </div> </section> <!-- Cookie banner end --> <!-- Skip to content start --> <div class="skip-to-content"> <a href="#main-content-area" class="skip-to-content__link visuallyhidden focusable">Skip to main content</a> </div> <!-- Skip to content end --> <div class="page-wrapper"> <!-- Notification banner start --> <!-- Notification banner end --> <!-- Header start --> <!--noindex--> <header class="site-header"> <div class="utility-nav"> <div class="utility-nav__wrapper"> <a href="/news" class="utility-nav__link ">News</a> <a href="/about-the-OAIC/join-our-team" class="utility-nav__link ">Join our team</a> <a href="/contact-us" class="utility-nav__link ">Contact us</a> </div> </div> <div class="header-content"> <a href="https://www.oaic.gov.au" class="header-logo"> <img src="https://www.oaic.gov.au/__data/assets/file/0020/13664/oaic-header-logo.svg" alt="Office of the Australian Information Commissioner (OAIC)"> </a> <button class="mobile-menu" aria-controls="header-nav" aria-expanded="false"> <img class="menu-icon menu-icon--burger" src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/hamburger-menu.svg" alt="open menu"> <img class="menu-icon menu-icon--close" src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/cancel-icon-white.svg" alt="close menu"> </button> <div class="search-container search-container--header"> <form class="input-form" action="https://www.oaic.gov.au/search" data-action="https://www.oaic.gov.au/search?SQ_ASSET_CONTENTS_RAW"> <input name="query" autocomplete="off" id="autoComplete" placeholder="Search…" class="search-box" aria-label="Search input" data-autocomplete-endpoint="https://dxp-au-search.funnelback.squiz.cloud/s/suggest.json?collection=113e9365-ffcc-4320-a995-5c1b98bea3bb~sp-oaic-web-new&profile=auto-completion-global&fmt=json%2B%2B&alpha=0.5&show=10"> <input type="hidden" name="form" value="result"> <button type="button" id="clear-text-btn" class="cancel-logo" aria-label="Clear text"> <img src="https://www.oaic.gov.au/__data/assets/file/0022/13666/cancel-icon.svg" alt="clear text cancel icon"> </button> <button type="submit" aria-label="Submit search"> <img class="search-icon" src="https://www.oaic.gov.au/__data/assets/file/0023/13667/search-outline.svg" alt="search icon thst submits form"> </button> </form> </div> <div id="header-nav" class="header-nav"> <nav class="header-nav__nav"> <div class="header-nav__item"> <a href="https://www.oaic.gov.au" class="header-nav__link " > Home </a> </div> <div class="header-nav__item"> <button class="header-nav__button current" aria-expanded="false" > Privacy <div class="header-nav__mobile-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-plus" alt="expand menu"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-minus" alt="collapse menu"> </div> <div class="header-nav__desktop-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/chevron-down-white.svg" alt="expand menu"> </div> </button> <div class="header-nav__sub"> <div class="header-nav__sub-wrapper"> <div class="header-nav__sub-first"> <a href="https://www.oaic.gov.au/privacy" class="header-nav__sub-link"> Privacy </a> </div> <div class="header-nav__sub-grid"> <a href="https://www.oaic.gov.au/privacy/your-privacy-rights" class="header-nav__sub-link"> Your privacy rights </a> <a href="https://www.oaic.gov.au/privacy/privacy-complaints" class="header-nav__sub-link"> Privacy complaints </a> <a href="https://www.oaic.gov.au/privacy/australian-privacy-principles" class="header-nav__sub-link"> Australian Privacy Principles </a> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies" class="header-nav__sub-link"> Privacy guidance for organisations and government agencies </a> <a href="https://www.oaic.gov.au/privacy/notifiable-data-breaches" class="header-nav__sub-link"> Notifiable data breaches </a> <a href="https://www.oaic.gov.au/privacy/privacy-legislation" class="header-nav__sub-link"> Privacy legislation </a> <a href="https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions" class="header-nav__sub-link"> Privacy assessments and decisions </a> <a href="https://www.oaic.gov.au/privacy/privacy-registers" class="header-nav__sub-link"> Privacy registers </a> </div> </div> </div> </div> <div class="header-nav__item"> <button class="header-nav__button " aria-expanded="false" > Freedom of information <div class="header-nav__mobile-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-plus" alt="expand menu"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-minus" alt="collapse menu"> </div> <div class="header-nav__desktop-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/chevron-down-white.svg" alt="expand menu"> </div> </button> <div class="header-nav__sub"> <div class="header-nav__sub-wrapper"> <div class="header-nav__sub-first"> <a href="https://www.oaic.gov.au/freedom-of-information" class="header-nav__sub-link"> Freedom of information </a> </div> <div class="header-nav__sub-grid"> <a href="https://www.oaic.gov.au/freedom-of-information/your-freedom-of-information-rights" class="header-nav__sub-link"> Your freedom of information rights </a> <a href="https://www.oaic.gov.au/freedom-of-information/how-to-access-government-information" class="header-nav__sub-link"> How to access government information </a> <a href="https://www.oaic.gov.au/freedom-of-information/freedom-of-information-guidance-for-government-agencies" class="header-nav__sub-link"> Freedom of information guidance for government agencies </a> <a href="https://www.oaic.gov.au/freedom-of-information/freedom-of-information-legislation-and-determinations" class="header-nav__sub-link"> Freedom of information legislation and determinations </a> <a href="https://www.oaic.gov.au/freedom-of-information/information-commissioner-decisions-and-reports" class="header-nav__sub-link"> Information Commissioner decisions and reports </a> <a href="https://www.oaic.gov.au/freedom-of-information/freedom-of-information-statistics-for-the-oaic" class="header-nav__sub-link"> Freedom of information statistics for the OAIC </a> <a href="https://www.oaic.gov.au/freedom-of-information/australian-government-freedom-of-information-statistics" class="header-nav__sub-link"> Australian Government freedom of information statistics </a> </div> </div> </div> </div> <div class="header-nav__item"> <button class="header-nav__button " aria-expanded="false" > Consumer Data Right <div class="header-nav__mobile-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-plus" alt="expand menu"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-minus" alt="collapse menu"> </div> <div class="header-nav__desktop-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/chevron-down-white.svg" alt="expand menu"> </div> </button> <div class="header-nav__sub"> <div class="header-nav__sub-wrapper"> <div class="header-nav__sub-first"> <a href="https://www.oaic.gov.au/consumer-data-right" class="header-nav__sub-link"> Consumer Data Right </a> </div> <div class="header-nav__sub-grid"> <a href="https://www.oaic.gov.au/consumer-data-right/information-for-consumers" class="header-nav__sub-link"> Information for consumers </a> <a href="https://www.oaic.gov.au/consumer-data-right/consumer-data-right-complaints" class="header-nav__sub-link"> Consumer Data Right complaints </a> <a href="https://www.oaic.gov.au/consumer-data-right/consumer-data-right-guidance-for-business" class="header-nav__sub-link"> Consumer Data Right guidance for business </a> <a href="https://www.oaic.gov.au/consumer-data-right/consumer-data-right-legislation,-regulation-and-definitions" class="header-nav__sub-link"> Consumer Data Right legislation, regulation and definitions </a> <a href="https://www.oaic.gov.au/consumer-data-right/consumer-data-right-assessments" class="header-nav__sub-link"> Consumer Data Right assessments </a> </div> </div> </div> </div> <div class="header-nav__item"> <a href="https://www.oaic.gov.au/digital-id" class="header-nav__link " > Digital ID </a> </div> <div class="header-nav__item"> <button class="header-nav__button " aria-expanded="false" > Engage with us <div class="header-nav__mobile-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-plus" alt="expand menu"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-minus" alt="collapse menu"> </div> <div class="header-nav__desktop-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/chevron-down-white.svg" alt="expand menu"> </div> </button> <div class="header-nav__sub"> <div class="header-nav__sub-wrapper"> <div class="header-nav__sub-first"> <a href="https://www.oaic.gov.au/engage-with-us" class="header-nav__sub-link"> Engage with us </a> </div> <div class="header-nav__sub-grid"> <a href="https://www.oaic.gov.au/engage-with-us/consultations" class="header-nav__sub-link"> Consultations </a> <a href="https://www.oaic.gov.au/engage-with-us/submissions" class="header-nav__sub-link"> Submissions </a> <a href="https://www.oaic.gov.au/engage-with-us/translations" class="header-nav__sub-link"> Translations </a> <a href="https://www.oaic.gov.au/engage-with-us/events" class="header-nav__sub-link"> Events </a> <a href="https://www.oaic.gov.au/engage-with-us/networks" class="header-nav__sub-link"> Networks </a> <a href="https://www.oaic.gov.au/engage-with-us/research-and-training-resources" class="header-nav__sub-link"> Research and training resources </a> </div> </div> </div> </div> <div class="header-nav__item"> <button class="header-nav__button " aria-expanded="false" > About the OAIC <div class="header-nav__mobile-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-plus" alt="expand menu"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-minus" alt="collapse menu"> </div> <div class="header-nav__desktop-toggle"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/chevron-down-white.svg" alt="expand menu"> </div> </button> <div class="header-nav__sub"> <div class="header-nav__sub-wrapper"> <div class="header-nav__sub-first"> <a href="https://www.oaic.gov.au/about-the-OAIC" class="header-nav__sub-link"> About the OAIC </a> </div> <div class="header-nav__sub-grid"> <a href="https://www.oaic.gov.au/about-the-OAIC/what-we-do" class="header-nav__sub-link"> What we do </a> <a href="https://www.oaic.gov.au/about-the-OAIC/who-we-are" class="header-nav__sub-link"> Who we are </a> <a href="https://www.oaic.gov.au/about-the-OAIC/join-our-team" class="header-nav__sub-link"> Join our team </a> <a href="https://www.oaic.gov.au/about-the-OAIC/access-our-information" class="header-nav__sub-link"> Access our information </a> <a href="https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach" class="header-nav__sub-link"> Our regulatory approach </a> <a href="https://www.oaic.gov.au/about-the-OAIC/our-corporate-information" class="header-nav__sub-link"> Our corporate information </a> <a href="https://www.oaic.gov.au/about-the-OAIC/information-policy" class="header-nav__sub-link"> Information policy </a> <a href="https://www.oaic.gov.au/about-the-OAIC/serving-legal-documents-on-the-australian-information-commissioner" class="header-nav__sub-link"> Serving legal documents on the Australian Information Commissioner </a> </div> </div> </div> </div> <div class="header-nav__item header-nav__item--mobile-only"> <a href="/news" class="header-nav__link">News</a> </div> <div class="header-nav__item header-nav__item--mobile-only"> <a href="/about-the-OAIC/join-our-team" class="header-nav__link">Join our team</a> </div> <div class="header-nav__item header-nav__item--mobile-only"> <a href="/contact-us" class="header-nav__link">Contact us</a> </div> </nav> </div> </div> </header> <div class="nav-close-overlay"></div> <!--endnoindex--> <!-- Header end --> <main class="main"> <div class="breadcrumb__wrapper"> <div class="section "> <div class="section-item flex-box "> <div class="breadcrumb breadcrumb--separator-chevron"> <nav class="breadcrumb__nav" aria-label="Breadcrumb"> <ul class="breadcrumb__list"> <span class="breadcrumb__list-item"><a href="https://www.oaic.gov.au" class="breadcrumb__list-item-link" aria-label="Go to home page"><svg xmlns="http://www.w3.org/2000/svg" version="1.0" viewBox="0 0 50 50" height="24" width="24"><path d="M25 9.0937 7.281 25.3747h5.563v15.531h24.312v-15.531h5.563L25 9.0937z" fill="currentColor"></path></svg></a></span> <li class="breadcrumb__list-item"> <a class="breadcrumb__list-item-link" href="https://www.oaic.gov.au/privacy">Privacy</a> </li> <li class="breadcrumb__list-item"> <a class="breadcrumb__list-item-link" href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies">Privacy guidance for organisations and government agencies</a> </li> <li class="breadcrumb__list-item"> <a class="breadcrumb__list-item-link" href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers">Health service providers</a> </li> <li class="breadcrumb__list-item"> <a class="breadcrumb__list-item-link" href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients">Communications with patients</a> </li> </ul> </nav> </div> </div> </div> </div> <div class="content-wrapper"> <div class="lhs-wrapper"> <div class="lhs-nav"> <a href="https://www.oaic.gov.au/privacy" class="lhs-nav__level-1"> Privacy </a> <div class="lhs-nav__nav-wrapper"> <div class="lhs-nav__level-2"> <h4> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies"> Privacy guidance for organisations and government agencies </a> </h4> <button class="lhs-nav__level-2-toggle" aria-expanded="false" aria-label="Expand Level 2 submenu: Privacy guidance for organisations and government agencies"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus-white.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus-white.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-3"> <li class="lhs-nav__level-3-link has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations"> Organisations </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: Organisations"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/credit-reporting" class=""> Credit reporting </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/direct-marketing" class=""> Direct marketing </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/employee-records-exemption" class=""> Employee records exemption </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/id-scanners" class=""> ID scanners </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/opting-in-to-the-privacy-act" class=""> Opting in to the Privacy Act </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/privacy-for-not-for-profits,-including-charities" class=""> Privacy for not-for-profits, including charities </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/privacy-management-plan-template" class=""> Privacy management plan template </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/selling-a-business" class=""> Selling a business </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/small-business" class=""> Small business </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/sporting-clubs" class=""> Sporting clubs </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/start-ups" class=""> Start-ups </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/tips-for-good-privacy-practice" class=""> Tips for good privacy practice </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/trading-in-personal-information" class=""> Trading in personal information </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/guidance-for-edr-schemes-when-handling-complaints-about-notifiable-data-breaches" class=""> Guidance for EDR schemes when handling complaints about notifiable data breaches </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/tracking-pixels-and-privacy-obligations" class=""> Tracking pixels and privacy obligations </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/facial-recognition-technology-a-guide-to-assessing-the-privacy-risks" class=""> Facial recognition technology: a guide to assessing the privacy risks </a> </li> </ul> </li> <li class="lhs-nav__level-3-link has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/government-agencies"> Government agencies </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: Government agencies"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/government-agencies/agency-referee-reports" class=""> Agency referee reports </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/government-agencies/australian-government-agencies-privacy-code" class=""> Australian Government Agencies Privacy Code </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/government-agencies/conducting-surveys" class=""> Conducting surveys </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/government-agencies/guidelines-on-data-matching-in-australian-government-administration" class=""> Guidelines on data matching in Australian Government administration </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/government-agencies/privacy-impact-assessment-register-assessment-program" class=""> Privacy impact assessment register assessment program </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/government-agencies/privacy-code-checklist" class=""> Privacy Code checklist </a> </li> </ul> </li> <li class="lhs-nav__level-3-link "> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-developing-and-training-generative-ai-models"> Guidance on privacy and developing and training generative AI models </a> </li> <li class="lhs-nav__level-3-link "> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products"> Guidance on privacy and the use of commercially available AI products </a> </li> <li class="lhs-nav__level-3-link current has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers"> Health service providers </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: Health service providers"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients" class="current"> Communications with patients </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/data-breach-action-plan-for-health-service-providers" class=""> Data breach action plan for health service providers </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/guide-to-health-privacy" class=""> Guide to health privacy </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/individual-healthcare-identifiers" class=""> Individual healthcare identifiers </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/my-health-record" class=""> My Health Record </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/privacy-action-plan-for-your-health-practice" class=""> Privacy action plan for your health practice </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/taking-photos-of-patients" class=""> Taking photos of patients </a> </li> </ul> </li> <li class="lhs-nav__level-3-link has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information"> Handling personal information </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: Handling personal information"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/anti-money-laundering-obligations" class=""> Anti-money laundering obligations </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/centrelink-requests-for-information" class=""> Centrelink requests for information </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/dealing-with-requests-for-access-to-personal-information" class=""> Dealing with requests for access to personal information </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/dealing-with-requests-for-correction-of-personal-information" class=""> Dealing with requests for correction of personal information </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/de-identification-and-the-privacy-act" class=""> De-identification and the Privacy Act </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/de-identification-decision-making-framework" class=""> De-identification Decision-Making Framework </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/guide-to-securing-personal-information" class=""> Guide to securing personal information </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/guide-to-the-privacy-persons-reported-as-missing-rule-2024" class=""> Guide to the Privacy (Persons Reported as Missing) Rule 2024 </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/guidelines-for-state-and-territory-governments-creating-nationally-consistent-requirements-to-collect-personal-information-for-contact-tracing-purposes" class=""> Guidelines for state and territory governments: creating nationally consistent requirements to collect personal information for contact tracing purposes </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/national-relay-service" class=""> National Relay Service </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/posting-photos-and-videos" class=""> Posting photos and videos </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/protecting-customers-personal-information" class=""> Protecting customers' personal information </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/sending-personal-information-overseas" class=""> Sending personal information overseas </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/the-privacy-tax-file-number-rule-2015-and-the-protection-of-tax-file-number-information" class=""> The Privacy (Tax File Number) Rule 2015 and the protection of tax file number information </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/transfer-of-financial-adviser-records" class=""> Transfer of financial adviser records </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/what-is-personal-information" class=""> What is personal information? </a> </li> </ul> </li> <li class="lhs-nav__level-3-link has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches"> Preventing, preparing for and responding to data breaches </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: Preventing, preparing for and responding to data breaches"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response" class=""> Data breach preparation and response </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches/preventing-data-breaches-advice-from-the-australian-cyber-security-centre" class=""> Preventing data breaches: advice from the Australian Cyber Security Centre </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches/guidance-for-entities-in-preparing-for-and-responding-to-cyber-incidents" class=""> Guidance for entities in preparing for and responding to cyber incidents </a> </li> </ul> </li> <li class="lhs-nav__level-3-link has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments"> Privacy impact assessments </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: Privacy impact assessments"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/10-steps-to-undertaking-a-privacy-impact-assessment" class=""> 10 steps to undertaking a privacy impact assessment </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/assessing-privacy-risks-in-changed-working-environments-privacy-impact-assessments" class=""> Assessing privacy risks in changed working environments: privacy impact assessments </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/guide-to-undertaking-privacy-impact-assessments" class=""> Guide to undertaking privacy impact assessments </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/privacy-by-design" class=""> Privacy by design </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/privacy-impact-assessment-tool" class=""> Privacy impact assessment tool </a> </li> </ul> </li> <li class="lhs-nav__level-3-link has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19"> COVID-19 </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: COVID-19"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/coronavirus-covid-19-understanding-your-privacy-obligations-to-your-staff" class=""> Coronavirus (COVID-19): understanding your privacy obligations to your staff </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/coronavirus-covid-19-vaccinations-understanding-your-privacy-obligations-to-your-staff" class=""> Coronavirus (COVID-19) vaccinations: understanding your privacy obligations to your staff </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/covidsafe-reports" class=""> COVIDSafe Reports </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/guidance-for-businesses-collecting-personal-information-for-contract-tracing" class=""> Guidance for businesses collecting personal information for contract tracing </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/national-covid-19-privacy-principles" class=""> National COVID-19 privacy principles </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/privacy-update-on-the-covidsafe-app" class=""> Privacy update on the COVIDSafe app </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/retention-and-deletion-of-personal-information-collected-during-covid-19" class=""> Retention and deletion of personal information collected during COVID-19 </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/covid-19/guidance-for-businesses-collecting-covid-19-vaccination-information" class=""> Guidance for businesses collecting COVID-19 vaccination information </a> </li> </ul> </li> <li class="lhs-nav__level-3-link has-children"> <div class="lhs-nav__level-3-accordion"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance"> More guidance </a> <button class="lhs-nav__level-3-toggle" aria-expanded="false" aria-label="Expand Level 3 submenu: More guidance"> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-plus.svg" class="icon-plus" aria-hidden="true" /> <img src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/icon-minus.svg" class="icon-minus" aria-hidden="true" /> </button> </div> <ul class="lhs-nav__level-4"> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/australian-bushfires-disaster-emergency-declaration-understanding-your-privacy-obligations" class=""> Australian Bushfires Disaster Emergency Declaration: understanding your privacy obligations </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/australian-entities-and-the-european-union-general-data-protection-regulation" class=""> Australian entities and the European Union General Data Protection Regulation </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/emergencies-and-disasters" class=""> Emergencies and disasters </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/guide-to-data-analytics-and-the-australian-privacy-principles" class=""> Guide to data analytics and the Australian Privacy Principles </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/guide-to-developing-an-app-privacy-policy" class=""> Guide to developing an APP privacy policy </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/how-to-develop-an-app-privacy-policy-poster" class=""> How to develop an APP privacy policy (poster) </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/guidelines-for-developing-codes" class=""> Guidelines for developing codes </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/guidelines-for-recognising-external-dispute-resolution-schemes" class=""> Guidelines for recognising external dispute resolution schemes </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/handling-privacy-complaints" class=""> Handling privacy complaints </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/keeping-records-of-disclosures-under-the-telecommunications-act-1997" class=""> Keeping records of disclosures under the Telecommunications Act 1997 </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/mobile-privacy-a-better-practice-guide-for-mobile-app-developers" class=""> Mobile privacy: a better practice guide for mobile app developers </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/privacy-management-framework-enabling-compliance-and-encouraging-good-practice" class=""> Privacy management framework: enabling compliance and encouraging good practice </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/privacy-public-interest-determination-guide" class=""> Privacy public interest determination guide </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/self-assessment-checklist-privacy-obligations-under-the-data-retention-scheme" class=""> Self-assessment checklist: privacy obligations under the Data Retention Scheme </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/telecommunications-service-providers-obligations-arising-under-the-privacy-act-1988-as-a-result-of-part-5-1a-of-the-telecommunications-interception-and-access-act-1979" class=""> Telecommunications service providers' obligations arising under the Privacy Act 1988 as a result of Part 5-1A of the Telecommunications (Interception and Access) Act 1979 </a> </li> <li class="lhs-nav__level-4-link"> <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/privacy-considerations-for-financial-services-entities-receiving-data-from-a-carrier-or-carriage-service-provider-under-the-telecommunications-regulations" class=""> Privacy considerations for financial services entities receiving data from a carrier or carriage service provider </a> </li> </ul> </li> </ul> </div> </div> </div> <div class="middle-wrapper"> <!-- Body start --> <div id="main-content-area" class="page-content"> <div class="toc"> <ul class="toc__list"> <li class="toc__heading"> <h2 class="toc-exclude">On this page</h2> </li> </ul> </div> <section class="banner-grey-newsroom__wrapper"> <div class="banner-grey-newsroom__content"> <h1 class="banner-grey-newsroom__title">Communications with patients</h1> </div> </section> <!--.banner-grey-newsroom__wrapper --> <script> if(document.querySelector('.banner-grey-newsroom__wrapper .banner-grey-newsroom__content')) { document.querySelector('.breadcrumb__wrapper').insertAdjacentElement('afterend',document.querySelector('.banner-grey-newsroom__wrapper .banner-grey-newsroom__content').closest(' .banner-grey-newsroom__wrapper')) } </script> <div class="gov-numbered-paragraphs" id="component_19112"> <div class="table-of-contents ResourcesPage"><div class="row"><div class="main-region col--sm-12 col--md-6 push--md-2 body-content "><div class="small update-date readable"></div><div class="directory-card__tags"></div></div></div><div class="row"><div id="page-content"><p>Publication date: November 2017</p><p>There are a number of different types of communications which health service providers may want to send to patients. These may include, for example, notifications of test results, disease screening reminders, notifications about care plans and practice newsletters.</p><p>The Australian Privacy Principles (APPs) establish a framework that facilitates an open relationship between health service providers and their patients where the provider and patient can reach a shared understanding of how the patient’s health information, including contact details, will be used and disclosed. This ensures that health information is generally only used and disclosed in accordance with a patient’s expectations.</p><p>The OAIC has developed a <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#flowchrt">flowchart</a> that outlines the considerations in sending communications to patients. The flow chart is designed to be read in conjunction with the information in this resource.</p><p>For many communications, a patient’s consent to receiving the communication can usually be implied, which means sending the communication will comply with the <em>Privacy Act 1988</em> (see <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#implied-consent">Implied consent</a>).</p><p>When it is not reasonable to imply the patient’s consent, you will need to consider whether there are other grounds under the Privacy Act that permit the communication to be sent (see <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#communications-without-implied-consent">Communications Without Implied Consent</a>).</p><p>Consent under the Privacy Act can be express or implied and consists of the following four elements:</p><ul><li>the individual is adequately informed before giving consent</li><li>the individual gives consent voluntarily</li><li>the consent is current and specific, and</li><li>the individual has the capacity to understand and communicate their consent.</li></ul><p>Further information on consent can be found in <a href="https://www.oaic.gov.au/_old/privacy/australian-privacy-principles-guidelines/chapter-b-key-concepts">Chapter B of the APP Guidelines</a>.</p><h2 id="implied-consent">Implied consent</h2><p>Implied consent arises where consent may reasonably be inferred in the circumstances from the conduct of the patient and the health service provider. Where there is open communication and information sharing between the provider and the patient, consent issues will usually be addressed during the course of the consultation. If the consultation discussion has provided the individual with an understanding about how their health information may be used, then it may be reasonable for you to rely on implied consent.</p><p>For example, in general practice, demographic and healthcare information is collected to provide both immediate and longitudinal care. Follow-up for continuing care is dependent on a multitude of factors. However, in accordance with accepted clinical guidelines, practices will initiate communications with patients where clinically appropriate. This is implicit in the doctor patient relationship and in accordance with the clinical duty of care.</p><p>In a healthcare setting, a patient may take certain actions that imply their consent to receiving communications from their health service provider. For example, when a parent takes their baby to the GP to get the recommended two month, four month and six month immunisations, it would be reasonable for the GP to imply the parent’s consent to being sent a reminder about the next immunisation due, if the parent does not book an appointment at the recommended time.</p><p>The requirements for demonstrating that it is reasonable to imply consent are often highly dependent on the context in which the health information is collected, used and disclosed. However, you are more readily able to rely on implied consent to send communications to a patient in situations where:</p><ul><li>the patient has previously received and/or discussed with you the particular service addressed in the particular communication</li><li>the patient regularly attends the clinic or health service</li><li>the patient recently attended the clinic or health service</li><li>the patient would reasonably expect you to communicate with them in that way based on prior provider-patient communications.</li></ul><p>You will need to decide, on a case-by-case basis, whether consent can be implied, as consent is highly dependent on the context in which health information is collected, used and disclosed. However, generally it is reasonable to imply the patient’s consent to receiving the following types of communications:</p><ul><li>notification of results, recalls and follow-up after disease screening, blood tests and other health assessments</li><li>reminder to attend the practice to follow up on or remove long acting contraception</li><li>a reminder is sent to a patient to attend a scheduled longer appointment</li><li>sending a letter to an elderly patient on statins for primary prevention to make an appointment to review their medications</li><li>follow-up on treatment the patient is currently receiving, such as an established care plan to assist with quitting smoking, ongoing treatment for a thyroid disorder, or hormone replacement therapy</li><li>communications in relation to an established care plan such as a chronic disease management plan (CDM) plan</li><li>a reminder to patients that an administrative fee may be incurred if they do not cancel and do not present at their scheduled appointment time if this appointment has been previously missed.</li></ul><p class="callout">Example: Chronic Disease Management Plan</p><p class="callout">Geoff has type 2 diabetes. His GP has developed an individualised Chronic Disease Management (CDM) Plan to help plan and coordinate the management and care of Geoff’s condition. As part of the CDM Plan, Geoff’s GP sends him reminders to attend the practice to test his HbA1c levels every 3 months to monitor glycaemic control.</p><p class="callout">Based on Geoff’s agreement to his CDM Plan, it is reasonable for the GP to imply Geoff’s consent to receiving this type of reminder.</p><h2 id="communications-without-implied-consent">Communications without implied consent</h2><p>If you are not confident that it is reasonable to imply a patient’s consent to receiving a particular communication, you will need to consider whether the communication is still permitted under the Privacy Act. The grounds on which the communication may be permitted will depend on whether or not the communication is direct marketing.</p><h3 id="is-the-communication-direct-marketing">Is the communication direct marketing?</h3><p>Direct marketing is where an entity directly promotes goods or services to an individual, using their personal information. It can encompass any communication made by or on behalf of an entity to an individual. The use or disclosure of personal information to direct market is regulated by APP 7.</p><h4>The Spam Act and the Do Not Call Register</h4><p>APP 7 only applies to direct marketing that is not regulated by the <em>Spam Act 2003 </em>and the <em>Do Not Call Register Act 2006</em> (DNCR Act). These Acts contain specific provisions that regulate direct marketing by electronic messaging (e.g. text and email) and telephone numbers that are registered on the Do Not Call Register.</p><p>Visit the <a href="https://www.acma.gov.au/" target="_blank">ACMA website</a> for more detailed information about the DNCR Act and the Spam Act.</p><h4>Express consent</h4><p>Under APP 7, <a href="https://www.oaic.gov.au/_old/privacy/guidance-and-advice/direct-marketing">direct marketing</a> using sensitive information, such as health information, is only permitted with the implied or express consent of the individual. Therefore, if consent cannot be implied for sending a specific communication to a patient, express consent is required.</p><p>Express consent is given explicitly, either orally or in writing. This could include a handwritten signature or an oral statement (such as a verbal agreement). Express consent does not last forever, and can be withdrawn at any time.</p><p>The best evidence of express consent is given when a person has to do something deliberate to indicate their consent, such as writing a letter, ticking a consent box or signing a statement indicating their consent. A patient may also give express consent face-to-face during a consultation with their health service provider.</p><p>Generally, express consent is needed for communications that are not targeted to an individual patient’s specific healthcare and which are sent in a more indiscriminate manner to a practice’s entire database. These communications might include, for example a letter sent to an entire practice’s database about the availability of the influenza vaccination, or a letter sent to an entire practice’s database to promote the addition of a physiotherapist to a multidisciplinary practice.</p><h3>Communications that are not direct marketing</h3><p>If the communication is not direct marketing, APP 6 will apply. Under APP 6, unless an exception applies, you can only use or disclose health information to send a particular communication if sending that communication is part of the primary purpose for which the information was collected. It is unlikely that a situation would arise where consent cannot be implied and yet the sending of a communication is for the primary purpose for which the patient’s contact details were collected. Therefore, if you are not confident that it is reasonable to imply your patient’s consent to receiving a communication, then it is unlikely that it is the primary purpose for which you collected the information and you should instead consider whether an exception applies.</p><p>Health information can be used for a secondary purpose if an exception applies. Exceptions that may be relevant in this context include where:</p><ul><li>the patient has expressly consented to a secondary use or disclosure<a id="ftnref1" href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#ftn1">[1]</a> (discussed below)</li><li>the patient would reasonably expect the health service provider to use or disclose their personal information for the secondary purpose and that purpose is directly related to the primary purpose (discussed below)</li><li>the use or disclosure is required or authorised by or under an Australian law or a court/tribunal order.</li></ul><p>The full range of exceptions is discussed in detail in the <a href="https://www.oaic.gov.au/_old/privacy/australian-privacy-principles-guidelines">APP guidelines</a>.</p><h4>Express consent to a secondary use or disclosure</h4><p>If a health service provider collects information for the primary purpose of providing healthcare to a patient, they will generally be able to use that information for the secondary purpose of sending out communications, if the patient has expressly consented to their information being used for that secondary purpose.</p><div><p class="callout">Example: Filling out a consent form</p><p class="callout">Anne attends a GP clinic for the first time and is asked to fill out a form with her personal details. The form also includes a checklist of different types of communications that the GP clinic sends out to patients that have indicated they would like to receive those specific communications.</p><p class="callout">Anne puts a tick next to some of the communications she would like to receive, and a cross next to the communications that she does not want to receive. The GP clinic would be authorised under APP 6 to send Anne the specific communications she has indicated she would like to receive. This is because, by ticking the checkbox, Anne has expressly consented to her contact details being used for the secondary purpose of sending her those specific communications.</p></div><h4>Reasonable expectation/directly related purpose</h4><p>Health information, including contact details, can be used for a secondary purpose if the patient would reasonably expect the health service provider to use or disclose the information for the secondary purpose, and the secondary purpose is directly related to the primary purpose of collection. This creates a two-limb test which focuses both on the reasonable expectations of the patient and the relationship between the primary and secondary purpose.</p><div><p class="callout">Example: Government screening program</p><p class="callout">Winston regularly attends his local GP clinic. His health information, including his contact details, have been collected by the clinic for the purpose of providing general practice services to diagnose and treat the conditions which Winston has presented with.</p><p class="callout">When Winston turned 50 years old he became eligible to participate in the Australian government’s National Bowel Cancer Screening Program. As a result, Winston’s GP initiated a discussion with him on preventative health recommendations related to bowel cancer. His GP then sent him a letter to encourage him to participate in the screening program and to use the free screening kit which he would receive via mail from the Department of Health. The letter’s sole purpose was to explain the screening program and to encourage Winston to participate.</p><p class="callout">This type of communication is allowed under APP 6 because Winston would reasonably expect his GP to use his contact details for the directly related secondary purpose of encouraging him to participate in the fully-funded government program for bowel cancer screening.</p></div><h2 id="appendix-a-flowchart"><a name="flowchrt"></a>Flowchart</h2><p>The flowchart below summarises the issues that a health service provider should consider before sending communications to patients.</p><p>Some of the key health privacy terms that are used are explained in the <a href="https://www.oaic.gov.au/_old/privacy/australian-privacy-principles-guidelines">APP Guidelines</a>.</p><p><img title="" src="https://www.oaic.gov.au/__data/assets/file/0010/1342/app6-flowchart.svg" alt="Flowchart image. Link to long text description follows." width="960" height="961" /></p><p><a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#long-text-description">View long text description of Flowchart</a></p><h2 id="long-text-description">Long text description of flowchart</h2><h3 id="q1">Question 1: Can you imply consent for the communication to be sent?</h3><ul><li>Yes: Sending the communication is acceptable under the APPs, as long as the other APPs are complied with</li><li>No: Go to <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#q2">Question 2</a></li></ul><h3 id="q2">Question 2: Is it a form of direct marketing that is covered by APP 7?</h3><ul><li>Yes: Go to <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#q3">Question 3</a></li><li>No: Go to <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#q4">Question 4</a></li></ul><h3 id="q3">Question 3: Do you have the patient’s express consent to send the communication?</h3><ul><li>Yes: Sending the communication is acceptable under the APPs, as long as the other APPs are complied with</li><li>No: Sending the communication would breach the APPs</li></ul><h3 id="q4">Question 4: Does an APP 6 exception apply?</h3><p>Further explanation below.</p><ul><li>Yes: Sending the communication is acceptable under the APPs, as long as the other APPs are complied with</li><li>No: Sending the communication would breach the APPs</li></ul><h4>When does an APP 6 exception apply?</h4><ul><li>the patient has expressly consented to a secondary use or disclosure</li><li>the patient would reasonably expect the health service provider to use or disclose their personal information for the secondary purpose and that purpose is directly related to the primary purpose</li><li>the use or disclosure is required or authorised by or under an Australian law or a court/tribunal order</li></ul><p><a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#appendix-a-flowchart">Back to Flowchart</a></p></div><div class="sidebar col--md-3 last" id="content-sidebar" role="complementary" aria-label="Sidebar"></div></div></div> </div> <div class="footnotes"><h2 id="footnotes">Footnote</h2><p><a id="ftn1" href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients#ftnref1">[1]</a> Implied consent is also an exception to APP 6 but is not mentioned in this list given this section of the guidance relates to health service providers sending communications where it is not reasonable for them to imply consent.</p></div> <div id="component_19008"> </div> </div> <!-- Body end --> </div> </div> <!-- Social share --> <div class="feedback"> <form id="form_email_240614" enctype="multipart/form-data" action="https://www.oaic.gov.au/_design/includes/feedback-form" method="post" ><input type="hidden" name="SQ_FORM_240614_PAGE" value="1" class="sq-form-field" id="SQ_FORM_240614_PAGE" /><input type="hidden" name="form_email_240614_referral_url" value="" /><!--noindex--> <input type="hidden" name="q240616:q4" value="19006"> <input type="hidden" name="q240616:q3" value="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients"> <input type="hidden" name="form_email_240614_submit" value="Submit" id="form_email_240614_submit"> <div class="feedback__section-1"> <fieldset class="feedback__fieldset"> <legend class="feedback__title">Did you find this helpful?</legend> <div class="feedback__radios-wrapper"> <div class="feedback__radio"> <input class="visuallyhidden" type="radio" name="q240616:q2" id="q240616_q2_0" value="0"> <img class="feedback__radio-icon" src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/thumbsup.svg" alt=""/> <label class="feedback__radio-label" for="q240616_q2_0">Yes</label> </div> <div class="feedback__radio"> <input class="visuallyhidden" type="radio" name="q240616:q2" id="q240616_q2_1" value="1"> <img class="feedback__radio-icon" src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/thumbsdown.svg" alt=""/> <label class="feedback__radio-label" for="q240616_q2_1">No</label> </div> </div> </fieldset> <div class="feedback__radio-response" id="yes"> <img class="feedback__radio-icon" src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/thumbsup.svg" alt=""/> <span>We'd love to hear more!</span> </div> <div class="feedback__radio-response" id="no"> <img class="feedback__radio-icon" src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/mysource_files/thumbsdown.svg" alt=""/> <span>Please tell us more</span> </div> </div> <div class="feedback__section-2"> <div class="feedback__section-2-content"> <span class="feedback__title">Rate your experience</span> <p>We'd love to hear more about your rating</p> <div class="feedback__textarea-group"> <label class="feedback__textarea-label" for="q240633_q1"><label class="sq-form-question-title" for="q240633_q1">What did you come here to do?</label></label> <textarea class="feedback__textarea-input" name="q240633:q1" id="q240633_q1" placeholder="Leave your feedback here"></textarea> </div> <div class="feedback__textarea-group"> <label class="feedback__textarea-label" for="q240633_q2"><label class="sq-form-question-title" for="q240633_q2">How can we improve this information?</label></label> <textarea class="feedback__textarea-input" name="q240633:q2" id="q240633_q2" placeholder="Leave your feedback here"></textarea> </div> <div class="feedback__recaptcha"> <script src="https://www.google.com/recaptcha/api.js" async defer></script> <div class="g-recaptcha" data-theme="light" data-size="normal" data-sitekey="6LcuGgUqAAAAAE0QfPrz025qaXiUh0HhlrNuHTWk" data-callback="feedbackGrepCallback" data-expired-callback="feedbackGrepExpiredCallback" ></div> </div> <div class="feedback__submit"> <input type="submit" name="form_email_240614_submit" value="Submit feedback" class="sq-form-submit" id="form_email_240614_submit" /> </div> <button type="button" tabindex="0" class="feedback__close-modal">⨯</button> </div> </div> <!--endnoindex--></form> <!--noindex--> <div class="feedback__share"> <div class="feedback__title">Share</div> <div class="feedback__share-links"> <a href="https://www.facebook.com/share.php?u=https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients" class="feedback__social-link"> <svg width="10" height="18" viewBox="0 0 10 18" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M9.17485 10.0485L9.68366 6.81553H6.50063V4.71845C6.50063 3.83376 6.94445 2.97087 8.37013 2.97087H9.81818V0.218447C9.81818 0.218447 8.5046 0 7.24931 0C4.62669 0 2.91409 1.54877 2.91409 4.35146V6.81553H0V10.0485H2.91409V17.8646C3.49913 17.9541 4.09765 18 4.70736 18C5.31707 18 5.91559 17.9541 6.50063 17.8646V10.0485H9.17485Z" fill="currentColor"/></svg> Facebook </a> <a href="https://twitter.com/intent/tweet?url=https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients" class="feedback__social-link"> <svg width="19" height="15" viewBox="0 0 1200 1227" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M714.163 519.284 1160.89 0h-105.86L667.137 450.887 357.328 0H0l468.492 681.821L0 1226.37h105.866l409.625-476.152 327.181 476.152H1200L714.137 519.284h.026ZM569.165 687.828l-47.468-67.894-377.686-540.24h162.604l304.797 435.991 47.468 67.894 396.2 566.721H892.476L569.165 687.854v-.026Z" fill="currentColor"></path></svg> Twitter </a> <a href="https://www.linkedin.com/sharing/share-offsite?url=https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/communications-with-patients" class="feedback__social-link"> <svg width="16" height="18" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M3.60001 16H0.199997V5.3H3.60001V16ZM1.9 3.8C0.800002 3.8 0 3 0 1.9C0 0.8 0.900002 0 1.9 0C3 0 3.8 0.8 3.8 1.9C3.8 3 3 3.8 1.9 3.8ZM16 16H12.6V10.2C12.6 8.5 11.9 8 10.9 8C9.89999 8 8.89999 8.8 8.89999 10.3V16H5.5V5.3H8.7V6.8C9 6.1 10.2 5 11.9 5C13.8 5 15.8 6.1 15.8 9.4V16H16Z" fill="currentColor"/></svg> Linkedin </a> </div> </div> <!--endnoindex--> </div> </main> <!-- Footer start --> <!--noindex--> <div class="footer"> <div class="footer__upper"> <div class="footer__upper--wrapper"> <div class="back-to-top__wrapper"> <button class="back-to-top" aria-label="Back to top"> <svg class="back-to-top__icon" aria-hidden="true" focusable="false" width="28" height="47" viewBox="0 0 28 47" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M6 8.82715L14 1.00106" stroke="white" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/><path d="M22 8.82715L14 1.00106" stroke="white" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/><path d="M14 21L14 1" stroke="white" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/><path d="M2.94 41V33.41H0.36V31.25H8.1V33.41H5.52V41H2.94ZM13.2027 41.18C12.5227 41.18 11.9027 41.065 11.3427 40.835C10.7927 40.605 10.3177 40.275 9.9177 39.845C9.5277 39.405 9.2227 38.87 9.0027 38.24C8.7827 37.6 8.6727 36.88 8.6727 36.08C8.6727 35.28 8.7827 34.57 9.0027 33.95C9.2227 33.32 9.5277 32.795 9.9177 32.375C10.3177 31.945 10.7927 31.62 11.3427 31.4C11.9027 31.18 12.5227 31.07 13.2027 31.07C13.8727 31.07 14.4877 31.18 15.0477 31.4C15.6077 31.62 16.0827 31.945 16.4727 32.375C16.8727 32.805 17.1827 33.33 17.4027 33.95C17.6227 34.57 17.7327 35.28 17.7327 36.08C17.7327 36.88 17.6227 37.6 17.4027 38.24C17.1827 38.87 16.8727 39.405 16.4727 39.845C16.0827 40.275 15.6077 40.605 15.0477 40.835C14.4877 41.065 13.8727 41.18 13.2027 41.18ZM13.2027 38.96C13.7927 38.96 14.2527 38.705 14.5827 38.195C14.9227 37.675 15.0927 36.97 15.0927 36.08C15.0927 35.19 14.9227 34.505 14.5827 34.025C14.2527 33.535 13.7927 33.29 13.2027 33.29C12.6127 33.29 12.1477 33.535 11.8077 34.025C11.4777 34.505 11.3127 35.19 11.3127 36.08C11.3127 36.97 11.4777 37.675 11.8077 38.195C12.1477 38.705 12.6127 38.96 13.2027 38.96ZM19.4784 41V31.25H23.0484C23.5784 31.25 24.0834 31.305 24.5634 31.415C25.0434 31.515 25.4634 31.695 25.8234 31.955C26.1834 32.205 26.4684 32.54 26.6784 32.96C26.8984 33.37 27.0084 33.88 27.0084 34.49C27.0084 35.09 26.8984 35.605 26.6784 36.035C26.4684 36.465 26.1834 36.82 25.8234 37.1C25.4634 37.37 25.0484 37.575 24.5784 37.715C24.1084 37.845 23.6184 37.91 23.1084 37.91H22.0584V41H19.4784ZM22.0584 35.87H22.9884C23.4984 35.87 23.8734 35.75 24.1134 35.51C24.3634 35.27 24.4884 34.93 24.4884 34.49C24.4884 34.05 24.3534 33.74 24.0834 33.56C23.8134 33.38 23.4284 33.29 22.9284 33.29H22.0584V35.87Z" fill="white"/></svg> </button> </div> <div class="footer__logo-group"> <img src="https://www.oaic.gov.au/__data/assets/file/0020/12962/logo.svg" class="logo--main" alt="OAIC logo"> <a href="https://www.oaic.gov.au/about-the-OAIC/access-our-information/freedom-of-information-requests-to-the-oaic" class="footer-logo" aria-label="OAIC sub-logo"> <img src="https://www.oaic.gov.au/__data/assets/file/0021/12963/logo2.svg" class="logo--sub" alt="OAIC sub logo"> </a> <a href="https://www.oaic.gov.au/about-the-OAIC/access-our-information/our-information-publication-scheme" class="footer-logo" aria-label="OAIC Information Publication Scheme"> <img src="https://www.oaic.gov.au/__data/assets/image/0026/91385/ips_white_text.png" class="logo--sub" width="120px" alt="Information Publication Scheme"> </a> </div><div class="footer__link-group"> <ul class="link-list"> <li><a href="https://www.oaic.gov.au/sitemap" class="footer-link" aria-label="Site map">Site map</a></li><li><a href="https://www.oaic.gov.au/about-the-OAIC/copyright" class="footer-link" aria-label="Copyright">Copyright</a></li><li><a href="https://www.oaic.gov.au/about-the-OAIC/terms-and-conditions" class="footer-link" aria-label="Terms and conditions">Terms and conditions</a></li><li><a href="https://www.oaic.gov.au/about-the-OAIC/our-corporate-information/plans-policies-and-procedures/privacy-policy" class="footer-link" aria-label="Privacy policy">Privacy policy</a></li><li><a href="https://www.oaic.gov.au/about-the-OAIC/accessibility" class="footer-link" aria-label="Accessibility">Accessibility</a></li> </ul> </div> </div> </div> <div class="footer__lower"> <div class="footer__util-group"> <div class="footer__contact"> <a href="https://www.oaic.gov.au/contact-us" class="contact--link" aria-label="Contact us">Contact us</a> <a href="tel:1300 363 992" class="contact--phone" aria-label="Call 1300 363 992">1300 363 992</a> <p class="contact--hours">Monday to Thursday 10 am to 4 pm (AEST/AEDT)</p> </div> <div id="footer_language_listing_13517"> <div class="footer__language-list"> <label for="languages">Translations</label> <select name="languages" id="languages" onChange="if (this.value.startsWith('https://www.oaic.gov.au')) window.location = this.value;"> <option value="">Please select…</option> <option lang="ar" value="https://www.oaic.gov.au/engage-with-us/translations/arabic">العربية</option><option lang="zh" value="https://www.oaic.gov.au/engage-with-us/translations/chinese">中文</option><option lang="el" value="https://www.oaic.gov.au/engage-with-us/translations/greek">ελληνικός</option><option lang="it" value="https://www.oaic.gov.au/engage-with-us/translations/italian">Italiano</option><option lang="es" value="https://www.oaic.gov.au/engage-with-us/translations/spanish">Español</option><option lang="th" value="https://www.oaic.gov.au/engage-with-us/translations/thai">ไทย</option><option lang="vi" value="https://www.oaic.gov.au/engage-with-us/translations/vietnamese">Tiếng Việt</option><option lang="pa-IN" value="https://www.oaic.gov.au/engage-with-us/translations/about-the-oaic-punjabi">ਪੰਜਾਬੀ</option><option lang="" value="https://www.oaic.gov.au/engage-with-us/translations/about-the-oaic-karen"></option><option lang="EN" value="https://www.oaic.gov.au/engage-with-us/translations/easy-english">Easy English</option> </select> </div> </div> <div class="footer__social"> <p class="social--header">Follow us</p> <ul class="social-list"> <li> <a href="https://www.facebook.com/OAICgov" class="social-link social-link--facebook" aria-label="OAIC on Facebook"> <img class="social-icon" src="https://www.oaic.gov.au/__data/assets/file/0025/12958/facebook.svg" alt="OAIC on Facebook"> </a> </li> <li> <a href="https://twitter.com/OAICgov" class="social-link social-link--twitter" aria-label="OAIC on Twitter" > <img class="social-icon" src="https://www.oaic.gov.au/__data/assets/file/0026/12959/x-logo.svg" alt="OAIC on Twitter"> </a> </li> <li> <a href="https://www.youtube.com/user/oaicgov" class="social-link social-link--youtube" aria-label="OAIC on Youtube" > <img class="social-icon" src="https://www.oaic.gov.au/__data/assets/file/0018/12960/youtube.svg" alt="OAIC on Youtube"> </a> </li> <li> <a href="https://au.linkedin.com/company/office-of-the-australian-information-commissioner" class="social-link social-link--linkedin" aria-label="OAIC on Linkedin"> <img class="social-icon" src="https://www.oaic.gov.au/__data/assets/file/0019/12961/linkedin.svg" alt="OAIC on Linkedin"> </a> </li> <li> <a href="https://www.instagram.com/oaicgov/" class="social-link social-link--Instagram" aria-label="OAIC on Instagram" > <img class="social-icon" src="https://www.oaic.gov.au/__data/assets/file/0023/91364/Instagram_Glyph_White.svg" alt="OAIC on Instagram"> </a> </li> </ul> </div> </div> <div class="footer__content-group"> <p class="footer__content-header">Acknowledgement of Country</p> <p class="footer__content-text">The OAIC acknowledges Traditional Custodians of Country across Australia and their continuing connection to land, waters and communities. We pay our respect to First Nations people, cultures and Elders past and present.</p> <p class="footer__content-copyright">© Commonwealth of Australia</p> </div> </div> </div><!-- /.footer --> <!--endnoindex--> <!-- Footer end --> </div> <!-- Footer JS start --> <!--noindex--> <div id="footer_js" style="display: none !important;"> <script src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/js/runtime.js?h=06ed308"></script> <script src="https://www.oaic.gov.au/__data/assets/git_bridge/0012/12063/js/main.js?h=06ed308"></script> <script src="https://www.oaic.gov.au/__data/assets/js_file/0025/242791/custom.js"></script> <script> var lhsWrapper = document.querySelector('.lhs-wrapper'); if(lhsWrapper) { lhsWrapper.innerHTML.trim() === '' ? lhsWrapper.style.display='none' : ''; } //Readpeaker function readSpeaker() { var readButtonContent = ` <div id="readspeaker_button1" class="rs_skip rsbtn rs_preserve"> <a rel="nofollow" class="rsbtn_play" accesskey="L" title="Listen to this page using ReadSpeaker webReader" href="//app-oc.readspeaker.com/cgi-bin/rsent?customerid=9755&lang=en_au&readclass=page-content&url=https%3A%2F%2Fwww.oaic.gov.au%2Fprivacy%2Fprivacy-guidance-for-organisations-and-government-agencies%2Fhealth-service-providers%2Fcommunications-with-patients"> <span class="rsbtn_left rsimg rspart"><span class="rsbtn_text"><span>Listen</span></span></span> <span class="rsbtn_right rsimg rsplay rspart"></span> </a> </div>`; var readButtonSearch = ` <div id="readspeaker_button2" class="rs_skip rsbtn rs_preserve"> <a rel="nofollow" class="rsbtn_play" accesskey="L" title="Listen to this page using ReadSpeaker webReader" href="//app-oc.readspeaker.com/cgi-bin/rsent?customerid=9755&lang=en_au&readclass=search-content&url=https%3A%2F%2Fwww.oaic.gov.au%2Fprivacy%2Fprivacy-guidance-for-organisations-and-government-agencies%2Fhealth-service-providers%2Fcommunications-with-patients"> <span class="rsbtn_left rsimg rspart"><span class="rsbtn_text"><span>Listen</span></span></span> <span class="rsbtn_right rsimg rsplay rspart"></span> </a> </div>`; //for content pages var pageContent = document.querySelector('.page-content'); //for search pages var pageSearch = document.querySelector('.search-content'); if(pageContent) pageContent.insertAdjacentHTML('afterbegin', readButtonContent); if(pageSearch) pageSearch.insertAdjacentHTML('afterbegin', readButtonSearch); } readSpeaker(); </script> <script> function feedbackGrepCallback(response) { if (response.length > 0) { document.querySelector(".feedback__submit input").disabled = false } } function feedbackGrepExpiredCallback(response) { if (!response) { document.querySelector(".feedback__submit input").disabled = true } } </script> </div> <style> .page-content section.banner-grey-newsroom__wrapper, .page-content section.landing-page { display: none; } </style> <!--endnoindex--> <!-- Footer JS end --> </body> </html>