Privacy & patient confidentiality Policy
AirMed is committed to protecting the privacy, dignity and confidentiality of our patients and to maintaining the security of the personal and health information entrusted to us.
In providing aeromedical and patient transport services, AirMed necessarily collects and handles personal and health information relating to patients. We recognise that this information is highly sensitive and that patients, their families, healthcare providers and our contracting partners expect it to be treated with the highest level of confidentiality.
AirMed handles personal information in accordance with applicable privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where applicable to the services we provide in New South Wales, AirMed also handles health information having regard to the Health Records and Information Privacy Act 2002 (NSW) and the Health Privacy Principles (HPPs).
These requirements regulate the collection, use, disclosure, storage, security, access, correction and disposal of personal and health information.
1. Scope
This policy applies to all AirMed employees, officers, healthcare professionals, Patient Transport Officers, contractors, consultants, agency personnel and other persons engaged by AirMed who may have access to personal or health information in the course of performing their duties.
All personnel are expected to maintain strict confidentiality in relation to patient information and must only access, use or disclose information where this is necessary for the proper performance of their duties or otherwise authorised or required by law.
2. Personal and Health Information
Personal information includes information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Health information is a particularly sensitive form of personal information and may include information concerning an individual's physical or mental health, disability, medical history, medications, treatment, healthcare requirements or other information collected in connection with the provision of a health service.
For AirMed, this may include information such as a patient's:
- name, address, date of birth and contact information;
- Medicare, hospital or other patient identifiers;
- medical history and current clinical condition;
- medications, allergies and treatment requirements;
- mobility, accessibility and transport requirements;
- referring and receiving hospital or healthcare facility;
- treating doctors, nurses and other healthcare professionals;
- clinical observations and patient care records;
- transport, flight, ambulance and transfer details;
- next of kin, guardian or emergency contact information; and
- other information reasonably required to safely coordinate and provide patient transport or aeromedical services.
3. Collection of Personal and Health Information
AirMed collects personal and health information where it is reasonably necessary to provide, coordinate, manage or support our aeromedical and patient transport services, or where collection is otherwise permitted or required by law.
Information may be provided directly by a patient or their representative, or received from organisations and individuals involved in arranging or providing the patient's care, including NSW Health, HealthShare NSW, Local Health Districts, hospitals, healthcare facilities, medical practitioners, nurses, ambulance providers, transport providers and other healthcare professionals.
Where practicable, AirMed will only collect the information reasonably required to safely and effectively perform the relevant service.
4. How AirMed Collects and Holds Information
Personal and health information may be collected through patient referrals, booking and transport requests, clinical handovers, telephone calls, email, secure electronic systems, patient care records, healthcare providers, hospitals and other organisations involved in the patient's treatment or transport.
Information may be held electronically or in paper records and may form part of operational, transport, clinical, financial or administrative records.
AirMed takes reasonable steps to protect personal and health information from misuse, interference, loss, unauthorised access, modification or disclosure.
Access to patient information is restricted to authorised personnel who require that information for a legitimate operational, clinical, administrative or legal purpose.
5. Use of Personal and Health Information
AirMed will generally use patient information for the purpose for which it was collected and for purposes directly related to the provision and management of healthcare and patient transport services.
This may include coordinating patient transfers; assessing transport and clinical requirements; planning flights, road transport and other logistics; providing care during transport; communicating with referring and receiving healthcare providers; maintaining clinical and transport records; quality and safety management; incident investigation; billing and contract administration; and meeting regulatory, contractual and legal obligations.
Patient information must not be accessed out of curiosity or for any purpose unrelated to an individual's duties.
6. Disclosure and Sharing of Patient Information
AirMed recognises that appropriate sharing of health information is often necessary to provide safe and effective continuity of care.
Where permitted, AirMed may disclose relevant patient information to healthcare professionals and organisations or individuals involved in the patient's care or transport, including referring and receiving hospitals, medical practitioners, nurses, ambulance services, NSW Health entities, HealthShare NSW, ground transport personel and other healthcare or transport providers.
Only information reasonably necessary for the relevant purpose should be disclosed.
AirMed may also disclose information where the patient has consented or where disclosure is otherwise authorised or required by law.
6.1 Patient Confidentiality
Patient confidentiality is a fundamental obligation of all AirMed personnel.
Information concerning a patient's identity, condition, treatment, transport or circumstances must not be discussed, accessed, photographed, copied, transmitted or disclosed except where necessary for the performance of authorised duties or where otherwise permitted by law.
Patient information must not be discussed in public areas or with family members, friends, colleagues or other persons who are not authorised to receive the information.
The obligation to maintain patient confidentiality continues after an employee, contractor or other person ceases working with AirMed.
6.2 Third-Party Service Providers
AirMed may engage third-party providers to support the delivery of its services, including technology providers, healthcare providers, transport providers and professional advisers.
Where those providers require access to personal or health information, AirMed will take reasonable steps to ensure appropriate confidentiality, privacy and information-security arrangements are in place.
6.3 Cross-Border Disclosure
AirMed will take reasonable steps to ensure that any transfer or disclosure of personal or health information outside Australia, or where applicable outside New South Wales, complies with relevant privacy legislation and appropriate security and confidentiality safeguards.
AirMed will not routinely disclose patient health information overseas unless this is necessary for the provision or administration of services, permitted by law, or appropriately authorised.
7. Access to Personal and Health Information
Individuals may request access to personal and health information held about them by AirMed.
Requests should be made in writing to AirMed's Quality Manager and should provide sufficient information to identify the individual and the records being requested.
AirMed will respond within a reasonable period and may require appropriate proof of identity before providing access.
In certain circumstances access may be limited or refused where permitted or required by law. Where appropriate, AirMed will explain the reason for the decision and the available complaint or review mechanisms.
8. Correction of Personal and Health Information
AirMed takes reasonable steps to ensure that personal and health information is accurate, complete, relevant and up to date.
An individual who believes information held by AirMed is inaccurate, incomplete, out of date or misleading may request that the information be corrected.
Where a clinical record cannot appropriately be altered, AirMed may add a notation or supplementary information to the record in accordance with applicable legal and clinical record-keeping requirements.
9. Security and Integrity of Patient Information
AirMed takes reasonable administrative, physical and technological measures to protect personal and health information against loss, misuse, interference, unauthorised access, modification or disclosure.
These measures may include access controls, passwords and authentication, secure electronic systems, physical security, confidentiality requirements, staff training, system monitoring and appropriate disposal of records.
Personnel must only access patient records where access is required for the performance of their duties.
Maintaining the confidentiality of patient information is everyone's responsibility.
10. Data Breaches and Notifiable Data Breaches
A data breach occurs where personal or health information is lost, accessed or disclosed without authorisation.
Examples may include lost or stolen devices or records, information being sent to an incorrect recipient, unauthorised access to patient records, cyber security incidents, inappropriate disclosure of patient information or the loss of documents containing patient information.
Any actual or suspected privacy or data breach must be reported immediately to AirMed's Quality Manager and in AirMed's Safety Management System.
AirMed will promptly investigate and assess suspected breaches, take reasonable steps to contain and remediate them and determine whether notification is required.
Where a breach constitutes an eligible data breach under the Notifiable Data Breaches scheme, AirMed will notify affected individuals and the Office of the Australian Information Commissioner as required by law. The NDB scheme applies to private-sector health service providers covered by the Privacy Act and requires notification where an eligible breach is likely to result in serious harm.
11. Privacy Complaints and Enquiries
AirMed takes concerns about patient privacy and confidentiality seriously.
An individual who has a question, concern or complaint regarding the way AirMed has collected, accessed, used, disclosed, stored or otherwise handled their personal or health information should contact AirMed's Quality Manager.
AirMed will investigate privacy complaints and respond within a reasonable period.
Where a person is not satisfied with AirMed's response, they may have the right to raise their concerns with an appropriate external privacy or regulatory authority, including the Office of the Australian Information Commissioner or, where applicable, the NSW Information and Privacy Commission.
12. Responsibilities of AirMed Personnel
All AirMed personnel who have access to personal or health information are responsible for protecting that information.
Personnel must comply with this policy, AirMed's confidentiality and information-security requirements and all applicable privacy obligations. Unauthorised access, use or disclosure of patient information may constitute a serious breach of AirMed policy and may result in disciplinary action, termination of employment or engagement and, where applicable, regulatory or legal consequences.
13. Policy Review
This policy will be reviewed periodically and updated where necessary to reflect changes to AirMed's operations, contractual obligations, technology, regulatory requirements and applicable privacy legislation.
