2 HOW RAMSAY HANDLES YOUR PERSONAL INFORMATION
2.1 Ramsay's Legal Obligations
2.2 Terms used
2.3 Who does Ramsay collect information from?
2.3.2 Other individuals
2.3.3 Anonymity and pseudonymity
2.4 What information does Ramsay collect?
2.4.2 Other individuals
2.5 How does Ramsay store your information?
2.5.2 Other individuals
2.6 How does Ramsay use your information?
Related secondary purposes include:
Patient specific examples:
(a) Use among health professionals to provide your treatment
(b) Assessment for provision of health care services
(c) Your local doctor
(d) Other health service providers
(e) Students and trainees
(f) Relatives, guardian, close friends or legal representative
(g) Other Ramsay entities
(h) Ramsay Pharmacy and other Pharmacy service providers
(i) Contracted services
(j) Sale or transfer of a Ramsay facility to a third party
(k) MyHealth Record
(l) Maternity services
(m) Invitation to participate in clinical trials
(n) Multi-disciplinary team meetings
(o) Ramsay Clinics
(p) Other common uses
(q) Other uses with your consent
Other non-patient specific examples:
(r) Accessing Ramsay facilities and associated services provided at Ramsay facilities
(s) Camera surveillance systems
(t) Contractors under agreement
(u) Application for accreditation by health professionals
(v) Job applications
(w) Students / Trainees
(x) Education and community engagement
(y) Clinical research
(z) Other common uses
(aa) Other uses with your consent
(bb) Online portals and forums
(cc) Workers’ Compensation
2.7 Access to and correction of your personal information
2.8 Data quality
2.9 Data security
2.10 Cross border disclosure
4 HOW RAMSAY HANDLES YOUR PERSONAL INFORMATION WHEN YOU VISIT OUR WEBSITE
4.3 Links to third party websites
4.4 Use and disclosure
4.5 Data quality
4.6 Data security
4.7 Access and correction
Ramsay Health Care Australia (Ramsay) is committed to ensuring the privacy and confidentiality of your personal information.
Ramsay must comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and other privacy laws that govern how private sector health service providers like Ramsay handle your personal information (including but not limited to patient health information).
If you require more detailed information about Ramsay's information handling practices, then you will need to read this document.
"Personal information" as it is defined in the Privacy Act 1988 (Cth) means information or an opinion about an identified individual, or an individual who is reasonably identifiable:
Personal information also includes 'sensitive information' which is information such as your race, religion, political opinions or sexual preferences, biometric information used for biometric verification or identification, and biometric templates, and health information. Information which is 'sensitive information' attracts a higher privacy standard under the Privacy Act 1988 (Cth) and is subject to additional mechanisms for your protection.
“Health information" as it is defined in the Privacy Act 1988 (Cth) is a particular subset of ‘personal information’ and means information or an opinion about:
“Primary purpose” means the specific function or activity for which the information is collected. Any use or disclosure of the personal information for another purpose is known as the “secondary purpose”.
“Ramsay facility/ies” means inpatient and outpatient services operated by Ramsay.
In order to provide you with the health care services that you have requested (including assessment for or information in relation to the provision of health care services), Ramsay will need to collect and use your personal information. If you provide incomplete or inaccurate information to us or withhold personal health information from us we may not be able to provide you with the services you are seeking.
In order to enable Ramsay to engage with you for the relevant primary purpose, Ramsay may need to collect and use your personal information. If you provide incomplete or inaccurate information to us or withhold personal information from us we may not be able to engage with you as required to meet that primary purpose.
You have the option of dealing with Ramsay anonymously or by using a pseudonym; however, we note that this may limit the services that we can provide to you if it is impracticable for us to deal with you in such an unidentified manner.
We collect personal information from you that is reasonably necessary to provide you with health care services and for administrative and internal business purposes related to your attendance at a Ramsay facility.
Often this may include collecting information about your health history, family history, your ethnic background or your current lifestyle to assist the health care team in diagnosing and treating your condition.
We will usually collect your health information directly from you. Sometimes, we may need to collect information about you from a third party (such as a relative or another health service provider). We will only do this if you have consented for us to collect your information in this way or where it is not reasonable or practical for us to collect this information directly from you, such as where your health may be at risk and we need your personal information to provide you with emergency medical treatment.
In some circumstances, Ramsay may collect information from an electronic Government record repository such as the Australian Immunisation Register or MyHealth Record (collectively ‘Government Record’). Ramsay may access personal information stored in your Government Record in accordance with the access controls that you have set within each system (as applicable). If you do not want Ramsay to access personal information stored in your Government Record, it is your responsibility to modify the access controls as required. Ramsay will only access information stored in the Government Record to the extent required for your treatment by Ramsay.
We collect personal information from you that is reasonably necessary to engage with you for the primary purpose, including the provision of services by Ramsay, for Ramsay’s functions or activities and for administrative and internal business purposes related to your dealings with Ramsay.
In relation to individuals employed or engaged by Ramsay, individuals providing services to Ramsay or Students, this may include sensitive information including criminal record or working with children checks, health information and biometric data.
We will usually collect your personal information directly from you. Sometimes we may need to collect information about you from a third party; however, we will only do this where it is not reasonable or practical for us to collect this information directly from you. Sensitive information will not be collected without your consent unless authorised by law.
Storage of personal information may be in physical (paper) form and may also include through an electronic medical record system or storage of personal information (including clinical images taken for diagnostic or treatment purposes) on some diagnostic equipment where you have undergone a diagnostic procedure using such equipment in a Ramsay facility. As some Ramsay facilities utilise shared resources, your patient medical records may be stored offsite with a third party provider or at another Ramsay facility.
Personal information may be stored in various forms including electronically via various data management software or systems in accordance with usual business practices, and depending on the primary purpose of your engagement with Ramsay.
Ramsay only uses your personal information for the primary purpose for which you have given the information to us, unless one of the following applies:
Ramsay may use or disclose your personal information as specified above via electronic processes, where available or relevant.
The following is a list of examples of related secondary purposes for which Ramsay may use your personal information, but is not an exhaustive list.
Modern health care practices mean that your treatment will be provided by a team of health professionals working together.
You may be referred for diagnostic tests such as pathology or radiology and our staff may consult with senior medical experts when determining your diagnosis or treatment. With developments in technology (e.g. telemedicine) our staff may consult with health professionals and medical experts located remotely, including outside Ramsay, in relation to your diagnosis or treatment, including by sending health information and clinical images. Our staff may also refer you to other health service providers for further treatment during and following your admission (for example, to a physiotherapist or outpatient or community health services). We may disclose your personal information to the relevant provider to the extent required for any such referral (including disclosing that information electronically).
Your personal information will only be disclosed to those health care workers involved in, or consulted in relation to, your treatment and associated administration and to the extent required to meet that purpose (including participation in multi-disciplinary team meetings). In some cases this information may be made available electronically including by way of secure portal or application.
These health professionals will share your personal information as part of the process of providing your treatment. We will only do this while maintaining confidentiality of all this information and protecting your privacy in accordance with the law.
If you require prosthesis or another medical implantable product as part of your treatment, we may in some cases disclose your personal information to the manufacturer or supplier of that product to ensure appropriate supply of that product and to enable appropriate follow up.
If you are referred to a Ramsay facility by your doctor, and you have previously attended the same Ramsay facility, we may, subject to the period of time that has passed between admissions, use the personal information (such as your address and contact details) we hold from your previous admission to streamline the referral process in our digital patient system.
Ramsay may collect your personal information for the purpose of assessing your suitability for health care services at a Ramsay facility. Where personal information is collected and you do not become a patient of the facility, your personal information may be stored for a limited period of time before destruction. Where your assessment has been conducted at the request of a Health Practitioner, Ramsay may report the outcome of the assessment to that Health Practitioner as it may be relevant to any ongoing treatment or care provided to you by them.
Where you undergo assessment by a third party provider (for example ACAT or a rehabilitation provider) during your admission to a Ramsay facility for the purpose of transferring your care to that third party, Ramsay may disclose your personal information to the third party provider for that purpose.
Ramsay will usually send a discharge summary to your referring medical practitioner or nominated general practitioner following an admission to one of our facilities. This is in accordance with long-standing health industry practice and is intended to inform your doctor of information that may be relevant to any ongoing care or treatment provided by them. This discharge summary may be sent to your referring medical practitioner or general practitioner electronically.
If you do not want us to provide a copy of your discharge summary to your nominated general practitioner you must let us know. Alternatively, if your nominated general practitioner has changed or your general practitioner's details have changed following a previous admission, you must let us know.
If in the future you are being treated by a medical practitioner or health care facility that needs to have access to the health record of your treatment at a Ramsay facility, we will generally require an authorisation from you to provide a copy of your record to that medical practitioner or health care facility.
However, we may provide information about your health records to another medical practitioner or health facility outside Ramsay without your consent in the event of an emergency where your life or health is at risk and you are not able to provide consent or as approved or authorised by law.
We may provide information about your condition to your spouse or partner, parent, child, other relatives, close personal friends, guardians, or a person exercising your power of attorney under an enduring power of attorney or who you have appointed your enduring guardian, unless you tell us that you do not wish us to disclose your personal information to any such person.
The Ramsay Pharmacy brand is owned by Ramsay Health Care. However, each retail Ramsay Pharmacy is an independently owned pharmacy business which is a franchise member of the Ramsay Pharmacy network.
Your personal information will only be provided to a retail pharmacy provider to provide services to you after your discharge from a Ramsay facility where you have requested that service and/or consented to that disclosure.
Ramsay provides some health services to public patients and to groups such as Defence or Customs personnel under contracts with government. Where you receive services from us under any such arrangements, Ramsay will provide your personal information (which in some cases may include a copy of your medical record for the relevant admission) to those government agencies as required under those contracts.
In accordance with best practice and to promote continuity of care, if Ramsay sells or transfers management or ownership of one of our facilities to a third party (including in circumstances where we have operated a facility and provided public patient services under a contract with a government authority and that contract expires or terminates), Ramsay may transfer your medical record to the new operator (which may, where public patient services have been provided, be a government authority). Ramsay will take reasonable steps to alert you in the event your personal and health information will be disclosed to a third party under this provision.
For patients who participate in the MyHealth Record program (operated by the Commonwealth Department of Health), Ramsay may upload personal information electronically to the MyHealth Record system unless you opt out.
Some of our facilities which provide maternity services offer postnatal accommodation programs which may include postnatal accommodation services offered and provided at hotels. If you are eligible to, and elect to, participate in any such program, Ramsay will disclose your personal details such as name, address and telephone number to the hotel for the purpose of satisfying the hotel’s check-in requirements.
At times Ramsay may become aware of clinical trials which may be relevant to your medical condition. Ramsay may use your personal information to assess your suitability for participation in the clinical trial in order to provide you with initial information about the clinical trial. Other than as authorised by law, Ramsay will not disclose your personal information to the clinical trial researcher without your consent.
Multi-disciplinary team meetings provide a forum for clinicians from different disciplines to provide individualized and integrated treatment planning (eg radiologist, pathologist, surgeon, hospital and rehabilitation). Following a multi-disciplinary team meeting, a summary of your case may be made available to the health practitioners involved in, or consulted in relation to, your care. This is in accordance with long-standing health industry practice and is intended to inform your doctor or health practitioners of information that may be relevant to any ongoing care or treatment provided by them. This summary may be sent to your doctor or health practitioners electronically.
Ramsay operates various Clinics providing outpatient allied health services (eg Ramsay Health Plus, Ramsay Psychology). Where you have been referred to a Ramsay Clinic by a medical practitioner, we will usually send a summary of the care provided to you back to that referring medical practitioner. This is in accordance with long-standing health industry practice and is intended to inform your Doctor of information that may be relevant to any ongoing care or treatment provided by them. This treatment summary may be sent to your referring medical practitioner electronically.
Where your outpatient allied health services are funded or coordinated by a third party in relation to an injury claim (eg WorkCover, TPD , MVA or similar), we may provide reasonable information to the third party (eg treatment plan, goals, attendance records, summary of care provided, recommendations etc) for the purpose of the third party administering your claim. This information may be sent to the third party electronically.
In order to provide the best possible environment in which to treat you, we may also use your personal information where necessary for:
activities such as quality assurance processes, in accordance with government accreditation or compliance for Centres of Excellence accreditation, audits, risk and claims management, patient satisfaction surveys and staff education and training;
invoicing, billing and account management, including storage of provider details on Ramsay billing software or engagement of third party providers to assist with debt collection;
to liaise with your health fund, Medicare, the Department of Veteran's Affairs or another payer and, where required, provide information to your health fund, Medicare, the Department of Veteran's Affairs or other payer to verify treatment provided to you, as applicable and as necessary;
the purpose of complying with any applicable laws – for example, in response to a subpoena or compulsory reporting to State or Federal authorities (for example, for specified law enforcement or public health and safety circumstances or upload to the Australian Immunisation Register where you have received a vaccination by Ramsay or at a Ramsay Facility);
the purpose of sending you standard reminders, for example for appointments and follow-up care, by text message or email to the number or address which you have provided to us; and
communicating important information to you regarding your health fund cover and any financial or management implications in respect of your care at a Ramsay Facility;
we may anonymise or aggregate the personal information that we collect for the purpose of carrying out customer, service, health outcome and other business analytics.
With your consent we may also use your information for other purposes such as including you on a marketing mail list, fundraising or research, statistical analysis, to promote Ramsay goods and services and to improve and personalise our service offerings (including pastoral care visits). Please note, however, that unless you provide us with your express consent for this purpose, we will not use your information in this way.
Ramsay may collect personal information (including details such as your name, email address and telephone number) to facilitate your access to Ramsay facilities (for example for Covid-19 screening purposes) and to provide associated services at Ramsay facilities (for example WIFI, Virtual Waiting Room), use of which is subject to any terms provided at the time of accessing the facility or relevant service. You may decline to provide personal information for this purpose but access to the facility or service may not be granted in that case.
Ramsay collects personal information from health professionals seeking accreditation and submitting to the credentialing process under its Facility Rules. Personal information provided by health professionals in this context is collected, used, stored and disclosed by Ramsay for the purposes of fulfilling its obligations in connection with the Facility Rules. Other uses of this information may include creating a digital account for health professionals to integrate with Ramsay systems, increase information security, and ultimately enhance the patient experience. You may decline to provide personal information for this purpose but this may prevent you being granted access to the facility or service.
Ramsay collects personal information of job applicants who have responded to an advertised position for the primary purpose of assessing and (if successful) engaging applicants. The purpose for which Ramsay uses personal information of job applicants includes:
Ramsay may also store information provided by job applicants who were unsuccessful for the purposes of future recruitment or employment opportunities.
Ramsay collects personal information of students, trainees, or doctors in training on placement for the primary purposes of providing the placement and facilitating assessment. The purposes for which Ramsay uses personal information of students, trainees and doctors in training include:
Ramsay may also store information provided by students or trainees following placement for the purpose of future recruitment or employment opportunities. If you do not want us to store your information in such circumstances, please let us know.
Ramsay may offer opportunities for health practitioners (including employed doctors, visiting medical officers and contracted doctors) to participate in training, educational events or seminars for the purpose of continuing professional development or community engagement. As such, Ramsay may use your personal information to contact you about such opportunities and manage your participation. When you register for or attend an event, Ramsay may collect your personal information for the purpose of providing the service and recording your attendance.
Ramsay may disclose your personal information to third parties for the purpose of confirming your attendance at the event including the provision of attendance records or certification. With your express consent, we may use your information for other purposes such as including you on a marketing mail list, fundraising or research, to promote Ramsay goods and services and to improve and personalise our service offerings.
Ramsay collects personal information contained within ethics review applications made to Ramsay Human Research Ethics Committees. Personal information provided in this context is collected, used, stored and disclosed by Ramsay for the purpose of managing the ethics review application.
Ramsay also collects personal information contained within research governance review applications relating to clinical research to be conducted at a Ramsay facility or involving data held by a Ramsay facility. Personal information provided in this context is collected, used, stored and disclosed by Ramsay for the purpose of managing the research governance review application.
We may also use your personal information where necessary for:
activities such as quality assurance processes, in accordance with government accreditation or compliance for Centres of Excellence accreditation, audits, statistical analysis, risk and claims management;
invoicing, billing and account management, including storage of provider details on Ramsay billing software;
the purpose of complying with any applicable laws – for example, in response to a subpoena or compulsory reporting to State or Federal authorities (for example, for specified law enforcement or public health and safety circumstances or upload to the Australian Immunisation Register where you have received a vaccination by Ramsay or at a Ramsay Facility); and
We may anonymise or aggregate the personal information that we collect for the purpose of carrying out customer, service and other business analytics.
With your consent we can also use your information for other purposes such as including you on a marketing mail list, fundraising or research, statistical analysis, to promote Ramsay goods and services and to improve and personalise our service offerings. Unless you provide us with your express consent for this purpose, we will not use your personal information in this way.
Ramsay may offer opportunities for you to register to use online portals or forums (eg the Ramsay MaternityCare Portal or Ramsay MaternityCare Online Community) operated by Ramsay. When you register for an online portal or forum, Ramsay will collect your personal information for the purpose of providing you with access to the service, including tailoring the platform to display information relevant to you. Using a portal or forum is subject to your acceptance of any terms or conditions provided at the time of registering for the relevant service.
Where you are also booked to be admitted or are admitted as a patient of a Ramsay facility, personal information collected via a portal or forum may be used or disclosed to relevant health care workers involved in, or consulted in relation to, your antenatal care, your admission or your treatment and associated administration and to the extent required to meet that purpose (for example, confirming an antenatal class booking). Personal information collected at a Ramsay facility may also be used to tailor the portal or forum to display information relevant to your use (for example, updating a class booking or adding information relevant to the discovery that you are having a multiple birth).
We will only do this while maintaining confidentiality of all this information and protecting your privacy in accordance with the law.
You have a right to have access to the personal information that we hold about you (for patients, this includes health information contained in your health record). You can also request an amendment to personal information that we hold about you should you believe that it contains inaccurate information.
Ramsay will allow access or make the requested changes unless there is a reason under the Privacy Act 1988 (Cth) or other relevant law to refuse such access or refuse to make the requested changes.
If we do not agree to change your personal information in accordance with your request, we will permit you to make a statement of the requested changes and we will enclose this with your personal information.
Should you wish to obtain access to or request changes to your personal information held by Ramsay you can ask for our Privacy Officer (see details below) who can give you more detailed information about Ramsay's access and correction procedure.
Ramsay may recover reasonable costs associated with supplying this information to you.
Ramsay will take reasonable steps to ensure that your personal information which we may collect, use or disclose is accurate, complete and up-to-date.
Ramsay will take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification or disclosure. We use technologies and processes such as access control procedures, network firewalls, encryption and physical security to protect your privacy.
Ramsay will destroy or permanently de-identify any of your information which is in its possession or control and which is no longer needed for the purpose for which it was collected provided Ramsay is not required under an Australian law or court/tribunal or otherwise to retain the information.
Ramsay may enter into arrangements with third parties to store data we collect or to access the data to provide services (such as data processing), and such data may include personal information, outside of Australia. Ramsay will take reasonable steps to ensure that the third parties do not breach the APPs. The steps Ramsay will take may include ensuring the third party is bound by privacy protection obligations which are the same (or substantially the same) as those which bind Ramsay and requiring that the third party has information security measures in place which are of an acceptable standard and approved by Ramsay.
|Corporate Privacy Officer, Ramsay Health Care
PO Box 1336
Crows Nest NSW 1585
|(02) 9433 3444
|(02) 9433 3460
|Corporate Privacy Officer
a. Ramsay does not agree to provide you with access to your personal information; or
b. you have or a complaint about our information handling practices,
you can lodge a complaint with or contact our Privacy Officer on the details above or directly with the Office of the Australian Information Commissioner. Full contact details can be found on the website www.oaic.gov.au
When you use our website, we do not attempt to identify you as an individual user and we will not collect personal information about you unless you specifically provide this to us.
Sometimes, we may collect your personal information if you choose to provide this to us via an online form or by email, for example, if you:
When you use our website, we use analytics tools such as Google Analytics to record and log for statistical purposes and abuse/fraud prevention purposes the following information about your visit, such as:
Our web-site management team use statistical data collected by Google Analytics to evaluate the effectiveness of our web-site.
Google makes available a browser “add-on” that prevents Google Analytics from collecting information about web site visits, we suggest you refer to the instructions for installation of Google Analytics Opt-out to learn more about this.
We are, however, obliged to allow law enforcement agencies and other government agencies with relevant legal authority to inspect our web server logs, if an investigation being conducted warrants such inspection.
A "cookie" is a small bit of data our server sends to your browser that allows our server to identify and interact more effectively with your computer. Cookies do not identify individual users, but they do identify your ISP and your browser type.
Personal information such as your email address is not collected unless you provide it to us. We do not disclose domain names or aggregate information to third parties other than agents who assist us with this website and who are under obligations of confidentiality. You can configure your browser to accept or reject all cookies and to notify you when a cookie is used. We suggest that you refer to your browser instructions or help screens to learn more about these functions. However, please note that if you configure your browser so as not to receive any cookies, a certain level of functionality of the Ramsay website and other websites may be lost.
We may create links to third party websites. We are not responsible for the content or privacy practices employed by websites that are linked from our website.
We will only use personal information collected via our website for the purposes for which you have given us this information.
We will not use or disclose your personal information to other organisations or anyone else unless:
you have consented for us to use or disclose your personal information for this purpose;
you would reasonably expect or we have told you (including via this policy) that your information is usually or may be used or disclosed to other organisations or persons for a related (or for sensitive information, a directly related purpose);
the use or disclosure is required or authorised by law;
the use or disclosure will prevent or lessen a serious and/or imminent threat to somebody's life, health or safety or to public health or public safety; or
the disclosure is reasonably necessary for law enforcement functions or for the protection of public revenue.
If we receive your email address because you sent us an email message, the email will only be used or disclosed for the purpose for which you have provided and we will not add your email address to an emailing list or disclose this to anyone else unless you provide us with consent for this purpose.
If we collect your personal information from our website, we will maintain and update your information as reasonably practical and necessary or when you advise us that your personal information has changed.
Ramsay is committed to protecting the security of your personal information. We use technologies and processes such as access control procedures, network firewalls, encryption and physical security to protect the privacy of information. We will take all reasonable steps to prevent your information from loss, misuse or alteration.
If you choose to complete our online forms or lodge enquiries via our website, we will ensure that your contact details are stored on password protected databases.
Staff members associated with website maintenance have access to our website's backend system. This is password protected. Our website service is also password protected.
If you wish to obtain information about how to access or correct your personal information collected via our website, please refer to Access and Correction at Item 2.7 of this document.
© The Ramsay Health Care Limited Group 2023