{"id":216,"date":"2025-10-09T16:55:30","date_gmt":"2025-10-09T06:55:30","guid":{"rendered":"https:\/\/escope.ages.com.au\/october-2025\/?p=216"},"modified":"2025-10-13T09:56:43","modified_gmt":"2025-10-12T23:56:43","slug":"avoid-escalating-privacy-issues-and-brush-up-on-the-basics","status":"publish","type":"post","link":"https:\/\/escope.ages.com.au\/october-2025\/avoid-escalating-privacy-issues-and-brush-up-on-the-basics\/","title":{"rendered":"Avoid escalating privacy issues and brush up on the basics"},"content":{"rendered":"\n<h1>\n\t\t\tAvoid escalating privacy issues and brush up on the basics\t<\/h1>\n\t\t\t\t<p>Imagine any one of these scenarios:<\/p>\n<ul>\n<li>A practice nurse accesses medical records of a family member to use in a Family Court matter.<\/li>\n<li>A practice manager sends a patient complete medical record to an insurance company, without checking the scope of the patient&#8217;s authority .<\/li>\n<li>A registrar shares an endoscopy still image in a WhatsApp group without patient consent.<\/li>\n<li>A patient&#8217;s appointment details are accidentally emailed to their ex-partner because their change of address request was not actioned promptly.<\/li>\n<li>An embryo-grading Artificial Intelligence (AI) tool is trialled, but patients are not given a clear explanation of how decisions are made.<\/li>\n<\/ul>\n<p>Scenarios like this have triggered privacy and professional conduct complaints in Australia and overseas. As technology makes it easier to capture, use and share personal information, there is a greater public demand for that information to be protected. Privacy laws are changing to provide greater protection for individuals and stronger enforcement powers for regulators.<\/p>\n\t\t\t<h3>Protecting patient information<\/h3>\t\t\t\n\t\t\t\t<p>You have always been required to protect patients&#8217; personal information, because of your obligation of confidentiality and the protections in the privacy legislation. The Australian Privacy Principles (APPs) in the Commonwealth <em>Privacy Act<\/em> set out the obligations for handling patient information, including how to protect it from the sorts of misuse listed in the scenarios above. \u00a0\u00a0<\/p>\n<p>Recent changes to the law clarified that the reasonable steps required to protect patient information include taking technical and organisational measures. Technical measures include securing access to premises, encrypting data, using anti-virus software and having strong passwords. Organisational measures include implementing processes and procedures for managing patient information, and training staff about these. \u00a0\u00a0<\/p>\n\t\t\t<h3>Increased enforcement powers<\/h3>\t\t\t\n\t\t\t\t<p>The Office of the Australian Information Commissioner (OAIC) now has increased powers to issue infringement notices and penalties. \u00a0<\/p>\n<p>The <a href=\"https:\/\/protect.checkpoint.com\/v2\/r04\/___https:\/www.oaic.gov.au\/about-the-OAIC\/our-regulatory-approach\/statement-of-regulatory-approach___.Y3A0YTp5cmRldmVudHM6YzpvOjE4OTNkNjdiNWQ3ZjgxNjRmODY3MzU5NWMyNDNkMjI5Ojc6Mjg4NjpkNTIxMGM2NDQ0MDAwYmZlNmIyMjg5MjljOGMzOWRmNWRjZGViYjEzYzk5ZDg2M2QzMWU2NTZiNzEyZjU2ODM3OnA6VDpG\" target=\"_blank\" rel=\"noopener\">OAIC has advised its approach<\/a> is to encourage and support compliance and that it is more likely to act where there is a substantial risk of harm or where there are systemic harms or contraventions. However, be aware procedural errors such as mishandling access requests or failing to maintain a compliant privacy policy could lead to fines. In gynaecology and endoscopy, where images and sensitive data are routine, it is particularly important to ensure your policies and procedures are robust.<\/p>\n\t\t\t<h3>Serious invasions of privacy<\/h3>\t\t\t\n\t\t\t\t<p>Since June this year, individuals can sue for damages for serious invasions of privacy. To pursue this new cause of action, the invasion of privacy must be serious, and either intentional or reckless. It applies to intrusions into someone&#8217;s physical privacy as well as misuse of private information. The person does not need to prove they experienced actual harm and the information disclosed does not have to be true.<\/p>\n<p>There must also be a reasonable expectation of privacy in all the circumstances. This is intended to be flexible test to be determined by the circumstances and context of each case.<\/p>\n\t\t\t<h3>Automated decision-making transparency <\/h3>\t\t\t\n\t\t\t\t<p>By 10 December 2026, your privacy policy must disclose if your practice uses automated decision-making that may significantly affect patients&#8217; rights or interests. As technology advances, use of tools for endoscopy image analysis, surgical planning, or fertility-related decision support could fall within the scope of this requirement. Plan now to be clear with patients about if and how you use such tools, including the types of patient information used by the tools and the sorts of decisions being made.<\/p>\n\t\t\t<h3>What this means for you<\/h3>\t\t\t\n\t\t\t\t<p>All the opening scenarios could have significant consequences for you and your practice. The new privacy requirements provide a good opportunity to review and refresh your privacy practices and ensure compliance. New regulatory powers include being able to issue fines of up to $66,000 for non-compliance and up to $660,000 for interferences with an individual&#8217;s privacy. \u00a0<\/p>\n<ul>\n<li><strong>Access requests:<\/strong> Have a clear, prompt process. Provide access to the information requested unless an exception applies. Charge only reasonable fees for retrieval and copying, and never for handling a complaint.<\/li>\n<li><strong>Policies and training:<\/strong> Keep your privacy policy current and specific to your workflows (imaging, endoscopy video, photo consent, report sharing). Only capture or collect the personal information you need. Limit access to a need-to-know basis. Train staff on your policies and procedures.<\/li>\n<li><strong>Clinical images and recordings:<\/strong> Do not take or share patient images or recordings without express consent and a clinical need. Treat all images as personal information and make sure they are stored securely.<\/li>\n<li><strong>Hospital settings:<\/strong> Assume access to records and privacy compliance will be audited. Follow hospital policies as any lapses can have employment and regulatory consequences.<\/li>\n<li><strong>Governance for automation:<\/strong> Map where automation could influence clinical decisions, update your privacy policy, and ensure there is human oversight.<\/li>\n<\/ul>\n\t\t\t<h3>Further reading<\/h3>\t\t\t\n\t\t\t\tAvant article: <a href=\"https:\/\/protect.checkpoint.com\/v2\/r04\/___https:\/avant.org.au\/resources\/why-every-practice-needs-a-strong-privacy-policy___.Y3A0YTp5cmRldmVudHM6YzpvOjE4OTNkNjdiNWQ3ZjgxNjRmODY3MzU5NWMyNDNkMjI5Ojc6ZWRjMjowNGVkMDRhYWNhZDY5MmM2MmY5YmU1NGI0MjcwOGM4ZDkyY2U5ZDI2NTU4MDgwZmI2Zjc4ZjdhMDM0NGEwOWVkOnA6VDpG\" target=\"_top\">Why every practice needs a strong privacy policy<\/a><br \/>\nAvant factsheet:\u00a0<a href=\"https:\/\/protect.checkpoint.com\/v2\/r04\/___https:\/avant.org.au\/resources\/privacy-basics-and-data-breaches___.Y3A0YTp5cmRldmVudHM6YzpvOjE4OTNkNjdiNWQ3ZjgxNjRmODY3MzU5NWMyNDNkMjI5Ojc6MzRlZjoyODJmY2I4ZWFmZWMxNjNlNDE5MTMzNTYwZWQ1Y2UwMTk0MDgwYjE2MmIzYTUzMGFmMmViYjk1ZjYxMDQ5YmE2OnA6VDpG\" target=\"_top\">Privacy: the essentials<\/a><br \/>\nAvant factsheet:\u00a0<a href=\"https:\/\/protect.checkpoint.com\/v2\/r04\/___https:\/avant.org.au\/resources\/clinical-images-a-snapshot-of-the-issues___.Y3A0YTp5cmRldmVudHM6YzpvOjE4OTNkNjdiNWQ3ZjgxNjRmODY3MzU5NWMyNDNkMjI5Ojc6MmE5NTpmYTZjNjg5OTE4YjdkNmEzODcwNDJiNzhmODcwYzEwMDFhMmZjMWQ4MjAyODY2MTBlMGVlNWY2Y2JjODJkNmQ2OnA6VDpG\" target=\"_top\">Clinical images &#8211; a snapshot of the issues\u00a0<\/a><br \/>\nAvant article:\u00a0<a href=\"https:\/\/protect.checkpoint.com\/v2\/r04\/___https:\/avant.org.au\/resources\/get-smart-clinical-images___.Y3A0YTp5cmRldmVudHM6YzpvOjE4OTNkNjdiNWQ3ZjgxNjRmODY3MzU5NWMyNDNkMjI5Ojc6MzJiYTo1YjJhNDk5MjAyMjg1NzNmZDg1NTYwMmRmN2RmYThjNjMwMjhiMmVkMzU4MTdhNTU3NzA0ODRlYWYzNTRlMDI2OnA6VDpG\" target=\"_top\">Get smart: clinical images and smartphones<\/a><br \/>\nAvant flowchart:\u00a0<a href=\"https:\/\/protect.checkpoint.com\/v2\/r04\/___https:\/avant.org.au\/resources\/taking-a-clinical-image___.Y3A0YTp5cmRldmVudHM6YzpvOjE4OTNkNjdiNWQ3ZjgxNjRmODY3MzU5NWMyNDNkMjI5Ojc6YTc4Njo1NjMxYmYwZTFiOTU5NzVlODg2Mzk5NWEyY2MzNTYyZDVmODRlOWU4MjNmNGU2OGI3MWY5NzJkOTY3YTNiOWU2OnA6VDpG\" target=\"_top\">Taking a clinical image<\/a><br \/>\nAvant factsheet: <a href=\"https:\/\/protect.checkpoint.com\/v2\/r04\/___https:\/avant.org.au\/resources\/emailing-patients-what-to-include-in-your-policy___.Y3A0YTp5cmRldmVudHM6YzpvOjE4OTNkNjdiNWQ3ZjgxNjRmODY3MzU5NWMyNDNkMjI5Ojc6YTEzMjo2NmMyODlhNzAxN2ZkOTg5ZDY2ZmEwYjExMDE2ZmM3N2U4MDQ0OTYyN2NjM2Y3ZGMwNTViZmE1NmQ1Y2RlNjQyOnA6VDpG\" target=\"_top\">Emailing patients: what to include in your policy<\/a>\n\n","protected":false},"excerpt":{"rendered":"<p>Privacy laws are changing to provide greater protection for individuals and stronger enforcement powers for regulators.<\/p>\n","protected":false},"author":1,"featured_media":72,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"no-sidebar","site-content-layout":"","ast-site-content-layout":"full-width-container","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1],"tags":[],"class_list":["post-216","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised"],"acf":[],"_links":{"self":[{"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/posts\/216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/comments?post=216"}],"version-history":[{"count":6,"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/posts\/216\/revisions"}],"predecessor-version":[{"id":258,"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/posts\/216\/revisions\/258"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/media\/72"}],"wp:attachment":[{"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/media?parent=216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/categories?post=216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/escope.ages.com.au\/october-2025\/wp-json\/wp\/v2\/tags?post=216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}