Protecting privacy and managing personal information appropriately are essential to safe, respectful and person-centred care.
Mental health and wellbeing services must manage personal and health information in accordance with the Health Records Act 2001 and the Privacy and Data Protection Act 2014 .
This material is intended for quick reference only. The full principles are set out in the above Acts.
Collection
Organisations can only collect personal information where it is necessary to perform one or more of its functions. They must collect information only by lawful and fair means, and not in an unreasonably intrusive way. They must provide notice of the collection, outlining matters such as the purpose of collection and how individuals can access the information. This is usually done by providing a Collection Notice, which should be consistent with an organisation’s Privacy Policy.
Use and disclosure
Health information should only be used or disclosed for the purpose for which it was collected, or for a directly related secondary purpose that a person would reasonably expect. In most other circumstances, consent is required.
Data quality
Take reasonable steps to ensure personal information is accurate, complete and up to date.
Data security and retention
Organisations must take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification or disclosure. Personal information should also be securely retained, destroyed or de-identified in accordance with legislative and record keeping requirements.
Openness
Organisations must have and maintain clear policies on the management of personal and health information and make them available to individuals on request.
Access and correction
Individuals have the right to access and request correction of their personal information. Access and correction requests are mostly handled under the Freedom of Information Act 1982.
Identifiers
Unique identifiers should only be assigned where reasonably necessary to carry out functions efficiently. Their use and disclosure should be limited to protect privacy and reduce the risk of inappropriate data matching.
Anonymity
Where lawful and practicable, individuals should have the option of not identifying themselves when accessing a service or making an enquiry.
Transborder data flows
Health information should only be transferred outside Victoria where appropriate privacy protections are in place and legislative requirements are met. Privacy protections should continue to apply when information is shared across jurisdictions.
Transfer/closure of a health service practice
Health service providers who sell, transfer or close a practice must take appropriate steps to notify past service users and ensure health information continues to be managed appropriately.
Sensitive information
Sensitive information requires additional protections and may only be collected, used and disclosed in accordance with legislative requirements. This includes information about a person's racial or ethnic origin, political views, religious beliefs, sexual orientation, group memberships or criminal history.
Making information available to another health service provider
Health service providers must make an individual's health information available to another health service provider when requested by the individual.
Updated

