Privacy Policy.
How Specialist Medical Services Group collects, uses, stores and shares your personal and health information, and your rights as a patient.
- We collect only what your care requires: identifying detail, health information, and payment records, and we don't collect what we don't need.
- We share your information with clinicians involved in your care, with services that process your investigations, and where the law requires. We don't share it for marketing or any commercial purpose outside your care.
- You can ask to see the records we hold about you, ask us to correct them, and withdraw consent for particular uses. Requests go to our Practice Operations team; contact details are in the block at the bottom of this page.
- We're bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and by the Health Records and Information Privacy Act 2002 (NSW). If our response doesn't resolve a concern, you can escalate to the OAIC or the NSW Privacy Commissioner.
- The full text below explains each of these in detail. If you'd rather just get in touch, our contact block is at the bottom of this page.
What this policy covers, and why.
This Privacy Policy sets out how Specialist Medical Services Group (SMSG, we, us, our) handles personal information and health information about patients, prospective patients, website visitors, and members of the public who interact with our centres.
We are bound by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and the Health Records and Information Privacy Act 2002 (NSW). Both apply to our handling of your information. This policy explains what we collect, how we use it, who we share it with, and how you can access and correct your own records.
Personal information and health information.
The information we collect about you depends on your relationship with us. In general, we collect three categories.
- Your full name, date of birth, gender, and address.
- Contact detail including phone number and email address.
- Medicare number, private health fund detail, DVA number, Health Care Card number, or other relevant identification.
- Emergency contact details you provide us.
- Your GP or referring practitioner, where relevant.
- Your medical history, including past diagnoses, procedures, and hospitalisations.
- Current medications, allergies, and adverse reactions.
- Immunisation status.
- Clinical notes from consultations at SMSG.
- Investigation results, including pathology, imaging, and specialist reports.
- Referral letters to and from other clinicians.
- Any other information a clinician records in your file for the purpose of your care.
- Payment method used at the centre.
- Medicare and private health fund transaction records.
- Outstanding accounts.
We collect this information because we cannot provide clinical care without it. We do not collect information we do not need.
Where the information comes from.
Most of the information we hold about you is collected directly from you, either at your appointment, over the phone, or through our patient registration process online.
Some information is collected from others with your consent. This includes:
- Referral letters from your GP or specialist.
- Pathology, imaging and other diagnostic results ordered by an SMSG clinician.
- Correspondence from hospitals, allied health providers, or other clinicians involved in your care.
- Medicare and private health fund transaction records.
- My Health Record data, where you have consented to us accessing it.
We only collect information from third parties where it is reasonably necessary for your care or where you have consented.
The primary purposes.
We use your personal and health information for the primary purposes of:
- Providing clinical care to you at your appointments.
- Coordinating your care across the clinicians involved in your treatment, including within SMSG and with external clinicians.
- Communicating with you about appointments, results, referrals, and follow-up care.
- Meeting our legal, professional and Medicare obligations.
- Billing you and processing Medicare rebates and private health fund claims.
- Improving the quality of care we provide, including through internal clinical audits and continuing professional development.
- Meeting accreditation requirements.
We may also use your information for secondary purposes reasonably related to your care, provided you would reasonably expect us to do so. These include:
- Following up on outstanding tests, referrals, or clinical concerns.
- Sending you appointment reminders and health promotion communications where you have consented.
- Providing information to the Medicare Benefits Schedule and Pharmaceutical Benefits Scheme as required by law.
- Reporting notifiable conditions (for example certain infectious diseases) as required by public health law.
If you have a My Health Record.
If you have a My Health Record, our clinicians may upload clinical documents to it (with your consent) and may access information you have consented to share.
You control what is uploaded to your My Health Record and who can see it. You can opt out of specific clinicians accessing it, restrict specific documents, or cancel your My Health Record altogether through myhealthrecord.gov.au.
Security of your records.
Your personal and health information is stored in our clinical practice management system, which is an Australian-based, secure electronic health record used by many Australian general practices. Access to the system is restricted to authorised clinicians and staff, and every access is logged.
We hold physical records in secure, locked storage where they exist in paper form. Paper records are being digitised progressively.
Our security measures include:
- Individual user logins with password requirements and multi-factor authentication for external access.
- Role-based access controls so staff can only see the information they need for their work.
- Access logs that can be reviewed.
- Regular backup and disaster recovery testing.
- Physical security at each of our centres (locked file rooms, staff-only areas).
- Encryption of data in transit and at rest.
- Contracts with our IT providers requiring them to meet Australian privacy standards.
Notwithstanding all reasonable precautions, no security system is impenetrable. Where a data breach affects your information, we will notify you and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
Access, correction, and choice.
You have the right to:
- Access your own records. You can request a copy of the information we hold about you. We will provide access within a reasonable time, usually within thirty days. A fee may apply where the request is complex or requires significant staff time; the fee is disclosed before we proceed.
- Correct inaccurate information. If you believe information we hold about you is incorrect or out of date, you can ask us to correct it. Corrections to clinical records are made by annotation rather than deletion (this is a clinical record-keeping requirement).
- Withdraw consent. You can withdraw consent for us to share your information with a specific third party or for a specific secondary purpose. Withdrawing consent does not affect information already shared, and it may affect our ability to provide certain aspects of your care.
- Make a privacy complaint. If you believe we have mishandled your information, you can contact us via email or phone. If our response does not resolve your concern, you can escalate to the Office of the Australian Information Commissioner or the NSW Privacy Commissioner.
To exercise any of these rights, contact our Practice Operations team. We may need to verify your identity before releasing information.
How long we keep your information.
Health records are retained for the periods required by NSW and Commonwealth law. In general:
- Adult patient records are retained for at least seven years from the date of last entry.
- Records of patients who were under 18 at the time of last entry are retained until the patient turns 25, or seven years from the date of last entry, whichever is longer.
- Some categories of records (for example, those relevant to compensation, medico-legal matters, or ongoing care) may be retained for longer.
Records are securely destroyed when they are no longer required, in accordance with our record retention protocol.
If our response doesn't resolve your concern.
You may escalate to either of these external bodies:
- Office of the Australian Information Commissioner
oaic.gov.au1300 363 992 - NSW Privacy Commissioner
ipc.nsw.gov.au1800 472 679
How we update this document.
This Privacy Policy may be updated from time to time to reflect changes in our practices or legal requirements. The current version is always the one published at this URL. The effective date at the top of this page indicates when the current version was published.
Material changes will be flagged with a notice on our website. Non-material changes (such as clarifications or contact detail updates) may be made without notice.
