1. About this Privacy Policy
MedStar Medical is committed to protecting the privacy and confidentiality of personal information entrusted to us.
This Privacy Policy explains how MedStar Medical collects, holds, uses and discloses personal information, including health information, and how patients may access and correct information held about them or make a privacy complaint.
MedStar Medical handles personal information in accordance with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy applies to MedStar Medical and to the administrative functions operated by MedStar Medical. Medical practitioners consulting at MedStar Medical may practise as independent practitioners and may have their own professional and privacy obligations.
If you have any questions about this Privacy Policy or how we handle your personal information, please contact our Privacy Officer using the contact details at the end of this policy.
2. What personal information do we collect?
The information we collect and hold may include:
Identification and contact information
* name;
* date of birth;
* address;
* telephone number;
* email address;
* emergency contact details;
* details of an authorised representative, parent, guardian or person responsible for your care.
Medicare and healthcare identifiers
Where required for healthcare administration, Medicare claiming or identification, we may collect:
* Medicare number and expiry date;
* Department of Veterans’ Affairs details;
* Individual Healthcare Identifier (IHI);
* private health insurance details;
* other relevant healthcare or government identifiers.
Health information
Where collected in connection with healthcare services, information may include:
* medical history;
* symptoms and diagnoses;
* treatment information;
* medications;
* allergies;
* pathology and imaging results;
* specialist and hospital reports;
* referrals;
* prescriptions;
* health assessments and care plans;
* information relevant to your ongoing healthcare.
Administrative information
We may also collect:
* appointment information;
* billing and payment information;
* Medicare claiming information;
* correspondence with healthcare providers;
* information required to manage accounts and administrative services;
* information provided when you contact the practice.
We only seek to collect information that is reasonably necessary for the functions and activities of MedStar Medical.
3. How do we collect personal information?
We may collect personal information:
* directly from you;
* when you make or attend an appointment;
* through our website or online forms;
* by telephone, SMS, email or other communication methods;
* from your authorised representative;
* from a parent, guardian or person responsible for your care;
* from your treating healthcare practitioners;
* from other healthcare providers involved in your care;
* from hospitals, specialists, pathology and diagnostic providers;
* through Medicare, DVA or other relevant government services where permitted;
* from health insurers where appropriate;
* through electronic medical record, appointment and practice-management systems.
Where practicable, we will collect personal information directly from you.
There may be circumstances where we collect information from another person or organisation where this is reasonably necessary for your healthcare, administration, safety or where permitted or required by law.
4. Why do we collect, hold, use and disclose personal information?
We may collect, hold, use and disclose personal information for purposes including:
* providing and coordinating healthcare;
* assessing and managing your health;
* maintaining your medical record;
* arranging and managing appointments;
* communicating with you about your healthcare and appointments;
* processing Medicare and DVA claims;
* processing payments and managing accounts;
* communicating with your health insurer where appropriate;
* arranging referrals and communicating with other healthcare providers involved in your care;
* receiving and communicating pathology, imaging and specialist reports;
* complying with legal and regulatory obligations;
* meeting mandatory reporting requirements;
* managing our practice and administrative systems;
* improving the safety and quality of our services;
* responding to privacy or other complaints;
* protecting the health and safety of patients, staff and other persons; and
* other purposes permitted or required by law.
We will not use or disclose personal information for purposes unrelated to the above unless permitted or required by law or otherwise authorised.
5. Independent medical practitioners
Doctors consulting at MedStar Medical may practise as independent medical practitioners.
Each practitioner is responsible for their own clinical assessment, diagnosis, treatment decisions and patient care.
Where appropriate, MedStar Medical may provide administrative, technological and practice-management support to independent practitioners.
Personal information may therefore be handled by MedStar Medical and/or the relevant treating practitioner in accordance with their respective legal and professional obligations.
6. Administrative and third-party service providers
MedStar Medical may use third-party service providers to assist with functions such as:
* appointment administration;
* telephone and reception support;
* information technology;
* software and practice-management systems;
* electronic communications;
* payment processing;
* document management;
* website hosting and analytics;
* SMS and other communication services.
Where a third-party provider is required to access personal information, we seek to limit access to information reasonably necessary for that provider to perform its contracted services.
We require relevant service providers to maintain appropriate confidentiality, privacy and information-security safeguards.
7. Overseas service providers
MedStar Medical engages third-party service providers to assist with certain administrative and telephone support functions.
Some of these service providers are located outside Australia.
Where reasonably necessary to perform their contracted functions, overseas service providers may have access to limited patient personal information.
For our telephone and administrative support functions, this may include:
* patient name;
* date of birth;
* contact details;
* address;
* appointment information; and
* Medicare details where reasonably necessary for identification, appointment administration or billing-related functions.
Access by overseas service providers is intended to be limited to information reasonably necessary for the functions they perform.
Unless specifically authorised and required for their contracted functions, overseas administrative and telephone support providers are not permitted to access clinical notes or the broader clinical record.
Our overseas service providers may be located in:
[INSERT COUNTRY/COUNTRIES]
MedStar Medical takes reasonable steps to ensure that overseas service providers handle personal information appropriately and securely, including through contractual confidentiality and privacy obligations, appropriate staff training, access controls and data-breach response procedures.
Where required by applicable privacy law, MedStar Medical takes reasonable steps to ensure that overseas recipients do not breach the Australian Privacy Principles in relation to personal information disclosed to them.
Patients may contact MedStar Medical if they have questions about our overseas service providers or the handling of their personal information overseas.
8. Medicare information and government identifiers
Medicare numbers and other government-related identifiers are handled carefully and only used or disclosed for purposes permitted by applicable law.
Where Medicare information is accessed by administrative or telephone support staff, access is limited to information reasonably necessary for legitimate administrative, identification, Medicare or billing-related purposes.
Medicare information must not be used for unrelated purposes or disclosed to persons who are not authorised to receive it.
9. Telephone communications
When communicating with patients by telephone, MedStar Medical may use reasonable identity-verification procedures before providing or discussing personal information.
Depending on the nature of the enquiry, we may ask for identifying information to confirm that we are speaking with the patient or an appropriately authorised person.
We will take reasonable steps to avoid disclosing personal or health information to an unauthorised person.
Where a person is not authorised to receive information about a patient, we may decline to provide information or take a message without disclosing confidential information.
Where appropriate, additional verification may be required before information is provided.
10. Telephone support provided by overseas staff
Where an overseas administrative or telephone support provider assists MedStar Medical, those staff are required to follow the privacy, confidentiality and security requirements applicable to their role.
Their access to patient information is restricted according to their functions.
Overseas staff must not:
* access information unrelated to their duties;
* disclose patient information to unauthorised persons;
* copy or download patient information unless expressly authorised;
* use patient information for personal purposes;
* disclose patient information to third parties without authorisation; or
* access clinical information that is not necessary for their role.
MedStar Medical may monitor access and system activity where appropriate to maintain privacy and security.
11. Electronic communications
We may communicate with patients using telephone, SMS, email and other electronic communication methods.
Patients should be aware that no electronic communication method can be guaranteed to be completely secure.
Where sensitive information is required to be transmitted electronically, MedStar Medical will seek to use appropriate secure systems and reasonable security measures.
Patients may contact the practice if they have concerns about receiving information by a particular communication method.
12. Website and cookies
Our website may collect technical and usage information such as:
* IP address;
* browser and device information;
* operating system;
* pages viewed;
* referring website;
* approximate location information;
* access times; and
* other information collected through analytics or similar technologies.
We may use cookies and analytics technologies to operate, maintain, secure and improve our website.
Where third-party analytics, advertising or other technologies are used, information may be handled by those providers in accordance with their own privacy policies and applicable law.
Our website may contain links to third-party websites. MedStar Medical is not responsible for the privacy practices of external websites.
13. Direct marketing and communications
Where permitted by law, MedStar Medical may contact patients about practice services, updates or information that may be relevant to them.
We will comply with applicable privacy and electronic marketing laws, including the Spam Act 2003 (Cth) where applicable.
Patients may opt out of receiving direct marketing communications by following the unsubscribe instructions provided or contacting the practice.
We will not sell personal information to third parties for marketing purposes.
14. Disclosure to other healthcare providers
Where appropriate and permitted by law, information may be disclosed to healthcare providers involved in your care, including:
* specialists;
* hospitals;
* allied health professionals;
* pathology providers;
* diagnostic imaging providers;
* pharmacies;
* aged-care providers; and
* other members of your treating team.
We will generally disclose only information reasonably necessary for the relevant healthcare purpose.
15. Disclosure to family members and authorised representatives
We may disclose relevant information to a person involved in your care where you have authorised us to do so or where disclosure is otherwise permitted or required by law.
We will take reasonable steps to verify the identity and authority of a person seeking access to your information.
16. Information security
MedStar Medical takes reasonable steps to protect personal information from:
* misuse;
* interference;
* loss;
* unauthorised access;
* unauthorised modification; and
* unauthorised disclosure.
Security measures may include:
* access controls;
* individual user accounts;
* password controls;
* multi-factor authentication where available;
* encryption;
* secure information systems;
* staff privacy and security training;
* physical security measures;
* system monitoring;
* controlled access to medical records; and
* procedures for responding to suspected data breaches.
Access to personal information is restricted according to the person’s role and legitimate need to access the information.
17. Data breaches
If MedStar Medical becomes aware of a suspected or actual data breach, we will assess and respond to the incident in accordance with applicable privacy laws and our data-breach response procedures.
Where the Notifiable Data Breaches scheme applies, MedStar Medical will comply with its obligations under the Privacy Act 1988 (Cth), including notification requirements where applicable.
Where an incident involves an overseas service provider, we will require the provider to notify MedStar Medical promptly and cooperate with our investigation and response.
18. Retention and destruction of information
Medical records and other personal information will be retained in accordance with applicable legal, regulatory and professional requirements.
When personal information is no longer required and there is no legal or regulatory requirement to retain it, MedStar Medical will take reasonable steps to securely destroy or de-identify the information.
19. Access to personal information
You generally have a right to request access to personal information held about you.
Requests should be directed to our Privacy Officer using the contact details below.
We may require reasonable identification and information about the nature of your request to ensure that information is provided to the correct person.
We will generally respond to access requests within 30 days, subject to the nature and complexity of the request and any applicable legal requirements.
In some circumstances, access may be refused or limited where permitted or required by law. If access is refused, we will provide an explanation where required.
20. Correction of personal information
If you believe information held about you is inaccurate, incomplete, out of date or misleading, you may request that it be corrected.
MedStar Medical will take reasonable steps to correct information where appropriate and as required by applicable law.
Where a disagreement remains about information contained in a medical record, an appropriate notation or statement may be added to the record in accordance with applicable legal and professional requirements.
21. Privacy complaints
If you have concerns about the way MedStar Medical has handled your personal information, please contact our Privacy Officer.
We will investigate your complaint and seek to resolve it in accordance with our privacy complaint procedures.
Privacy Officer- Jay Patel
MedStar Medical
Phone: 07 3154 0400
Email: admin@medstarmedical.com.au
Postal address: 283-285 Henty Drive, redbank plains
We will generally acknowledge and respond to privacy complaints within 30 days, subject to the nature and complexity of the complaint.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
OAIC website: https://www.oaic.gov.au/
22. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
* privacy laws;
* healthcare requirements;
* technology;
* our services;
* our service providers; or
* our information-handling practices.
23. This practice may use AI-assisted clinical documentation tools (including Heidi Health and Lyrebird Health) to help prepare consultation notes. These tools securely process the conversation during your consultation to generate a draft clinical record, which is reviewed, edited and approved by your doctor before being added to your medical record. Your privacy is protected in accordance with Australian privacy legislation and practice policies. Please advise your doctor if you do not consent to the use of an AI scribe during your consultation.
Last reviewed: 15/08/2026