Dr Carolina Gonzalez Private Clinical Practice (the Practice, we, us) provides health services and is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Health privacy laws and professional obligations may also apply. This policy explains how we manage personal information, including sensitive health information.
1. Information we collect and hold
Depending on your relationship with the Practice, we may collect and hold:
- identity and contact details, including your name, email address, telephone number, and location;
- health and other sensitive information, including symptoms, health history, treatments, test results, clinical records, practitioner observations, care plans, and relevant lifestyle, family, or relationship circumstances;
- application, referral, appointment, engagement, account, billing, and payment-status information;
- documents, correspondence, portal entries, reflection notes, questions, feedback, complaints, and access or correction requests;
- information supplied by a referrer or authorised representative, including their identity, role, and contact details; and
- technical information needed to operate and secure the website and portal, such as IP address, browser or device information, authentication and session data, and server or security logs.
We collect sensitive information only where you consent or where collection is otherwise permitted by law, and where it is reasonably necessary for our functions or activities.
2. How we collect information
We usually collect information directly from you through website forms, the client portal, consultations, telephone calls, email, documents, and other correspondence. We may also collect information from a person you authorise, a referrer, another health practitioner, a laboratory or service provider, or another source where you consent or the law permits.
If you give us personal information about another person, you must have their consent or other lawful authority to do so and, where practicable, make this policy available to them.
You may make a general inquiry anonymously or using a pseudonym where practicable. We will usually need your correct identity to assess an application, provide health services, maintain clinical records, or give portal access.
3. Why we collect, use, and disclose information
We collect, hold, use, and disclose personal information to:
- assess applications and referrals and communicate about next steps;
- provide, coordinate, and review clinical care and maintain health records;
- manage appointments, portal access, documents, engagements, billing, and Practice administration;
- communicate with health practitioners, laboratories, or other people involved in your care where you authorise us or the law permits;
- protect clients, the Practice, and its systems, and investigate suspected misuse or security incidents; and
- meet legal, regulatory, insurance, professional, accounting, and record-keeping obligations and respond to complaints or legal processes.
If required information is not provided, we may be unable to assess an application or referral, provide suitable care, communicate with you, or meet our professional obligations.
4. Who we may disclose information to
We disclose personal information only for the purpose for which it was collected, for a related purpose you would reasonably expect, with your consent, or where permitted or required by law. Recipients may include:
- health practitioners, laboratories, and other care providers you authorise;
- service providers supporting secure hosting, data or file storage, email delivery, information technology, communications, payments, accounting, legal services, or Practice administration;
- insurers, professional advisers, regulators, courts, tribunals, law-enforcement bodies, or government agencies where authorised or required by law; and
- people or organisations necessary to lessen or prevent a serious threat to health or safety, or in another permitted health situation.
Service providers may access only the information reasonably needed to perform their services. We do not sell personal information. We do not use or disclose health information for direct marketing unless we have your express consent and the law permits it.
Applications and referrals are reviewed by a person. At the date of this policy, we do not use automated decision-making to determine access to clinical care.
5. Overseas storage and disclosure
The Practice's website, application, and database use cloud infrastructure located in the United States. Email delivery and other technical service providers may also process or store personal information in the United States.
When we work with a person outside Australia, information may be disclosed in that person's country to the person or to a practitioner or service provider they authorise. The countries involved depend on the person's location and requested care. Where required, we take reasonable steps under APP 8 before disclosing personal information to an overseas recipient.
6. Security and retention
We take reasonable administrative and technical steps appropriate to the sensitivity of health information to protect it from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include access-controlled systems, authenticated portal access, encrypted network connections, service-provider controls, and limiting access to people who need the information for an authorised purpose.
No internet transmission or storage system is completely secure. Please avoid sending unnecessary health information through ordinary email and tell us promptly if you believe your information or portal access has been compromised.
We retain health records and other information for as long as required by applicable laws and professional obligations, and otherwise only for as long as reasonably necessary. When information is no longer required, we take reasonable steps to destroy it securely or de-identify it, subject to lawful retention, backup, and record-keeping requirements.
7. Access and correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. Contact the Privacy Officer at hello@drcarolina.co and describe the information and the access or correction requested.
We may need to verify your identity. We will respond within a reasonable period, generally within 30 days. There is no charge to make a request, although a reasonable charge may apply to providing access where the law allows and we tell you in advance. If we refuse access or correction, we will give written reasons and explain available complaint options unless the law permits otherwise.
8. Privacy complaints
To make a privacy complaint, write to the Privacy Officer at hello@drcarolina.co. Please describe what happened, include relevant dates and contact details, and state the outcome you are seeking. We will acknowledge the complaint, investigate it fairly, and aim to respond within 30 days.
If you are not satisfied with our response, or we have not responded within a reasonable time, you may complain to the Office of the Australian Information Commissioner (OAIC) online or by calling 1300 363 992. You may also have a right to contact an applicable state or territory health complaints body.
9. Data breaches
We assess suspected data breaches and take steps to contain and remediate them. Where the Notifiable Data Breaches scheme applies, we will notify affected individuals and the OAIC when required by law.
10. Updates and contact
We review this policy regularly and will publish changes on this page with a revised update date. You may request a free copy in another reasonably available form.
For questions, access or correction requests, complaints, or an alternative copy, contact:
Privacy OfficerDr Carolina Gonzalez Private Clinical Practice
hello@drcarolina.co