cohealth’s staff are required to respect the confidentiality of personal information and the privacy of individuals.
cohealth has in place steps to protect the personal information cohealth holds from misuse, interference and loss, and from unauthorised access, modification, and disclosure. We use various physical and technological security measures to protect the personal information we hold, including locked storage of paper records and passworded access rights to computerised records.
We store your information securely and where possible, we keep it in an electronic file.
We have a data breach response plan, which we would follow in the unlikely event of a privacy or data breach. We are also required to comply with the mandatory ‘notifiable data breach’ scheme (the NDB scheme) under the Privacy Act. The NDB scheme applies when an ‘eligible data breach’ of personal information occurs.
An ‘eligible data breach’ occurs when:
- there is unauthorised access to or unauthorised disclosure of personal information, or a loss of personal information, that an organisation holds
- this is likely to result in serious harm to one or more individuals
- the organisation has not been able to prevent the likely risk of serious harm with remedial action
An organisation may take remedial steps to prevent the likelihood of serious harm occurring for any affected individuals after a data breach has occurred, in which case, the data breach is not an ‘eligible data breach’.
Where we have reasonable grounds to believe that we have experienced an eligible data breach, and remedial action cannot be used, we will promptly notify affected individuals and the Office of the Australian Information Commissioner about the breach in accordance with the Privacy Act.
When your personal information is no longer required, and in the case of your health information, the information has been retained for the required periods under the HPPs or otherwise under law, we will take steps to securely destroy the information or to ensure that the information is permanently de-identified. Note that under law we are generally required to hold your health information for a minimum of seven years from the date of last entry for an adult, and for any clients who are children until they would have reached 25 years old.