Privacy policy
How Zenith Cardiology collects, uses, discloses and safeguards your personal and health information.
Updated July 2025
We are committed to protecting your privacy and managing personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and relevant healthcare accreditation standards, including the Diagnostic Imaging Accreditation Scheme (DIAS) and NATA expectations.
This policy explains how we collect, use, disclose and safeguard personal and health information.
Types of information collected
We may collect:
Personal information
- Name, date of birth, address and contact details
- Medicare, DVA or private insurance information
- Referrer and GP details
Health information
- Medical history relevant to investigations
- Diagnostic test results and reports
- Referral documentation and clinical notes
Health information is considered sensitive information under Australian law.
How information is collected
Information may be collected:
- From patients directly
- From referring practitioners
- Through secure messaging systems
- Via electronic referral platforms
- During diagnostic testing
- From Medicare, DVA or insurers where relevant
Use of information
Information is used to:
- Provide diagnostic cardiology services
- Produce clinical reports
- Communicate with referring practitioners
- Manage billing and administration
- Meet accreditation, quality assurance and audit obligations
- Maintain clinical records and regulatory compliance
- Improve service delivery
AI-assisted administrative processing
We may use secure AI-assisted tools for administrative functions such as:
- Extracting information from referrals
- Workflow optimisation
- Document organisation
Safeguards include:
- Human clinical oversight
- Secure Australian-hosted or compliant systems where possible
- No automated clinical decision-making without clinician review
Disclosure of information
We may disclose information to:
- Healthcare providers involved in patient care
- Medicare, DVA and insurers
- Accreditation bodies (DIAS, NATA)
- IT service providers bound by confidentiality agreements
- Regulatory authorities where required by law
We do not sell personal health information.
Data security
We maintain safeguards including:
- Secure clinical information systems
- Encryption and access controls
- Audit trails and user authentication
- Staff confidentiality obligations
- Secure backup and disaster recovery procedures
These measures align with healthcare accreditation expectations.
Overseas disclosure
Where IT providers store or process data overseas, reasonable steps are taken to ensure compliance with the Australian Privacy Principles, and contractual confidentiality protections are applied. Patients may request further details.
Access and correction
Patients may request access to their personal information, or correction where needed, by contacting us directly.
Retention of records
Health records are retained in accordance with state and Commonwealth healthcare record requirements and accreditation standards. Typically:
- Adults: a minimum of 7 years
- Children: until age 25, or as required by law
Complaints
Privacy concerns can be directed to our Privacy Officer at [email protected]. If a concern remains unresolved, complaints may be made to the Office of the Australian Information Commissioner (OAIC).
Policy updates
This policy may be updated periodically to reflect regulatory or operational changes.