Health Professional Councils Authority Logo

A quick guide to privacy

Optometry

Article

Published on 30 Mar 2026

Healthcare practitioners operate in an environment where the handling of personal and health information is central to clinical care, patient trust, and professional accountability. Clinicians must navigate the regulatory framework that governs the collection, use, disclosure, and safeguarding of sensitive health information. This applies across all practice settings – including public hospitals, private clinics, allied health services, pathology, and digital health.

Understanding the Health Records and Information Privacy Act 2002 (NSW) is essential to ensure lawful practice, upholding ethical duties of confidentiality, and maintaining patient confidence in the healthcare system.

Access the Privacy Act

The Act governs how health information is managed within NSW. It sets out 15 Health Privacy Principles (HPPs) that regulate how health service providers collect, store, use, disclose, and provide access to health information. The Act applies to both public and private sector health organisations in NSW, and individual practitioners. For clinicians, the Act is the primary statutory guide for ensuring patient information is dealt with lawfully.

Health Privacy Principles – a quick guide  

1. A purpose for collection. Only collect health information when it is lawful, directly related to your clinical or organisational function, and reasonably necessary for that purpose.

2. Collection must be relevant, accurate, and not intrusive. Ensure collected information is relevant, minimal, accurate, and collected in a way that does not unreasonably intrude on the patient’s personal affairs.

3. Collection from the individual. Collect health information directly from the patient unless it is unreasonable or impractical to do so.

4. Patient awareness (notification). When collecting information, take reasonable steps to inform the patient of who you are, why you are collecting it, how it will be used, who it may be disclosed to, and their rights to access it.

5. Retention and security. Keep health information only as long as necessary, dispose of it securely, and protect it against loss, misuse, and unauthorised access or disclosure.

6. Transparency about information held. Patients must be able to find out whether you hold health information about them, what you hold, how it is used, and their entitlement to access it.

7. Access. Provide patients with timely, affordable access to their health information, subject only to lawful exceptions.

8. Correction. On request, amend health information to ensure it is accurate, complete, up-to-date, and not misleading, or attach a patient statement if you decline the request.

9. Accuracy before use. Before using health information, take reasonable steps to ensure it is accurate, relevant, up-to-date, and not misleading about the purpose for which it will be used.

10. Limits on use. Use health information only for the purpose it was collected unless consent is given or a lawful exception applies (e.g. emergency, threat to life, research, or management of health services).

11. Limits on disclosure. Do not disclose health information unless the patient has consented, the disclosure is expected and directly related to the primary purpose, or another legal exception applies (e.g. emergency, public safety, investigation).

12. Identifiers. Only assign, adopt, use, or disclose identifiers when necessary for efficient function or permitted by law.

13. Anonymity. Provide opportunities for patients to remain anonymous where lawful and practicable, such as when providing general information or some services.

14. Transborder data flows. Do not send health information outside NSW or to a Commonwealth agency unless adequate protections exist or another legal basis applies (e.g. consent, contract necessity, emergency).

15. Linkage of health records. Health information cannot be linked in a records linkage system without the patient’s express consent, unless a lawful exemption applies.

Data breaches

A health data breach is not defined as a standalone statutory term. However, in practice it refers to any event in which health information held by a NSW public or private health organisation is accessed, used, disclosed, altered, or lost in a way that contravenes the HPPs. This may include:

Related resources