A quick guide to privacy
Optometry
Published on 30 Mar 2026
Healthcare practitioners operate in an environment where the handling of personal and health information is central to clinical care, patient trust, and professional accountability. Clinicians must navigate the regulatory framework that governs the collection, use, disclosure, and safeguarding of sensitive health information. This applies across all practice settings – including public hospitals, private clinics, allied health services, pathology, and digital health.
Understanding the Health Records and Information Privacy Act 2002 (NSW) is essential to ensure lawful practice, upholding ethical duties of confidentiality, and maintaining patient confidence in the healthcare system.
The Act governs how health information is managed within NSW. It sets out 15 Health Privacy Principles (HPPs) that regulate how health service providers collect, store, use, disclose, and provide access to health information. The Act applies to both public and private sector health organisations in NSW, and individual practitioners. For clinicians, the Act is the primary statutory guide for ensuring patient information is dealt with lawfully.
Health Privacy Principles – a quick guide
1. A purpose for collection. Only collect health information when it is lawful, directly related to your clinical or organisational function, and reasonably necessary for that purpose.
2. Collection must be relevant, accurate, and not intrusive. Ensure collected information is relevant, minimal, accurate, and collected in a way that does not unreasonably intrude on the patient’s personal affairs.
3. Collection from the individual. Collect health information directly from the patient unless it is unreasonable or impractical to do so.
4. Patient awareness (notification). When collecting information, take reasonable steps to inform the patient of who you are, why you are collecting it, how it will be used, who it may be disclosed to, and their rights to access it.
5. Retention and security. Keep health information only as long as necessary, dispose of it securely, and protect it against loss, misuse, and unauthorised access or disclosure.
6. Transparency about information held. Patients must be able to find out whether you hold health information about them, what you hold, how it is used, and their entitlement to access it.
7. Access. Provide patients with timely, affordable access to their health information, subject only to lawful exceptions.
8. Correction. On request, amend health information to ensure it is accurate, complete, up-to-date, and not misleading, or attach a patient statement if you decline the request.
9. Accuracy before use. Before using health information, take reasonable steps to ensure it is accurate, relevant, up-to-date, and not misleading about the purpose for which it will be used.
10. Limits on use. Use health information only for the purpose it was collected unless consent is given or a lawful exception applies (e.g. emergency, threat to life, research, or management of health services).
11. Limits on disclosure. Do not disclose health information unless the patient has consented, the disclosure is expected and directly related to the primary purpose, or another legal exception applies (e.g. emergency, public safety, investigation).
12. Identifiers. Only assign, adopt, use, or disclose identifiers when necessary for efficient function or permitted by law.
13. Anonymity. Provide opportunities for patients to remain anonymous where lawful and practicable, such as when providing general information or some services.
14. Transborder data flows. Do not send health information outside NSW or to a Commonwealth agency unless adequate protections exist or another legal basis applies (e.g. consent, contract necessity, emergency).
15. Linkage of health records. Health information cannot be linked in a records linkage system without the patient’s express consent, unless a lawful exemption applies.
Data breaches
A health data breach is not defined as a standalone statutory term. However, in practice it refers to any event in which health information held by a NSW public or private health organisation is accessed, used, disclosed, altered, or lost in a way that contravenes the HPPs. This may include:
- Unauthorised access – someone gains access to health information without a lawful basis e.g. a staff member viewing a patient’s record out of curiosity, or unauthorised access due to poor access controls.
- Unauthorised use – health information is used for a purpose not permitted under the HPPs e.g. using patient data for research, marketing, or training without consent or another lawful exception.
- Unauthorised disclosure – health information is shared with a person or body that is not entitled to receive it e.g. emailing results to the wrong patient, disclosing details to a family member without consent, or improper verbal disclosures.
- Loss of health information – where an organisation loses information in circumstances that create a risk of unauthorised access or disclosure e.g. lost USB drives, misplaced files, or misdirected documents that cannot be recovered.
- Failure to protect health information – security failures, either technical, physical, or administrative, that allow a confidentiality breach. These may be caused by:
- cyberattacks (ransomware, phishing)
- poor password practices
- inadequate storage or destruction processes.
Related resources
How to be a better practitioner and avoid complaints against you
Listen to our joint podcast with Optometry Australia to hear expert tips for responding to patient complaints - and how to avoid them in the first place.
PodcastFor health practitionersOptometry

Webinars with Optometry Australia
VideoFor health practitionersOptometry