Privacy Policy

Introduction and Purpose

We are committed to protecting the privacy of your personal and health information. This policy explains how we collect, use, and disclose your information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Health Records Act 2001 (Vic).

Collection of Information

We collect information necessary to provide you with specialist medical treatment. This includes:

Personal Identifiers: Name, date of birth, contact details, and Medicare/insurance information.

Sensitive Health Information: Medical history, clinical notes, diagnostic results, and treatment plans.

Clinical Images: We may take photographs or images for your medical record with your express consent.

AI-Generated Information: Data processed through AI-enabled tools used during your consultation.

Website Privacy and Cookies

When you visit our website, we may use 'cookies' and similar technology to collect non-identifiable information about your visit.

What we collect: This includes your IP address, browser type, pages visited, and the time of your visit. This data is used solely for website analytics and to improve your user experience.

No Personal Info: We do not use cookies to collect personal health information or to identify individual users personally.

Tracking Pixels: We do not use third-party tracking pixels (such as the Meta Pixel) to track your health interests for advertising purposes.

Opt-Out: You can choose to disable cookies through your individual browser settings, though this may affect some website functionality.

Use of Artificial Intelligence

Our practice utilises Heidi, an AI clinical assistant, to ensure an accurate and comprehensive record of your care.

Transcription: Heidi transcribes clinical consultations simultaneously; no audio recordings of your appointment are stored.

Data Storage: All data processed by Heidi is locally hosted in Australia.

Human Oversight: All AI-generated outputs are subject to human review and clinical oversight by your surgeon.

No Model Training: Your personal information is not used to train AI models without your express consent.

Security: The platform complies with global security standards, including ISO 27001 and SOC 2.

Consent

When you first attend our practice, we will ask you to confirm your consent to the collection of your information. This consent allows our staff and practitioners to use your health information to facilitate your healthcare. You may withdraw your consent at any time.

Children’s Privacy

We manage the health information of minors with the same level of care and security as our adult patients.

Collection: Information regarding children is generally collected from a parent or legal guardian.

Consent: We rely on parental/guardian consent unless the minor is deemed 'Gillick competent' to provide their own consent under Australian law. The rights of children to the privacy of their health information, based on the professional judgement of the doctor and consistent with law, may restrict access to the child’s information by parents or guardians.

Record Retention: In accordance with Victorian law, records for children are retained until the individual reaches the age of 25, or for 7 years after the last clinical contact, whichever is longer.

Disclosure of Health Information

We may disclose your health information to third parties as part of your clinical care. This includes:

Healthcare Providers: Your General Practitioner, other specialists, pathology labs, imaging centres, and hospitals involved in your treatment.

Service Providers: Third parties who provide technical or administrative services (such as Heidi Health for clinical documentation or our practice management software), provided they comply with Australian privacy standards.

Legal Requirements: We may disclose information if required by law (e.g., a subpoena, court order, or mandatory reporting of a communicable disease).

Safety: To protect the safety of a patient or the public in accordance with ethical and legal obligations.

Data Security and Retention

We implement robust technical and administrative measures to protect your data from unauthorised access or loss. This includes:

Secure electronic medical record systems with role-based access.

Regular staff training on privacy and cybersecurity.

Retention: Records are kept in accordance with legal obligations and are destroyed securely once no longer required.

Change in Privacy Policy

As we plan to ensure our privacy policy remains current, this policy is subject to change. We may modify this policy at any time, in our sole discretion and all modifications will be effective immediately upon our posting of the modifications on this website. Please return periodically to review our privacy policy.

Access, Correction, and Complaints

You have the right to access and seek correction of your personal information. To do so, please contact us at hello@ravijain.com.au and we will endeavour to respond within 48 hours.