Privacy and Dignity Policy

Ayre Allied Health is committed to protecting the privacy and dignity of all individuals who engage with our services, including NDIS participants, clients, families, employees, and stakeholders. In the course of delivering high-quality allied health services, we are required to collect, store, use and disclose personal information in accordance with:

  • The Privacy Act 1988 (Cth), including the Privacy Amendment (Notifiable Data Breaches) Act 2017,

  • The Australian Privacy Principles (APPs),

  • The NDIS Practice Standards,

  • Professional codes of conduct relevant to registered health practitioners (e.g. AHPRA and SPA standards).

This policy outlines how Ayre Allied Health manages your personal information, ensuring privacy, confidentiality, respect, and informed consent.

This policy aligns with the Information Management and Participant Rights Quality Indicators under the NDIS Practice Standards as regulated by the NDIS Quality and Safeguards Commission.

Guiding Principles:

Outcome: Each participant accesses supports that respect and protects their dignity and right to privacy.

Indicators:

  • Privacy is embedded in all service delivery practices and environments.

  • Participants are informed, in a manner they understand, about what personal information will be collected, why, and how it will be stored or disclosed.

  • Consent is actively sought before sharing information.

  • All staff uphold a culture of confidentiality, response, and ethical practice in line with professional and regulatory obligations.\

What is Personal Information:

‘Personal information’ includes any information or opinion (true or not) that identifies or could reasonably identify an individual. This may include:

  • Name, address, contact details

  • Date of birth, Medicare number, NDIS number

  • Clinical notes, assessments, diagnoses, reports

  • Audio/video recordings

  • Payment details

  • Any other data provided in the course of delivering support

Sensitive information (e.g. health status, disability, cultural background, legal history) is given additional protection under privacy laws.

Information Storage and Security:

Client data is securely stored using:

  • Splose is a secure, cloud-based practice management system used by Ayre Allied Health. All client information is encrypted in transit and at rest, ensuring data security and privacy. Access to Splose is restricted to authorised clinicians and administrative staff, with Two-Factor Authentication (2FA) enabled for all users to protect sensitive health information.

  • Microsoft 365, protected by multi-factor authentication (MFA) and FIPS 140-2- compliant encryption.

  • Where cloud based systems store data outside Australia, Ayre Allied Health ensures providers comply with international data protection standards equivalent to Australian Privacy Principles.

Paper records are avoided unless necessary. Any physical documentation is stored in a locked filing system and securely destroyed by shredding services.

Access to client information is strictly role-based. Staff can only access information necessary to perform their duties. User access permissions are reviewed periodically to ensure appropriateness.

How is Personal Information Collected:

We collect personal information via:

  • Intake or referral forms

  • Phone or email communications

  • Online assessments

  • Direct interaction with clinicians

  • Exchange of information from third parties (e.g. GPs, Support Coordinators)

  • Consent forms and signed agreements

  • Website enquiry and appointment booking forms (including forms used to book a free intake call via Facebook or Instagram ads)

Website, Cookies and Online Advertising:

Our website uses cookies and similar tracking technologies, including the Meta Pixel, to understand how visitors use our site and to measure and improve the performance of our advertising on Facebook and Instagram.

  • Information collected this way may be shared with Meta Platforms, Inc. to deliver and measure our ads.

  • We do not send Meta any clinical or health information through the Pixel.

  • You can control how your data is used for advertising through your Facebook Ad Preferences, or by managing cookies in your browser settings.

Why We Collect Personal Information:

We collect personal information to:

  • Deliver high-quality, evidence-based allied health services

  • Comply with legal, clinical, and funding body requirements (e.g. NDIS)

  • Collaborate with other professionals when required (with consent)

  • Conduct supervision or clinical governance (with de-identification)

  • Monitor, evaluate, and improve our service delivery

When Personal Information is Disclosed:

Your information will only be shared under the following conditions:

  • You provide written informed consent

  • Disclosure is required by law (e.g. subpoena, child protection)

  • Failure to disclose may place you or another person at serious risk

  • It is reasonably necessary for your ongoing care (e.g. referrals to other health professionals)

  • De-identified information may be shared for supervision, research, or training purposes, where applicable and appropriate

All disclosures follow legal and ethical guidelines and are limited to what is necessary for the stated purpose.

Accessing and Amending Your Information:

You have the right to access your records. Requests must be made in writing to your clinician. Access is subject to clinical discretion, consistent with the Privacy Act.

  • A summary may be provided instead of the full file

  • Appointments may be required to review records

  • Standard fees apply for accessing or amending information

  • Requests to correct inaccurate personal information can be submitted in writing

Informed consent must be specific to the type of information being released and the recipient. Generic annual consent is insufficient.

Participants may nominate an advocate, guardian, or support person to assist in accessing or understanding their records. Information will be provided in accessible formats upon request (e.g. plain language summaries, visual supports, Easy Read).

Client Consent:

By engaging with Ayre Allied Health, you consent to:

  • The collection, storage, and use of your personal information as described in this policy

  • Participation in consultations where records are maintained securely

  • Information being shared only where lawful, ethical, and with consent

  • Participants may withdraw or modify their consent at any time in writing

  • Withdrawal of consent will not result in retaliation or disadvantage, though it may impact the ability to deliver certain services

  • The implications of withdrawing consent will be explained prior to action

Secondary uses (e.g. marketing, newsletters) will only occur with your explicit consent or opt-in.

Where restrictive practices are authorised and implemented, associated documentation is managed with heightened confidentiality and shared strictly in accordance with legal and regulatory requirements.

Privacy in Service Environments:

Ayre Allied Health ensures:

  • Private consultation rooms are used where possible in community environments

  • Conversations with private information cannot be overheard in public areas.

  • Screens are positioned to prevent unauthorized viewing.

  • Telehealth sessions are conducted in secure, private settings.

Privacy During Clinical Supervision:

Client cases may be discussed in supervision to ensure clinical quality and professional development. In these instances:

  • Information is de-identified where possible.

  • Supervisors are bound by confidentiality agreements and professional codes.

Archiving and Disposal:

  • Records for adult clients are kept for 7 years after the last service.

  • For children, records are kept until the client turns 25.

  • Files are stored electronically (Splose) or securely archived (SharePoint, encrypted folders).

  • Disposal includes permanent digital deletion and shredding of paper files.

Privacy Breach and Data Breach Notification:

We take all reasonable steps to protect your information. In the event of a breach:

  1. Immediate containment measures are implemented.

  2. The Clinical Director is notified.

  3. A risk assessment is conducted to determine likelihood of serious harm.

  4. Affected individuals are notified where required.

  5. The Office of the Australian Information Commissioner (OAIC) is notified if threshold is met under the Notifiable Data Breaches Scheme.

  6. The incident is recorded in the Incident Register.

  7. Corrective actions are implemented and reviewed.

Staff Confidentiality Obligations:

All staff, contractors and students:

  • Sign confidentiality agreement prior to commencement.

  • Complete privacy training at induction.

  • Participate in annual refresher training.

  • Understand that breaches may result in disciplinary action or regulatory notification.

Confidentiality obligations continue beyond employment.

Ayre Allied Health does not use covert recording. Any audio or video recording of sessions requires explicit written consent.

Complaints:

If you believe your privacy has been breached, you can:

  • Speak with your clinician or management.

  • Submit a written complaint via our Feedback and Complaints Form.

  • Contact the Office of the Australian Information Commissioner (OAIC) if unsatisfied:

Participants will not experience adverse consequences for raising privacy concerns or complaints.

Monitoring and Continuous Improvement:

Compliance with this policy is monitored through:

  • Periodic file audits

  • Access log reviews

  • Staff supervision

  • Incident trend analysis

  • Annual policy review

Findings are documented in the Continuous Improvement Register.

Policy Updates:

This policy is reviewed regularly and may be updated to reflect changes in legislation or service delivery. Clients will be informed of significant updates.

Contact Us:

For further information or to raise a concern, contact us at info@ayrealliedhealth.com.