ACTEVATE PRIVACY POLICY AND DATA BREACH RESPONSE PLAN

Introduction

1. Actevate considers privacy as freedom from intrusion and public attention.

2. Confidentiality is the assurance that written and spoken information is protected from access and use by unauthorised persons. With respect to confidentiality, Actevate staff members are to refer to the Code of Conduct for Workplace Rehabilitation Providers and are to note that the disclosure or misuse of confidential information held on official records, including client files, is illegal.

Position Statement

3. Actevate recognises that each person has the right, in all aspects of their lives, to privacy, confidentiality and to be treated with dignity. The organisation is committed to protecting clients’ personal and health information. Actevate will ensure that its collection, documentation, use, disclosure, storage, access, correction, retention and disposal practices comply with the Australian Privacy Principles and, in relation to health information handled in New South Wales, the Health Privacy Principles under the Health Records and Information Privacy Act 2002 (NSW). Actevate will only collect information that is necessary for the provision of services to each client and will keep records in a standardised, accurate, objective and efficient manner. All client information will be kept in accordance with legal requirements, ensuring that the privacy and confidentiality of personal information is maintained at all times. Actevate will make information kept about a client available for that individual or their substitute decision makers to access at any time.

Legislation

4. In compliance with the following legislation – Privacy Act 1988 (Cth), Health Records (Privacy and Access) Act 1997 (ACT), and the NSW Health Records and Information Privacy Act 2002 – our service adheres to the privacy principles as outlined in this policy.

5. Application of Privacy Principles

The Australian Privacy Principles apply to personal information handled by Actevate under the Privacy Act 1988 (Cth).

Health information handled in New South Wales is also subject to the 15 Health Privacy Principles contained in Schedule 1 of the Health Records and Information Privacy Act 2002 (NSW). Health information includes information or an opinion about an individual’s physical or mental health, disability, expressed wishes about future health services, a health service provided or to be provided, and other personal information collected in connection with providing a health service.

Where more than one privacy requirement applies, Actevate will handle the information in a manner that complies with all applicable requirements. Where the requirements differ, Actevate will apply the requirement that provides the greater protection, unless otherwise required or authorised by law.

For services delivered in the Australian Capital Territory, Actevate will also comply with the Territory Privacy Principles and applicable health record requirements under the Health Records (Privacy and Access) Act 1997 (ACT).

Privacy Principles

Health Privacy Principles (HPP)

In addition to the Australian Privacy Principles outlined below, Actevate applies the NSW Health Privacy Principles to health information as follows:

HPP 1: Lawful collection: Actevate will only collect health information for a lawful purpose that is directly related to its functions or activities and where the collection is reasonably necessary for that purpose. Information will be collected by lawful means.

HPP 2: Relevant collection: Actevate will take reasonable steps to ensure that health information collected is relevant, accurate, up to date, complete and not excessive, and that its collection does not unreasonably intrude into the individual’s personal affairs.

HPP 3: Direct collection: Health information will be collected directly from the individual where reasonable and practicable. Where information is obtained from another person or organisation, Actevate will ensure that the collection is authorised, consented to or otherwise permitted by law.

HPP 4: Open collection: At or before collection, or as soon as practicable afterwards, Actevate will take reasonable steps to explain why the information is being collected, its intended uses and recipients, whether collection is required or voluntary, any consequences of not providing it, Actevate’s contact details, and the individual’s access and correction rights. Reasonable notification will also be provided where health information is collected from a third party.

HPP 5: Secure storage: Health information will be protected through reasonable physical, technical and organisational safeguards against loss, unauthorised access, use, modification, disclosure or other misuse. Information will not be retained for longer than required and will be securely disposed of or de-identified when lawful and appropriate.

HPP 6: Transparency: On request, Actevate will take reasonable steps to explain whether it holds health information about an individual, the nature of that information, the purposes for which it is used, and the individual’s access rights.

HPP 7: Access: Individuals may request access to their health information without unreasonable delay or expense, subject to applicable legal exceptions and identity-verification requirements.

HPP 8: Correction: Individuals may request that their health information be amended where it is inaccurate, incomplete, irrelevant, out of date or misleading. Requests will be managed in accordance with applicable legislation.

HPP 9: Accuracy before use: Before using health information, Actevate will take reasonable steps appropriate to the circumstances to ensure it is relevant, accurate, up to date, complete and not misleading.

HPP 10: Limited use: Health information will generally only be used for the purpose for which it was collected or for a directly related purpose that the individual would reasonably expect. A secondary use requires consent unless it is otherwise authorised or permitted by law.

HPP 11: Limited disclosure: Health information will generally only be disclosed for the purpose for which it was collected or for a directly related purpose that the individual would reasonably expect. Any other disclosure requires consent unless it is otherwise authorised or permitted by law.

HPP 12: Identifiers: Actevate will only assign or use a unique identifier where this is reasonably necessary to carry out its functions efficiently.

HPP 13: Anonymity: Where lawful and practicable, individuals will be given the option of interacting with Actevate anonymously. Actevate may need to verify identity where this is required to provide workplace rehabilitation, assessment or other funded services.

HPP 14: Transferrals: Health information will only be transferred outside New South Wales where the requirements of HPP 14 are satisfied, including where the individual has consented, the transfer is necessary for an agreed service and appropriate safeguards apply, or the transfer is otherwise authorised or permitted by law. This includes consideration of cloud-based and AI service providers whose systems may process information outside New South Wales.

HPP 15: Linkage: Actevate will not include health information in a health records linkage system, or disclose an identifier for that purpose, without the individual’s express consent unless the linkage is otherwise authorised or permitted by law.

These requirements are applied together with the relevant APP provisions below. Exceptions will only be relied upon where supported by applicable legislation and appropriately documented.

Australian Privacy Principles (APP)

APP 1: Open and transparent management of personal information

This principle sets out how Actevate can use and disclose personal information. Health service providers need to be open about how they handle health information.

On first meeting with the client, staff / contractors of Actevate are to provide a copy of the Consent Form and Actevate Privacy Policy. Clients are to sign the Consent Form to indicate that they have consented to the referral to our service and that they have been informed about what information will be gathered about them during the assessment process and how that information will be utilised/stored.

a. Informing the person from whom information is collected

By providing the Privacy Policy and signing the Consent Form, Actevate will clarify with the client the accuracy of information received through the referral process and will make them aware:

  • That information is being collected and for which purposes
  • Of the intended recipients of the information
  • Whether the supply of the information by the individual is required by law or is voluntary, and any consequences for the individual if the information (or any part of it) is not provided
  • Of the client’s right of access to, and correction of the information
  • How records are kept – i.e., electronic database
  • That the client has the right to withhold information for privacy reasons. (Clarification that withholding information may impact service planning)
  • The only information held by Actevate about a client will be information necessary to assess the need for a service, and to provide the service. Information will be as objective as possible, yet relevant and up to date.

Artificial Intelligence (AI) Usage

Actevate may use approved Artificial Intelligence (AI) technologies to support the delivery of workplace rehabilitation services and business operations. AI may assist with administrative tasks, documentation, drafting correspondence and reports, summarising information, transcription (where applicable), and improving operational efficiency.

AI technologies are used as support tools only and do not replace the professional judgement, clinical reasoning or decision-making of Actevate staff.

Where AI technologies are used, Actevate will take reasonable steps to ensure that:

  • AI is used in accordance with applicable privacy legislation, confidentiality obligations and the Australian Privacy Principles.
  • Personal information is only processed through approved AI systems where necessary for legitimate business purposes and in accordance with applicable privacy requirements and, where required, client consent.
  • Where practicable, de-identified or anonymised information is used in preference to identifiable personal information.
  • Access to personal information processed through AI systems is restricted to authorised personnel.
  • AI-generated outputs are reviewed by an appropriately qualified staff member for accuracy, relevance and appropriateness before being relied upon or shared.
  • Clients may request information about how their personal information is managed, including where approved AI technologies are used.

Actevate does not use client information to train publicly available AI models. Where third-party AI providers are engaged, Actevate will take reasonable steps to ensure appropriate contractual, privacy and security safeguards are in place.

APP 2 – Anonymity and pseudonymity

For clients receiving services, Actevate is required to identify them to funding bodies (insurers). It is therefore unlawful and impractical for us to deal with clients who have not identified themselves.

Where it is lawful and practicable to do so, individuals may deal with us anonymously (e.g., when enquiring about our products and services generally).

APP3 – Collection of solicited personal information

Actevate collects personal and sensitive information from people only if this information is necessary for the provision of our service, functions and activities and only if consented to by the person.

Actevate only collects information in accordance with permitted general and health situations in relation to our service delivery. Actevate will only collect information by lawful and fair means.

a. Purpose of Collecting Information The purposes may include:

  • Prioritising and processing referrals
  • Providing information regarding appropriate services
  • Referring clients on to other services (with their permission)
  • Assessing clients’ service needs, offering service, referral and equipment to meet those needs
  • Providing relevant agreed services to clients
  • Assessing WH&S status of client’s homes/workplaces for service provision
  • Service provision
  • Continuity of care
  • Keeping client records
  • Sending out and processing client accounts
  • Meeting funding, legal and regulatory requirements
  • Quality measurement and management

b. Type of information collected and held Includes but is not limited to:

  • Name and contact details
  • Details of birth, language preference and cultural affiliations
  • Pre-injury earnings
  • Accommodation, living arrangements
  • Health, medication
  • Functional abilities
  • Quality of life issues
  • Referral requirements
  • Workplace details and contacts
  • Present and future service requirements
  • Outcomes

Documentation kept on the client’s individual file includes but is not limited to:

  • Referral information
  • Health screening data
  • Physical assessment data
  • Assessment reports – Actevate and other
  • Assessment of ability to perform duties and tasks of daily living
  • SIRA Certificate of Capacity
  • WH&S risk assessment and risk management plan (if required)
  • Consent forms
  • Complaints
  • Reports/information from and to other health practitioners
  • Client progress notes

c. Staff, Contractors and Students

Actevate collects information from you which is necessary to properly manage and operate its business. This includes collecting personal information such as your name, address and contact details, professional experience, qualifications and past employers, and any other information which may be necessary appropriately conduct its business.

d. Job applicants and Students

Actevate collects information from you which is necessary to assess and engage job applicants. This includes collecting personal information such as your name, address and contact details, professional experience, qualifications, references and past employers, and any other information which is necessary to process your job application.

APP 4 – Dealing with unsolicited personal information

Actevate will advise clients of any information obtained or collected, including unsolicited personal or sensitive information. If the information received is not relevant to the provision of Actevate services, function and activities it will either destroy or de-identify the information.

APP 5 – Notification of the collection of personal information

All Actevate clients will be advised during referral and assessment processes about what information we collect and for what purpose.

Actevate will not collect information from sources that the client has not consented to.

a. Sources of information

We obtain personal information from the following:

  • The individual to whom the information relates
  • The parent or guardian if a person is under the age of 16 years or has an official guardian who is authorised to pass on such information
  • Other persons whom the individual has authorised to pass on the information
  • Other health or service providers whom the individual has authorised to pass on information to Actevate
  • Workplace representatives

APP 6 – Use or disclosure of personal information

The organisation does not disclose any of the above information to others without the client’s or the client’s authorised representative’s consent.

Actevate does not disclose or release client information to any persons or entities outside of Australia.

Actevate releases or discloses personal information only as permitted by general and health situations and only as required under Australian legislation i.e., mandatory reporting, reporting as per government funding contracts.

1. Disclosure of Client Information

In certain circumstances, Actevate may obtain and release personal information from:

  1. A client’s agent (insurer)
  2. An individual’s representatives (e.g. authorised representatives or legal advisers)
  3. An individual’s employer
  4. An individual’s health service provider / treating health professional

We may also disclose information with the consent of the person responsible where:

  • The client to whom the information relates is deceased or physically or legally incapable of giving consent to the disclosure, or physically cannot communicate consent to the disclosure; and
  • The disclosure is not contrary to any wish (of which the organisation is aware) expressed by the client before that person became unable to give or communicate consent
  • Information is needed urgently for medical treatment or when disclosure is essential to protect a person from imminent harm. Even in these circumstances, the client, guardian or “person responsible” would, if possible, be asked permission to release confidential information.

These disclosures and others to third parties may be for:

  • Referrals and feedback to other service providers, including health professionals and community services providers
  • Client service provision by external contractors, e.g. cleaners, lawn mowing services
  • Workers compensation authorities

Actevate obtains some services from external service providers. Some clients’ information may be provided to them on a confidential basis if the client gives his or her consent.

APP 7 – Direct marketing

Actevate does not collect a client’s personal information for the purposes of marketing nor provide direct marketing communications to clients.

For stakeholders utilising services other than workplace rehabilitation services (e.g., pre-employment services, OH&S Training), Actevate will seek consent to use or disclose personal information for the purposes of informing individuals about:

  • Actevate products and services that may be of interest and suit their requirements and
  • promotions or other opportunities in which they may be interested
  • We assume we have consent to use service providers to assist us with marketing (e.g. mailing services or advertising agencies) unless we are told otherwise (see ‘Contacting us’ below).

Actevate does provide newsletters to other scheme stakeholders (i.e. scheme agents, employers) quarterly. These do not contain client personal information and stakeholders can elect not to receive these communications.

APP 8 – Cross border disclosure of personal information

As per APP 6 above.

Some approved AI service providers engaged by Actevate may process information using cloud-based infrastructure located outside Australia. Where this occurs, Actevate will take reasonable steps to ensure appropriate privacy protections are in place and that the provider complies with Actevate’s contractual and privacy requirements.

APP 9 – Adoption, use or disclosure of government related identifiers

Actevate does not adopt, use or disclose government related identifiers.

APP 10 – Quality of personal information

a. Data quality

Actevate will take reasonable steps to ensure that your personal information which is collected, used or disclosed is accurate, complete and up to date.

APP 11 – Security of personal information

Actevate ensures that it provides security and protection of client personal information from misuse, interference and loss and unauthorised access, modification or disclosure.

a. Storage

All personal information held by Actevate is stored securely in either hard copy or electronic form.

b. Data security

Actevate strives to ensure the security, integrity and privacy of personal information, and will take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Actevate reviews and updates (where necessary) its security measures considering current technologies.

To protect personal information, Actevate’s electronic safeguards include:

  • Electronic client information is password protected - each user has his/her own security profile to access the Internet Technology infrastructure including the Case Manager® software. Access rights can be limited to read only, modify or full access.
  • Client information is not sent through unprotected emails
  • Access to client information is limited to authorised staff
  • Actevate servers (including Case Manager® application) is hosted by a third party company iTonCloud, who monitor, maintain and manage the IT infrastructure. All systems are backed up daily with media being sent off site once verification of a successful backup has been completed.

The organisation’s procedural safeguards include:

  • All staff are trained in confidentiality and the Privacy Act
  • If an outside person enters the office, the staff member closes the computer screen if it shows personal client information
  • Meetings with visitors take place in organisation’s meeting rooms whenever possible
  • Meetings with clients will only be conducted in an area which allows sufficient privacy

Artificial Intelligence and Information Security

Where Actevate uses approved AI-enabled systems provided by third-party suppliers, Actevate will take reasonable steps to ensure appropriate privacy, confidentiality and information security safeguards are in place to protect personal information from unauthorised access, misuse, interference, loss, modification or disclosure.

This includes considering, where appropriate:

  • the provider’s privacy and security practices;
  • user authentication and access controls;
  • encryption and data transmission security;
  • data storage and retention arrangements;
  • whether information is retained or used by the provider for product improvement or model training; and
  • compliance with applicable Australian privacy requirements and contractual obligations.

c. Online transfer of information

While Actevate does all it can to protect the privacy of your personal information, no data transfer over the internet is 100% secure. When you share your personal information with Actevate via an online process, it is at your own risk.

There are ways you can help maintain the privacy of your personal information, including:

  • (a) always closing your browser when you have finished your user session
  • (b) always ensuring others cannot access your personal information and emails if you use a public computer
  • (c) never disclosing your username and password to third parties

(d) Use of cookies

A ‘cookie’ is a small data file placed on your machine or device which lets Actevate identify and interact more effectively with your computer.

Cookies which are industry standard and are used by most web sites, including those operated by Actevate, can facilitate a user’s ongoing access to and use of a site. They allow Actevate to customise our website to the needs of our users. If you do not want information collected through the use of cookies, there is a simple procedure in most browsers that allows you to deny or accept the cookie feature. However, cookies may be necessary to provide you with some features of our on-line services via the Actevate website.

(e) Links to other sites

Actevate may provide links to third party websites. These linked sites may not be under our control and Actevate is not responsible for the content or privacy practices employed by those websites. Before disclosing your personal information on any other website, we recommend that you carefully read the terms and conditions of use and privacy statement of the relevant website.

(f) Data breaches and the Notifiable Data Breaches scheme

A data breach occurs where personal or health information is subject to unauthorised access or disclosure, is lost in circumstances where unauthorised access or disclosure is likely, or is otherwise compromised. This includes actual and suspected data breaches involving Actevate staff, contractors, systems, third-party service providers and approved AI technologies.

Actevate will respond to actual and suspected data breaches in accordance with its Data Breach Response Plan and the four-step approach recommended by the Office of the Australian Information Commissioner (OAIC):

  • Contain the breach.
  • Assess the breach and associated risks.
  • Notify affected individuals and relevant parties where required.
  • Review the incident and take action to prevent recurrence.

An eligible data breach arises under the Privacy Act 1988 where:

  • there has been unauthorised access to or disclosure of personal information, or loss of personal information held by Actevate;
  • a reasonable person would conclude that the breach is likely to result in serious harm to one or more individuals; and
  • Actevate has not been able to prevent the likely risk of serious harm through remedial action.

Where Actevate has reasonable grounds to suspect that an eligible data breach may have occurred, it will conduct a reasonable and expeditious assessment. Actevate will take all reasonable steps to complete the assessment within 30 calendar days after becoming aware of the grounds for suspicion and, wherever practicable, will complete it sooner.

Where Actevate has reasonable grounds to believe that an eligible data breach has occurred, it will prepare and submit a statement to the Australian Information Commissioner and notify affected individuals, or individuals at risk of serious harm, as soon as practicable, unless an exception applies.

Notifications will include Actevate’s identity and contact details, a description of the breach, the kinds of information involved, and recommended steps individuals should take in response.

Actevate will also consider whether notification is required to another regulator, scheme authority, insurer, contracting organisation, law-enforcement body, cyber-security authority or other affected entity.

APP 12 – Access to personal information

a). Access to own information

Clients have the right to access their own information held by Actevate. If a request to access personal information is made, Actevate will validate the identity of anyone making a request to access client information. This is to ensure that information is not passed to a person who is not authorised to receive it.

While Actevate aims to meet all requests for access to personal information, in a small number of cases and where permitted to do so by law, Actevate may not give access or may do so only under conditions.

Subject to applicable laws, Actevate may destroy records containing personal information when the record is no longer required by Actevate.

APP 13 – Correction of personal information

If clients find that the personal information held is not correct, complete or up to date, Actevate will correct their records accordingly.

a). Length of Time Records Are Held

All information regarding clients will be destroyed seven years after clients cease to receive services or in the case of children when the client reaches 25 years of age, whichever is the latest

Data Breach Response Plan

A data breach occurs when personal or health information is lost, accessed or disclosed without authorisation, or otherwise compromised. This includes actual or suspected breaches involving Actevate staff, contractors, systems or third-party service providers.

All staff and contractors must immediately report an actual or suspected data breach to their direct manager and the Actevate General Manager. The General Manager, or their delegate, is responsible for coordinating and documenting the response and engaging relevant internal or external expertise where required.

Actevate will respond using the following four-step process, based on the Office of the Australian Information Commissioner’s (OAIC) Data Breach Action Plan for Health Service Providers:

Reporting and activation

  1. Any staff member or contractor who becomes aware of an actual or suspected data breach must immediately:
  • take safe and practicable steps to prevent further disclosure or loss;
  • notify their direct manager and the General Manager;
  • avoid deleting or altering relevant records, emails, logs or other evidence; and
  • record when and how the incident was discovered.
  1. The General Manager, or delegated Privacy Officer, will determine whether to activate the Data Breach Response Team.
  2. The response team may include, depending on the incident:
  • the General Manager or delegate, as response lead;
  • the person responsible for privacy and governance;
  • relevant operational management;
  • IT, cyber-security or forensic support;
  • legal, risk, communications or records-management support; and/or
  • relevant third-party service providers.
  1. The response lead will maintain an incident record documenting decisions, actions, evidence, notifications, responsibilities and relevant dates.
Data Breach Response Plan
Containment
  1. Record when and how the breach was identified and when this response plan was activated.
  2. Take immediate steps to stop or limit the breach and prevent further compromise. Depending on the circumstances, this may include recovering information, recalling an email, securing accounts, changing access permissions or passwords, disconnecting an affected system, or contacting an IT or third-party service provider.
  3. Preserve relevant records, emails, system logs and other evidence while ensuring that containment actions do not create additional risks.
Assessment
  1. Gather and document relevant information, including:
    • what occurred and how;
    • the date, time, location and duration of the breach;
    • the information and systems involved;
    • who accessed or may have accessed the information;
    • the individuals or organisations potentially affected; and
    • the containment or remedial actions already taken.
  2. Assess the possible consequences for affected individuals, including physical, psychological, emotional, financial, identity-related, employment-related or reputational harm.
  3. Determine whether:
    • remedial action has prevented the likelihood of serious harm; or
    • the breach is likely to result in serious harm and meets the criteria for an eligible data breach under the Privacy Act 1988.
  4. Where an eligible data breach is suspected, Actevate will take all reasonable steps to complete its assessment within 30 calendar days of becoming aware of the grounds for suspicion. The assessment process, evidence considered and outcome must be documented.
Notification
  1. Where Actevate has reasonable grounds to believe that an eligible data breach has occurred, it will notify the Office of the Australian Information Commissioner and affected individuals, or individuals at risk of serious harm, as soon as practicable.
  2. Notifications will include:
    • Actevate’s identity and contact details;
    • a description of the breach;
    • the types of information involved; and
    • recommended steps individuals can take to reduce potential harm.
  3. Actevate will also consider whether notification is required to any relevant insurer, employer, contracting organisation, scheme authority, regulator, cyber-security body, law-enforcement agency or third-party service provider.
Prevention
  1. Investigate the cause of the breach and evaluate whether Actevate’s response was timely and effective.
  2. Implement and document corrective and preventive actions where required, including changes to systems, security controls, access permissions, policies, procedures, contractual arrangements or staff training.
  3. Review the effectiveness of the completed actions and update this Data Breach Response Plan where necessary.

6. Requests for Access to Records, Complaints and Record Updates

Individuals who wish to access their records, who believe that Actevate may have breached their privacy rights or to update personal information held by Actevate should contact us via:

All correspondence to be addressed to - The Director: Actevate

By phone: 1300 663 155 (Head office)

Email: admin@actevate.com.au

In writing: GPO Box 3408, Sydney NSW 2001

Web link: https://www.actevate.com.au/page/contact-us

If we do not satisfactorily answer concerns, clients have the right to make a complaint to the Privacy Commissioner:

In writing: Office of Privacy Commissioner GPO Box 5218, Sydney NSW 1042

By phone: 1300 363 992

Cross Referencing and Further Reading