Privacy and patient records
Keeping patient information secure, private conversations, keeping what people buy private, cyber security, and disposing of records.
Version 1 · approved 23 Sept 2026 by Sam Nguyen
Why this matters
Patient health information is protected by the Privacy Act 1988 and Victoria's Health Records Act 2001. It is used and shared only to care for the patient and run the pharmacy, in ways the patient would expect, with their consent, or where the law requires or allows it — for example PBS claims, SafeScript, or a serious threat to someone's safety.
Legal requirement Privacy Act 1988 (APPs) · Health Records Act 2001 (Vic) · Schedule cl 9(c) · OAIC Guide to Health Privacy ch 3
A patient asking to see or correct their information
A patient who asks to see or correct their information is referred to the pharmacist in charge, who responds within 30 days.
Pharmacy's own choice OAIC Guide to Health Privacy ch 4 · Health Records Act 2001 (Vic)
Where patient records are kept
Paper patient records should be kept in the dispensary or in a locked facility. Electronic records should be held securely on site or with a secure cloud provider. Ours: not yet recorded.
Regulator guidance VPA Guidelines G1.3.1 · VPA self-audit 1.3.2
Not giving information away by accident
Medicine details should be given only to the person they belong to, unless that person agrees otherwise. Take care that family members paying an account, anyone paying for someone else, and account-processing or statistics companies don't learn what medicines a person takes by accident. This doesn't stop disclosures the law requires, such as PBS claims.
Regulator guidance VPA Guidelines G1.3.2 and G2.4.10
Private conversations
Prescriptions are handed in, and counselling happens, at a private counselling point where others can't overhear. Staff use these points routinely for all prescription transactions. Where a longer or more sensitive conversation is needed, use the consultation room if there is one.
Legal requirement Schedule cl 9(g) · VPA Guidelines G2.4.6 and G2.4.7
Keeping medicines private at the counter
No one else in the pharmacy should be able to tell what medicine a customer is buying or collecting. Dispensed medicines go to the checkout covered or bagged, never in open baskets. Scripts waiting for collection are stored so no one can link them to the person.
Legal requirement Schedule cl 9(h) · VPA Guidelines G2.4.10
At the checkout
Checkout staff don't read out or discuss the medicine.
Pharmacy's own choice VPA Guidelines G2.4.10
Staff confidentiality
Every staff member should be told that everything they learn about customers is confidential.
Regulator guidance VPA Guidelines G2.4.10
Cyber security
- Everyone should have their own login with a strong password, and logins should never be shared. - Multi-factor authentication should be on for the daily login and every system holding patient information. - Software and operating systems should update automatically on every device. - Data should be backed up regularly to an encrypted, separate device or secure cloud, and a restore tested regularly (we do it quarterly). - Anti-virus and firewall software should be current. - Wi-Fi should be password-protected, the default password changed, and the network kept away from public use. - No personal or non-work apps should be installed on work devices. - Staff should be trained to spot phishing emails and texts.
Regulator guidance VPA Guidelines G1.3.2.1 · VPA self-audit 1.3.2
If there is a cyber incident
If a device, account or system may have been compromised: disconnect it from the network, tell the pharmacist in charge and the licensee straight away, and log it as an incident. Follow the pharmacy's cyber incident procedure and fill in the incident report form.
Pharmacy's own choice VPA Guidelines G1.3.2.1
Deciding whether to notify
The licensee assesses within 30 days whether it is a notifiable data breach. If it is, the licensee notifies the OAIC and affected patients as soon as practicable. Any breach involving My Health Record is reported to the Australian Digital Health Agency.
Legal requirement Privacy Act 1988 Part IIIC · OAIC Notifiable Data Breaches scheme · My Health Records Act 2012 (Cth)
Disposing of records
Records no longer needed — and only once any legal retention period has passed — are destroyed securely. Paper with patient details is shredded or placed in a locked secure-destruction bin, never in general waste. Old devices are wiped or destroyed before disposal.
Pharmacy's own choice VPA self-audit 1.3.2
Checks that go with this policy
- Test a data backup restore — Quarterly
PharmPolicy supports compliance. It is not legal advice, and it does not replace the licensee's own judgement or obligations under the Pharmacy Regulation Act 2010 and other laws.