1.1. Regenerate Health considers privacy as freedom from intrusion and public attention.
1.2. Confidentiality is the assurance that written and spoken information is protected from access and use by unauthorised persons. With respect to confidentiality, Regenerate Health staff members are to refer to the Code of Conduct for Workplace Rehabilitation Providers and are to note that the disclosure or misuse of confidential information held on official records, including client files, is illegal.
2.1. Regenerate Health recognises that each person has the right, in all aspects of their lives, to privacy, confidentiality and to be treated with dignity. The organisation is committed to protecting clients' personal and health information. Regenerate Health will ensure that its collection, documentation, use, disclosure, storage, access, correction, retention and disposal practices comply with the Australian Privacy Principles and, in relation to health information handled in New South Wales, the Health Privacy Principles under the Health Records and Information Privacy Act 2002 (NSW). Regenerate Health will only collect information that is necessary for the provision of services to each client and will keep records in a standardised, accurate, objective and efficient manner. All client information will be kept in accordance with legal requirements, ensuring that the privacy and confidentiality of personal information is maintained at all times. Regenerate Health will make information kept about a client available for that individual or their substitute decision makers to access at any time.
3.1. In compliance with the following legislation – Privacy Act 1988 (Cth), Health Records (Privacy and Access) Act 1997 (ACT), and the NSW Health Records and Information Privacy Act 2002 – our service adheres to the privacy principles as outlined in this policy.
3.2. Application of Privacy Principles
The Australian Privacy Principles apply to personal information handled by Regenerate Health under the Privacy Act 1988 (Cth).
Health information handled in New South Wales is also subject to the 15 Health Privacy Principles contained in Schedule 1 of the Health Records and Information Privacy Act 2002 (NSW). Health information includes information or an opinion about an individual's physical or mental health, disability, expressed wishes about future health services, a health service provided or to be provided, and other personal information collected in connection with providing a health service.
Where more than one privacy requirement applies, Regenerate Health will handle the information in a manner that complies with all applicable requirements. Where the requirements differ, Regenerate Health will apply the requirement that provides the greater protection, unless otherwise required or authorised by law.
For services delivered in the Australian Capital Territory, Regenerate Health will also comply with the Territory Privacy Principles and applicable health record requirements under the Health Records (Privacy and Access) Act 1997 (ACT).
In addition to the Australian Privacy Principles outlined below, Regenerate Health applies the NSW Health Privacy Principles to health information as follows:
HPP 1: Lawful collection: Regenerate Health will only collect health information for a lawful purpose that is directly related to its functions or activities and where the collection is reasonably necessary for that purpose. Information will be collected by lawful means.
HPP 2: Relevant collection: Regenerate Health will take reasonable steps to ensure that health information collected is relevant, accurate, up to date, complete and not excessive, and that its collection does not unreasonably intrude into the individual's personal affairs.
HPP 3: Direct collection: Health information will be collected directly from the individual where reasonable and practicable. Where information is obtained from another person or organisation, Regenerate Health will ensure that the collection is authorised, consented to or otherwise permitted by law.
HPP 4: Open collection: At or before collection, or as soon as practicable afterwards, Regenerate Health will take reasonable steps to explain why the information is being collected, its intended uses and recipients, whether collection is required or voluntary, any consequences of not providing it, Regenerate Health's contact details, and the individual's access and correction rights. Reasonable notification will also be provided where health information is collected from a third party.
HPP 5: Secure storage: Health information will be protected through reasonable physical, technical and organisational safeguards against loss, unauthorised access, use, modification, disclosure or other misuse. Information will not be retained for longer than required and will be securely disposed of or de-identified when lawful and appropriate.
HPP 6: Transparency: On request, Regenerate Health will take reasonable steps to explain whether it holds health information about an individual, the nature of that information, the purposes for which it is used, and the individual's access rights.
HPP 7: Access: Individuals may request access to their health information without unreasonable delay or expense, subject to applicable legal exceptions and identity-verification requirements.
HPP 8: Correction: Individuals may request that their health information be amended where it is inaccurate, incomplete, irrelevant, out of date or misleading. Requests will be managed in accordance with applicable legislation.
HPP 9: Accuracy before use: Before using health information, Regenerate Health will take reasonable steps appropriate to the circumstances to ensure it is relevant, accurate, up to date, complete and not misleading.
HPP 10: Limited use: Health information will generally only be used for the purpose for which it was collected or for a directly related purpose that the individual would reasonably expect. A secondary use requires consent unless it is otherwise authorised or permitted by law.
HPP 11: Limited disclosure: Health information will generally only be disclosed for the purpose for which it was collected or for a directly related purpose that the individual would reasonably expect. Any other disclosure requires consent unless it is otherwise authorised or permitted by law.
HPP 12: Identifiers: Regenerate Health will only assign or use a unique identifier where this is reasonably necessary to carry out its functions efficiently.
HPP 13: Anonymity: Where lawful and practicable, individuals will be given the option of interacting with Regenerate Health anonymously. Regenerate Health may need to verify identity where this is required to provide workplace rehabilitation, assessment or other funded services.
HPP 14: Transferrals: Health information will only be transferred outside New South Wales where the requirements of HPP 14 are satisfied, including where the individual has consented, the transfer is necessary for an agreed service and appropriate safeguards apply, or the transfer is otherwise authorised or permitted by law. This includes consideration of cloud-based and AI service providers whose systems may process information outside New South Wales.
HPP 15: Linkage: Regenerate Health will not include health information in a health records linkage system, or disclose an identifier for that purpose, without the individual's express consent unless the linkage is otherwise authorised or permitted by law.
These requirements are applied together with the relevant APP provisions below. Exceptions will only be relied upon where supported by applicable legislation and appropriately documented.
APP 1: Open and transparent management of personal information
This principle sets out how Regenerate Health can use and disclose personal information. Health service providers need to be open about how they handle health information.
On first meeting with the client, staff / contractors of Regenerate Health are to provide a copy of the Consent Form and Regenerate Health Privacy Policy. Clients are to sign the Consent Form to indicate that they have consented to the referral to our service and that they have been informed about what information will be gathered about them during the assessment process and how that information will be utilised/stored.
a. Informing the person from whom information is collected
By providing the Privacy Policy and signing the Consent Form, Regenerate Health will clarify with the client the accuracy of information received through the referral process and will make them aware:
That information is being collected and for which purposes
Of the intended recipients of the information
Whether the supply of the information by the individual is required by law or is voluntary, and any consequences for the individual if the information (or any part of it) is not provided
Of the client's right of access to, and correction of the information
How records are kept – i.e., electronic database
That the client has the right to withhold information for privacy reasons. (Clarification that withholding information may impact service planning)
The only information held by Regenerate Health about a client will be information necessary to assess the need for a service, and to provide the service. Information will be as objective as possible, yet relevant and up to date.
Artificial Intelligence (AI) Usage
Regenerate Health may use approved Artificial Intelligence (AI) technologies to support the delivery of workplace rehabilitation services and business operations. AI may assist with administrative tasks, documentation, drafting correspondence and reports, summarising information, transcription (where applicable), and improving operational efficiency.
AI technologies are used as support tools only and do not replace the professional judgement, clinical reasoning or decision-making of Regenerate Health staff.
Where AI technologies are used, Regenerate Health will take reasonable steps to ensure that:
AI is used in accordance with applicable privacy legislation, confidentiality obligations and the Australian Privacy Principles.
Personal information is only processed through approved AI systems where necessary for legitimate business purposes and in accordance with applicable privacy requirements and, where required, client consent.
Where practicable, de-identified or anonymised information is used in preference to identifiable personal information.
Access to personal information processed through AI systems is restricted to authorised personnel.
AI-generated outputs are reviewed by an appropriately qualified staff member for accuracy, relevance and appropriateness before being relied upon or shared.
Clients may request information about how their personal information is managed, including where approved AI technologies are used.
Regenerate Health does not use client information to train publicly available AI models. Where third-party AI providers are engaged, Regenerate Health will take reasonable steps to ensure appropriate contractual, privacy and security safeguards are in place.
APP 2 – Anonymity and pseudonymity
For clients receiving services, Regenerate Health is required to identify them to funding bodies (insurers). It is therefore unlawful and impractical for us to deal with clients who have not identified themselves.
Where it is lawful and practicable to do so, individuals may deal with us anonymously (e.g., when enquiring about our products and services generally).
APP 3 – Collection of solicited personal information
Regenerate Health collects personal and sensitive information from people only if this information is necessary for the provision of our service, functions and activities and only if consented to by the person.
Regenerate Health only collects information in accordance with permitted general and health situations in relation to our service delivery. Regenerate Health will only collect information by lawful and fair means.
a. Purpose of Collecting Information
The purposes may include:
Prioritising and processing referrals
Providing information regarding appropriate services
Referring clients on to other services (with their permission)
Assessing clients' service needs, offering service, referral and equipment to meet those needs
Providing relevant agreed services to clients
Assessing WH&S status of client's homes/workplaces for service provision
Service provision
Continuity of care
Keeping client records
Sending out and processing client accounts
Meeting funding, legal and regulatory requirements
Quality measurement and management
b. Type of information collected and held
Includes but is not limited to:
Name and contact details
Details of birth, language preference and cultural affiliations
Pre-injury earnings
Accommodation, living arrangements
Health, medication
Functional abilities
Quality of life issues
Referral requirements
Workplace details and contacts
Present and future service requirements
Outcomes
Documentation kept on the client's individual file includes but is not limited to:
Referral information
Health screening data
Physical assessment data
Assessment reports – Regenerate Health and other
Assessment of ability to perform duties and tasks of daily living
SIRA Certificate of Capacity
WH&S risk assessment and risk management plan (if required)
Consent forms
Complaints
Reports/information from and to other health practitioners
Client progress notes
c. Staff, Contractors and Students
Regenerate Health collects information from you which is necessary to properly manage and operate its business. This includes collecting personal information such as your name, address and contact details, professional experience, qualifications and past employers, and any other information which may be necessary appropriately conduct its business.
d. Job applicants and Students
Regenerate Health collects information from you which is necessary to assess and engage job applicants. This includes collecting personal information such as your name, address and contact details, professional experience, qualifications, references and past employers, and any other information which is necessary to process your job application.
APP 4 – Dealing with unsolicited personal information
Regenerate Health will advise clients of any information obtained or collected, including unsolicited personal or sensitive information. If the information received is not relevant to the provision of Regenerate Health services, function and activities it will either destroy or de-identify the information.
APP 5 – Notification of the collection of personal information
All Regenerate Health clients will be advised during referral and assessment processes about what information we collect and for what purpose.
Regenerate Health will not collect information from sources that the client has not consented to.
a. Sources of information
We obtain personal information from the following:
The individual to whom the information relates
The parent or guardian if a person is under the age of 16 years or has an official guardian who is authorised to pass on such information
Other persons whom the individual has authorised to pass on the information
Other health or service providers whom the individual has authorised to pass on information to Regenerate Health
Workplace representatives
APP 6 – Use or disclosure of personal information
The organisation does not disclose any of the above information to others without the client's or the client's authorised representative's consent.
Regenerate Health does not disclose or release client information to any persons or entities outside of Australia.
Regenerate Health releases or discloses personal information only as permitted by general and health situations and only as required under Australian legislation i.e., mandatory reporting, reporting as per government funding contracts.
Disclosure of Client Information
In certain circumstances, Regenerate Health may obtain and release personal information from:
A client's agent (insurer)
An individual's representatives (e.g. authorised representatives or legal advisers)
An individual's employer
An individual's health service provider / treating health professional
We may also disclose information with the consent of the person responsible where:
The client to whom the information relates is deceased or physically or legally incapable of giving consent to the disclosure, or physically cannot communicate consent to the disclosure; and
The disclosure is not contrary to any wish (of which the organisation is aware) expressed by the client before that person became unable to give or communicate consent
Information is needed urgently for medical treatment or when disclosure is essential to protect a person from imminent harm. Even in these circumstances, the client, guardian or "person responsible" would, if possible, be asked permission to release confidential information.
These disclosures and others to third parties may be for:
Referrals and feedback to other service providers, including health professionals and community services providers
Client service provision by external contractors, e.g. cleaners, lawn mowing services
Workers compensation authorities
Regenerate Health obtains some services from external service providers. Some clients' information may be provided to them on a confidential basis if the client gives his or her consent.
APP 7 – Direct marketing
Regenerate Health does not collect a client's personal information for the purposes of marketing nor provide direct marketing communications to clients.
For stakeholders utilising services other than workplace rehabilitation services (e.g., pre-employment services, OH&S Training), Regenerate Health will seek consent to use or disclose personal information for the purposes of informing individuals about:
Regenerate Health products and services that may be of interest and suit their requirements and
promotions or other opportunities in which they may be interested
We assume we have consent to use service providers to assist us with marketing (e.g. mailing services or advertising agencies) unless we are told otherwise (see 'Contacting us' below).
Regenerate Health does provide newsletters to other scheme stakeholders (i.e. scheme agents, employers) quarterly. These do not contain client personal information and stakeholders can elect not to receive these communications.
APP 8 – Cross border disclosure of personal information
As per APP 6 above.
Some approved AI service providers engaged by Regenerate Health may process information using cloud-based infrastructure located outside Australia. Where this occurs, Regenerate Health will take reasonable steps to ensure appropriate privacy protections are in place and that the provider complies with Regenerate Health's contractual and privacy requirements.
APP 9 – Adoption, use or disclosure of government related identifiers
Regenerate Health does not adopt, use or disclose government related identifiers.
APP 10 – Quality of personal information
a. Data quality
Regenerate Health will take reasonable steps to ensure that your personal information which is collected, used or disclosed is accurate, complete and up to date.
APP 11 – Security of personal information
Regenerate Health ensures that it provides security and protection of client personal information from misuse, interference and loss and unauthorised access, modification or disclosure.
a. Storage
All personal information held by Regenerate Health is stored securely in either hard copy or electronic form.
b. Data security
Regenerate Health strives to ensure the security, integrity and privacy of personal information, and will take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Regenerate Health reviews and updates (where necessary) its security measures considering current technologies.
To protect personal information, Regenerate Health's electronic safeguards include:
Electronic client information is password protected - each user has his/her own security profile to access the Internet Technology infrastructure including the Case Manager® software. Access rights can be limited to read only, modify or full access.
Client information is not sent through unprotected emails
Access to client information is limited to authorised staff
Regenerate Health servers (including Case Manager® application) is hosted by a third party company iTonCloud, who monitor, maintain and manage the IT infrastructure. All systems are backed up daily with media being sent off site once verification of a successful backup has been completed.
The organisation's procedural safeguards include:
All staff are trained in confidentiality and the Privacy Act
If an outside person enters the office, the staff member closes the computer screen if it shows personal client information
Meetings with visitors take place in organisation's meeting rooms whenever possible
Meetings with clients will only be conducted in an area which allows sufficient privacy
Artificial Intelligence and Information Security
Where Regenerate Health uses approved AI-enabled systems provided by third-party suppliers, Regenerate Health will take reasonable steps to ensure appropriate privacy, confidentiality and information security safeguards are in place to protect personal information from unauthorised access, misuse, interference, loss, modification or disclosure.
This includes considering, where appropriate:
the provider's privacy and security practices;
user authentication and access controls;
encryption and data transmission security;
data storage and retention arrangements;
whether information is retained or used by the provider for product improvement or model training; and
compliance with applicable Australian privacy requirements and contractual obligations.
c. Online transfer of information
While Regenerate Health does all it can to protect the privacy of your personal information, no data transfer over the internet is 100% secure. When you share your personal information with Regenerate Health via an online process, it is at your own risk.
There are ways you can help maintain the privacy of your personal information, including:
(a) always closing your browser when you have finished your user session
(b) always ensuring others cannot access your personal information and emails if you use a public computer
(c) never disclosing your username and password to third parties
(d) Use of cookies
A 'cookie' is a small data file placed on your machine or device which lets Regenerate Health identify and interact more effectively with your computer.
Cookies which are industry standard and are used by most web sites, including those operated by Regenerate Health, can facilitate a user's ongoing access to and use of a site. They allow Regenerate Health to customise our website to the needs of our users. If you do not want information collected through the use of cookies, there is a simple procedure in most browsers that allows you to deny or accept the cookie feature. However, cookies may be necessary to provide you with some features of our on-line services via the Regenerate Health website.
(e) Links to other sites
Regenerate Health may provide links to third party websites. These linked sites may not be under our control and Regenerate Health is not responsible for the content or privacy practices employed by those websites. Before disclosing your personal information on any other website, we recommend that you carefully read the terms and conditions of use and privacy statement of the relevant website.
(f) Data breaches and the Notifiable Data Breaches scheme
A data breach occurs where personal or health information is subject to unauthorised access or disclosure, is lost in circumstances where unauthorised access or disclosure is likely, or is otherwise compromised. This includes actual and suspected data breaches involving Regenerate Health staff, contractors, systems, third-party service providers and approved AI technologies.
Regenerate Health will respond to actual and suspected data breaches in accordance with its Data Breach Response Plan and the four-step approach recommended by the Office of the Australian Information Commissioner (OAIC):
Contain the breach.
Assess the breach and associated risks.
Notify affected individuals and relevant parties where required.
Review the incident and take action to prevent recurrence.
An eligible data breach arises under the Privacy Act 1988 where:
there has been unauthorised access to or disclosure of personal information, or loss of personal information held by Regenerate Health;
a reasonable person would conclude that the breach is likely to result in serious harm to one or more individuals; and
Regenerate Health has not been able to prevent the likely risk of serious harm through remedial action.
Where Regenerate Health has reasonable grounds to suspect that an eligible data breach may have occurred, it will conduct a reasonable and expeditious assessment. Regenerate Health will take all reasonable steps to complete the assessment within 30 calendar days after becoming aware of the grounds for suspicion and, wherever practicable, will complete it sooner.
Where Regenerate Health has reasonable grounds to believe that an eligible data breach has occurred, it will prepare and submit a statement to the Australian Information Commissioner and notify affected individuals, or individuals at risk of serious harm, as soon as practicable, unless an exception applies.
Notifications will include Regenerate Health's identity and contact details, a description of the breach, the kinds of information involved, and recommended steps individuals should take in response.
Regenerate Health will also consider whether notification is required to another regulator, scheme authority, insurer, contracting organisation, law-enforcement body, cyber-security authority or other affected entity.
APP 12 – Access to personal information
a). Access to own information
Clients have the right to access their own information held by Regenerate Health. If a request to access personal information is made, Regenerate Health will validate the identity of anyone making a request to access client information. This is to ensure that information is not passed to a person who is not authorised to receive it.
While Regenerate Health aims to meet all requests for access to personal information, in a small number of cases and where permitted to do so by law, Regenerate Health may not give access or may do so only under conditions.
Subject to applicable laws, Regenerate Health may destroy records containing personal information when the record is no longer required by Regenerate Health.
APP 13 – Correction of personal information
If clients find that the personal information held is not correct, complete or up to date, Regenerate Health will correct their records accordingly.
a). Length of Time Records Are Held
All information regarding clients will be destroyed seven years after clients cease to receive services or in the case of children when the client reaches 25 years of age, whichever is the latest
A data breach occurs when personal or health information is lost, accessed or disclosed without authorisation, or otherwise compromised. This includes actual or suspected breaches involving Regenerate Health staff, contractors, systems or third-party service providers.
All staff and contractors must immediately report an actual or suspected data breach to their direct manager and/or the Regenerate Health General Manager. The General Manager, or their delegate, is responsible for coordinating and documenting the response and engaging relevant internal or external expertise where required.
Regenerate Health will respond using the following seven-step Reporting and Activation procedure, and Data Breach Response Plan. This is based on the Office of the Australian Information Commissioner's (OAIC) Data Breach Action Plan for Health Service Providers:
Reporting and Activation
Any staff member or contractor who becomes aware of an actual or suspected data breach must immediately:
take safe and practicable steps to prevent further disclosure, access or loss;
notify their direct manager and/or the General Manager by email or, where urgent, by telephone followed by email (use the Internal Data Breach Report – Email Template);
avoid deleting or altering relevant emails, records, system logs or other evidence; and
record when and how the incident was discovered.
The initial report should include as much of the following information as is known, the Internal Data Breach Report – Email Template below should be used:
the name and contact details of the person reporting the incident;
when the incident occurred and when it was discovered;
a factual description of what occurred;
the type of personal or health information involved;
the individuals or organisations affected, or the estimated number affected;
who accessed, received or may have received the information;
the systems, accounts, devices, documents or third-party providers involved;
whether the information remains accessible or the breach is ongoing;
any immediate containment or remedial action already taken; and
the location of any relevant emails, documents, screenshots or other evidence.
Staff must not delay reporting because some information is unknown or has not yet been confirmed. Additional information may be provided as it becomes available.
Staff must not contact affected individuals, unintended recipients, regulators or other external parties unless this forms part of an immediate and safe containment action or they have been authorised to do so by the General Manager or delegated response lead.
The General Manager, or their delegate, will appoint a response lead and determine whether the Data Breach Response Team needs to be activated. The response lead is responsible for coordinating and documenting the response.
Depending on the nature and seriousness of the incident, the Data Breach Response Team may include:
the General Manager or delegate;
the person responsible for privacy and governance;
the relevant operational manager;
IT, cyber-security or forensic support;
legal, risk, communications or records-management support; and/or
relevant third-party service providers.
The appointed response lead must:
promptly record the actual or suspected breach in Regenerate Health's Privacy and Data Breach Register;
coordinate the containment, assessment, notification and review of the incident;
document relevant evidence, actions, decisions, responsibilities and dates;
keep the register updated as the response progresses; and
record the outcome, notification decisions, corrective actions and closure date.
The staff member or contractor who identifies the incident is responsible for reporting it promptly and providing all available information. They are not responsible for determining whether the breach is notifiable or completing the Privacy and Data Breach Register unless specifically appointed or directed to do so.
Internal Data Breach Report – Email Template
To: Direct Manager; General Manager
Subject: URGENT – Actual or Suspected Data Breach – [brief description/date]
Hi [Manager/General Manager],
I am reporting an actual or suspected data breach. The information currently known is provided below.
Date and time the incident occurred: [Insert, or state "unknown"]
Date and time the incident was discovered:
What occurred and how it was discovered: [Provide a brief, factual description]
Information involved in the breach: [Describe the personal, health or other sensitive information involved]
Individuals or organisations potentially affected: [Names, if known, and/or estimated number affected]
Who accessed, received or may have received the information: [Include any unintended recipient or unauthorised person, if known]
Systems, accounts, devices, documents or service providers involved:
Is the information still accessible or is the breach ongoing? [Yes / No / Unknown, with details]
Immediate action already taken: [For example, email recall attempted, recipient contacted to request deletion, account secured or IT notified]
Location of relevant evidence: [Identify relevant emails, records, screenshots or system information without deleting or altering the originals]
Other relevant information or immediate concerns:
Please let me know if any further information or action is required. I will preserve all relevant records and provide additional information as it becomes available.
Kind regards,
[Name]
Data Breach Response Plan
Containment
Record when and how the breach was identified and when this response plan was activated.
Take immediate steps to stop or limit the breach and prevent further compromise. Depending on the circumstances, this may include recovering information, recalling an email, securing accounts, changing access permissions or passwords, disconnecting an affected system, or contacting an IT or third-party service provider.
Preserve relevant records, emails, system logs and other evidence while ensuring that containment actions do not create additional risks.
Assessment
Gather and document relevant information, including:
what occurred and how;
the date, time, location and duration of the breach;
the information and systems involved;
who accessed or may have accessed the information;
the individuals or organisations potentially affected; and
the containment or remedial actions already taken.
Assess the possible consequences for affected individuals, including physical, psychological, emotional, financial, identity-related, employment-related or reputational harm.
Determine whether:
remedial action has prevented the likelihood of serious harm; or
the breach is likely to result in serious harm and meets the criteria for an eligible data breach under the Privacy Act 1988.
Where an eligible data breach is suspected, Regenerate Health will take all reasonable steps to complete its assessment within 30 calendar days of becoming aware of the grounds for suspicion. The assessment process, evidence considered and outcome must be documented.
Notification
Where Regenerate Health has reasonable grounds to believe that an eligible data breach has occurred, it will notify the Office of the Australian Information Commissioner and affected individuals, or individuals at risk of serious harm, as soon as practicable.
Notifications will include:
Regenerate Health's identity and contact details;
a description of the breach;
the types of information involved; and
recommended steps individuals can take to reduce potential harm.
Regenerate Health will also consider whether notification is required to any relevant insurer, employer, contracting organisation, scheme authority, regulator, cyber-security body, law-enforcement agency or third-party service provider.
Prevention
Investigate the cause of the breach and evaluate whether Regenerate Health's response was timely and effective.
Implement and document corrective and preventive actions where required, including changes to systems, security controls, access permissions, policies, procedures, contractual arrangements or staff training.
Review the effectiveness of the completed actions and update this Data Breach Response Plan where necessary.
Individuals who wish to access their records, who believe that Regenerate Health may have breached their privacy rights or to update personal information held by Regenerate Health should contact us via:
All correspondence to be addressed to - The Director: Regenerate Health
By phone: 1300 663 155 (Head office)
Email: admin@actevate.com.au
In writing: GPO Box 3408, Sydney NSW 2001
Web link: https://www.actevate.com.au/page/contact-us
If we do not satisfactorily answer concerns, clients have the right to make a complaint to the Privacy Commissioner:
In writing: Office of Privacy Commissioner GPO Box 5218, Sydney NSW 1042
By phone: 1300 363 992
Consent and Authority to Exchange Information Form
Artificial Intelligence (AI) Usage Policy
Artificial Intelligence Transcription Consent and Explainer
Code of Conduct for Workplace Rehabilitation Providers
Office of the Australian Information Commissioner (OAIC), Data Breach Action Plan for Health Service Providers, available at: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/data-breach-action-plan-for-health-service-providers
