Medical privacy or health privacy is the practice of maintaining the security and confidentiality of patient records. This involves both the conversational discretion by health care providers and the security of medical records. The terms can also refer to the physical privacy of patients from other patients and providers while in a medical facility. Modern concerns include the degree of disclosure to insurance companies, employers, and other third parties. The advent of electronic medical records (EMR) has raised new concerns about privacy, balanced with efforts to reduce duplication of services and medical errors.
In the course of having or being part of a medical practice, doctors may obtain information that they wish to share with the medical or research community. If this information is shared or published, the privacy of the patients must be respected. Likewise, participants in medical research that are outside the realm of direct patient care have a right to privacy as well.
On July 1 2012, the Australian Government launched the Personally Controlled Electronic Health Record (PCEHR) (eHealth) system. The system's full implementation will incorporate an electronic summary prepared by nominated healthcare providers along with consumer-provided notes. The summary will include information on the individual's allergies, adverse reactions, medications, immunizations, diagnoses, and treatments. The consumer notes will operate as a personal medical diary that only the individual can view and edit. The opt-in system gives people the option to choose whether to register for the eHealth record or not.
The Personally Controlled Electronic Health Records Act 2012 and Privacy Act 1988 govern how eHealth record information is managed and protected. The PCEHR System Operator abides by the Information Privacy Principles in the Privacy Act 1988 (Commonwealth) as well as any applicable State or Territory privacy laws. A Privacy Statement sets out the application of the collection of personal information by the System Operator. The statement includes an explanation of the types of personal information collected, what the information is used for, and how the information is stored. The statement covers measures in place to protect personal information from misuse, loss, unauthorized access, modification, and disclosure.