Health Information Privacy in Aged Care: What You Must Document

A guide to privacy requirements under the Privacy Act and Australian Privacy Principles. Learn how to document health information securely and compliantly.

Published by Regulatory & Compliance Team

Why Privacy Documentation Matters for Aged Care

Aged care facilities hold highly sensitive health information: medical conditions, medication lists, family details, incident reports, and risk assessments. Under the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs), you have strict obligations to protect this information and to document how you collect, use, and store it.

The Office of the Australian Information Commissioner (OAIC) regularly investigates aged care privacy breaches. Common violations include unauthorised access, inadequate security, improper disclosure, and failing to notify individuals of how their information is used.

Key Privacy Act Requirements for Aged Care

1. Consent and Notification (APP 1)

You must obtain informed consent before collecting health information and notify the individual of how you'll use and disclose their information.

What to document:

  • Consent forms signed by the resident or their authorised representative
  • Evidence that you explained what information you're collecting and why
  • Notices provided to residents outlining your privacy practices
  • Records of any special information requests (e.g., "Keep this diagnosis confidential from family")

2. Collection Limitation (APP 3)

You must collect only information that is necessary for your functions.

What to document:

  • Policies on what information you collect and why
  • Evidence that you're not collecting unnecessary sensitive information
  • Records showing you've obtained information directly from the individual where practicable
  • Procedures for updating and purging outdated information

3. Access and Correction (APP 12 & 13)

Individuals have the right to access their health information and request corrections.

What to document:

  • Procedures for handling access requests (timelines, format options)
  • Records of all access requests received and how they were handled
  • Records of correction requests and outcomes
  • Reasons for any denials (e.g., safety concerns)

4. Data Security (APP 11)

You must protect health information from loss, misuse, and unauthorised access.

What to document:

  • Physical security measures (locked files, restricted access areas)
  • Digital security measures (encryption, password protection, access logs)
  • Staff training on privacy and confidentiality
  • Incident logs of any suspected breaches or unauthorised access
  • Contracts with third parties requiring them to protect health information

5. Openness (APP 1)

You must be transparent about your privacy practices.

What to document:

  • Published Privacy Policy outlining your practices
  • Staff training records showing all team members understand privacy obligations
  • Regular privacy audits or reviews
  • Evidence that you've addressed any privacy concerns raised by residents or families

Privacy Documentation in Progress Notes Specifically

Progress notes are health information and require particular care:

  • Access control: Only staff who need to know (primary carers, clinical managers, GPs) should have access
  • Secure storage: Notes should be stored in locked systems with user-level access controls
  • Confidentiality: Don't discuss resident information in public areas or with unauthorised staff
  • Disclosure: Don't share progress notes with family members without explicit consent from the resident
  • Retention: Keep notes for the legally required period (check state-specific aged care legislation) then securely delete

Common Privacy Breaches to Avoid

  • Discussing residents by name in public areas — e.g., "Margaret's diabetes is flaring up" overheard in the hallway
  • Sharing notes with family without consent — even well-intentioned disclosure can breach privacy if not consented to
  • Leaving progress notes visible on desks or computers — screen should be locked, papers stored securely
  • Using notes for purposes other than care — e.g., using a resident's health information in a facility newsletter without consent
  • Inadequate staff training — staff must understand which information is confidential and when disclosure is permitted
  • No audit trail of who accessed information — if using digital systems, ensure access logs are maintained

Building a Privacy Documentation System

Develop a documented privacy framework that covers:

  1. Privacy Policy (what information you collect, how you use it, residents' rights)
  2. Consent and notification procedures
  3. Access control and security procedures
  4. Staff training requirements and records
  5. Incident management and breach procedures
  6. Retention and deletion schedules
  7. Dispute resolution procedures

Use secure, Australian-based care documentation software that enforces privacy controls (user-level access, audit logs, encryption) rather than relying on manual processes.


This article was written by AccuNote's Regulatory & Compliance Team in consultation with privacy law experts. It is general guidance — consult your own legal counsel for specific privacy compliance questions.