+61 (8) 7231 5096

johnsonadmin@sahi.org.au

Privacy Policy

Privacy Policy

Last updated: 3 August 2026

1. About this Privacy Policy

Dr Luke Johnson is committed to protecting the privacy, confidentiality and security of personal information.

This Privacy Policy explains how we collect, hold, use and disclose personal information when you:

  • visit or use our website;
  • contact us;
  • submit an online enquiry or appointment request;
  • become, or seek to become, a patient;
  • communicate with our practice; or
  • otherwise interact with us.

We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, applicable health-records requirements and other laws that apply to our practice.

This Privacy Policy applies to this website and any related online forms, patient communications and digital services operated by or on behalf of Dr Luke Johnson.

An APP privacy policy must be clearly expressed, current and readily available, and must explain an organisation’s personal-information handling practices.

2. Meaning of personal information and sensitive information

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Sensitive information includes health information and certain other information given greater protection under privacy law.

Health information may include information or opinions about:

  • your physical or mental health;
  • your symptoms, condition, diagnosis or treatment;
  • medications, allergies or medical history;
  • healthcare services provided or proposed;
  • test results, medical imaging or clinical reports;
  • referrals and correspondence from other healthcare providers;
  • billing, Medicare, private health insurance or compensation details; and
  • other information collected in connection with providing a health service.

3. Personal information we may collect

Depending on how you interact with us, we may collect:

  • your name, date of birth and contact details;
  • your address and emergency-contact information;
  • information submitted through website forms;
  • appointment and booking information;
  • health and medical information;
  • referral letters, medical reports, imaging and test results;
  • Medicare, Department of Veterans’ Affairs, private health insurance or other payer information;
  • billing, payment and transaction details;
  • details of your general practitioner, specialist or other healthcare providers;
  • communications between you and the practice;
  • information needed to respond to complaints, enquiries or legal matters;
  • employment or contractor information where relevant; and
  • technical information generated when you use the website.

We seek to collect only information that is reasonably necessary for our functions and activities or directly related to providing healthcare and operating the practice.

4. How we collect personal information

We may collect personal information:

  • directly from you;
  • through website contact or appointment forms;
  • by telephone, email, SMS, post or in person;
  • when you register as a patient or attend an appointment;
  • from a referring practitioner or another healthcare provider;
  • from a hospital, pathology provider, imaging provider, pharmacy or allied-health provider;
  • from a family member, guardian, carer or authorised representative;
  • from Medicare, an insurer, compensation authority or another payer;
  • from our booking, practice-management, billing or communications providers;
  • from cookies, analytics tools and website server logs; and
  • where permitted or required by law.

Where reasonable and practicable, we collect personal information directly from the individual concerned.

When information is collected, organisations must take reasonable steps to notify people about matters including who is collecting it, why it is being collected, the consequences of not providing it, usual disclosures, access and correction, complaints, and likely overseas disclosures.

5. If you do not provide information

You may choose not to provide personal information.

However, if we do not receive information that is reasonably required, we may be unable to:

  • respond to your enquiry;
  • arrange or confirm an appointment;
  • provide safe and appropriate healthcare;
  • communicate with your treating team;
  • process accounts, Medicare claims or insurance matters; or
  • comply with our legal and professional obligations.

Where lawful and practicable, you may interact with us anonymously or using a pseudonym. This may not be practicable where we need to identify you in order to provide healthcare, manage appointments, maintain medical records or process payments and claims.

6. Why we collect, hold, use and disclose information

We may collect, hold, use and disclose personal information for purposes including:

  • assessing, diagnosing and treating patients;
  • managing referrals, appointments and follow-up care;
  • communicating with patients and their authorised representatives;
  • coordinating care with general practitioners, specialists, hospitals and other healthcare providers;
  • obtaining and reviewing test results, imaging and clinical records;
  • maintaining accurate clinical and administrative records;
  • processing accounts, Medicare claims, insurance claims and other payments;
  • operating, managing and improving the practice;
  • responding to enquiries, feedback and complaints;
  • maintaining website and information-system security;
  • meeting accreditation, insurance, audit, clinical-governance and professional requirements;
  • training, quality assurance and risk management;
  • complying with legal obligations, court orders and regulatory requirements;
  • managing actual or threatened legal claims;
  • preventing or investigating suspected fraud, misconduct, security incidents or unlawful activity; and
  • any other purpose for which you have consented or which is permitted or required by law.

Personal information will generally only be used or disclosed for the purpose for which it was collected, for a related purpose that you would reasonably expect, with your consent, or where another legal exception applies.

7. Health information and consent

We will generally collect sensitive information, including health information, with your consent and where the information is reasonably necessary to provide a health service or perform another legitimate practice function.

Consent may be express or implied, depending on the circumstances and the applicable law.

There are limited circumstances in which health information may be collected, used or disclosed without consent, including where permitted or required by law or where a recognised permitted health situation applies.

8. Disclosure of personal information

We may disclose personal information, where appropriate, to:

  • general practitioners, specialists and other members of your treating team;
  • hospitals, day-procedure facilities and healthcare organisations;
  • pathology, imaging, pharmacy and allied-health providers;
  • your guardian, carer, authorised representative or nominated contact;
  • Medicare, the Department of Veterans’ Affairs, private health insurers and compensation authorities;
  • accountants, auditors, insurers, lawyers and professional advisers;
  • website, information-technology, cloud-storage, booking, communications, billing and practice-management service providers;
  • contractors who assist us in operating the practice;
  • regulators, courts, tribunals, law-enforcement bodies or government agencies;
  • debt-recovery providers, where lawful and necessary; and
  • other persons or organisations with your consent or as permitted or required by law.

We do not sell patient information.

Service providers are expected to handle personal information securely and only for the purposes for which they have been engaged.

9. Website enquiries are not a substitute for medical care

Information submitted through the website may not be reviewed immediately.

Do not use the website or a general email address to seek urgent medical assistance or send information requiring an immediate clinical response.

In an emergency, call 000 or attend the nearest emergency department.

Website enquiries do not, by themselves, create a doctor–patient relationship.

10. Website and technical information

When you visit the website, our systems or service providers may automatically collect technical information such as:

  • your internet protocol address;
  • browser type and version;
  • device type and operating system;
  • date and time of access;
  • pages viewed;
  • referring website;
  • approximate location derived from technical data;
  • website interactions; and
  • security and diagnostic information.

We may use this information to:

  • operate and secure the website;
  • diagnose technical problems;
  • understand general website usage;
  • improve website content and functionality; and
  • detect misuse or suspicious activity.

Some technical data may constitute personal information depending on the circumstances.

11. Cookies and analytics

The website may use cookies and similar technologies.

Cookies are small data files stored on your device. They may be used for:

  • essential website functions;
  • security;
  • remembering preferences;
  • measuring website traffic and performance; and
  • understanding how visitors use the website.

You can usually manage or block cookies through your browser settings. Blocking some cookies may affect website functionality.

Where third-party analytics, embedded content or advertising tools are used, those providers may also collect information in accordance with their own privacy terms.

The practice should identify the actual tools used on the website in this section—for example, Google Analytics, Google Maps, reCAPTCHA, Meta Pixel or an online booking widget—rather than leaving this wording generic.

12. Online forms and email

Information transmitted over the internet carries inherent security risks.

Although we take reasonable steps to protect online information, ordinary email and website forms may not always be suitable for highly sensitive or urgent medical information.

Please contact the practice if you need to arrange a more secure method of communication.

13. Overseas disclosures

Some external service providers may store, process or access information outside Australia.

Where we disclose personal information to an overseas recipient, we will take reasonable steps as required by the Australian Privacy Principles to ensure the information is handled consistently with Australian privacy requirements, unless an exception applies.

Where practicable, this Privacy Policy will identify the countries in which overseas recipients are likely to be located.

Under APP 8, an organisation will generally need to take reasonable steps to ensure an overseas recipient complies with the APPs and may remain accountable for the recipient’s handling of the information.

Website implementation note: This clause should not be published without checking where the following providers host or access data:

  • website hosting;
  • web forms;
  • email;
  • booking software;
  • practice-management software;
  • cloud storage;
  • analytics;
  • backups; and
  • payment processing.

If overseas locations are known, they should be listed.

14. Direct marketing

We may send information about practice services, updates or other relevant matters where permitted by law.

We will not use health information for direct marketing unless the required consent exists.

Commercial electronic messages will be sent in accordance with applicable Australian spam laws and will ordinarily include a practical means of unsubscribing.

You may opt out of marketing communications at any time by:

  • using the unsubscribe function in the message; or
  • contacting the practice.

Opting out of marketing will not prevent us from sending clinical, safety, billing, appointment or administrative communications.

Direct marketing using sensitive information such as health information requires consent. Australian spam laws also generally require consent, sender identification and a functioning unsubscribe method for commercial electronic messages.

15. Security

We take reasonable steps to protect personal information from:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

Security measures may include, where appropriate:

  • access controls and user authentication;
  • secure systems and encryption;
  • password and device-security controls;
  • staff confidentiality requirements;
  • secure storage and disposal;
  • backups and system monitoring;
  • security updates;
  • service-provider due diligence; and
  • incident-response procedures.

No internet transmission or electronic-storage method is completely secure. We cannot guarantee absolute security, but we will take reasonable and proportionate steps to protect information.

16. Data retention and destruction

We retain personal information for as long as reasonably necessary to:

  • provide healthcare;
  • maintain appropriate clinical records;
  • meet legal, professional, insurance and regulatory requirements;
  • manage disputes and legal claims; and
  • operate the practice.

When personal information is no longer required and we are not legally required to retain it, we will take reasonable steps to destroy it securely or permanently de-identify it.

Medical records may be subject to minimum retention requirements. Those requirements may vary according to the patient’s age, the type of record and the applicable professional, contractual or legal obligations.

17. Access to personal information

You may request access to personal information we hold about you.

Requests should be made using the contact details below. We may ask you to verify your identity and clarify the information requested.

We will respond within a reasonable period.

Access may be refused or limited where permitted by law. For example, access may be restricted where it would:

  • pose a serious threat to a person’s life, health or safety;
  • unreasonably affect another person’s privacy;
  • relate to existing or anticipated legal proceedings;
  • reveal commercially sensitive evaluative information; or
  • otherwise fall within a lawful exception.

Where access is refused, we will generally provide written reasons and information about available complaint mechanisms, unless it would be unreasonable or unlawful to do so.

A reasonable administrative charge may apply where permitted by law. We will not charge merely for making an access request.

The APPs provide rights to request access and correction, subject to limited exceptions.

18. Correction of personal information

We take reasonable steps to ensure that personal information is accurate, up to date, complete, relevant and not misleading.

You may ask us to correct information that you believe is inaccurate, out of date, incomplete, irrelevant or misleading.

We may retain the original clinical entry where required for record integrity, but may add a correction, clarification or notation to the record.

Where appropriate and required, we may notify relevant third parties of a correction.

19. Data breaches

A data breach may occur where personal information is lost or accessed or disclosed without authorisation.

We maintain processes for responding to suspected or actual data breaches.

Where a breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will take the steps required by law, which may include notifying affected individuals and the Office of the Australian Information Commissioner.

Entities covered by the Privacy Act must notify affected individuals and the OAIC of eligible data breaches that are likely to result in serious harm.

20. Children and people requiring assistance

We may collect personal information about children and people who require assistance in making decisions where this is necessary to provide healthcare or manage the practice.

Consent and communications may involve a parent, guardian, substitute decision-maker or authorised representative, depending on:

  • the individual’s age and capacity;
  • the nature of the healthcare;
  • professional obligations; and
  • applicable law.

We will seek to involve the patient in decisions about their information to the extent reasonably practicable and appropriate.

The US-specific children’s-law section in the old policy should be deleted. It is not an appropriate basis for an Australian medical-practice privacy policy.

21. Third-party websites

The website may contain links to external websites or services.

We are not responsible for the privacy, security or content practices of third parties. You should review the privacy terms of any external site before providing personal information.

22. Complaints

You may contact us if you have a question or complaint about how we have handled personal information.

Please provide sufficient information for us to understand and investigate the matter.

We will:

  1. acknowledge the complaint within a reasonable period;
  2. investigate the complaint;
  3. communicate the outcome; and
  4. take appropriate corrective action where required.

If you are not satisfied with our response, you may be entitled to lodge a complaint with the Office of the Australian Information Commissioner.

The practice should ordinarily be given a reasonable opportunity to respond before the matter is escalated.

23. Contact details

Privacy enquiries, access requests, correction requests and complaints may be directed to:

Privacy Officer
Dr Luke Johnson 
Email: johnsonadmin@sahi.org.au

The legal entity operating the practice should be named here. “Dr Luke Johnson” alone may not be sufficient if services are legally provided through a company, trust, partnership or separate medical-practice entity.

24. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to:

  • legislation;
  • regulatory guidance;
  • practice operations;
  • technology;
  • service providers; or
  • information-handling practices.