Policy

Privacy and Confidentiality Policy

How Access Support collects, uses, stores, discloses and protects your personal and health information, and how you can access or correct it.

1. Purpose and scope

Ametz Group pty ltd. T/A Access Support (“Access Support”, “we”, “us”) is an NDIS registered allied health provider. This policy explains how we handle personal information and health information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), the Health Privacy Principles under the Health Records and Information Privacy Act 2002 (NSW), the NDIS Practice Standards and the NDIS Code of Conduct.

It applies to all directors, employees, students, contracted clinicians, administration staff and volunteers, and to every participant, client, family member, carer, referrer and job applicant whose information we hold.

2. Your rights

  • To be treated with dignity and to have your privacy respected in every setting, including your home, clinic and telehealth sessions.
  • To know what information we hold, why we hold it and who we share it with.
  • To give, withhold or withdraw consent for information sharing, and to be told the consequences of doing so.
  • To request access to your records and to ask us to correct anything inaccurate, out of date or misleading.
  • To use a support person, advocate, interpreter or nominee when discussing your information.
  • To deal with us anonymously or by pseudonym for general enquiries, where it is lawful and practicable.
  • To make a complaint without it affecting the services you receive.

3. What information we collect

We collect only what we need to deliver safe, effective services and to meet our legal and funding obligations. Health information is 'sensitive information' and is collected with your consent unless the law requires or permits otherwise.

  • Identity and contact details: name, date of birth, address, phone, email, preferred language and communication needs.
  • Health information: diagnoses, medical and therapy history, assessment results, clinical notes, reports, medications, mealtime and swallowing risk, images or video used for clinical assessment.
  • Funding and administrative information: NDIS participant number and plan details, plan management type, My Aged Care client ID and referral code, Medicare number and IRN, DVA file number, icare claim or participant number, private health fund details, invoices and payment records.
  • Support network details: nominee, guardian, family, carers, support coordinator, plan manager, GP and other treating practitioners.
  • Consent records, service agreements, incident and complaint records, and feedback.

4. How we collect it

When we collect information about you from someone else, we take reasonable steps to make sure you are aware of the collection and of this policy.

  • Directly from you, your nominee or guardian during intake, assessment and therapy.
  • From your referrer — GP, specialist, support coordinator, plan manager, aged care assessor, insurer or case manager — with your consent.
  • From forms you complete on our website, by phone, by email or in person.
  • From the NDIA, My Aged Care, Services Australia, DVA or icare where this is part of administering your funding.

5. How we use and disclose it

We use your information for the primary purpose of providing allied health services to you, and for directly related purposes such as billing, clinical supervision, quality improvement and mandatory reporting.

  • Within our team: only staff involved in your care or its administration can access your record.
  • With your care team: GPs, specialists, schools, support workers, support coordinators and plan managers — with your consent.
  • With funders: the NDIA and NDIS Quality and Safeguards Commission, My Aged Care or your aged care provider, Services Australia, DVA, icare or your insurer, as required to claim or acquit funding.
  • Where required or authorised by law: subpoenas, court orders, mandatory child protection or reportable incident obligations, or to lessen a serious and imminent threat to life, health or safety.

6. What we never do

  • We do not sell your information, or use it for direct marketing without your express consent.
  • We do not use government identifiers (such as your Medicare or NDIS number) as our own client identifier.
  • We do not share your information with other providers in exchange for referrals, payments or benefits.
  • We do not discuss your information in public areas, or with family members who are not authorised.

7. Storage, security and overseas disclosure

  • Records are held in an access-controlled, encrypted practice management system with individual logins, multi-factor authentication and audit logging.
  • Paper records are stored in locked cabinets at our head office and are never left in vehicles or homes.
  • Staff sign confidentiality undertakings, complete privacy training at induction and annually, and have access limited to their role.
  • Devices are password protected and encrypted; clinical information is not stored in personal email or consumer messaging apps.
  • Where a cloud service stores data outside Australia, we take reasonable steps to ensure the provider handles information consistently with the APPs, and we tell you which countries are involved on request.

8. Retention and destruction

  • Adult clinical records are retained for at least 7 years from the date of last service.
  • Records for a person who was under 18 are retained until they turn 25.
  • NDIS service and financial records are retained for at least 7 years as required by the NDIS Act and Rules.
  • When retention periods expire, records are destroyed securely by shredding or certified digital deletion.

9. Access and correction

You can request a copy of your record at any time by contacting our head office in writing. We will respond within 30 days and, in most cases, provide the record at no cost other than reasonable copying charges.

In rare cases we may withhold part of a record — for example where release would pose a serious threat to life or health, or would unreasonably affect another person's privacy. If we do, we will explain why in writing and tell you how to seek review.

If information is wrong, tell us and we will correct it. Where a clinical opinion cannot simply be changed, we will add your statement to the record.

10. Data breach response

  • Any suspected breach must be reported to the Director immediately and logged in our incident register.
  • We contain the breach, then assess within 30 days whether it is likely to result in serious harm.
  • Where serious harm is likely, we notify affected individuals and the Office of the Australian Information Commissioner as an eligible data breach under the Notifiable Data Breaches scheme, and the NDIS Commission where a participant is affected.
  • Every breach triggers a review of the control that failed, with corrective actions tracked to completion.

11. Cookies and our website

Our website collects only what you submit through our contact, booking and referral forms, plus anonymous usage statistics used to improve the site. We do not use your form data for advertising.

12. Complaints

If you believe your privacy has been breached, contact us on 0485 835 045 or ah@accesssupport.au. We acknowledge complaints within 2 business days and aim to resolve them within 21 days.

You can also complain to the NDIS Quality and Safeguards Commission (1800 035 544), the Office of the Australian Information Commissioner (1300 363 992), or the NSW Information and Privacy Commission (1800 472 679). You may use an advocate at any time.