DMP v Sydney Local Health District [2021] NSWCATAD 246

DMP v Sydney Local Health District [2021] NSWCATAD 246

The Tribunal determined that no identified use of DMP's health information occurred during training sessions; the evidence supported that security safeguards implemented for the non-production database were reasonable; collection of personal identifiers and Medicare details upon hospital admission was lawful and necessary; treating DMP anonymously was neither lawful nor practicable; SLHD was not required to update the health information as requested; lawful exception applied for disclosure to the Privacy Commissioner; DMP had no standing concerning complaints of privacy breaches relating to third parties. Consequently, no contraventions of the relevant Health Privacy Principles were...

Parties
Applicant: DMP; Respondent: Sydney Local Health District
Jurisdiction
Australia
Judgment Date
18 August 2021
Procedural Posture
Administrative Review / Final Decision
Outcome
No action taken; all applications dismissed
Legal Topics
Health Records, Health Privacy Principles, Use and Retention of Health Information, Anonymity in Health Care, Security Safeguards for Health Information, Disclosure to Privacy Commissioner

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 5 Authorities cited 19 Party arguments 2
Sign in to unlock

Parties

DMP

Applicant

Sydney Local Health District

Respondent

Procedural Posture

Administrative Review / Final Decision

  1. 1 Whether Sydney Local Health District breached Health Privacy Principles (HPPs) in its use and retention of DMP's health information for training purposes within the eMR/eCERT system;
  2. 2 Whether adequate security safeguards were implemented to protect health information in non-production environments;
  3. 3 Whether Sydney Local Health District unlawfully coerced DMP into identifying himself and providing his Medicare card on 6 June 2018;

Ratio Decidendi

The Tribunal determined that no identified use of DMP's health information occurred during training sessions; the evidence supported that security safeguards implemented for the non-production database were reasonable; collection of personal identifiers and Medicare details upon hospital admission was lawful and necessary; treating DMP anonymously was neither lawful nor practicable; SLHD was not required to update the health information as requested; lawful exception applied for disclosure to the Privacy Commissioner; DMP had no standing concerning complaints of privacy breaches relating to third parties. Consequently, no contraventions of the relevant Health Privacy Principles were...

Court Disposition

No action taken; all applications dismissed

Orders

  • The Tribunal decides not to take any action in the matters.