DMP v Sydney Local Health District [2021] NSWCATAD 246
The Tribunal determined that no identified use of DMP's health information occurred during training sessions; the evidence supported that security safeguards implemented for the non-production database were reasonable; collection of personal identifiers and Medicare details upon hospital admission was lawful and necessary; treating DMP anonymously was neither lawful nor practicable; SLHD was not required to update the health information as requested; lawful exception applied for disclosure to the Privacy Commissioner; DMP had no standing concerning complaints of privacy breaches relating to third parties. Consequently, no contraventions of the relevant Health Privacy Principles were...
- Parties
- Applicant: DMP; Respondent: Sydney Local Health District
- Jurisdiction
- Australia
- Judgment Date
- 18 August 2021
- Procedural Posture
- Administrative Review / Final Decision
- Outcome
- No action taken; all applications dismissed
- Legal Topics
- Health Records, Health Privacy Principles, Use and Retention of Health Information, Anonymity in Health Care, Security Safeguards for Health Information, Disclosure to Privacy Commissioner
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
DMP
Applicant
Sydney Local Health District
Respondent
Procedural Posture
Administrative Review / Final Decision
Legal Issues
- 1 Whether Sydney Local Health District breached Health Privacy Principles (HPPs) in its use and retention of DMP's health information for training purposes within the eMR/eCERT system;
- 2 Whether adequate security safeguards were implemented to protect health information in non-production environments;
- 3 Whether Sydney Local Health District unlawfully coerced DMP into identifying himself and providing his Medicare card on 6 June 2018;
Ratio Decidendi
The Tribunal determined that no identified use of DMP's health information occurred during training sessions; the evidence supported that security safeguards implemented for the non-production database were reasonable; collection of personal identifiers and Medicare details upon hospital admission was lawful and necessary; treating DMP anonymously was neither lawful nor practicable; SLHD was not required to update the health information as requested; lawful exception applied for disclosure to the Privacy Commissioner; DMP had no standing concerning complaints of privacy breaches relating to third parties. Consequently, no contraventions of the relevant Health Privacy Principles were...
Court Disposition
No action taken; all applications dismissed
Orders
- The Tribunal decides not to take any action in the matters.
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment