Privacy Policy
About this policy
EsyTech Pty Ltd (ABN 23 692 043 646) builds and operates ESYRIS, a hosted radiology information system for Australian diagnostic imaging practices. In this policy, we, us and our mean EsyTech Pty Ltd.
This policy explains how we handle personal information, including health information. It is our privacy policy for the purposes of Australian Privacy Principle 1 under the Privacy Act 1988 (Cth), and it also covers our obligations under the Healthcare Identifiers Act 2010 (Cth) and the My Health Records Act 2012 (Cth).
Current status of ESYRIS
ESYRIS is in development. It is not yet in clinical use, and it does not yet hold information about any patient.
We are publishing this policy now so that practices considering ESYRIS, and the people they care for, can see how information will be handled before any of it is entrusted to us. We will review this policy before the first practice goes live, and again whenever what we do with information changes.
Our two roles — please read this first
We handle personal information in two distinct capacities, and the difference matters for your rights.
1. Information we collect for ourselves. People who contact us, visit our website, work for a practice we deal with, apply to work with us, or represent a supplier. We are the entity responsible for this information and you deal with us directly about it.
2. Information we hold on behalf of a practice. When a diagnostic imaging practice uses ESYRIS, the practice remains the health service provider responsible for its patients’ records. We hold and process that information as the practice’s service provider, under contract and on the practice’s instructions. If you are a patient, your practice is your first point of contact — it is the practice’s record, and the practice controls access to it, corrections to it, and how long it is kept. We will always help a practice respond to you, and you can also contact us directly if you prefer.
What we collect and hold
Information we collect for ourselves
- Contact and business information — name, role, practice or company, email address, telephone number, and the content of your correspondence with us.
- Account and access information — usernames, access permissions and audit records for the people at a practice who are authorised to use ESYRIS or to contact us for support.
- Records of dealings — support requests, service records, contracts, and billing and payment records.
- Applicant and contractor information — where someone applies to work with us or is engaged by us, the information needed to assess and manage that engagement.
Our website is a plain information page. It does not use cookies, analytics, tracking pixels or advertising technology, and it does not collect information about visitors.
Information we hold on behalf of practices
Once ESYRIS is in clinical use, the information a practice will hold in it includes:
- Patient identity and contact details — name, date of birth, sex, address, contact numbers, next of kin or carer details.
- Government identifiers — Medicare number and individual reference number, Department of Veterans’ Affairs file number, pension or concession card details, and Individual Healthcare Identifiers (IHIs).
- Health information — referrals and clinical indications, examinations performed, radiology reports, and the clinical correspondence that goes with them.
- Claiming and financial information — Medicare and DVA claim records, item numbers, benefit and payment records, and assignment-of-benefit records.
- Provider information — referring and treating practitioner details, provider numbers and Healthcare Provider Identifiers (HPI-I and HPI-O).
- Records of every interaction with a government service — a transaction journal recording each exchange with Services Australia, the Healthcare Identifiers Service and My Health Record. The journal deliberately records redacted summaries rather than clinical content.
How we collect information
We collect information we hold for ourselves directly from you — when you contact us, when your practice nominates you as a user, or when we deal with you as a supplier or applicant.
Information about patients is not collected by us from patients. It is entered by the practice, received from a referring practitioner, or obtained from a government service at the practice’s direction — for example, verifying a Medicare number with Services Australia, or looking up an IHI through the Healthcare Identifiers Service to make sure the right record is attached to the right person.
Why we collect, hold, use and disclose information
We use information we hold for ourselves to answer enquiries, provide and support ESYRIS, manage our contracts and accounts, meet our obligations to Services Australia and the Australian Digital Health Agency, and run our business.
We use information held on behalf of a practice only to provide the ESYRIS service to that practice, and only for the purposes the practice has engaged us for: registering and scheduling patients, producing and distributing reports, verifying eligibility and claiming with Medicare and DVA, matching records using healthcare identifiers, uploading diagnostic imaging reports to My Health Record where the practice has chosen to do so, and supporting, securing and maintaining the system.
We do not sell personal information. We do not use it for marketing. We do not use patient information for our own purposes, and we do not use it to train machine-learning models.
Healthcare identifiers
Healthcare identifiers — IHIs, HPI-Is and HPI-Os — are specially protected. We collect, use and disclose them only as permitted by the Healthcare Identifiers Act 2010 and its regulations: to identify the right individual or provider, to communicate or manage health information about that individual, and for the associated claiming and record-keeping purposes. We do not use a healthcare identifier as a general account or reference number, and we do not disclose one except as that Act allows.
My Health Record
Where a practice uses ESYRIS to interact with the My Health Record system, we do so as a contracted service provider to that practice and are bound by the My Health Records Act 2012. We act only on the practice’s instructions and only within the access the practice holds. We keep records of relevant exceptions for at least two years, as that Act requires. Any decision to upload a report to a My Health Record, and any patient’s decision not to have one uploaded, rests with the patient and the practice — not with us.
Who we disclose information to
- The practice whose information it is.
- Services Australia — for Medicare and DVA eligibility verification and claiming, and to the extent required under our agreement with the agency.
- The Healthcare Identifiers Service and the Australian Digital Health Agency — for identifier lookups and, where a practice uses it, My Health Record.
- Our contracted service providers — an Australian software development company we engage to build and support the platform, and our Australian cloud hosting provider. They are permitted to access information only to the extent needed to perform those services, and are bound to protect it. We will name them on request.
- Where required or authorised by law — including to a court, tribunal or regulator.
We do not disclose personal information to anyone else without your consent, or the practice’s, unless the law requires it.
Overseas disclosure
We do not disclose personal information to overseas recipients.
ESYRIS is designed and required to operate wholly within Australia.
It is hosted in Australia, in the Sydney region of Amazon Web Services
(Asia Pacific (Sydney), ap-southeast-2). We require every
contractor engaged on ESYRIS to perform development, testing, support
and operational work within Australia.
If that position ever changes, we will amend this policy and notify affected practices before the change takes effect.
How we store and protect information
ESYRIS is built to hold health information safely, and the protections are engineering controls rather than promises:
- Separation between practices. Every record is bound to the practice it belongs to, at the level of the data model and of each government interaction, so one practice cannot reach another’s information.
- Credentials are never stored in the system. Government credentials and certificates are held in a dedicated encrypted secrets store; ESYRIS holds only a reference to them and resolves them at the moment of use.
- Encryption. Information is encrypted in transit and at rest, using algorithms approved by the Australian Signals Directorate. Communication with the Healthcare Identifiers Service uses mutual certificate authentication and digitally signed messages.
- Logs are cleaned of clinical content. Our logging deliberately redacts Medicare numbers, healthcare identifiers, tokens and key material, and this is verified by automated tests.
- Access control and accountability. Access is limited to those who need it, multi-factor authentication is required for administrative access, and every interaction with a government service is journalled.
- Independent testing. We commission independent penetration testing of the system and address what it finds.
We work to the Australian Government Information Security Manual and to the security requirements of Services Australia and the Australian Digital Health Agency, and our compliance with those requirements is assessed as part of the certification we must complete before ESYRIS may transact with either agency.
How long we keep information
Information held for a practice is kept for as long as the practice requires and as long as the law requires. Health records in Victoria must generally be kept for at least seven years from the last occasion of service, or until a person who was a child at the time turns 25 — whichever is later — and ESYRIS is built to support that. Our transaction journal is retained for at least seven years. My Health Record exception records are kept for at least two years. Information we hold for ourselves is kept only as long as we need it, and then destroyed or de-identified.
When a practice stops using ESYRIS, we return its records to it in a usable form and then destroy our copies, other than anything we are required to retain by law.
Data breaches
If a data breach occurs that is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and we will notify the affected practice and the relevant government agency within the timeframes we are contractually required to meet. We maintain an incident response plan for this purpose and test it.
Anonymity and pseudonymity
You can contact us with a general enquiry without identifying yourself. We cannot provide the ESYRIS service, verify a Medicare entitlement, submit a claim or look up a healthcare identifier anonymously or under a pseudonym — the law and the government systems involved require a correctly identified person.
Accessing and correcting your information
If you are a patient: contact the practice that cared for you. It holds your record and it decides on access and correction. We will support the practice in responding to you, and if you contact us directly we will help you reach the right practice.
For information we hold about you for ourselves: write to us at the address below. We will respond within 30 days. There is no charge for making a request; if giving access involves substantial work we may charge a reasonable cost, and we will tell you before we do. If we cannot give you access or make a correction, we will tell you why in writing and how to have that decision reviewed.
Complaints
If you think we have mishandled your personal information, please tell us first. Write to our Privacy Officer at the address below, describing what happened. We will acknowledge your complaint within five business days and respond within 30 days.
If you are not satisfied with our response, or you would rather not deal with us, you can complain to the Office of the Australian Information Commissioner, which also handles complaints about healthcare identifiers and My Health Record:
- Online: www.oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
Changes to this policy
We will update this policy when what we do with information changes, and in any case we review it at least annually. The version and date below always show the current edition. Where a change materially affects information we hold for a practice, we will notify that practice before the change takes effect.
How to contact us
| Privacy Officer | Dr Piyush Siwach, Director |
| admin@esytech.com.au | |
| Post | The Privacy Officer, EsyTech Pty Ltd, 76 Park Street, Moonee Ponds VIC 3039, Australia |
| Entity | EsyTech Pty Ltd, ABN 23 692 043 646, ACN 692 043 646 |