Flowchart
Did My Employee Break Patient Policy?
One page. You start at the top with what actually happened, and you finish at a decision you can defend.
We do not send a generic PDF.
That is why we ask for your job title and your company. Every resource is tailored dynamically around both, so what reaches you speaks to the decisions your role actually owns, inside an organisation like yours.
Generated around your role, then checked by us before it goes out. That is what the 48 hours is for.
Request your copy
Four fields. Your job title and company shape the document you get back, within 48 hours.
What you get
- The decision path from the first report through to whether this is a notifiable data breach.
- The line between a policy breach and a privacy incident, which are not the same thing and get confused constantly.
- What you record even when the answer is that no patient was harmed.
- The point at which you stop handling it internally and call your privacy officer or your insurer.
Who it is for
For the manager who has just been told something and has to decide what happens in the next hour.
Questions this raises
Do patients need to be told when AI is used in their care?
Transparency is one of the guardrails in the Voluntary AI Safety Standard, which asks organisations to be clear with the people affected about where and how AI is used (Source: DISR, Voluntary AI Safety Standard, September 2024). Ahpra separately expects practitioners to meet their existing code of conduct obligations when using AI, which include informed consent (Source: Ahpra, Meeting your professional obligations when using Artificial Intelligence in healthcare).
Is health information handled differently from other data?
Yes. Health information is sensitive information under the Privacy Act and attracts a higher standard than ordinary personal information, and the reforms enacted in 2025 increased the consequences of mishandling it (Source: Attorney General's Department, Privacy Act Review Report 2023, reforms enacted 2025). Any AI tool touching a clinical record inherits that standard.
Does a patient-facing policy need to name specific tools?
Naming tools dates the policy the moment you change vendors. Describing categories of use, who is accountable for each, and how a patient raises a concern lasts longer and matches the contestability guardrail in the Voluntary AI Safety Standard (Source: DISR, Voluntary AI Safety Standard, September 2024).
Still scrolling? The form is at the top of the page.