Acurio Health Privacy Policy

1. About this policy

Who we are

Acurio Health and its subsidiaries (“we, us, our or Acurio) provide health and related services in New South Wales. We are committed to protecting the privacy of the personal information we collect and hold, and to handling it openly and transparently. Our facilities include:

  • Acurio Services Pty Ltd, Level 8, 187 Macquarie Street, Sydney NSW 2000 (corporate office)
  • The George Centre, 1A The Hermitage Way, Gledswood Hills NSW 2557
  • Sydney Day Hospital, Level 1, Park House, 187 Macquarie Street, Sydney NSW 2000

Our legal obligations

We handle personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), the Health Records and Information Privacy Act 2002 (NSW) (HRIP Act), the My Health Records Act 2012 (Cth), the Privacy (Tax File Number) Rule 2015, and other applicable privacy laws as amended from time to time.

Who this policy applies to

This policy explains how we handle personal information about:

  • patients of our facilities;
  • visitors to our facilities;
  • job applicants, employees and contractors; and
  • visitors to our website.

Each group is dealt with separately below. The matters in section 6 (storage and security, overseas disclosure, access and correction, complaints and contact) apply to everyone.

How we provide notice

This is our main privacy policy. Consistent with the layered approach endorsed by the Office of the Australian Information Commissioner (OAIC), we also provide shorter collection notices at the point we collect your information, for example on patient admission forms, recruitment and onboarding forms, and signage at our facilities. Those notices should be read together with this policy.

Terms we use

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.

Sensitive information is a subset of personal information that attracts additional protection. It includes:

  • racial or ethnic origin;
  • political opinions or associations;
  • religious or philosophical beliefs;
  • trade union membership or associations;
  • sexual orientation or practices;
  • criminal record;
  • health or genetic information; and
  • some aspects of biometric information.

Health information is a subset of sensitive information, and includes information or an opinion about the health or disability of an individual, their expressed wishes about future health services, and a health service provided or to be provided to them.

2. Patients

What we collect

To assess, plan and provide your care, we may collect:

  • your name, date of birth, gender and contact details (residential, postal and electronic addresses and telephone numbers);
  • your marital status, occupation, country of birth, language spoken and Indigenous status;
  • your religious beliefs or affiliations, where relevant to your care;
  • details of your next of kin, emergency contacts, family, carers or escorts;
  • Medicare, Department of Veterans’ Affairs and concession card details, health fund membership and other healthcare identifiers;
  • workers compensation, insurance or other claim details;
  • your medical and family medical history, and details of allergies, sensitivities and adverse reactions;
  • details of examinations, investigations, results, treatments, operations and other health information;
  • the names of your general practitioner, referring practitioner and other practitioners involved in your care;
  • billing and accounting details associated with your care; and
  • information you provide through questionnaires and surveys.

How we collect it

We usually collect your information directly from you. Sometimes we collect it from others, such as your referring or treating practitioners, a relative, carer or representative, Medicare, your health fund, the Department of Veterans’ Affairs or an insurer, or from electronic record systems such as the My Health Record system or the Australian Immunisation Register (in accordance with the access settings you have set). We collect from third parties only where you have consented, where it is unreasonable or impracticable to collect from you directly, or where we are otherwise authorised by law, and we take reasonable steps to notify you when we do.

Because we are a health service provider, we collect health and other sensitive information where it is necessary to provide a health service to you and the collection is required or authorised by law, and otherwise with your consent.

Why we collect and use it

Our primary purpose is to assess, plan and provide health services and treatment to you, together with the associated administration, including admissions, scheduling, billing and claims, and meeting our statutory, accreditation and quality assurance obligations.

We may also use and disclose your information for related secondary purposes that you would reasonably expect, including:

  • disclosure to the practitioners and others involved in or consulted about your care, including specialists, pathology and radiology providers and multidisciplinary team meetings;
  • sending a discharge summary or treatment summary to your general practitioner or referring practitioner;
  • disclosure to other hospitals or health services involved in your ongoing care;
  • liaising with Medicare, your health fund, the Department of Veterans’ Affairs or another payer for billing and claims;
  • uploading information to the My Health Record system (unless you have opted out) and using healthcare identifier services;
  • provision of information to our contracted service providers who help us operate our facilities (for example IT, cloud storage, billing and document management providers), who are required to handle your information consistently with applicable privacy laws;
  • accreditation, audit, clinical benchmarking, quality assurance, and risk and claims management, in de-identified form where practicable;
  • disclosure to insurers and legal advisers in connection with claims or liability;
  • disclosure to your relatives, carers or representatives, unless you ask us not to; and
  • disclosure where required or authorised by law (for example mandatory reporting of notifiable diseases, child protection reporting, responding to a subpoena, or to lessen a serious threat to an individual’s life, health or safety, or to public health or safety).

My Health Record

Some of our facilities participate in the My Health Record system. Where you participate, we may upload your information to, and access information in, your My Health Record in accordance with the My Health Records Act and your access settings, unless you have opted out. It is your responsibility to set the access controls within that system if you wish to limit access.

3. Visitors to our facilities

If you visit one of our facilities, we may collect limited personal information from you, such as your name and contact details if you sign in, and any information we need to manage access to the facility and to respond to safety or security incidents. We use this information to facilitate access, to maintain the safety and security of patients, visitors and staff, and to meet our legal obligations.

Camera surveillance (CCTV)

Our facilities are monitored by closed-circuit television (CCTV) for the safety and security of patients, visitors and staff and to assist with the investigation of incidents. Signage is displayed at our premises. We handle CCTV footage in accordance with the Privacy Act, the Workplace Surveillance Act 2005 (NSW) and this policy. Footage may be used and disclosed for security and safety purposes, incident investigation, or where otherwise required or authorised by law.

4. Job applicants, employees and contractors

This section applies to job applicants, and to employees and contractors engaged by Acurio (including agency staff and others engaged to provide services). It should be read together with the collection notices we provide during recruitment and onboarding.

Job applicants

We collect personal information from job applicants to assess your application and, if you are successful, to complete your onboarding and the associated administration. Depending on the role you have applied for, this may include:

  • your name, contact details and date of birth;
  • proof of your identity and your right to work in Australia;
  • your work history, qualifications, education and training;
  • professional registration, licensing or membership details (for example AHPRA registration);
  • the names and contact details of your referees, and the information they provide;
  • the results of reference, qualification and background checks and, where relevant to the role, national police checks and working with children checks;
  • where relevant to the role, vaccination or immunisation status and other information about your fitness for the role; and
  • the information contained in your application and any supporting documents (such as your resume and cover letter), and notes from interviews or assessments.

We usually collect this information directly from you. Where you have nominated them or as otherwise authorised, we may also collect it from your referees, previous employers, professional bodies and registration boards (such as AHPRA), educational institutions, recruitment agencies, and background and police check providers. We take reasonable steps to notify you when we collect your information from a third party.

We use this information to assess your suitability and manage our recruitment process, to verify your identity, qualifications and right to work, to conduct reference and background checks, to assess your fitness for the role, and to meet our legal obligations, including under the Fair Work Act 2009 (Cth), work health and safety legislation, and any applicable immunisation, registration or screening requirements. We collect sensitive information, such as health, immunisation or criminal record information, only where it is reasonably necessary for these purposes and with your consent or as otherwise authorised by law. If you do not provide the information we request, we may be unable to assess your application or consider you for the role. If your application is unsuccessful, we keep your information only as described in section 6 of this Policy.

Employees and contractors

If you are engaged by Acurio as an employee or contractor (including as agency staff or to provide services), we collect and hold the kinds of information described above, together with:

  • payroll, banking and superannuation details, and your Tax File Number, which we handle in accordance with the Privacy (Tax File Number) Rule 2015;
  • emergency contact and next of kin details;
  • records relating to your role, performance, conduct, training, credentialing and professional registration;
  • leave, attendance and rostering information;
  • work health and safety records, including incident, injury and any workers compensation claim information;
  • health information relevant to your fitness for work, any workplace adjustments, or immunisation requirements; and
  • records of your access to and use of Acurio’s systems and facilities, including building access and security records and CCTV footage (see section 3).

We use this information to manage your employment or engagement, including payroll, superannuation and taxation; rostering and scheduling; performance and conduct; training, credentialing and professional registration; work health and safety; insurance and workers compensation; IT access and security; and our general business administration. We also use it to meet our legal obligations, including under the Fair Work Act 2009 (Cth), taxation, superannuation and work health and safety laws, professional registration requirements, and applicable immunisation or screening requirements.

We collect this information directly from you and, where relevant, from third parties such as your referees and previous employers, registration boards, background check providers, superannuation funds and government agencies. Where you make a workers compensation claim or we manage a workplace injury, we may also collect information from your treating practitioners and our insurers.

We may provide this information to:

  • our recruitment, human resources and payroll service providers, including online application, background check, payroll and superannuation platforms;
  • our IT, cloud storage and document management providers;
  • the Australian Taxation Office, superannuation funds and other government agencies where required or authorised by law;
  • professional registration boards and providers of training, credentialing and screening;
  • our insurers, workers compensation insurers, and our legal and professional advisers;
  • other entities within the Acurio group involved in your engagement or management; and
  • others where required or authorised by law.

5. Visitors to our website

When you visit our website, our systems may automatically record information for each page accessed, including your Internet Protocol (IP) address, your top-level domain name (for example .com, .gov, .au), the date and time of your visit, the pages and documents you access, and the type of browser and operating system you use.

We use this information in aggregate for statistical purposes, to maintain the security of our website, and to improve the website and the services it offers. We do not attempt to identify individual users from this information.

Cookies and analytics

Our website may use cookies (small pieces of data stored by your browser) and analytics tools to help the website function and to understand how it is used. You can configure your browser to refuse cookies or to notify you when one is used, although some functionality of the website may be lost if you do so. Our website may also contain links to third-party websites; we are not responsible for the content or privacy practices of those websites.

Forms, enquiries and feedback

Where you choose to provide personal information through an online form, enquiry or feedback facility, we use it only for the purpose for which you provided it (for example, to respond to your enquiry) and handle it in accordance with this policy. We will not add your details to a mailing list without your consent.

6. Matters that apply to everyone

How we store and protect your information

We store personal information in secure physical and electronic forms, including cloud-based systems. We take reasonable steps to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure, including through access controls, unique user credentials, confidentiality obligations on our staff, encryption, physical security and staff training.

Overseas disclosure

Most of your information is stored and handled in Australia. Where we make personal information accessible to our service providers located overseas, we limit it to the minimum necessary and require it to be handled in accordance with Australian privacy law.

Data quality

We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, complete and up to date. Please tell us if your details change or if you believe information we hold is inaccurate. If we do not hold accurate and complete information, this may affect the services we are able to provide.

Retention and destruction

We keep personal information only for as long as it is needed for the purposes described in this policy or as required by law, after which we securely destroy or de-identify it. Some records, including health records and employment records, are subject to minimum legal retention periods and will be retained accordingly.

Anonymity and pseudonymity

Where it is lawful and practicable, you have the option of dealing with us anonymously or by using a pseudonym. In many cases, particularly where we are providing health services, it will not be practicable for us to do so, and this may limit the services we can provide.

Access and correction

You may request access to, and correction of, the personal information we hold about you (for patients, this includes the health information in your record). Access to health information is dealt with under the HRIP Act and the Privacy Act. Requests should be made in writing to our Privacy Officer. We may ask you to verify your identity and, where a third party is requesting access on your behalf, to provide written authority, and a reasonable fee may apply for access to health records.

We will provide access or make the requested correction unless an exception under the applicable law applies. If we decline to correct information, we will tell you why and you may ask us to attach a statement of the requested correction to your record.

Complaints and how to contact us

If you have any questions about this policy, or wish to access or correct your information or make a privacy complaint, please contact our Privacy Officer:

We will acknowledge your complaint and respond within a reasonable time. If you are not satisfied with our response, or you do not receive a response within 30 days, you may lodge a complaint with the Office of the Australian Information Commissioner:

Complaints about the handling of health information in New South Wales may also be made to the Information and Privacy Commission New South Wales (the NSW Privacy Commissioner).

Changes to this policy

This policy was last updated in July 2026 and may change from time to time. The current version is available on our website or on request from our Privacy Officer.

ACURIO Health is a provider of surgical facilities in the greater Sydney metropolitan area.

A CULTURE OF CARE

Copyright 2026 | ACURIO | Privacy Policy