MedicineInsight privacy, security and governance
The Commission understands its role as a data custodian of primary healthcare data and is committed to ensuring it is managed in a manner which is consistent with the requirements of relevant state and territory laws and standards.
We extract non-identifiable, unit-level data from participating general practice systems. Non-identifiable data are the output of the de-identification process, which involves the removal or alteration of information that identifies a person, or is reasonably likely to identify them, as well the application of any additional protections to prevent identification; including re-identification risks.
Access to MedicineInsight data
Data access is facilitated by an application pathway - only applications from Australian-based researchers and for non-commercial purposes are considered. All applications received are subject to internal risk and data feasibility assessments before progressing to our Data Governance Committee. Preparation of data extracts following Application approval is dependent upon resourcing and may not commence immediately. Please contact medicineinsight@safetyandquality.gov.au for more information.
How we safeguard privacy
Security of data storage
The Commission takes robust precautions to protect data held from misuse and loss, and from unauthorised access, modification and disclosure. Processes and policies include:
- Data extracted from practices are encrypted to government standards, to ensure unauthorised parties are unable to interrogate or ‘translate’ the data for their own use
- Data are stored only in Australia
- Robust and effective security controls are in place to protect the data
- Data are only accessible by authorised staff
- A data-sharing agreement must be in place which outlines the responsibilities and obligations of researchers that access MedicineInsight data.