Being aware and compliant with privacy policies in your state can help build trust between you and your staff
Knowing information, such as the medical background of an employee, helps employers adjust and accommodate them in the workplace – but there is a limit on the information companies are allowed to access before breaching privacy laws.
With regards to medical records, how much information can employers access and does the employee need to give consent whenever a company needs to access them?
The terms privacy and personal information are used closely to complement each other but do not share the same meaning. Privacy is the action of keeping certain information to themselves and a selected amount of selected people.
Meanwhile, personal information is the information that is used to identify an individual, such as name, addresses, phone numbers, bank account details, government identification numbers, academic records, and even medical background. It differs from the term privacy since privacy is the act that protects personal information from being shared with others without the consent of the owner.
Although it sounds like basic information that people share regularly, some personal information must remain private as people can use it for the wrong reasons, like blackmail, scams and identity theft. This sensitive information can include political opinions, religious or philosophical beliefs, trade union membership, criminal record, sexual orientation and medical history.
Privacy can also ease the worry and stress of someone prying into someone else’s information they wish not to share. Therefore, Commonwealth privacy laws have set restraints on collecting and handling private personal information.
Read more: How HR can help prevent data breaches
Australia takes privacy seriously and has set laws protecting employees’ information and the right to keep personal information like health and medical background.
The Privacy Act 1988 is the primary Australian legislation in protecting and handling employees' personal information. It covers the collection, use and disclosure of personal information in the federal public and private sectors.
Under the Privacy Act 1988, there are 13 Australian Privacy Principles (APP) that help protect sensitive personal information but not to the extent of restricting organizations with stringent policies. It includes guidelines on transparency, anonymity, collection, dealing, notifying, use, security, access, correction and quality of personal information. The APPs apply to government agencies and the private sector businesses that have an annual turnover of $3m or more, including private health service providers and some small businesses.
When a breach of an APP happens, the Office of the Australian Information Commissioner (OAIC) reviews and investigates the cases.
The Privacy Act is supported by other federal laws such as the Privacy Regulation 2013 and the Privacy (Credit Reporting) Code 2014. In addition, the states and territories also have their own privacy laws they follow alongside the Privacy Act, such as:
Regarding accessing information on an employee’s medical background, employers are not allowed to request a copy of a medical record from a medical professional or agency without the consent of the employee.
However, an employer could request for an employee’s medical records only when it is needed to determine whether they are fit to work or perform moderated duties. The information an employer could access is limited as the Privacy Act does not allow companies to request for full medical history records of an employee.
An employer could also request for a medical certificate when an employee files an accrued paid sick leave when they are sick. The medical certificate proves that the employee is unfit to work due to a personal illness or injury.
Trish Low, previous national leader – equal opportunity and training at Herbert Smith Freehills, told HC employers have the right to question an employee’s medical clearance in certain cases.
“If your employee is cleared to come back to work but you're genuinely worried that it's not safe for them to do so, you can get a second medical opinion. You do have the right to direct them to a medical professional and you can choose the doctor.” Low said.
Requesting a second medical opinion assures employers they’re not putting the employee’s health at risk when they return to work, which could make the employer liable if the from a workers’ compensation point of view if ever the employee reinjured themselves on the job.
Read more: When can you require an employee to undergo an independent medical examination?
Employers and employees alike should have an understanding of the privacy laws of their state to avoid any legal breaches in the future that could be costly in legal fees and ruin the image and relationship of the employee and employer. Being aware and compliant with policies about privacy can help build trust between the two parties that can boost motivation and loyalty in the workplace.