Consultation Paper on ICD-10-AM/ACHI/ACS Fourteenth Edition and AR-DRG V13.0 Development

Have your say

Privacy

Information is logged when you visit this website, our server makes a record of your visit and logs the following information for statistical purposes or systems administration purposes:

  • your server address
  • your top level domain name (for example .com, .gov, .au, .uk etc)
  • the date and time of your visit to the site
  • the pages you accessed and documents downloaded
  • the previous site you have visited
  • the type of browser you are using.
  • No attempt will be made to identify users or their browsing activities, except in the unlikely event of an investigation where a law enforcement agency may exercise a warrant to inspect the logs.

The Privacy Policy (Policy) applies to the functions of the Independent Health and Aged Care Pricing Authority (IHACPA). IHACPA’s collection, use, disclosure and storage of your personal information is regulated by the Privacy Act 1988 (Cth) (the Privacy Act), the Australian Privacy Principles (APPs) and related legislation.

Where relevant, IHACPA will also apply this Policy to the following data it collects in its role to the extent that it is practicable for IHACPA to do so:

  • activity based funding data and National Hospital Cost Data Collection data (collectively referred to herein as hospital data) and
  • hospital pricing and costing information and aged care pricing and costing data (collectively referred to herein as pricing and costing information).

The requirements under this Policy apply to all IHACPA employees, officers, persons engaged as contractors and employees of contracted service providers.

This Policy will be reviewed on an annual basis, or earlier, if required. Updates to this Policy will be published on our website.

If you have any questions regarding this Policy or our privacy practices generally, please contact our Privacy Officer using their details set out at the end of this Policy.

The purpose of this Policy is to:

  • give you an understanding of the types of personal information that we collect and hold
  • communicate how and when your personal information is collected, disclosed, used, held and otherwise handled by us
  • inform you about the purposes for which we collect, hold, use and disclose personal information
  • provide you with information about how you may access your personal information and seek correction of your personal information
  • provide information about how to make a complaint regarding IHACPA’s handling of your personal information, and how we will respond to your complaint.

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in a material form or not. It includes your name, date of birth or age, gender and contact details as well as health information (which is also sensitive information). In this Policy, a reference to personal information includes sensitive or health information.

Personal information collected by us will usually fall into one of the following categories:

  • contact information (name, age, address, email address and telephone numbers)
  • Commonwealth identifiers (for example Aged Care Identifier, tax file number and individual healthcare identifier)
  • employment information (for example employment history, qualifications, work performance, absences, workplace incidents and next of kin information)
  • financial information (for example bank account details and superannuation details)
  • sensitive information (for example information about your health, medical history, criminal history, religious beliefs and trade union activity)
  • information obtained to assist in managing client and business relationships (for example feedback and complaints, photographs, video and/or audio recordings).

We may collect your information from you in a variety of ways including when:

  • we provide services to you, for example assessment of refundable accommodation deposits
  • you visit our website
  • you contact us by any method, such as face to face, over the telephone, through an online form or portal, through a paper form or by email
  • you submit your information in response to IHACPA educational and/or marketing events or other activities.

In some instances, we will collect personal information from third parties or publicly available sources, including where:

  • you have provided consent
  • we are required or authorised by law
  • it is unreasonable or impracticable to collect the information directly from you
  • information obtained through IHACPA consultation processes or reference groups
  • information is collected on behalf of a state or territory government department or health care organisation
  • information is provided by goods and services providers (including contractors). 

You may choose to deal with us anonymously or under a pseudonym. However, in some circumstances, anonymity or the use of a pseudonym will render us unable to provide the relevant service or reasonably conduct our business, and we may request that you identify yourself. 

You may also choose not to provide us with your personal information. Depending on the circumstances in which you do so, however, we may be unable to provide you with our services as a result.

All unsolicited information received by IHACPA will be handled in accordance with the obligations imposed under the APPs.

IHACPA collects a range of hospital data pursuant to its functions outlined in the National Health Reform Act 2011 (NHR Act). The use of hospital data is subject to secrecy provisions contained in the NHR Act which relate to ‘protected Pricing Authority information’, ‘Health care pricing and costing information and Aged care information’. The NHR Act recognises the importance of protecting patient confidentiality and imposes strict obligations on the use, disclosure and publishing of information that is likely to enable the identification of a patient. 

Hospital data contains demographic information, clinical information, the nature of care provided and financial information. IHACPA receives hospital data from various sources as outlined below:

  • state and territory departments of health and private hospital groups: Activity based funding data and the National Hospital Cost Data Collection data 
  • Commonwealth Department of Health, Disability and Ageing: Hospital Casemix Protocol data, Medicare Benefits Schedule data, Pharmaceutical Benefits Scheme data, Private Hospital Data Bureau collection
  • Services Australia: Australian Government Medicare PIN (‘Submission B’) 
  • Australian Institute of Health and Welfare: Public Hospital Expenditure data
  • project specific data collections.

IHACPA handles all hospital data in accordance with the obligations imposed by the NHR Act and other applicable legislation and has implemented measures to further secure hospital data, such as only disclosing de-identified data, assigning unique identifiers, using zeroing or aggregation methods and customising configurations to platforms and systems preventing the search or combination of hospital data. 

As a result of these measures, IHACPA only uses de-identified data in its work. Most hospital data held by IHACPA is not subject to the Privacy Act. Where data could be classed as personal information, such as Individual Healthcare Identifier or Medicare PIN, IHACPA has procedures to ensure that access is limited and encrypted. 

IHACPA treats its hospital data with care and manages the data consistently with this Policy, the Privacy Act and the APPs.

IHACPA’s functions include the provision of advice to the Commonwealth in relation to:

  • health care pricing or costing matters (whether or not the matters relate to health care services provided by public hospitals)
  • aged care pricing or costing matters, including in relation to methods for calculating amounts of subsidies to be paid under the Aged Care Act 2024 (the Aged Care Act). 

To perform these functions, IHACPA may conduct, or arrange for the conduct of costing and other studies, consultations, and collections and reviews of data.

Specific to its aged care pricing and costing functions under the NHR Act and the Aged Care Act, IHACPA collects:

  • Commonwealth Department of Health, Disability and Ageing: Australian National Aged Care Classification assessment data, Aged Care Financial Reporting and Quarterly Financial Report data, residential aged care services data, subsidy, supplement, and service utilisation data
  • Refundable aged care deposits (RAD) applications
  • project specific data collections:

- residential aged care provider data such as cost, time and activity data from participating facilities

- in-home aged care data such as cost, time and activity data from participating providers

- other projects include Multi-Purpose Service Program and National Aboriginal and Torres Strait Islander Flexible Aged Care Program projects and hotel tiering (some of which may require ad hoc collections).

This data includes information about Commonwealth funded residential aged care providers and residential aged care recipients. 

Pricing and costing data is ‘protected Pricing Authority information’ which can only be used and disclosed in accordance with the secrecy provisions in the NHR Act. Pricing and costing data that is aged care information may also be ‘protected information’ under the Aged Care Act.

Typically, pricing and costing information is obtained in de-identified form. It is also subject to strict controls within IHACPA to prevent potential re-identification. As a result, pricing and costing data is de-identified and not subject to the Privacy Act. However, like hospital data, IHACPA handles aged care data consistently with this Policy, the Privacy Act and the APPs.

We collect, use and store your personal information to provide you with our services which include:

  • performance or exercise of IHACPA’s legislative and administrative functions or powers including:

    - functions related to public hospitals and health care pricing and costing 

    - functions related to providing advice to the Minister in relation to health care pricing or costing matters and aged care pricing and costing matters 

    - identifying and receiving information from providers who participate in aged care costing studies 

    - assessing applications from providers to charge higher than maximum residential aged care accommodation payments under section 290 of the Aged Care Act (referred to as RAD applications).

  • responding to enquiries and otherwise engaging with stakeholders
  • policy development and research
  • managing contracts and procurement processes
  • providing marketing information about goods, services, events or initiatives which may be of interest
  • training and education
  • client and business relationship management
  • managing requests for data access and release
  • managing requests for access to documents held including requests under the Freedom of Information Act 1982 (FOI Act)
  • managing employment, work health and safety and personnel matters
  • managing fraud and compliance investigations and audits
  • engaging and managing its workforce; and/or
  • meeting its legal obligations.

We may also collect, use and store your personal information:

  • for marketing purposes, engagement or consultation events in order to provide you information about the services we offer
  • to respond to your questions or suggestions
  • to improve the quality of our services
  • to improve the quality of your visit to our website
  • to undertake employee recruitment activities; or
  • to assist with data analytic processes.

You may opt out of receiving marketing information by notifying us accordingly, or by using any unsubscribe facility we provide for that purpose. If you opt out of receiving marketing information, we may still contact you in connection with the services we provide to you.

Ordinarily, IHACPA discloses personal information to other government agencies or organisations only for the purpose the information was collected. 

Personal information may be disclosed for a secondary purpose with the individual’s consent, where the individual would reasonably expect that their information will be disclosed, or if disclosure is otherwise required or authorised by or under law.

For example, personal information will be used and/or disclosed: 

  • to other Commonwealth, state or territory government departments and external bodies or contracted service providers responsible for performing IHACPA’s functions or assisting IHACPA to perform its functions
  • to liaise with nominated contacts for RAD applications, including to notify the application outcome
  • to manage new and ongoing employees’ employment such as leave applications and approvals and pay related records
  • to monitor employees’ phone and internet usage, code of conduct investigations, police checks and security clearances, while undertaking fraud or audit functions or for other purposes relevant to employer powers under the Public Service Act 1999
  • to Comcare for worker’s compensation matters and/or Comcare rehabilitation providers for rehabilitation purposes and legal advisors for workers’ compensation matters
  • to decision makers, which may include external parties, such as ministers or the Chair of relevant committees
  • biographical information on IHACPA’s website or media announcements regarding particular appointments
  • for stakeholder engagement purposes including IHACPA promotional activities.

We may also disclose your personal information to government agencies, private sector organisations or other entities where required or permitted to do so by law, which may include the following circumstances:

  • you have consented to such disclosure
  • we believe that you would reasonably expect, or have been told, that information of that kind is usually passed to those individuals, bodies or agencies, and it is being disclosed for a purpose related (or directly related, in the case of sensitive information) to the reason we collected the information
  • we are required or authorised to make such disclosure by law 
  • a permitted general situation or permitted health situation (as defined in the Privacy Act) exists in relation to the disclosure
  • we believe it is reasonably necessary for enforcement related activities conducted by, or on behalf of, an enforcement body (for example police, Australian Securities & Investments Commission, Department of Home Affairs).

IHACPA does not store data offshore. If there is a need to send data offshore, IHACPA has procedures and systems in place for ensuring that the information will be handled in accordance with the APPs.

Protecting and storing your personal information

We understand the importance of keeping personal information secure. Some of the ways we do this are:

  • requiring employees and contractors to enter into confidentiality agreements
  • destroying or de-identifying personal information if it is no longer required to perform its functions and its retention is not required under Australian law
  • imposing a range of physical and electronic security measures including restricted physical access to IHACPA’s premises and protections to electronic records in accordance with Australian Government security policies, including the Department of Home Affairs’ Protective Security Framework and the Australian Signals Directorate’s Information Security Manual. 
  • providing discreet environments for confidential discussions
  • implementing security measures for our website(s).

Additionally, IHACPA does not keep paper records. All records are kept electronically on either the IHACPA Secure Data Management System or the Department of Health, Disability and Ageing’s environment.

How can I access my personal information and contact IHACPA?

You have a right under the FOI Act and the Privacy Act to access personal information that we hold about you. 

In certain circumstances such as costing studies where individuals are involved, the individual can request access to information about their hospital stay or aged care service under the FOI Act. 

Access and correction requests regarding hospital data and pricing and costing information may be referred to various sources that supplied the information such as the jurisdiction or entity as appropriate.

You also have a right to request correction of your personal information if it is inaccurate, out of date, incomplete, irrelevant or misleading. 

We have a designated Privacy Officer who is responsible for the management of:

  • requests for access to personal information
  • complaints regarding our management of personal information.

Alternatively, you can make an FOI request.

The procedure for obtaining access including requesting correction is as follows:

  • all requests for access to personal information to be made in writing and addressed to our Privacy Officer. All requests should specify how the information is proposed to be accessed (hard copy, electronic copy, or visual sighting)
  • we will endeavour to acknowledge your request as soon as reasonably possible
  • access will usually be provided within 30 calendar days. If access cannot be processed within that time for whatever reason, we will let you know the anticipated timeframe for IHACPA to provide you with a response
  • you will need to verify your identity and authority before access to personal information is granted
  • we may charge a reasonable fee for access to personal information, which will be notified and required to be paid prior to the release of any information. Once the request has been processed by us, you will be notified of our response and proposal for suitable access (hard copy, electronic copy, or visual sighting)
  • we may refuse to grant access to personal information if there is an exception to such disclosure which applies under relevant privacy or FOI legislation
  • if, as a result of access being granted, you are aware that we hold personal information that you regard as no longer accurate or correct, you may request the correction of such information
  • upon receipt of a request to correct the personal information, we will either make such corrections or provide written reasons as to why we declined to make such alterations.

In the event that you disagree with the outcome of an access or correction request decision made by IHACPA, you can make a complaint to the Office of the Australian Information Commissioner (OAIC). 

For information regarding privacy, contact our Privacy Officer using the details set out at the end of this Policy:

If you consider that there has been a breach of the APPs, you are entitled to complain to IHACPA.

Complaints can be made in writing or by phone and directed to the Privacy Officer using the contact details below. 

The Privacy Officer will investigate the complaint and attempt to resolve it within 30 business days after the complaint was received. Where it is anticipated that this timeframe is not achievable, we will contact you to provide an estimate of how long it will take to investigate and respond to it.

If you are not satisfied with the outcome of IHACPA’s investigation and decision, you are entitled to raise your complaint with the OAIC. Further information can be found on the OAIC website (https://www.oaic.gov.au/privacy/privacy-complaints).

Contact IHACPA’s Privacy Officer:

Name: Nancy Hatem
Title: Director, Governance, Legal and Secretariat
Postal Address: PO Box 483, Darlinghurst, NSW 1300
Telephone: (02) 7242 0029
Email: nancy.hatem@ihacpa.gov.au
Online enquiry form: https://www.ihacpa.gov.au/contact-us  

Documents

Last updated: 24 September 2026
Is this page useful?

Help us improve your IHACPA experience.

We'd like to know more about your visit today

 

Was this page useful?
Describe your experience
Describe your experience
What sector do you represent?