Mildura Health Fund Privacy Policy
1. Our commitment to your Privacy
Mildura Health Fund (MHF) Privacy Policy details our commitment to your privacy and outlines the procedures and systems that are in place to ensure compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This ensures protection against inappropriate use of your personal information. This policy applies to all your dealings with MHF whether it be in person or electronically. Please read it carefully and contact us if you have any questions.
2. Whose personal information do we collect
Our commitment to privacy covers all persons whose personal information we hold.
Therefore, any reference in this Privacy Policy to ‘you’ should be taken to mean and include a reference to the member named as the policy holder, any dependants of that member and any other persons whose personal information we hold.
3. What personal information do we collect?
Personal information is any information or an opinion about you where your identity is apparent or can reasonably be ascertained. Sensitive information includes, but is not limited to, any information relating to a person’s ethnicity or race, religion, any health information collected or obtained directly from you, through third parties, or through our post-natal service for members that participate in this service.
For the purposes of providing health insurance, we collect and hold a range of personal information, including, but not limited to:
- Identifying information such as your name, address, date of birth, and contact details, including telephone numbers and email addresses;
- Your dependents names, dates of birth, and education facilities where they are registered as a student dependent on your health insurance policy;
- Information about your health including benefit claims for any medical, hospital or other health service or treatment, including details of where, when and from whom you have received that service or treatment and the nature of it;
- Information about your health, medical treatment and services provided by our post-natal service including details of where, when and from whom you have received that treatment or service and the nature of it.
- Financial information including your bank account details;
- Details about your premiums and claims (if any) history;
- Medicare numbers of you and your dependants;
- Your employment details, including employer name, if you pay your premiums through a payroll deduction scheme; and
- Information about your usage of our website and mobile claims app.
MHF uses its own membership numbers to identify members. While in certain circumstances we are required to collect government identifiers such as your Medicare number, we do not disclose this information other than when it is required or authorised by law, including under the Privacy Act. We do not use your Medicare number to identify you.
4. Why do we collect personal information?
We collect, hold, use and disclose your personal information for a range of functions and activities to provide the products and services you have come to expect from us as a health insurer, including, but not limited to:
- establishing and maintaining your membership, which includes processing applications and related administrative tasks such as changes to your contact details or other health insurance policy information;
- processing health insurance claims, and paying benefits;
- updating the terms and conditions of your membership from time to time in accordance with changes to Fund rules;
- providing you with information about products and services offered by us and others which we believe may contribute to the overall health of you and your dependants or meet your other insurance requirements;
- providing you with access to your membership via our website member portal and our mobile claims app;
- collecting, compiling and disclosing information to government agencies where we are required by law to make such a disclosure;
- enabling you to collect the Australian Government Rebate on private health insurance by using your Medicare number;
- determining cover and eligibility for benefits by using information from your previous health insurer;
- determining waiting periods that may apply by referring to pre-existing ailment information;
- making any other use of disclosure of that information as may be required by law;
- manage and develop health insurance products;
- conduct marketing activities through communication channels such as email, newsletter or survey software, or SMS;
- obtain feedback and engage in research projects such as satisfaction and trust surveys; and
- manage and/or resolve any legal, clinical or commercial complaint or issue.
Your personal information is collected when you provide it to us as a service provider, contractor, or prospective employee, for the purposes for which you have provided the information, and any related purposes.
5. When do we collect personal information?
We may collect personal information at various times for the purpose of providing health insurance, including when you:
- contact us by telephone, mail, email or online, or you visit us in person;
- start or complete a request for a quote, an application form, change your level of cover or any other type of request in relation to our products and services;
- make a claim for benefits;
- visit our website or when you input or allow collection of information through our mobile claiming app.
6. How do we collect personal information?
We will collect personal information directly from you or from third parties only where it is necessary for one or more of our functions or activities. We will do this in a lawful and fair manner with the following providing a list of potential sources of information:
- We aim to collect personal information about you from you directly (in writing, in person, via email or telephone) however, in many instances, this may not be practicable and as such we may collect it from family members, especially where a family member is the member named as the policy holder in a family cover policy;
- Hospitals, medical, post-natal and other health service providers;
- Your employer if you are part of a payroll deduction scheme or similar;
- Government agencies;
- If you are a health service provider, from relevant government or industry services, databases and directories;
- CCTV cameras at our offices and branches;
- Payment system operators and financial institutions;
- Persons who are authorised to share personal information with us. These include people you have authorised to deal with us in relation to your policy, such as attorneys you have appointed under a power of attorney, a delegated authority, your guardian, or other agents or representatives appointed by you;
- Another health insurer and your co-insured, if you have requested a transfer of your health insurance between that fund and us.
We aim to store your private information securely and have a number of information and physical security controls in place which are designed to protect your personal information. Our employees and contractors receive privacy training. We take responsible steps in order to make sure that the personal information about you is accurate, complete, up to date and relevant.
Member Correspondence
Any correspondence received by MHF, including via the post or email, is retained and recorded within MHF membership communications. MHF keeps these records in order to maintain the highest possible customer service levels and for any future enquiries. MHF also retains any correspondence MHF sends to you.
The retention of these records may also help us in the investigation of potential fraud and violations of the MHF User Agreements. We maintain policies and procedures for the retention of documents and data which governs the use of, and access to such material.
7. How do we collect sensitive information
We will only collect sensitive information (specifically health information) directly from you or from third parties with all necessary consents. Where you are under the age of 16 years, necessary consent may mean the consent of an appropriate adult who is most likely to be the member named as policy holder in respect of any family cover policy where there may be entitlement to benefits if you receive treatment.
By directly supplying sensitive information about yourself or any dependant or through a third party in order to make a claim for benefits you will be taken to have given your consent to the collection of that information.
8. Use of your personal information
We may use personal information for any of the following purposes;
- to manage our relationship with you, to identify and communicate with you, or to provide you with products, services or information that has been requested by you;
- to manage and resolve any legal, clinical or commercial complaints or issues;
- to analyse, investigate, pursue and prevent suspected fraudulent or criminal activities;
- where we record your calls, to identify you and manage our relationship with you. We may also use call recordings, for training, coaching and development purposes unless you ask us not to at the time of the call;
- to manage, review, improve and develop our membership offering, products and services or our business and operational processes and systems. This includes obtaining feedback, and undertaking business intelligence, analytics and research activities and projects or partnering with third parties to assist us to do so;
- to assist you with assessing your suitability for health insurance products or health related services;
- to undertake other general functions and activities relating to the operation of our business and assets. This includes training, coaching, development and audit.
9. Disclosing your personal information
We will only disclose your personal information in order to carry out our business functions and activities. The types of individuals and/or organisations to whom and the purposes for which we disclose your personal information include, but are not limited to:
- The member named as the policy holder (or partner) under a family type cover policy concerning matters relating to the policy including levels of benefits available or paid under the policy;
- our contracted service providers who promote or assist us in administering or providing our products and services such as, for example, external printers, mailing-houses, IT companies, internet service providers, newsletter services and other relevant service providers;
- your employer if you are part of a payroll deduction scheme or similar;
- hospitals, medical, post-natal and other health service providers with whom you have had or may have a treatment episode and to whom fees may be payable;
- other organisations who assist us to detect , investigate, pursue and prevent suspected fraudulent activities;
- our professional advisers, for example, an independent medical adviser to review and validate claims;
- payment system operators and financial institutions;
- Government agencies or other parties, where we are required by law to disclose this personal information;
- another health insurer, if you have requested a transfer of your health insurance to that health insurer between that fund and us; and
- to comply with our legal rights or enforce our legal rights, or as otherwise required or authorised by law.
MHF does not generally disclose information to overseas recipients but on the rare occasion that we are required to do so, we will always ensure that you have consented to such disclosure.
10. Collection of information via the Mildura Health Fund website
When you visit our website, information about the computer or web device you are using is automatically recorded by our website. This includes your IP address, your domain name, the date and time of your visit to our site, the pages you accessed or downloaded, the last site you visited, your operating system, and the type of browser used.
This information is collected for statistical and administrative purposes, and to improve our web-based services. It does not readily identify individuals, and we will not attempt to identify individuals from the records generated unless it is necessary to do so for law enforcement purposes.
We may also use cookies to assign your device a user ID. Cookies contain information that allows us to identify your device. We may use this information to determine whether to display standard or personalised content. You can configure your browser so that it does not accept cookies, however this may minimise our ability to provide you with customised information.
We use third-party services to collect general information about how people use our website (Google Analytics). This anonymous information is aggregated and doesn’t reveal personally identifiable information about anyone who uses our website.
Further details can be found in the Website and App Terms and Conditions under Term of Use on the MHF website.
11. Communicating with you and direct marketing
When you become a member of MHF, you consent to us using your personal information for direct marketing purposes unless you contact us to withdraw your consent. Marketing will be limited to MHF product and member services, and relevant member information.
If you provide us with an email address, we will send most service-related communications to you by email. Service-related communications provide essential information about our products and services, for example, in relation to your insurance cover, service-related communications may include annual tax statements, changes to premiums and renewal notices.
We may use your personal information to contact you (including by phone, text message, email or online) about products, services or information about your policy that we think may be of interest to you or necessary for you to be aware of. This may include our own, or a third party’s products or services.
We may contact you about products and services we think may be of interest to you after you cease to hold a private health insurance policy with us. For example, we might contact you about renewing your old policy, taking out a new policy or completing a survey.
12. How can I opt-out of receiving marketing communications
You can opt-out of receiving marketing communications from us at any time by:
- calling us on (03) 5023 0269
- emailing us at mhf@mildurahealthfund.com.au
Please allow five working days for your request to be actioned by us.
You will still receive service-related communications from us.
13. Security and quality of personal information
MHF takes all necessary and reasonable steps to ensure that the personal information we collect is relevant, accurate, complete and up to date.
All personal information is stored by MHF and reasonable steps are taken to protect your information from interference, misuse, loss, modification or disclosure from unauthorised access, in accordance with the requirements of the Australian Privacy Principles. We have in place a range of information security policies and procedures that aim to protect your information from both internal and external risk of unauthorised access and use.
Once the information collected is no longer required in accordance with business and legal obligations, it will be destroyed or de-identified.
In the unlikely event that security of data is compromised, we will take reasonable steps to confirm any possible breach. If a breach is confirmed and it has the potential to cause you serious harm, we will notify you and provide you with a description of the breach, the kinds of information involved, and any recommended actions you could take to protect yourself.
14. Dealing with us anonymously or using a pseudonym
Where it is lawful and practicable for us, you can choose not to identify yourself when dealing with us and to use a pseudonym (false name or alias). You may choose to do this for several reasons, for example, but not limited to, the following situations:
- if you are making a general inquiry about the benefits we pay on a procedure with no need to provide your personal details; and
- if you contact us to obtain a quote for health insurance, you are not obliged to provide us with personal details including your name or address however, the quote may not include any rebate, lifetime health cover or age based discount calculations specific to your circumstances.
In many situations, we need your identity details. For example, we need your name and date of birth if you want to receive the applicable government rebate on the private health insurance you hold with us. We need to verify your identity if you are making a claim or applying to become a member, and to allow you to access your policy and the health insurance records.
If you do not provide or allow us to have your personal information when we need it, we may not be able to provide you with some or all of the products and services you require.
15. Disposing of your personal information
We keep your personal information for as long as we deem it required in order to provide you with products and services or to comply with our business and legal obligations and requirements. When we deem this information is no longer required, we will destroy or de-identify this information. If you request access to your old personal information, we may not be able to provide you with your records as they may have been destroyed or de-identified.
16. Access to your personal information
You may request details of the personal information we hold about you, or about any dependant aged less than 16 years or about any dependant of impaired capacity by contacting us via email, mail or in person.
We will not charge a fee just because you make a request for access to your personal information. However, we reserve the right to charge a fee for the costs incurred in providing personal information in response to your request.
To protect you and us from fraud and misuse of your information, we will need to be reasonably satisfied of your identity or that of a person you have authorised to deal with us on your behalf. We may require you, or your agent, to verify your identity by providing us with you certified ID.
We will provide requested personal information in line with the Privacy Act. Where we are not obliged to provide the requested information, we may refuse your request on the basis that:
- providing access would pose a serious threat (or in the case of personal information other than the health information, a serious and imminent threat) to the life, health or safety of any individual or to public health or public safety; or
- providing access would have an unreasonable impact upon the privacy of other individuals; or
- your request for access is frivolous or vexatious; or
- the information relates to existing or anticipated legal proceedings involving MHF and would not be accessible by the process of discovery in these proceedings; or
- it is otherwise appropriate for us to refuse your request so that we can meet our obligations to you or others in accordance with the law and the Australian Privacy Principles.
We will respond to your request within 30 calendar days. If we refuse you access to any personal information, we will provide you with a reason for the refusal in writing. We may also consider the use of an agreed intermediary to receive the personal information rather than you if this is appropriate, or we may try to reach an amicable solution that meets the needs of all concerned.
17. Correction of your personal information
If we become aware that information, we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading we will take steps to correct the information.
If you are aware that any of your personal information that we hold is inaccurate, incomplete or out of date, please let us know so that we can update our file. If any of your personal information is incorrect, we will correct that information, or if we refuse to do so, you will be provided with a reason for the refusal within 30 days. In any event, if we do refuse to make a correction, we will record a statement from you claiming that the disputed information, in your opinion, is not accurate, complete or up to date.
You may request that we notify any third party to whom we have disclosed the inaccurate information. We will take steps to have the third party correct, to the extent that it is practicable or lawful to do so.
18. Unsolicited personal information
If MHF receives any unsolicited personal information we will take steps to ascertain whether we could or could not have collected this information under Australian Privacy law and related guidelines.
If we should not have collected the information, then we will destroy or de-identify this information as soon as practicable, providing it is reasonable and lawful to do so.
19. Relationship breakdowns
If the policy holder and their partner under a family type health insurance policy separate or divorce, we suggest that the partner be removed from the policy and take out a separate health insurance policy. This is intended to protect the privacy of both the policy holder and their ex-partner. In this regard, we cannot provide information to either the policy holder or their ex-partner about the other’s health insurance policies. Please inform us promptly if this occurs so that we can take the steps to make relevant changes.
We also cannot provide information about whether or not dependent children are covered under the health insurance policies of the other.
If you are a victim of domestic violence or stalking, or have concerns about your personal safety, we encourage you to let us know to discuss further privacy protections that we may be able to provide to you.
You may opt to pay for another person’s policy, but absent from them giving you authority, this does not permit us to otherwise disclose information about the policy to you. However, you can contact us to cease your payments, but need to be aware that if you do this, we will contact the policy holder to advise them that their policy will be or is unfinancial due to a cancelled payment or failed direct debit.
20. Your right to complain
You can make a complaint at any time to us about any actual or perceived breach of our privacy obligations to you. Complaints about possible breaches of our Privacy Policy should be directed to our Privacy Officer. Upon receipt of your complaint, our Privacy Officer will contact you (in writing and / or by telephone) to confirm receipt of your complaint and, if necessary, to advise you of any additional information we require to investigate your complaint.
Within 30 days of confirming receipt of your complaint (or receiving any further information required to investigate the complaint), we will respond in writing to you with the outcome of the investigation of your complaint including, if applicable, how we propose to resolve your complaint.
If you believe, we have not resolved the issue you may refer the matter to the Office of the Australian Information Commissioner.
21. How you can contact us or the Australian Information Commissioner’s Office
You can contact us at Mildura Health Fund:
Address: 79 Deakin Avenue Mildura, VIC 3500
Postal: PO Box 5046 Mildura, VIC 3502
Telephone: (03) 5023 0269
Email: memberexperience@mildurahealthfund.com.au
You can contact the Office of the Australian Information Commissioner at:
Address: GPO Box 5218 SYDNEY NSW 1042
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au
Website: www.oaic.gov.au
Changes to this Privacy Policy
We may change this privacy policy from time to time and encourage you to check the Mildura Health website at www.mildurahealthfund.com.au for the latest version.
Effective Date: 1 November 2024