Privacy Policy

How Moorditj Koort collects, uses, protects and shares your personal and health information.

Last updated: September 2026

Moorditj Koort Aboriginal Corporation (MKAC, "we", "us", "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store and share personal information, including health information, and how you can access or correct it or make a complaint.

We are bound by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and, as a health service provider, the rules that apply to health information. We also follow the My Health Records Act 2012 (Cth) where it applies.

1What information we collect

Depending on how you deal with us, we may collect:

  • Identity and contact details - name, date of birth, address, phone, email, emergency contact, Medicare number, Aboriginal and/or Torres Strait Islander status (only where you choose to tell us and it is needed to deliver culturally safe care or programs).
  • Health information - medical history, conditions, medications, test results, referrals, care plans, and notes from consultations, when you use our GP clinic, specialist clinics or health programs.
  • Program and service information - details needed to enrol you in a program (for example Integrated Team Care, Elder Care Support, NDIS-related services) and to report to funding bodies in de-identified form.
  • Employment and volunteering information - if you apply to work or volunteer with us.
  • Website information - see section 7.

2How we collect it

We collect information directly from you when you register as a patient or client, attend an appointment, join a program, fill in a form on our website, call or email us, or apply for a job. We may also receive information from other health providers involved in your care (for example a hospital, specialist or pathology service), from Medicare or the NDIS, or from a person you have authorised to act for you.

3Why we collect and use it

  • To provide you with health care and community services, and to communicate with you about your care and appointments.
  • To coordinate your care with other health professionals you have agreed we can work with.
  • To claim Medicare, NDIS and other benefits on your behalf.
  • To meet our legal obligations, including mandatory reporting and notifiable diseases.
  • To report to our funding bodies, accreditation bodies and the Board - in de-identified or aggregated form wherever possible.
  • To improve our services, plan programs and respond to feedback and complaints.

We will not use your health information for any other purpose without your consent, unless the law requires or permits it.

4Who we share it with

We may share your information with:

  • other health professionals and services involved in your care, with your consent;
  • Medicare, the NDIS and other government agencies where required to provide or fund your care;
  • secure IT and clinical software providers who store information on our behalf;
  • anyone you have authorised us to share it with; or
  • where required by law (for example a court order or public health requirement).

We do not sell personal information. We do not send personal information overseas except where a service provider stores data on secure servers outside Australia; in that case we take reasonable steps to ensure it is protected to Australian standards.

5How we keep it safe

Health records are held in secure clinical software with access limited to authorised staff. Paper records are stored in locked areas. Our IT systems use access controls, encryption, backups and monitoring. All staff are bound by confidentiality obligations and receive privacy training. We keep health records for the period required by law (generally at least 7 years for adults, or until a child turns 25) and then securely destroy them.

6Your rights - access and correction

You can ask to see or get a copy of your personal information, or ask us to correct it, by contacting our Privacy Officer (details below). We will respond within 30 days. In limited circumstances the law lets us refuse access (for example where it would pose a serious threat to someone's health); if so we will tell you why.

7Our website

  • Forms - information you enter in our contact, feedback, donation or program forms is sent to us by email and stored securely. Please do not include detailed health information in a website form; contact the clinic directly instead.
  • Cookies and analytics - our website uses cookies and analytics tools (such as Google Analytics) to understand how the site is used. This information is aggregated and does not identify you. You can disable cookies in your browser.
  • Links - our site links to other websites (for example Facebook, Instagram, government services). We are not responsible for their privacy practices.
  • Security - the site uses HTTPS encryption. No internet transmission is completely secure, so please take care with what you send.

8Anonymity

Where it is lawful and practical you may deal with us anonymously or using a pseudonym - for example when asking a general question. This is usually not possible when we are providing health care to you.

9Complaints

If you think we have breached your privacy, please contact our Privacy Officer first. We take complaints seriously and will respond within 30 days. If you are not satisfied you can complain to the Office of the Australian Information Commissioner (OAIC) on 1300 363 992, or to the Health and Disability Services Complaints Office (HaDSCO) WA on 1800 813 583.

Contact us

Privacy Officer
Moorditj Koort Aboriginal Corporation
Phone: (08) 6174 7000
Email: [email protected]
Post: 1 Sutherland Parade, Parmelia WA 6167

11Changes to this policy

We may update this policy from time to time. The current version is always available on this page.

Logo