Today’s correspondent is
… a Paramedic in regional NSW in an area that has a high workload of mental health. The declared mental health facility for the area regularly has mental health patients being watched by NSW health hospital security guards in the safe assessment rooms.
It has progressively become common for security guards to request ambulance documentation and or/section 20 paperwork once the patient is assigned to this area by the NUM. If this is not provided to them, they will often obtain all the patient documentation whilst the patient is under their supervision in these areas.
This was brought up with operational management and the initial response was “Hospital security fall under the same confidentiality agreement by health” this information was discussed but I was not part of the email chain enquiring further.
My question is: Are NSW health hospital security authorised to receive and/or view ambulance EMR printouts and/or section 20 documents. These documents (especially EMR printout) contain confidential patient history and information that does not serve relevance to the security staff’s duty to supervise these patients. Hospital security are often provided brief information from ambulance such as voluntary/involuntary, violent/non-violent (with ambulance staff), or potential for absconding based on ambulance observation. Should they be requesting ambulance EMR/section 20 from us (or hospital staff) at all? Or does this provide a breach in patient confidentiality by them having access to this information?
I have reviewed many NSW health confidentiality documents and the closest I could find was NSW health security would only be required to have access to information relevant to their role. Past medical history and current detailed history from ambulance assessment to me does not fall into this category.
Unfortunately I’m not given the reference to the document my correspondent discovered but working from first principles, it must be true that “Hospital security fall under the same confidentiality’ obligations of all health staff. By working in a hospital security staff, the cleaners, the kitchen staff etc all come into contact with confidential health information. Even the fact that someone is in hospital is confidential and they may on occasions over hear discussions regarding a patient’s health information. They are duty bound to keep that information confidential but that does not mean they are entitled or would be expected to access health records that are not relevant to their task.
Section 20 of the Mental Health Act 2007 (NSW) says that an ambulance officer may take a person to a declared mental health facility. Section 18 says that the staff of that facility may detain the person who is brought to them under s 20. There is no ‘prescribed’ section 20 paperwork but NSW Health has developed a form for use by ambulance officers to record the reasons for their belief that the person ‘appears to be mentally ill or mentally disturbed and that it would be beneficial to the person’s welfare to be dealt with in accordance with’ the Mental Health Act (s 20(1); see https://www.health.nsw.gov.au/mentalhealth/legislation/Documents/nh606721a.pdf).
Health Principle 10 (set out in schedule 1 to the Health Records and Information Privacy Act 2002 (NSW)) says that an ‘An organisation that holds health information must not use the information for a purpose (a “secondary purpose”) other than the purpose (the “primary purpose”) for which it was collected’. When paramedics hand over their patient to a health care facility they communicate their observations and details of their treatment to allow for the patient’s ongoing care. They obtained the information to provide health care for the benefit of the patient and providing that information to the triage nurse is using the information for the primary purpose for which it was obtained.
Some information may also be given to an admissions clerk to allow them to start a file and to match the patient’s records with records of prior admissions and in some cases to ensure accurate billing. Some of that is also to ensure continuity of care so is part of the primary purpose for which health information is obtained, but some of it may be for secondary administrative purposes. There is however no breach of the Health Principles where information is passed on for the secondary purpose where ‘the secondary purpose is directly related to the primary purpose and the individual would reasonably expect the organisation to use the information for the secondary purpose’ (Health Principle 10(b)).
The security staff work for the hospital so whether they need to have information about the patient relates to their role. Advising the security staff about the patient’s risk to other patient’s or staff, or that the patient is being detained as an involuntary patient and may therefore be restrained if they try to leave would be consistent with the use of that information for both the primary purpose (patient care) or secondary purpose (hospital security). But that does not mean the security staff, any more than the catering staff who know patient A is on a diabetic diet, need to know intimate details about the patient’s diagnosis or treatment. It really is a question of ‘what do they need to know to do their job?’; and the answer to that depends on what they are tasked to do and it may be more than simply standing at the door saying ‘no you cannot leave’. Maybe they are encouraged to interact with patient’s in which case some knowledge of the background may help.. They may be tasked with securing the patient’s health care record in which case they need the paramedics’ records to attach them to a file that they are responsible for securing. I don’t know, and the job may be different from institution to institution.
Conclusion
The basic principle is that security staff, like all staff in a health care setting, should have access to the confidential information they need to do their job and no more. What that information is depends on what they are being tasked to do. There is no specific law that answers the question ‘Are NSW health hospital security authorised to receive and/or view ambulance EMR printouts and/or section 20 documents?’ They are if for example the standard operating procedures at that hospital are, for example, that the section 20 documents stay with the patients and are to be handed to the security staff. If the security staff can access the patient’s entire medical record it is up to the hospital to determine if that is necessary and good practice.
If I was ‘a Paramedic in regional NSW in an area that has a high workload of mental health’ where this is an issue I would be asking, via the Ambulance Service or my industrial organisation, for the relevant health service to set out its expectations on hand-over. If the expectation is that all clinical notes are given to the triage nurse, then you do that and let the hospital decide who has access to that information. If the hospital’s standard operating procedure is that you hand the section 20 form to the security staff when you deliver the patient, then you do that. If the SOP is that you hand the documents to the triage nurse, but security then ask for a copy, you direct them to the triage nurse to get whatever information the hospital has decided they need to know. It really is up to the hospital, not the paramedics, to determine what information the security staff need to have to do their job and to then make arrangements, and document those arrangements, for the benefit of everyone.
This blog is a general discussion of legal principles only. It is not legal advice. Do not rely on the information here to make decisions regarding your legal position or to make decisions that affect your legal rights or responsibilities. For advice on your particular circumstances always consult an admitted legal practitioner in your state or territory.