1. Purpose
Medical Response Industries (MRI) is committed to respecting the privacy of individuals and safeguarding personal and health information.
MRI upholds privacy rights and manages privacy-related complaints fairly, respectfully, and in accordance with New Zealand law and best practice standards.
2. Relevant Legislation, Codes and Standards
This policy is informed by:
- Privacy Act 2020
- Health Information Privacy Code 2020
- Health (Retention of Health Information) Regulations 1996
- Code of Health and Disability Services Consumers' Rights (1996)
- Health Information Security Framework (HISO 10029:2015)
3. Scope
This policy applies to all MRI personnel, including staff, contractors, clinicians, and volunteers.
It applies to all personal and health information MRI collects, stores, uses, and shares in the course of delivering services.
4. Guiding Principles
MRI is guided by the Information Privacy Principles outlined in the Privacy Act 2020, with particular attention to:
- Transparency and fairness in collection
- Purpose limitation
- Storage and security
- Access and correction rights
- Responsible sharing and disclosure
5. Privacy Commitments and Compliance with Principles
Principles 1–4: Collection of Information
MRI collects personal information only when necessary to deliver our services, such as event medical care, first aid services, or administrative processes.
Information is generally collected directly from the individual, unless impractical in emergency or critical care settings.
All collection is done lawfully, fairly, and with respect for cultural safety and personal dignity.
Principle 5: Storage and Security
MRI securely stores all personal and health information, whether paper-based or electronic.
We implement appropriate safeguards including role-based access controls, encryption, and secure storage facilities.
Staff are trained to follow our data security procedures, and all data is retained only as long as necessary.
Principle 6: Access to Information
Individuals have the right to access their personal and health information. Requests must be made in writing to:
Privacy Officer
Medical Response Industries (MRI)
Email: privacy.officer@mri.nz
We may request proof of identity before fulfilling access requests.
Principle 7: Correction of Information
Individuals may request corrections to information. Where correction is not possible (e.g. clinical judgement), a note of the request will be recorded.
Principle 8: Accuracy
Before using or disclosing personal information, MRI will take reasonable steps to ensure the information is accurate, current, and relevant.
Principle 9: Retention of Health Information
MRI retains health information for a minimum of 10 years from the date of care, in accordance with regulatory requirements.
Non-health personal information is kept only as long as is necessary for service delivery or legal obligations.
Principle 10: Use of Information
Personal information is used only for the purpose it was collected, unless permitted by law or the individual consents.
Secondary uses (e.g. clinical auditing, quality improvement, or training) are permitted under specific legal provisions and with ethical safeguards.
Principle 11: Disclosure of Information
Disclosure is limited to:
- The individual concerned
- Healthcare providers involved in their care
- Agencies authorised by law
- Others, with the individual's consent
Exceptions may apply in emergencies or where the law mandates disclosure.
Principle 12: Overseas Disclosure
MRI may store or process personal information using overseas service providers (e.g. cloud platforms). We ensure any such transfer complies with New Zealand privacy law and that equivalent safeguards are in place.
Principle 13: Unique Identifiers
MRI assigns unique identifiers (e.g. incident numbers) only where necessary to deliver services efficiently and securely.
6. Privacy Breaches
A privacy breach involves unauthorised access, loss, or misuse of personal information.
Serious breaches must be notified to the Privacy Commissioner and affected individuals where required.
Staff must report any suspected breach to their manager and the Privacy Officer immediately via privacy.officer@mri.nz
MRI uses the Privacy Commissioner's guidance and tools to assess breach severity and determine appropriate responses.
7. Responsibilities
- All personnel are responsible for handling information in accordance with this policy.
- Managers must monitor compliance within their teams.
- The Privacy Officer oversees complaints, breach responses, and provides advice on complex cases.
8. Monitoring and Compliance
MRI's compliance with this policy is monitored through internal audits and reviewed periodically by the Privacy Officer and the Director of Operations.
9. Definitions
- Personal Information
- Any information that can identify a living individual.
- Health Information
- Any information relating to a person's physical or mental health, disabilities, or healthcare services.
- Privacy Breach
- An unauthorised or accidental access, disclosure, or loss of personal information.
- Notifiable Privacy Breach
- A breach likely to cause serious harm, requiring notification under the Privacy Act.
10. Related Documents
- MRI Privacy Notice
- ICT Security Policy
- SOP: Release of Personal Information
- Clinical Records and Data Handling Procedure
Policy Number: MRI-PP-001
Date Issued: 01/07/24
Issued By: National Director of Operations
