1. Purpose and Alignment
This policy provides guidance for the use of social media by all staff of St. Andrews Health. Its purpose is to :
- Protect patient confidentiality and privacy in accordance with the Privacy Act 1988 (Cth), the Health Records Act 2001 (Vic), and RACGP standards.
- Uphold the professional standards expected by the Australian Health Practitioner Regulation Agency (AHPRA) and the Royal Australian College of General Practitioners (RACGP).
- Safeguard the reputation of the practice.
- Comply with RACGP Criterion 6.4 G and the associated guidelines provided in the RACGP’s Information security in general practice and Guide for the use of social media in general practice.
2. Scope
This policy applies to all employees, contractors, students, and volunteers of St. Andrews Health. It governs all use of social media that relates to the practice or could be perceived as such, whether conducted on practice systems or personal devices.
3. Definition of Social Media
Social media includes all digital platforms for creating and sharing content, such as Facebook, Instagram, Twitter (X), LinkedIn, TikTok, YouTube, blogs, forums, and review sites (e.g., Google Reviews).
4. Roles and Responsibilities
- Designated IT Security Officer : Dr Kamra and Dr Keyi has primary responsibility for computer security, including advising on this policy, educating staff on security protocols, and monitoring compliance.
- All Staff : Are responsible for understanding and adhering to this policy, maintaining the security of their unique login credentials, and completing relevant training.
5. Professional Use of Social Media
Official practice social media accounts must be managed securely and professionally.
- Authorisation: Only staff members explicitly authorised by the Practice Manager may post on behalf of the practice.
- Content Standards: All content must be accurate, evidence-based, and professional, reflecting the practice’s values.
- Patient Interaction: Social media must not be used for providing specific medical advice or diagnoses. Direct patients to official channels (phone, appointment systems).
- Patient Consent: Written consent using the clinic’s official form is mandatory before posting any patient-identifiable information, stories, or images.
- Responding to Feedback: Respond to comments professionally. Escalate negative or complex comments to the Practice Manager. Never disclose patient information in a public reply.
- Access Security: Official social media accounts must be accessed using unique individual logins and passwords, which must be kept secure and not shared.
6. Personal Use of Social Media
Staff must use social media responsibly in their personal lives, understanding that their online conduct can reflect on the practice.
- Confidentiality is Paramount: Never post any information that could identify a patient, their condition, or their treatment. Discussing clinical cases, even anonymously, is prohibited.
- Separation of Personal and Professional: Use a disclaimer such as: “The views expressed are my own and do not represent the views of St. Andrews Health.”
- Respect and Reputation: Avoid posting disparaging comments about the practice, colleagues, or patients.
- Professional Boundaries: Do not accept “friend” requests from current patients on personal social media accounts.
7. Privacy, Confidentiality, and Information Security
This policy works in conjunction with our Practice Privacy Policy and IT Security Policy to protect information.
8. Managing Online Reviews and Feedback
- Staff must not post reviews of the practice on any platform.
- Notify the Practice Manager of any reviews. The Practice Manager will coordinate any official response, which will always protect patient privacy and direct concerns to our formal complaints process.
9. Breaches and Consequences
Breaches of this policy will be taken seriously and may constitute misconduct.
- Disciplinary Action: Breaches may result in disciplinary action, up to and including termination of employment.
- Legal and Regulatory Consequences: Serious breaches, particularly those involving patient privacy, will be reported to the relevant authorities, including AHPRA and the Office of the Australian Information Commissioner (OAIC), as required by law.
- Reporting Breaches: Staff must report any suspected breaches of this policy to the Practice Manager or the Designated IT Security Officer immediately.
10. Policy Review and Relationship to Other Policies
This policy will be reviewed annually by the Practice Manager and the Designated IT Security Officer, or in response to changes in legislation or RACGP guidelines.
This Social Media Policy is part of our practice’s comprehensive approach to information security and should be read in conjunction with our:
- Privacy Policy
- Email Policy
- IT Security and Access Policy
- Business Continuity and Information Recovery Plan