Acceptable Use Policy
1. Purpose
This Acceptable Use Policy describes the standards that apply to access and use of the MH Health Connect Platform.
The Policy is intended to:
- promote safe, lawful and responsible use of the Platform;
- protect patient privacy and information security;
- support compliance with professional and regulatory obligations;
- maintain the integrity and availability of the Platform; and
- protect MH Health Connect, Healthcare Organisations and authorised users.
Compliance with this Policy is a condition of accessing and using the Platform.
2. Scope
This Policy applies to all users of the Platform, including Healthcare Organisations, healthcare professionals, administrative staff, contractors and any other authorised users.
The Policy applies regardless of how the Platform is accessed, including through web browsers, mobile devices, integrations, APIs and other approved access methods.
3. Guiding Principles
Users must:
- act professionally, ethically and lawfully;
- protect patient privacy and confidentiality;
- access only information they are authorised to access;
- maintain appropriate security practices; and
- remain accountable for actions performed using their accounts.
Healthcare professionals remain responsible for their own clinical decisions and professional obligations.
4. Authorised Users
Access to the Platform is limited to individuals authorised by a Healthcare Organisation or MH Health Connect.
Users must:
- use only their own account;
- maintain accurate account information;
- protect login credentials;
- comply with this Policy; and
- promptly report suspected unauthorised access.
Healthcare Organisations are responsible for managing user access and removing access when it is no longer required.
5. Appropriate Use
The Platform may be used only for legitimate healthcare, administrative and business purposes authorised by the relevant Healthcare Organisation.
Users may use the Platform to manage patient information, support healthcare workflows, generate clinical and administrative documents, communicate with authorised users and perform other functions made available by MH Health Connect.
Users should review all clinically significant information and outputs before relying on or using them.
6. Prohibited Activities
Users must not:
- access information without authorisation;
- share user accounts or passwords;
- impersonate another person;
- attempt to access another organisation's information;
- introduce malicious software;
- interfere with Platform security or operation;
- bypass security controls;
- reverse engineer the Platform except where permitted by law;
- use automated tools to extract information without authorisation;
- submit false or misleading information;
- use the Platform for unlawful, fraudulent or malicious purposes; or
- engage in any activity that may compromise patients, Healthcare Organisations or the Platform.
MH Health Connect may suspend or terminate access where misuse is identified.
7. Clinical Responsibility
MH Health Connect provides software that supports healthcare workflows and administrative processes.
The Platform does not replace professional clinical judgement.
Healthcare professionals remain responsible for patient assessment, diagnosis, treatment decisions, prescribing, referrals, investigations and all information submitted or generated using the Platform.
Users must review and approve clinically significant documents, recommendations, submissions and communications before they are relied upon or submitted externally.
8. Government Systems (HPOS, PRODA & Medicare)
Where the Platform integrates with government healthcare systems, including Services Australia, Medicare, HPOS, PRODA and PBS Authority services, users remain responsible for complying with all applicable government requirements.
Users must:
- be authorised to access the relevant system;
- ensure information submitted is accurate and complete;
- review submissions before transmission; and
- protect government-issued credentials.
MH Health Connect provides tools that may assist with preparing or submitting information but does not replace user responsibility for any submission made using government systems.
MH Health Connect does not support the circumvention of authentication, security or regulatory controls imposed by government agencies.
MH Health Connect may modify, restrict or suspend government-related functionality where necessary to comply with legal, regulatory or security requirements.
Users must not:
- share PRODA credentials;
- share Medicare credentials;
- provide their authentication credentials to another individual;
- allow another person to submit transactions under their identity unless permitted by law and authorised by the relevant government system.
Healthcare Organisations remain responsible for ensuring access to government systems is appropriately managed.
Users acknowledge that access to government systems may be subject to additional:
- legislation;
- policies;
- contractual terms;
- acceptable use requirements;
- technical restrictions; and
- security requirements.
Users agree to comply with those requirements in addition to this Policy.
Where a conflict exists between this Policy and mandatory requirements imposed by a government agency, the mandatory government requirements prevail.
9. Third-Party Systems
The Platform may integrate with third-party systems and services.
Users are responsible for ensuring they have appropriate authority to access those systems and must comply with any applicable terms of use.
MH Health Connect is not responsible for the availability, performance or security of third-party systems outside our reasonable control.
10. Security Responsibilities
Users must take reasonable steps to protect Platform security, including:
- maintaining secure passwords;
- using multi-factor authentication where available;
- protecting credentials;
- securing devices used to access the Platform;
- reporting suspected security incidents; and
- complying with applicable organisational security policies.
Healthcare Organisations remain responsible for managing user access and maintaining appropriate internal security controls.
MH Health Connect may temporarily restrict access where necessary to protect the security of the Platform or its users.
11. Monitoring and Enforcement
MH Health Connect may monitor and log Platform activity for security, operational, compliance and support purposes.
Where misuse, security risks or breaches of this Policy are identified, MH Health Connect may investigate the matter and take appropriate action, including restricting or suspending access to the Platform.
Where required by law, MH Health Connect may cooperate with regulators, law enforcement agencies or other authorised bodies.
12. Reporting Concerns
Users should promptly report suspected:
- security incidents;
- privacy breaches;
- unauthorised access;
- misuse of patient information;
- fraud; or
- breaches of this Policy.
Reports may be made to the relevant Healthcare Organisation or directly to MH Health Connect.
MH Health Connect will investigate reported concerns as appropriate and will treat reports confidentially where reasonably practicable.
13. Policy Updates
MH Health Connect may update this Policy from time to time to reflect changes in technology, legislation, regulatory requirements, security practices or Platform functionality.
The current version of this Policy will be available through the Platform or our website.
Where material changes affect user obligations, reasonable notice will be provided where practicable.
14. Contact Information
Questions regarding this Acceptable Use Policy may be directed to:
MH Health Connect Pty Ltd
Email: support@mhhealthconnect.com.au
For privacy-related matters:
Privacy Officer
Email: privacy@mhhealthconnect.com.au
For security-related matters:
Security Officer
Email: security@mhhealthconnect.com.au