There is a growing concern in society about invasions of personal privacy, whether actual or potential. Health records (that is, all medical records, whether used for treatment or for other legitimate purposes such as public health surveillance) may contain large amounts of personal information of a nature which many people would regard as sensitive. Therefore, it is necessary to ensure that all personal information is handled wisely. This Department’s policy on privacy in health and medical records is embodied in the general principles listed below.