When you need patient consent for QI, the Privacy Act quality assurance exemption, and the line where in-practice QI becomes research.
Last reviewed: July 2026. Part of the complete CPD and QI FAQ.
No, in most cases, if the data is de-identified and used within the practice for QI purposes. The Privacy Act 1988 includes a quality assurance and evaluation exemption that covers most in-practice QI work. The exemption has specific conditions, and your practice's privacy policy should describe how QI data is handled.
The exemption is in section 95 (for HREC-approved QI) and section 95A (for activities that do not need full HREC review). Most in-practice QI fits the latter, where the activity is conducted by a health service provider for the purpose of evaluating or improving safety or quality of healthcare.
Note in your plan the legal basis (de-identified data, in-practice use, quality improvement purpose), the data fields, the data storage, the access controls, and any patient opt-out requests received. This documentation is what you rely on at audit.
Limit identifiers to what is needed for the activity. If you need to re-contact patients, retain a separate re-identification key on a secure local system. If the activity is fully anonymous, identifiers are unnecessary.
When the activity aims to generate generalisable knowledge, is published externally, or is conducted by someone outside the treating team, it shifts from QI to research. Research requires ethics review. Most practice-internal QI does not.
Browse all CPD and QI answers · Run a PDSA cycle with a guide
CPD requirements, hour allocations and category structures are set by the MBA, RACGP and ACRRM. The PIP QI measures and payment rates are set by the Department of Health and Aged Care and Services Australia. Always verify current requirements directly with the relevant body before finalising your CPD plan. This page is general guidance and does not replace official college or government resources.