We've written before about why the Privacy Act applies to health practices regardless of size. This one is about what actually happens once something goes wrong: the Notifiable Data Breaches scheme.
The NDB scheme sits in Part IIIC of the Privacy Act. It's been in force since February 2018, and it applies in full to health service providers. There's no small business exemption for medical, dental, physio, psychology or any other health practice, no matter how small the turnover.
What counts as an eligible data breach
Under section 26WE, an eligible data breach has three elements that all need to be true:
- There's unauthorised access to, unauthorised disclosure of, or loss of personal information the practice holds.
- That's likely to result in serious harm to one or more of the people it's about.
- The practice hasn't been able to prevent that likely harm through remedial action.
A lost laptop with unencrypted patient files on it is a candidate. A phishing email that gives an attacker access to a shared mailbox full of booking confirmations and Medicare numbers is a candidate. A misdirected fax or email containing one patient's file, sent to the wrong recipient, might or might not qualify depending on what was in it and who received it.
The 30-day clock, and what it actually measures
Once a practice has reasonable grounds to suspect an eligible data breach might have happened, it has to carry out a reasonable and expeditious assessment. The Privacy Act gives a maximum of 30 calendar days to complete that assessment.
The OAIC is clear that 30 days is a ceiling, not a target. If a practice already knows within three days that patient records were exposed, the clock doesn't reset a fresh 30-day period, the assessment should already be done.
It's also worth being precise about what the 30 days covers. It's the assessment window, the time to work out whether what happened actually meets the "eligible data breach" definition. Once that's confirmed, a separate obligation kicks in: notify the OAIC and affected individuals "as soon as practicable." There's no additional 30 days at that point.
What a notification has to contain
If the assessment confirms an eligible data breach, the statement to the OAIC (and to affected individuals) needs to include:
- Who the practice is and how to contact them
- A description of what happened
- What kind of information was involved
- What people should do in response
For a practice, that last point usually means practical advice: watch for phishing attempts referencing appointment history, consider whether Medicare or health fund details need monitoring, who to contact with questions.
Why this is worth planning for before it happens
Two things tend to go wrong when a breach happens without preparation. The first is delay: nobody's sure whose job it is to decide whether something counts as "eligible," so the 30-day clock runs out on internal indecision rather than a genuine assessment. The second is scope: practices under-assess how much data was actually exposed, because nobody's mapped where patient data actually lives across email, practice management software and shared drives
Serious or repeated interferences with privacy can attract penalties of up to $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover, whichever is greater, under the 2022 Privacy Act amendments. Enforcement at that scale is aimed at large entities, not a solo allied health clinic, but the reputational and clinical trust damage from a breach tends to matter more to a small practice than the theoretical penalty ceiling anyway.
Having an incident response plan, even a one-page version naming who assesses a suspected breach and who has authority to notify the OAIC, is the difference between a genuine 30-day assessment and a much longer, messier one.
.jpg&w=3840&q=75)