The Privacy Act Doesn't Care How Small Your Practice Is
One of the most common things we hear from practice owners is some version of "we're a small business, the Privacy Act doesn't apply to us." It's an understandable assumption. The Act does carve out an exemption for small businesses with annual turnover of $3 million or less, and most allied health practices sit comfortably under that figure.
The exemption doesn't apply to you, though, if you're a health service provider.
Health providers are covered regardless of turnover
The Privacy Act 1988 defines a health service provider broadly, under section 6FB, as any private sector organisation that provides a health service and holds health information in connection with it. That covers GPs, dentists, physiotherapists, psychologists, chiropractors, podiatrists, and most other allied health practitioners, along with complementary therapists like naturopaths. Turnover is irrelevant. A solo practitioner clinic is bound by the same Australian Privacy Principles as a $500 million health insurer (OAIC).
In practice, this means every allied health practice needs to comply with all 13 APPs, not just the ones that feel obviously relevant. Two are worth knowing well:
APP 1 requires an up to date, clearly written privacy policy describing how your practice collects, holds, uses, and discloses personal information, made available to patients on request or on your website.
APP 11 requires you to take reasonable steps to protect the personal information you hold from misuse, interference, loss, unauthorised access, and disclosure. This is the one that connects most directly to IT: weak passwords, no multi-factor authentication, or an unpatched server all sit squarely in APP 11 territory.
What happens when it goes wrong
The consequences aren't theoretical. In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties over a 2022 data breach at its Medlab Pathology business, which exposed the personal information of more than 223,000 people. It was the first time civil penalties had been enforced under the Privacy Act, and the case turned partly on whether the company had taken reasonable steps to protect the data and whether its breach assessment had been reasonable and expeditious, the exact language of APP 11 and the Notifiable Data Breaches scheme (OAIC). Medlab was a pathology provider, which makes this case particularly relevant reading for anyone else handling health information as a smaller operator.
Penalties are also considerably higher than they used to be. For a serious or repeated interference with privacy, a body corporate now faces the greatest of $50 million, three times the value of any benefit gained from the breach, or 30 percent of adjusted turnover during the breach period. Since December 2024, the OAIC has also had a mid-tier penalty option of up to $3.3 million for contraventions that don't meet the "serious" threshold, giving it a lower-cost enforcement path for smaller matters (OAIC).
The 30-day clock most practices don't know about
If your practice suspects it may have experienced an eligible data breach, one likely to cause serious harm, the Privacy Act gives you a maximum of 30 calendar days to assess whether that's actually the case, starting from when you first became aware of grounds for suspicion. If the assessment confirms an eligible breach, you then need to notify affected individuals and the OAIC as soon as practicable (OAIC).
Thirty days sounds generous until it's your practice trying to work out what happened, which patients are affected, and what to tell them, all while still seeing clients. Practices that already know what a breach looks like, who needs to be told internally, and roughly what a notification should say get through that process in a fraction of the time of those working it out from scratch under pressure.
A newer risk to know about
Since 10 June 2025, individuals in Australia have also had a direct right to sue for serious invasions of privacy under a new statutory tort, separate from the OAIC complaints process entirely. It covers intrusion upon someone's seclusion and misuse of their information, requires the conduct to be intentional or reckless rather than merely careless, and doesn't require the person to prove they suffered actual damage (OAIC). It's a genuinely new avenue for patients, and it sits on top of, not instead of, existing Privacy Act obligations.
What this means practically
None of this requires a legal department. It requires a handful of things most practices can put in place without much disruption:
- A current, accurate privacy policy that reflects what your practice actually does with patient information
- Documented, reasonable security safeguards under APP 11, matched to the sensitivity of health information (this is where your MFA, device management, and backup arrangements come in)
- A short, written data breach response plan so the first hour of an incident isn't spent figuring out who does what
- Staff who know what an eligible data breach looks like and who to escalate a suspected one to
If your practice hasn't looked at any of this since it first opened its doors, it's worth revisiting now rather than after an incident forces the issue. Our cyber security checklist for allied health practices is a practical starting point for the security side of this.
.jpg&w=3840&q=75)