Healthcare is Australia's most persistently breached sector. Year after year, the Office of the Australian Information Commissioner (OAIC) reports that health information is among the most frequently compromised category of personal data in the country. Yet conversations with healthcare providers — from GP practices in regional Queensland to allied health networks in inner Sydney — reveal a consistent pattern: most practitioners know they have privacy obligations, but remarkably few understand exactly what those obligations require of them.
This matters enormously in 2026. The OAIC has significantly increased its enforcement activity. The 2024 amendments to the Privacy Act 1988 (Cth) expanded the Commissioner's powers and raised maximum civil penalties to $50 million for serious or repeated breaches. Healthcare providers who treated privacy compliance as a background administrative concern now find themselves in a very different regulatory environment.
This guide explains what the Privacy Act actually requires of healthcare providers — in plain language, without legal jargon — and the five practical steps your practice should take today to reduce your exposure.
What APP 11 Actually Requires
APP 11 is the security obligation under the Privacy Act. It states, in plain terms, that every organisation holding personal information must "take such steps as are reasonable in the circumstances" to protect that information from misuse, loss, and unauthorised access, modification, or disclosure. When that information is health information — which the Privacy Act classifies as sensitive information — the standard of what is "reasonable" is higher.
"Reasonable steps" is not defined in the legislation — it is assessed by the OAIC on a case-by-case basis, considering: the sensitivity of the information held, the volume of records, the organisation's size and resources, the potential harm from a breach, and what security measures are available and affordable given those factors. The OAIC has consistently held that for healthcare providers, implementing the ACSC Essential Eight at Maturity Level 1 represents a reasonable minimum baseline.
Critically, APP 11 is not a "best efforts" obligation — it is an obligation of outcome. If your practice suffers a data breach because you failed to implement reasonable security controls (no MFA on email, no encryption on laptops, no backup system), the OAIC will not accept "we tried our best" as a defence. The obligation is to actually implement the controls, not to intend to do so.
Health Information: Broader Than Most Practitioners Realise
A common misconception among healthcare providers is that "health information" means clinical records and diagnoses. The Privacy Act's definition is considerably broader. Health information includes any information about an individual's physical or mental health — past, present, or anticipated future — and it extends to:
The breadth of this definition surprises many practitioners. A physiotherapy appointment book that records patient names and appointment times is health information — it reveals that those individuals have a health condition requiring physiotherapy. An optometry invoice sent by email that includes the patient's name and "prescription lenses" is health information. Any document that connects an individual to a health service or treatment is health information, and is subject to the full protections of the Privacy Act.
The 30-Day NDB Notification Rule
The Notifiable Data Breaches (NDB) scheme requires organisations to notify the OAIC and affected individuals when a data breach is likely to result in "serious harm" to any individual. The notification must be made as soon as practicable, and an assessment of whether notification is required must be completed within 30 days of becoming aware of the suspected breach.
"Serious harm" is assessed on an objective basis, considering factors including: the sensitivity of the information, the nature of the harm that could result (identity theft, financial loss, discrimination, physical safety risks, reputational damage, psychological harm), and the circumstances of the breach. For health information — which is sensitive by definition — the serious harm threshold is frequently met. A ransomware attack that exfiltrates patient records is almost certainly a notifiable breach. A misdelivered email containing a patient's mental health diagnosis almost certainly is too.
The 30-day clock starts when you become aware or suspect a breach has occurred — not when you confirm it. Delaying an assessment to avoid the notification obligation is a compliance failure, not a strategy.
OAIC Enforcement Trends in 2026
The OAIC's enforcement posture has shifted materially in 2026. Several trends are now clearly established:
More Investigations
The OAIC has increased the number of own-motion investigations — investigations the Commissioner initiates without receiving a complaint — particularly in healthcare. A data breach notification can trigger a follow-up investigation examining not just the breach itself but the adequacy of the organisation's overall security framework.
Larger Enforceable Undertakings
Enforceable undertakings now routinely require ongoing compliance reporting, mandatory security audits, staff training programs, and in some cases appointment of an independent privacy auditor. These undertakings are binding and expensive to comply with.
Public Reporting
The OAIC increasingly publishes investigation reports that name the organisation and describe the breach and its causes in detail. These public reports cause lasting reputational damage, particularly for healthcare providers whose patients value privacy and trust.
Focus on Systemic Failures
The OAIC is less interested in one-off human errors and more focused on systemic failures: organisations that had no MFA, no encryption, no incident response plan, no staff training. These systemic failures demonstrate that the organisation never took its APP 11 obligations seriously.
5 Practical Steps to Achieve Privacy Act Compliance
Deploy MFA on All Systems Containing Health Data
Multi-factor authentication on email, practice management systems, cloud storage, and billing platforms is the single highest-impact security control you can implement. It prevents credential phishing — the most common pathway to a healthcare data breach. Microsoft Authenticator and Google Authenticator are free. There is no justifiable reason for any healthcare provider not to have MFA enabled in 2026.
Encrypt All Devices and Stored Patient Data
Enable BitLocker on every Windows device, FileVault on Macs. Ensure your patient management system's database is stored encrypted. Encrypted USB drives only — never use unencrypted USB drives to transport patient data. Device encryption means a stolen laptop is a hardware loss, not a data breach.
Implement and Test a 3-2-1 Backup
Three copies of patient data, on two different media types, with one offline or offsite. Test the restoration every month. Document the test. Without a tested backup, a ransomware attack is a catastrophe. With one, it is a recoverable event.
Train Staff Annually (Minimum)
Every staff member with access to patient data must understand phishing, password security, clean desk obligations, and what to do if they suspect a breach. Annual training is the minimum; quarterly phishing simulations are best practice. The human layer is where most healthcare breaches begin.
Document an Incident Response Plan
Write down what you will do if a breach occurs: who is responsible, who to call, how to contain it, when to notify the OAIC. Without a written plan, the 30-day NDB clock is very difficult to meet. The plan should be reviewed annually and tested in a tabletop exercise.
Common Misconceptions That Get Healthcare Providers in Trouble
Is Your Practice Actually Compliant?
ShieldForce provides free Privacy Act compliance assessments for Australian healthcare providers. Identify your gaps before the OAIC does.
Book a Free Compliance AssessmentRelated Articles
References
See our full author credentials
