Stop Breaches: 6 clinic steps to meet the Australian Privacy Principles
Stop Breaches: 6 clinic steps to meet the Australian Privacy Principles

Yes, all 13 Australian Privacy Principles apply to health information, which must be treated as sensitive data requiring extra care. Your top priorities are a public-facing privacy policy, documented consent for primary and secondary purposes, strong security controls under APP 11, and a tested data breach response plan. Get these four right and you’ve covered most of your regulatory risk.
TL;DR:
- Almost all health providers, regardless of size, must comply with the Australian Privacy Principles when handling patient health information.
- Maintaining a clear, practice-specific privacy policy and documenting consent for secondary data uses are essential to meet APP 1, 3, and 5 requirements.
- Using, sharing, or storing health data offshore or with cloud vendors increases compliance risks, requiring careful contract review and security assurances beforehand.
- Regularly reviewing access logs, testing breach response plans, and training staff are critical steps to stay audit-ready and demonstrate ongoing privacy management.
- Building trust with patients relies on strong privacy measures, which can also streamline operations and improve referral pathways through better data handling.
Table of Contents
- What are the Australian Privacy Principles for healthcare?
- Which health providers does the Privacy Act cover?
- How do the key APPs apply to patient records?
- How do you build a working privacy management plan?
- When do you need consent versus relying on primary purpose?
- What should you check with overseas and cloud providers?
- What’s the minimum checklist to be audit-ready?
- Why privacy compliance builds clinical trust
- How Meddle supports privacy-aware patient matching
- Sources
- FAQ
What are the Australian Privacy Principles for healthcare?
The 13 APPs sit under the Privacy Act 1988 and follow the lifecycle of a patient’s information, from first contact to correction requests years later. The OAIC’s quick reference guide groups them into five clusters:
- Open and transparent management (APP 1-2): your privacy policy and how patients can stay anonymous where practical
- Collection (APP 3-5): what you can collect, and the notices you must give
- Dealing with information (APP 6-9): use, disclosure, direct marketing, and cross-border transfers
- Data integrity (APP 10-11): accuracy and security
- Access and correction (APP 12-13): what patients can demand to see or fix
Health information sits in the “sensitive information” category under the Act, which means it usually needs explicit consent before you collect it, unlike routine personal details such as a phone number.
Which health providers does the Privacy Act cover?
Almost every practice handling clinical data is caught. This includes GPs, allied health clinics, private hospitals, telehealth providers, pharmacies, and even gyms or wellness studios that record health assessments.
The critical detail administrators miss: the small-business exemption (turnover under $3 million) does not apply once you provide a health service and hold health information. The Australian Law Reform Commission’s analysis confirms this carve-out excludes health providers from the exemption entirely, regardless of practice size.
Run this check now: does your service record anything beyond basic employee files, like intake notes, treatment history, or referral letters? If yes, you’re covered, full stop.

How do the key APPs apply to patient records?
Reading the Act’s legal language and knowing what to do on a Tuesday afternoon in a busy clinic are two different things. Here’s the practical translation:
- APP 1 (privacy policy): your policy must be clearly written, specific to your practice (not a generic template), and freely available without a login wall. It should explain what you collect, why, how you store it, and how patients complain, according to OAIC’s APP 1 guidance.
- APP 3 and APP 5 (collection and notice): because health data is sensitive, you generally need consent before collecting it, and you must tell patients at the point of collection what you’re gathering and why.
- APP 6 (use and disclosure): you can use information for the primary purpose it was collected for, such as treatment or billing. Anything beyond that, like sharing with a researcher, needs separate consent or a specific exception.
- APP 8 (overseas disclosure): if your practice management software or scheduling platform stores data offshore, you carry the compliance risk, not just the vendor.
- APP 10 and APP 11 (accuracy and security): records must stay current, and you need genuine technical safeguards. Think encryption, access logs, and role-based permissions, not just a locked filing cabinet.
- APP 12 and APP 13 (access and correction): patients can request their records and corrections. Patients can request their records and corrections; practices should respond within a reasonable time frame.
Pro Tip: Treat Medicare numbers and other healthcare identifiers with the same rigour as clinical notes. Mishandling identifiers can trigger obligations under the Healthcare Identifiers Act on top of the Privacy Act, and a mishap here routinely escalates into a Notifiable Data Breach.
How do you build a working privacy management plan?
The OAIC doesn’t just list rules, it recommends a cycle: embed, establish, evaluate, enhance. This structure, set out in the Guide to health privacy updated in May 2025, gives clinics a repeatable framework rather than a one-off compliance exercise.

Embed: assign someone real accountability for privacy (not just a title on paper), and train every staff member who touches patient data, from reception through to billing.
Establish: map exactly where health information lives, paper files, practice software, cloud backups, then write your privacy policy around that map and vet every vendor accordingly.
Evaluate: run regular access reviews, audit who’s opened which records, and actually test your breach response plan before you need it for real.
Enhance: after any incident or near-miss, update your policy and keep a written record of what changed and why.
One detail worth flagging clearly: the OAIC’s chapter on embedding privacy recommends destroying or de-identifying information once you no longer need it, not simply archiving it indefinitely. Under the Notifiable Data Breaches scheme, any breach likely to cause serious harm must be reported to the OAIC and affected patients as soon as practicable.
When do you need consent versus relying on primary purpose?
Primary purpose covers the reason a patient walked in the door: treatment, billing, referral to a specialist. You don’t need fresh consent for these because the patient reasonably expects them.
Secondary uses are different. Using patient data for research, marketing, or even internal quality audits generally needs explicit consent unless a specific exception applies.
- Permitted without extra consent: responding to a serious threat to life or health, uses required by law, and certain permitted health situations such as some research activities under strict conditions
- Needs consent: marketing communications, sharing data with a third party for a new study, or using de-identified data commercially
Keep your collection notice specific. A vague “we may use your information for other purposes” won’t hold up, document exactly what patients agreed to and when.
What should you check with overseas and cloud providers?
You remain accountable for your patients’ data even after it leaves your building. If a booking system or backup server sits offshore, APP 8 puts the compliance burden squarely on you, not the vendor.
Before signing any contract, check for:
- Clear data residency clauses stating where information is physically stored
- A published subprocessor list, so you know who else touches the data
- Contractual incident notification timeframes
- Recognised security certifications for the vendor’s infrastructure
Pro Tip: Get vendor security assurances in writing before go-live, not after an incident. A structured security questionnaire makes this due diligence far less painful, and platforms like ClaroClaim publish useful frameworks for benchmarking what “reasonable steps” actually looks like in practice.
What’s the minimum checklist to be audit-ready?
If you do nothing else this quarter, work through this list:
- Publish a privacy policy tailored to your practice, not a generic download
- Complete a data map covering every place health information is stored, paper and digital
- Train staff and keep signed attendance records as evidence
- Lock down technical security: encryption, access controls, and audit logs under APP 11
- Write and test a data breach response plan against the NDB scheme
- Review every overseas or cloud vendor contract and confirm My Health Record procedures are current
| Action | Owner | Frequency |
|---|---|---|
| Privacy policy review | Practice manager | Annually |
| Staff privacy training | Practice manager / HR | Onboarding + annual refresh |
| Access log audit | IT lead or delegate | Quarterly |
| Breach response drill | Compliance lead | Annually |
| Vendor contract review | Practice owner | On renewal |
Why privacy compliance builds clinical trust
Patients disclose more when they trust a practice with their information, and the OAIC’s own framing ties privacy directly to that trust. We see the same pattern across every clinic we work with: tight privacy processes don’t just reduce risk, they cut admin friction and smooth referral pathways because everyone downstream trusts the handover. Compliance isn’t separate from good care. It’s part of it.
— Taylor
How Meddle supports privacy-aware patient matching
Some healthcare platforms build privacy-by-design into their matching process, helping practices manage compliance while growing their patient list. Instead of adding another system to audit, you get a platform that already treats health information the way the OAIC expects it to be treated.

If you’re weighing up a new intake or referral tool, check how it handles My Health Record compliance before you sign anything. Meddle’s matching platform is built specifically for allied health clinics that need secure records handling alongside faster patient-practitioner matching. This isn’t a replacement for your own legal advice or the OAIC’s guidance, it’s a practical layer that sits on top of a compliant practice. See how Meddle works for your clinic and book a walkthrough to see the privacy controls in action.
Sources
For anything you need to verify directly against the source rather than take on trust, start here:
- Australian Privacy Principles — quick reference (OAIC)
- Chapter 3: Using or disclosing health information (OAIC)
- Individual healthcare identifiers obligations for private health service providers (OAIC)
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
FAQ
What are the 13 Australian Privacy Principles?
They’re the rules under the Privacy Act 1988 governing how organisations collect, use, store, and disclose personal information, grouped into open management, collection, dealing with information, data integrity, and access/correction, as set out in the OAIC’s quick reference.
What are the privacy and confidentiality obligations in healthcare in Australia?
Health providers must collect health information with consent in most cases, use it only for its primary purpose unless an exception applies, secure it under APP 11, and report serious breaches under the Notifiable Data Breaches scheme.
Does the Privacy Act apply to hospitals?
Yes, private hospitals are covered as health service providers, and the small-business exemption never applies to organisations holding health information regardless of size.
What are the 10 privacy principles?
Australia currently operates under 13 APPs, not 10. The “10 principles” reference usually points to an earlier version of the framework or a different jurisdiction’s model, so always check the current OAIC list rather than an older summary.
How does Meddle handle patient privacy during matching?
Meddle builds privacy safeguards into its matching process from the ground up, aligning with the same principles clinics must apply to their own records, and its My Health Record compliance resources outline how this works in practice.