Medical practices hold some of the most sensitive personal information, making them prime targets for cyber attacks. Understanding and meeting your legal obligations for cybersecurity is essential.
Legal Framework
Privacy Act Requirements
The Privacy Act 1988 and Australian Privacy Principles (APPs) require practices to:
- Take reasonable steps to protect personal information
- Implement appropriate security measures
- Prevent unauthorised access, modification, or disclosure
- Destroy or de-identify information when no longer needed
Notifiable Data Breaches Scheme
Practices must notify the OAIC and affected individuals when:
- There is unauthorised access to or disclosure of personal information
- The breach is likely to result in serious harm
- Remedial action cannot prevent serious harm
My Health Records Act 2012
Medical practices that are registered healthcare provider organisations face an additional and separate mandatory notification obligation under section 75 of the My Health Records Act 2012 (Cth). Notifications are made to the System Operator (the Australian Digital Health Agency) and, for private sector practices, to the Office of the Australian Information Commissioner, which regulates the scheme.
Notification is required as soon as practicable if the practice becomes aware that:
- A person has, or may have, contravened the Act in a way involving unauthorised collection, use or disclosure of health information in a My Health Record
- An event has, or may have, occurred that compromises the security or integrity of the My Health Record system
- Circumstances have, or may have, arisen that compromise the security or integrity of the system
Who to notify: both the System Operator (ADHA) and the Office of the Australian Information Commissioner. The civil penalty for failure to notify is 1,500 penalty units. If a breach may seriously affect individual healthcare recipients, the practice must contain the breach, assess the risks, and ask the System Operator to notify all affected healthcare recipients.
This regime is distinct from the NDB scheme, and to prevent double reporting the NDB scheme does not apply to unauthorised access, disclosure or loss of information that has been, or is required to be, notified under section 75 (section 26WD of the Privacy Act 1988 (Cth)). A single cyber incident can still engage both regimes where it affects My Health Record information (notified under section 75) and other personal information held by the practice (assessed under the NDB scheme).
Minimum Security Standards
Technical Controls
Medical practices should implement:
- Firewalls and intrusion detection
- Secure Wi-Fi configuration
- Network segmentation
- Regular vulnerability scanning
- Multi-factor authentication
- Role-based access permissions
- Regular access reviews
- Strong password policies
- Encryption at rest and in transit
- Secure backup systems
- Data loss prevention tools
- Endpoint protection
Incident Response
When a breach occurs:
- 1Contain: Isolate affected systems immediately
- 2Assess: Determine scope and impact
- 3Notify: Meet notification obligations
- 4Remediate: Fix vulnerabilities
- 5Review: Learn and improve
Conclusion
Cybersecurity is not optional for medical practices; it's a legal obligation. Implementing appropriate security measures protects patients, meets regulatory requirements, and safeguards your practice.