Notifiable data breaches: what an Australian practice must do in 30 days

Health service providers are covered by the Privacy Act 1988 no matter how small they are — the small-business exemption does not apply when you handle health information. That means the Notifiable Data Breaches scheme applies to your practice today, not after some future reform.
The trigger: an eligible data breach
Three conditions must all be met: there is unauthorised access to or disclosure of personal information, a reasonable person would conclude it is likely to result in serious harm, and the harm could not be prevented by remedial action.
A compromised clinical mailbox usually satisfies the first two comfortably. Referral letters, results, Medicare numbers and dates of birth are exactly the material the scheme was written about.
The 30-day clock
Once you become aware of grounds to suspect an eligible breach, you have 30 days to carry out a reasonable and expeditious assessment. If it is an eligible breach, you must notify the OAIC and affected individuals as soon as practicable — not at day 30.
The practical difficulty is scoping. Answering 'which patients were in that mailbox and what did the attacker access' requires admin audit logs that were retained and enabled before the incident. Practices that discover their logging was off spend that 30 days guessing.
Other obligations that stack on top
- My Health Records Act 2012 — separate, stricter notification duties to the System Operator and OAIC where the My Health Record system is involved
- State legislation — the Health Records Act 2001 (Vic) and Health Records and Information Privacy Act 2002 (NSW) impose their own handling standards
- RACGP information security standards — expected practice for accredited general practices
What reduces the exposure beforehand
Enforced MFA on every clinical account, no legacy protocol access, no external auto-forwarding, tight external sharing, and audit logging retained long enough to reconstruct events. None of that is exotic; all of it changes what you can honestly tell the OAIC.
The scheme does not punish having an incident. It punishes not being able to explain one. Log retention and access control are what buy you that explanation.
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.

