SecureMyEmail logoSecureMyEmail
← All articles
Healthcare2 July 2026 · 6 min read

Notifiable data breaches: what an Australian practice must do in 30 days

Reception desk of an Australian medical practice with patient records and a computer

▶ Watch the short explainer for this tip

Health service providers are covered by the Privacy Act 1988 no matter how small they are — the small-business exemption does not apply when you handle health information. That means the Notifiable Data Breaches scheme applies to your practice today, not after some future reform.

The trigger: an eligible data breach

Three conditions must all be met: there is unauthorised access to or disclosure of personal information, a reasonable person would conclude it is likely to result in serious harm, and the harm could not be prevented by remedial action.

A compromised clinical mailbox usually satisfies the first two comfortably. Referral letters, results, Medicare numbers and dates of birth are exactly the material the scheme was written about.

The 30-day clock

Once you become aware of grounds to suspect an eligible breach, you have 30 days to carry out a reasonable and expeditious assessment. If it is an eligible breach, you must notify the OAIC and affected individuals as soon as practicable — not at day 30.

The practical difficulty is scoping. Answering 'which patients were in that mailbox and what did the attacker access' requires admin audit logs that were retained and enabled before the incident. Practices that discover their logging was off spend that 30 days guessing.

Other obligations that stack on top

  • My Health Records Act 2012 — separate, stricter notification duties to the System Operator and OAIC where the My Health Record system is involved
  • State legislation — the Health Records Act 2001 (Vic) and Health Records and Information Privacy Act 2002 (NSW) impose their own handling standards
  • RACGP information security standards — expected practice for accredited general practices

What reduces the exposure beforehand

Enforced MFA on every clinical account, no legacy protocol access, no external auto-forwarding, tight external sharing, and audit logging retained long enough to reconstruct events. None of that is exotic; all of it changes what you can honestly tell the OAIC.

The scheme does not punish having an incident. It punishes not being able to explain one. Log retention and access control are what buy you that explanation.

Frequently asked questions

Does the NDB scheme apply to a small medical practice?
Yes. Health service providers are covered regardless of turnover, so the usual small-business exemption under the Privacy Act does not apply.
How quickly do we have to report a breach?
You must assess a suspected eligible breach within 30 days and notify the OAIC and affected individuals as soon as practicable once it is confirmed. In practice the first 72 hours decide how defensible your response looks.
Is a compromised mailbox automatically a notifiable breach?
Not automatically, but you must assess it. If the mailbox held health information and you cannot prove what was accessed, it is very hard to conclude serious harm is unlikely.
What evidence do we need to keep?
Sign-in and audit logs, mailbox rule history and your assessment notes. Without adequate log retention you cannot rule out access, which pushes you toward notification by default.

Sources

Every reference below was link-checked when this article was published.

  1. 1.Notifiable Data Breaches schemeOffice of the Australian Information Commissioner
  2. 2.Data breach preparation and responseOffice of the Australian Information Commissioner
  3. 3.Report a cybercrime or cyber security incidentAustralian Signals Directorate — ACSC
  4. 4.Business Email CompromiseAustralian Signals Directorate — ACSC

Want to know where your own tenant stands?

The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.