Cybersecurity and Privacy Risks Associated with AI Use in Australian Healthcare
The adoption of artificial intelligence (AI) technologies by healthcare organisations in Australia has the significant potential to transform patient care, improve diagnostic accuracy, and streamline administrative processes. Moreover, over the coming years, AI tools and technologies are expected to dramatically change how healthcare organisations operate – from sole operator allied health providers to large hospital cooperatives. In fact, many practices have already successfully adopted technologies such as generative AI and large language models (LLM) to streamline their operations and enhance patient care.
However, the use of AI technologies within healthcare settings is not without its challenges. Instead, health service providers must mitigate numerous cybersecurity and privacy risks when adopting such technologies. Understanding these key risks is essential for protecting patient data, securing the provider’s digital environment, and maintaining compliance with the relevant legal frameworks.
Key Points
- AI technologies have the potential to enhance patient care and streamline operations in healthcare settings. However, these technologies also come with numerous cybersecurity and privacy risks.
- Don’t be fooled by the hype – AI tools can have the same vulnerabilities and misconfigurations as other third-party software and thus need to be carefully vetted before being adopted.
- Health service providers must ensure their compliance with the Privacy Act when leveraging AI technologies. Notably, obligations under the Privacy Act apply to both the input and output of personal information and patient data.
- Healthcare organisations should perform comprehensive third-party cybersecurity assessments, privacy impact assessments, and establish robust data backup and redundancy plans when adopting AI technologies.
Cybersecurity Implications

Most commercial AI tools, applications and software that leverage AI involve a “wrapper” that bridges the complex AI model with the end user. A “wrapper” is a tool or piece of code that simplifies complicated processes to present a straightforward interface for the end user. While this is great for simplicity, these wrappers, like all general software, can introduce numerous cybersecurity risks stemming from vulnerabilities, misconfigurations, insecure integration or third-party dependencies.
Additionally, as there is this extra level of abstraction, it is also not always clear how the inputted data is handled, transmitted, or where it is stored. It must also be noted that when organisations use these technologies, they are ultimately relying on third-party developers to adequately secure their own environment. Consequently, any third-party breaches or security issues could lead to supply chain attacks or disruptions to elements of patient care that rely on such technologies.
The key point here is that just because an application or tool has the word “AI” in it doesn’t mean it is exempt from the numerous cyber risks. Nor should it be treated as less risky than any other third-party application. Organisations should always perform thorough due diligence before introducing new technologies into their healthcare environment, including performing a comprehensive third-party cybersecurity review. Such a review should be re-completed at least annually to ensure any key changes to the applications haven’t introduced new risks into the practice’s environment.
Privacy Considerations
Health Service Providers using AI systems must be vigilant about handling personal information, as obligations under the Privacy Act apply to both input and output data. Notably, this includes inferred or artificially generated data about identifiable individuals, such as deepfakes. Moreover, under Australian Privacy Principle (APP) 6, personal information should only be used for its primary purpose unless consent is given, or secondary use is reasonably expected.

Given this, health service providers should ensure that they obtain explicit patient consent for any secondary uses associated with AI technologies.
Another key consideration is that AI-generated personal information must comply with APP 3, ensuring that its generation is necessary and conducted by lawful and fair means. Special care is therefore needed for sensitive data, which generally requires explicit consent, especially for decisions impacting individual rights.
Moreover, when evaluating potential new AI technologies in healthcare settings it is critical to perform a privacy impact assessment to clearly establish how the associated application may impact patient privacy. Health Service Providers should also update their privacy policies and notices to reflect the use of AI in the context of patient data.
Finally, without any suitable mitigative controls, health service providers should avoid entering sensitive information or patient data into public AI tools to prevent any consequential privacy or cybersecurity impacts.
Recommendations

Healthcare organisations can leverage AI’s benefits while safeguarding personal information by proactively mitigating the risks discussed throughout this article. Just Protect recommends that Australian Health Service Providers perform the following non-exhaustive list of proactive actions when looking to adopt AI technologies as part of healthcare operations:
- Perform a comprehensive third-party cybersecurity risk assessment of the associated application. Ask the vendor what cybersecurity measures are in place and whether they align with any industry standards or compliance frameworks.
- Perform a privacy impact assessment to determine what personal information and patient data is collected, used, shared, or maintained. As part of this, it is also essential to understand how this data is transferred, where it is stored, and what cybersecurity controls are in place to prevent authorised access.
- Create a redundancy and backup plan. Health Services Providers should have a standard operating procedure that accounts for any outages in the associated AI technologies and what backup measures will minimise disruptions to patient care.
- Ensure that adequate cybersecurity controls and measures are in place to detect, prevent and mitigate any incidents that occur due to the exploitation of the AI application. Such measures could include endpoint security, network security, regular updates and backups, and the use of multi-factor authentication.
- Just Protect also recommends that Australian Health Service Providers make the time to review the excellent and very comprehensive guide put together by the OAIC on AI technologies.
Conclusion
The adoption of AI is undoubtedly an exciting time for the industry, with many positive use cases and outcomes for patient care. However, as highlighted in this article, there are numerous cybersecurity and privacy risks that health service providers need to navigate. By adopting a proactive approach to addressing these risks, Australian health service providers can safely leverage AI technologies to enhance patient care whilst also securing their digital environment.
How We Can Help
Are you looking to adopt new AI technologies within your environment and not sure what key risks to look out for?
As a healthcare-focused cybersecurity and IT specialist, Just Protect offers a range of services that enable Australian Health Service Providers to adapt to the increased adoption of AI technologies in healthcare settings. Some of our services include third-party cybersecurity risk assessments, managed IT services, and a comprehensive range of healthcare-centric cybersecurity solutions. For a complete list, please review our services page or contact us for a chat!
References
- Australian Government, Privacy Act 1988
- Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products
