Understanding the Key Changes to Australia’s Privacy Act for Health Service Providers


Although the holiday period may have organisations winding down, Christmas has come early for Australian privacy buffs with some exciting new developments! 

Approximately 14 months after the release of the Australian Government’s response to the Privacy Act Review Report, the Privacy and Other Legislation Amendment Bill 2024 was passed by both houses of Parliament on 29 November 2024. Following this, the Bill received Royal Assent on 10 December 2024 (Act no. 128, 2024).

The Privacy Act 1988 was originally created to promote and protect the privacy of individuals and regulate how certain Australian organisations handle personal information. The Privacy and Other Legislation Amendment Bill 2024 endeavoured to further strengthen these privacy protections by implementing a first tranche of recommendations from the Privacy Act Review.

These encompassing changes are undoubtedly exciting steps towards further protecting the privacy of Australians at a time when data breach fatigue is at an all-time high. However, these changes will subsequently require increased attention from Australian healthcare organisations to ensure they are fully compliant.

At a high level, some of these key changes include:

  • The establishment of a statutory tort for serious invasions of privacy, providing individuals with a legal avenue to seek redress for privacy violations.
  • The enhancement of the the Office of the Australian Information Commissioner’s (OAIC) enforcement and investigation capabilities, including new levels of civil penalties and the authority to issue infringement notices.
  • A directive for the OAIC to create a Children’s Online Privacy Code, applicable not only to social media platforms but also to any online services likely to be accessed by children.
  • The introduction of a system to designate a list of countries and binding schemes with adequate privacy protections to facilitate cross-border data transfers.
  • A requirement for privacy policies to include information about substantially automated decisions that significantly impact individuals’ rights or interests, detailing the types of decisions and the personal information used.

One of the more material changes within the Bill from a cybersecurity perspective has been the further tightening of the language surrounding APP 11 – Security of personal information. Specifically, the Bill has added subclause 11.3, which states that associated steps include technical and organisational measures.

Further clarity was also given in the Bill’s explanatory memorandum, specifically stating that:

“101. Examples of technical measures include protecting personal information through physical measures, and software and hardware – for example through securing access to premises, encrypting data, anti-virus software and strong passwords.”

102. Examples of organisational measures include steps, processes and actions an entity should put in place – for example, training employees on data protection, and developing standard operating procedures and policies for securing personal information.

As a result, the definition of reasonable steps necessary to protect personal information has been further clarified, and these changes have now vividly highlighted the need for robust cybersecurity.

Another key update to the act is the introduction of new penalty tiers, which could increase the OAIC’s ability to penalise organisations that breach the Australian Privacy Principles. 

As part of this, OAIC will gain a wider array of enforcement options along with new functions and capabilities. Among these are two new provisions that allow civil penalties to be adjusted according to the severity of the privacy breach.

This change aims to fill the current legal gap, where the Australian Information Commissioner can only pursue civil penalties for the most severe or egregious privacy violations. 

According to the Bill’s explanatory memorandum, The Bill’s new civil penalty provisions for breaches of certain privacy obligations of the APPs and non-compliant eligible data breach statements would be subject to infringement notices. The memorandum explains that the maximum associated penalty for bodies corporate is 1,000 penalty units, which equates to approximately $330,000. The explanatory memorandum provides an explicit example of such a breach by stating that:

“These civil penalties have a lower maximum penalty amount to section 13H and target specific obligations that are administrative in nature and where a contravention can be easily established, such as an APP entity failing to include the requisite information in a privacy policy.”

As evident from the above, these amendments increase the scope of the OAIC’s investigative and enforcement powers and broaden the applicability of various lower levels of penalties. 

As a healthcare-focused IT and cybersecurity specialist, Just Protect offers a range of services that enable Australian Health Service Providers to adapt to the changes to the Privacy Act and ensure their continued compliance. 

Our services are specifically designed to enable you to do what you do best: deliver excellent quality patient care!

Our services include privacy audits and impact assessments, managed IT services, and a comprehensive range of healthcare-centric cybersecurity solutions. We have also recently launched our virtual Privacy Officer service, designed to empower Healthcare SMBs to navigate the complex compliance landscape and ensure the protection of patient privacy.

Not sure where to get started on your privacy journey? Please get in touch for a free and no obligation introductory Privacy Assessment for Healthcare SMBs!

Disclaimer: Please note that this blog post does not constitute legal advice. The information provided is for general informational purposes only and should not be relied upon as legal advice. Always consult with a qualified legal professional for specific legal guidance.

Similar Posts