Savira -- Making Compliance Easy
Be the business people trust

Healthcare Privacy Compliance: What Australian Providers Must Know in 2026

Give patients visibility and control over their health information.

Health service providers handle some of the most sensitive personal information in Australia. The OAIC's recent determinations against collecting patient data via third-party tracking pixels without consent signal that regulators are scrutinising healthcare websites, not just in-clinic practices. With penalties now reaching $50 million for serious breaches, the stakes could not be higher.

Making Compliance easy

This guide explains what has changed, why healthcare is under regulatory scrutiny, and what your practice must do now to avoid enforcement action.

Key takeaways

Privacy reform is now a real business risk

Penalties up to $50M

Serious or repeated privacy breaches can attract penalties up to AU$50 million, 30 percent of adjusted turnover, or three times the benefit gained.

No small business exemption

Health service providers are explicitly excluded from the Privacy Act's small business exemption. Every health provider - regardless of size or turnover - is bound by the Australian Privacy Principles.

Tracking pixels in the spotlight

The OAIC has found two healthcare providers breached the Privacy Act by allowing third-party tracking pixels on their websites to collect sensitive health data without consent. The OAIC inspected 50 health provider websites as part of this investigation.

Sensitive information - stricter rules

Health information is classified as "sensitive information" under the Privacy Act. Stricter obligations apply to its collection, use, and disclosure than for ordinary personal information.

Individuals can sue

Since 10 June 2025, individuals can bring legal action for serious invasions of privacy - including for reckless or intentional handling of health data. Non-economic damages are capped at AU$500,000.

Mandatory breach notification

Healthcare providers must notify the OAIC and affected individuals of eligible data breaches likely to cause serious harm. Additional notification obligations apply to breaches of My Health Record data.

Does this apply to you?

Does the Privacy Act apply to your practice?

Unlike most sectors, health service providers have no small business exemption. Every health service provider is covered by the Privacy Act 1988, regardless of annual turnover or number of staff. This is not an area where size creates a carve-out.

The definition of "health service provider" is deliberately broad. It covers not just hospitals and GPs, but a wide range of organisations that handle health information in the course of their activities.

General practitionersPrivate hospitalsSpecialistsPharmacistsPsychologistsPhysiotherapistsDentistsOptometristsAllied health practitionersAged care providersIVF and fertility clinicsPathology and radiologyComplementary medicine practitionersTelehealth providersOnline health servicesGyms and weight loss clinicsPrivate schools and childcare centresDisability service providersDrug and alcohol servicesBlood and tissue banks

What has changed under the privacy act?

Much stronger enforcement powers

The Privacy and Other Legislation Amendment Act 2024 significantly expanded the powers of the OAIC, including the ability to issue infringement notices for certain breaches, stronger investigation and information-gathering powers, and the ability to conduct public inquiries into systemic privacy practices across sectors - including healthcare.

Significantly higher penalties

Maximum penalties for serious or repeated interferences with privacy have been raised to the greater of AU$50 million, three times the value of benefit obtained, or 30% of adjusted turnover during the breach period. For healthcare providers handling sensitive data, the exposure is substantial.

Individuals can now sue

The statutory cause of action for serious invasions of privacy commenced on 10 June 2025. Individuals can bring legal action where a privacy invasion was intentional or reckless, serious in nature, and where they had a reasonable expectation of privacy. This creates real litigation and class action risk for health providers with systemic data handling failures.

Tracking pixels now require consent

In June 2026, the Privacy Commissioner determined that using tracking pixels on health-related websites - where those pixels collect sensitive health data and enable targeting on social media platforms - requires explicit user consent. This decision directly affects any health provider whose website uses analytics, advertising or retargeting tools from third-party platforms.

WHY IT MATTERS

Why is healthcare under regulatory scrutiny?

Health information is among the most sensitive personal information an individual can share. When it is mishandled - whether in a clinic, through a website, or via a third-party platform - the consequences for patients can be profound. Regulators treat any failure seriously.

Common risk areas the OAIC has flagged for health providers include: websites with third-party pixels firing before consent is captured, privacy policies that do not reflect actual data handling practices, over-collection of information during patient intake, inadequate security over patient records held in cloud systems, and staff disclosing health information in contexts the patient did not anticipate or consent to.

The OAIC's June 2026 determinations against Medmate Australia and Monash IVF found both providers interfered with the privacy of individuals whose sensitive information was collected via third-party tracking pixels on their telehealth and fertility services websites. Alongside those determinations, the OAIC published findings from an inspection of 50 health service provider websites - a clear signal that regulators are actively auditing the sector's digital practices, not just responding to complaints.

9 in 10
Australians consider it neither fair nor reasonable to be targeted with advertising based on their sensitive health data - according to the OAIC's own community attitudes research, cited in the June 2026 determination.

WHY IT MATTERS

Real examples of regulatory action

Person reading The Australian newspaper article about Australian privacy compliance on a tablet device

The OAIC found that a GP had disclosed a patient's health information to a police officer without valid authority - despite the police being an "enforcement body". The Commissioner concluded the GP could not rely on the enforcement exception because there was no evidence the disclosure was connected to an actual enforcement activity. The GP had failed to consider the risks of disclosing without consent. The patient made a successful privacy complaint.

THE APPS

Key obligations under the Australian Privacy Principles

APP 1 – Open and transparent management

APP 1 – Open and transparent management

Health providers must maintain a current, accurate and accessible privacy policy covering what information is collected, why, how it is used and disclosed, and how patients can access, correct or complain. Many practice policies are out of date, fail to mention website data collection, or omit details about third-party software tools and cloud providers.

APP 2 - Anonymity and pseudonymity

APP 2 - Anonymity and pseudonymity

Providers must consider whether it is practicable to offer patients the option of not identifying themselves, or using a pseudonym. Where this is lawful and practical - for example, certain counselling or information services - it should be considered and communicated to patients in your privacy policy.

APP 3 and 5 – Collection and notification

APP 3 and 5 – Collection and notification

Health information should be collected directly from the patient, by lawful and fair means, and only where the patient has consented and the information is reasonably necessary for your activities. At or before collection, you must notify the patient of who you are, why you are collecting the information, how it will be used, and how they can access or complain. This includes information collected via your website or intake forms, not just in-clinic interactions.

APP 6 - Use and disclosure

APP 6 - Use and disclosure

Health information should only be used or disclosed for the primary purpose for which it was collected. Secondary uses - such as marketing, research, or disclosures to third parties outside the treating team - require patient consent or must fit a specific exception. Using patient contact details to send promotional emails is a common and avoidable breach point.

APP 7 - Direct marketing

APP 7 - Direct marketing

Health information cannot be used for direct marketing without consent, and patients must always have a functional opt-out. The OAIC can issue infringement notices for direct marketing breaches. This applies to appointment reminders that include promotional content, newsletter campaigns, and any form of targeted advertising using patient data.

APP 8 - Cross-border disclosure

APP 8 - Cross-border disclosure

Transferring patient data to overseas services - including cloud-hosted practice management software, overseas pathology platforms, and US-based analytics or advertising tools - triggers APP 8 obligations. Providers must take reasonable steps to ensure overseas recipients uphold comparable privacy protections. Standard reliance on platform terms and conditions is increasingly insufficient.

APP 11 - Security

APP 11 - Security

Providers must take reasonable steps to protect patient information from misuse, interference, loss, and unauthorised access, modification or disclosure. Reasonable steps include governance and training, ICT security controls, access management, physical security, third-party provider review, and de-identification or destruction of records no longer needed.

APP 12 & 13 - Access and correction

APP 12 & 13 - Access and correction

Patients have a right to access the health information you hold about them, and you must generally respond to access requests within 30 calendar days. If you refuse access, you must provide a written notice explaining the grounds and available complaint mechanisms. Providers must also correct health information that is inaccurate, out of date or misleading upon request.

NDB - Scheme Notifiable data breaches

NDB - Scheme Notifiable data breaches

If patient data is accessed, modified, disclosed, lost or used without authorisation, and this is likely to cause serious harm, you must notify the OAIC and affected individuals. Additional mandatory notification obligations apply to breaches involving My Health Record data. You must have a documented breach response plan in place before a breach occurs - not after.

YOUR COMPLIANCE ROADMAP

What providers should do now

Good privacy governance in healthcare requires structured action across three timeframes. Immediate steps close the most urgent gaps. Medium-term work builds the systems and culture needed for sustainable compliance. Strategic initiatives embed privacy as a genuine practice value.

Immediate (0-3 months)

Fix critical privacy gaps now

Medium term (3-12 months)

Build governance and processes

Strategic (12-18 months)

Embed long-term privacy strategy

Immediate: 0 to 3 months

  • Audit your website for third-party tracking pixels - Google, Meta, LinkedIn and similar tools - and confirm no pixel fires before valid patient consent is captured.
  • Review and update your privacy policy so it accurately reflects how you collect, hold, use and disclose health information, including via your website and third-party software.
  • Check that intake forms and in-clinic collection processes include a compliant privacy notice that patients receive before providing their information.
  • Confirm that patient contact details are not being used for promotional or marketing purposes without documented consent and a functional opt-out.
  • Appoint a privacy lead or point of accountability within the practice.
  • Tighten access controls on clinical and administrative systems - remove dormant accounts and enforce stronger authentication for all staff accessing patient records.

Medium term: 3 to 12 months

  • Develop and implement a privacy management plan aligned to the OAIC's four-step framework: embed, establish, evaluate, enhance.
  • Create a documented record of all personal information your practice holds, how it is collected, where it is stored, and how long it is retained.
  • Review all third-party software, cloud storage and overseas service providers for APP 8 compliance and adequate data processing arrangements.
  • Establish data retention schedules and implement deletion or de-identification processes for records no longer needed.
  • Develop a data breach response plan that covers identification, containment, assessment, notification to the OAIC and affected patients, and review.
  • Deliver privacy training for all staff, covering obligations specific to their role - clinical, administrative, and reception staff each face different risk points.
  • Implement documented processes for receiving and responding to patient access and correction requests within the 30-day timeframe.

Strategic: 12 to 18 months

  • Monitor upcoming reforms affecting healthcare - particularly around automated decision-making in clinical tools, AI-assisted diagnostics, and children's health data.
  • Conduct privacy impact assessments before deploying new digital health tools, patient portals, or AI-assisted clinical software.
  • Build consent management into all patient-facing digital touchpoints as a default design requirement rather than a retrofit.
  • Integrate privacy risk into practice governance, board or management reporting, and professional indemnity insurance reviews.
  • Consider privacy capability as a genuine differentiator in patient communications and in relationships with referring providers.
  • Review state and territory health privacy legislation in each jurisdiction where you operate - obligations may vary from Commonwealth requirements.
Free tool

Practical checklist

Use this as an accountability tool. Assign an owner in your team to each item and track progress against it.

AreaImmediate PriorityNext Phase
Privacy PolicyUpdate to reflect current data practices, website tracking and third-party toolsSchedule annual review; assign a named owner
Website and pixelsAudit and remove or gate all third-party tracking pixels behind valid consentBuild consent-first tagging as standard for any new website or digital tool
Collection and noticesConfirm intake forms and in-clinic processes include a compliant privacy noticeStandardise privacy notices across all offices, clinics and intake channels
Direct marketingConfirm all patient contact lists have documented consent; add functional opt-outsConduct full patient database governance review; set and enforce consent expiry rules
Third-party vendorsIdentify all software tools processing patient data; review for APP 8 complianceImplement data processing agreements; flag and remediate non-compliant providers
SecurityTighten access controls; remove dormant accounts; enforce MFA on clinical systemsCommission periodic risk assessments; review physical and ICT security controls
Breach responseDesignate a breach response lead; document the steps your practice will takeFormalise a breach response plan; test it; maintain a breach register
Access requestsDocument the process for responding to patient access requests within 30 daysTrain staff; implement a tracking system for active requests
TrainingInitial all-staff session with role-specific examples for clinical and admin teamsBuild annual refresh into practice calendar; include scenario-based exercises
GovernanceAppoint a privacy lead; create a documented privacy management planIntegrate privacy risk into practice governance, reporting and risk register
Privacy Policy
Immediate PriorityUpdate to reflect current data practices, website tracking and third-party tools
Next PhaseSchedule annual review; assign a named owner
Website and pixels
Immediate PriorityAudit and remove or gate all third-party tracking pixels behind valid consent
Next PhaseBuild consent-first tagging as standard for any new website or digital tool
Collection and notices
Immediate PriorityConfirm intake forms and in-clinic processes include a compliant privacy notice
Next PhaseStandardise privacy notices across all offices, clinics and intake channels
Direct marketing
Immediate PriorityConfirm all patient contact lists have documented consent; add functional opt-outs
Next PhaseConduct full patient database governance review; set and enforce consent expiry rules
Third-party vendors
Immediate PriorityIdentify all software tools processing patient data; review for APP 8 compliance
Next PhaseImplement data processing agreements; flag and remediate non-compliant providers
Security
Immediate PriorityTighten access controls; remove dormant accounts; enforce MFA on clinical systems
Next PhaseCommission periodic risk assessments; review physical and ICT security controls
Breach response
Immediate PriorityDesignate a breach response lead; document the steps your practice will take
Next PhaseFormalise a breach response plan; test it; maintain a breach register
Access requests
Immediate PriorityDocument the process for responding to patient access requests within 30 days
Next PhaseTrain staff; implement a tracking system for active requests
Training
Immediate PriorityInitial all-staff session with role-specific examples for clinical and admin teams
Next PhaseBuild annual refresh into practice calendar; include scenario-based exercises
Governance
Immediate PriorityAppoint a privacy lead; create a documented privacy management plan
Next PhaseIntegrate privacy risk into practice governance, reporting and risk register
Common questions

What businesses like yours ask

No. Providing a health service removes the exemption entirely, regardless of turnover. A single-practitioner clinic has the same obligations under the Australian Privacy Principles as a large group.
That is set by state and territory health records legislation rather than the Privacy Act, and the periods differ. Records for minors generally have to be kept until a specified age. Check the rules in your jurisdiction, then set retention periods you can actually apply, because holding records indefinitely is its own risk.
Yes, and the booking tool does not cover you. Your site is likely running analytics and possibly advertising scripts, and those collect information about people researching a health concern, which is sensitive territory. Anything that fires before consent is collection you have not asked for.
It is, because a policy has to reflect what you actually do. Most practices have added online booking, a patient portal, telehealth, SMS reminders and analytics since the policy was written. Health information carries stricter obligations than most personal information, so a policy that understates what you collect is a poor position to be in.
Generally yes, under APP 12, with limited exceptions such as where access would pose a serious threat to someone's life or health. Have a documented process covering who assesses a request and within what timeframe, and make sure it accounts for information held outside the clinical system, including the booking tool and the mailing list.
How savira can help

Structured privacy governance for health service providers

Savira helps Australian healthcare practices handle the parts of privacy compliance that are ongoing rather than one-off. Generate and maintain a privacy policy that reflects how your practice handles health information, collect and record consent through your website, and keep an auditable record of who agreed to what and when, so you can answer a patient or a regulator without digging through inboxes.

Whether you are a single clinic or a multi-site group, Savira gives you the compliance foundations without needing a consultant or a developer.

Staying current with privacy reform

This guide was last updated 28 August 2026 to reflect the OAIC's June 2026 tracking pixel determinations against Medmate and Monash IVF, and the publication of the OAIC's "Your life, pixelated" report. Australian privacy law continues to evolve. Register to stay informed of regulatory changes affecting health service providers.