Compliance8 min read

Privacy and Data Breaches: What Every Care Provider Needs to Know

Many care providers assume they're too small for the Privacy Act. If you hold health information, you're covered — regardless of turnover. Here's what a data breach obligation actually looks like, in plain English.

The Accorda Team · 20 August 2026

There's a belief that quietly does the rounds among smaller providers: the Privacy Act is for the big end of town — banks, telcos, the businesses that got hacked and made the news. Not a clinic with six staff. Not a small NDIS provider.

It's an understandable assumption. It's also the one that catches people out. If your service holds information about someone's health, the size of your business doesn't get you out of the Privacy Act. And in a sector that handles more sensitive personal information than almost any other, that's worth understanding calmly and early — long before there's a problem to respond to.

Here's what the rules actually ask of you, in plain English.

"We're too small for that" is the myth to let go of

Most small businesses — those with an annual turnover of $3 million or less — are exempt from the Privacy Act. That's the general rule, and it's probably where the belief comes from.

But there's a list of exceptions, and the first one on it is health service providers. The Office of the Australian Information Commissioner (OAIC) puts it plainly: regardless of turnover, the Privacy Act covers any business that is a health service provider. That net is wide. The OAIC's own examples include private hospitals and day surgeries, medical practitioners, pharmacists and allied health professionals, complementary therapists, child care centres and private schools.

If you assess, maintain or care for someone's health, or you simply hold health records about the people you support, you are very likely a health service provider under the Act — no matter how small you are. For most NDIS providers, allied health and dental practices, pharmacies, aged care providers and childcare services, that means the turnover exemption never applied in the first place.

The general small-business exemption has a long list of exceptions. Health service providers sit right at the top of it — covered regardless of size.

The practical upshot: this isn't optional, and it isn't only a big-provider concern. It's worth confirming your own status if you're unsure — but for most care providers, the answer is that you're in.

Why care providers are squarely in the frame

This isn't a theoretical risk that lives on a lawyer's shelf. Health is consistently the most-affected sector in Australia's data-breach figures.

In the OAIC's report for January to June 2025, there were 532 data breach notifications in total — and the health sector accounted for 18% of them, more than any other industry. It's a pattern that's held for years, not a one-off spike.

Just as important is how those breaches happen. It's tempting to picture a sophisticated overseas hacker, and criminal or malicious attacks were indeed the leading cause, at 59% of notifications. But human error accounted for 37% — up from 29% in the previous period. An email sent to the wrong client. A spreadsheet of participant details attached by mistake. A file left accessible to someone who shouldn't see it.

That second number matters, because it's the one you have the most direct control over. You can't personally repel every cyber attack. You can make sure your team knows how to handle sensitive information — and knows what to do the moment something goes wrong.

What actually counts as a "data breach"

Not every slip is a notifiable event, and it helps to know where the line sits so you're not either panicking over nothing or missing something real.

Under the Notifiable Data Breaches (NDB) scheme, an eligible data breach is one where three things are true:

  • There's been unauthorised access to, unauthorised disclosure of, or loss of personal information your organisation holds.

  • That breach is likely to result in serious harm to one or more of the people the information relates to.

  • You haven't been able to prevent that harm through remedial action.

"Serious harm" is broad — it can be physical, psychological, emotional, financial or reputational. The test is objective: would a reasonable person in your position conclude that serious harm is likely? And "likely" has a specific meaning here — it means more probable than not, not merely possible.

For care providers, the "serious harm" threshold is often easier to cross than in other sectors, precisely because the information is so sensitive. A leaked list of who receives which support, a participant's diagnosis, a child's records — this is exactly the kind of information whose exposure can cause real harm.

The clock: what you have to do, and when

This is the part worth committing to memory, because a breach is stressful and the timeframes don't pause while you find your footing.

If you suspect an eligible data breach but aren't yet sure, you must carry out a reasonable and expeditious assessment. The scheme sets an outer limit of 30 calendar days from when you became aware of the grounds for suspicion — but the OAIC is clear that 30 days is a maximum, not a target. You're expected to move much faster than that.

If the assessment confirms an eligible breach, you must notify both the OAIC and the affected individuals as soon as practicable. Your statement needs to set out who you are, a description of the breach, the kinds of information involved, and the steps you recommend people take to protect themselves. If it isn't practicable to contact individuals directly, you publish the statement and take reasonable steps to publicise it.

The scramble in a breach is rarely the notification itself. It's reconstructing what happened, when you knew, and what you did — after the fact, under pressure.

It's a compliance problem, not just an IT problem

Here's the distinction that's easy to miss. A data breach has two halves, and they're handled by different people with different tools.

The first half is prevention and security — firewalls, access controls, secure systems, staff who don't click the dodgy link. That's the work of good IT and good habits, and no compliance platform replaces it. Accorda doesn't, and we won't pretend otherwise. It will not stop a hacker or secure your network.

The second half is governance and evidence — being prepared before a breach, responding correctly during one, and being able to prove both afterwards. That's a compliance job, and it's where the sector tends to come unstuck: the policy that was never signed off, the response plan nobody could find at 9pm, the timeline that couldn't be reconstructed because the records were editable and undated.

This is the half Accorda is built for. A breach is, in the end, an incident — so you can log it, triage it, track the assessment against the clock, and record every action and notification in one place. A privacy and data-breach-response policy, written and reviewed and signed off by your staff, means people know how to spot and escalate a breach before it becomes a bigger one — which is the single best defence against that 37% of breaches caused by human error. Tamper-evident records mean that when someone asks when did you become aware, and what did you do?, you have a straight answer with the dates to back it. And when it's time to show a regulator, a one-click evidence pack pulls it together.

You secure the data. Accorda helps you prove you were ready, and that you responded properly.

The rules are still moving

Privacy law in Australia is in the middle of the most significant reform in a generation, so this isn't a "set and forget" area.

As part of that reform, a new statutory tort for serious invasions of privacy commenced on 10 June 2025. In plain terms, it gives individuals a direct legal pathway to sue over a serious invasion of privacy — whether by intruding on their seclusion or misusing their personal information — where they had a reasonable expectation of privacy. Courts can award damages and other remedies. Further changes have been flagged, and more are expected.

The point isn't to alarm you. It's that the goalposts genuinely move here, and "we set up our privacy policy years ago" is no longer a safe position. This is exactly the kind of shift Accorda's Regulatory Radar is designed to catch — flagging a relevant change and pointing you to the policies it affects, so a reform doesn't quietly outrun your paperwork.

A short readiness checklist

You don't need to become a privacy lawyer. You need a few things in place, kept current:

  • Confirm whether the Privacy Act applies to you — for most care providers holding health information, it does.

  • Have a current privacy policy and a written data-breach-response plan that names who does what.

  • Make sure your team knows how to recognise and escalate a suspected breach, and can show they've been trained.

  • Keep dated, tamper-evident records of information-handling and any incidents, so a timeline can be reconstructed cleanly.

  • Watch for regulatory change, and review your policies when it lands.

Get those right and a data breach becomes what it should be: a bad day, handled properly — not a bad day that becomes a compliance failure on top of everything else.

Want your breach response, privacy policy and staff sign-offs in one place, ready to prove? See how Accorda helps you stay audit-ready.

Sources

Disclaimer

Disclaimer This article is general information only, current as at August 2026, and is not legal or compliance advice. Regulatory requirements can change.

Start today

See your compliance audit-ready in one place

Try Accorda free for 14 days. Every feature, no credit card, no auto-charge.