privacy compliance

Privacy determination –Sensitive Information stored in garden shed

HomePrivate: BlogLegal insightsPrivacy determination –Sensitive Information stored in garden shed

by

reviewed by

Malcolm Burrows

The Privacy Commissioner, Timothy Pilgrim, has found that a Melbourne medical centre has breached the Privacy Act 1988 (Cth) (Privacy Act) in failing to provide adequate security to protect Sensitive Information contained in medical information. The breach occurred before the Australian Privacy Principles (APPs) took effect and therefore the medical centre was found to have breached the National Privacy Principles (NPPs).

The medical centre stored the files of around 960 patients in a locked garden shed. The security of the files was compromised when the shed was broken into. The files contained detailed personal information including individuals’ full name, address, date of birth, Medicare number, treatment details as well as patient’s discharge summaries.

Under section 6(1)(b) of the Privacy Act Sensitive Information includes Health information which under section 6(1)(a) includes, but it not limited to, information or an opinion about: the health or a disability (at any time) of an individual that is also personal information; or other personal information collected to provide, or in providing, a health service.

The Privacy Commissioner highlighted the insecure, temporary nature of a garden shed and its inadequacy to protect sensitive information from unauthorised access and misuse. The files belonged to many patients that existed prior to 2004. In these circumstances many of the patient files should have been destroyed or de-identified as they were no longer necessary for the purpose in which they were collected. The files could have been shredded or disposed of using another secure method. In failing to take these steps, the medical centre placed its patients at risk of identity fraud.

The Commissioner advised the medical center to undergo a privacy risk assessment, train staff and develop a privacy breach response plan.

The amendments

The Privacy Act now contains thirteen (13) new Australian Privacy Principles aimed at protecting Personal Information.   The APPs apply to business with an annual turnover of more than $3 million, as well as some small businesses including Health Service providers. The actions of the medical center breached the new APP 11 which requires businesses to take reasonable steps to secure Personal Information. The finding suggests that keeping Sensitive Information in a locked garden shed does not constitute “reasonable steps”.

Civil Penalty Provisions

Recent amendments to the Privacy Act have provided the privacy commissioner with the new powers. The Commissioner may apply to the Federal Court for civil penalties orders. The civil penalty provisions currently allow for penalties of up to:

  • $A340,000 for an individual; and
  • $A1.7 million for a company.

While the substance of the principles under the Privacy Act have not changed. The penalties and prescriptive requirements have become more onerous. Health Services providers and other small business should consider this finding when assessing the adequacy of their current security procedures.

Links and further references

Legislation

Privacy Act 1988 (Cth)

Privacy Amendment (Enhancing Privacy Protection) Act 2012

Other references

Office of the Australian Information Commissioner, APP Guidelines

Office of the Australian Information Commissioner, Australian Privacy Principles

Further information

If you need further information about complying with the Privacy Act 1988 (Cth), contact us for a confidential and obligation-free discussion:


Related insights about privacy compliance

  • OAIC Notifiable Data Breaches report – July 2020

    OAIC Notifiable Data Breaches report – July 2020

    The OAIC’s Notifiable Data Breaches Report reveals 518 data breaches reported by eligible entities in the first half of 2020. Learn more about the types of personal information involved, the highest reporting sector, and the key takeaways from the report to protect your data.

    Read more …

  • Revisiting software as a service agreement

    Revisiting software as a service agreement

    Discover the legal considerations of commercialising a SaaS (Software-as-a-Service) Agreement as a business model. Uncover the key issues to consider when going to market with a SaaS offering, such as subscription terms, service levels, data handling, intellectual property (IP) in customizations, and more.

    Read more …

  • Data breaches: what is serious harm?

    Data breaches: what is serious harm?

    This article looks at the notifiable data breaches scheme, and the factors to consider when determining if an eligible data breach would likely result in serious harm. It also provides an in-depth look at the Office of the Australian Information Commissioner observations in its ‘Notifiable Data Breaches Statistics Report’.

    Read more …

  • Abhorrent violent content prohibited

    Abhorrent violent content prohibited

    Organizations hosting abhorrent violent material, such as terrorism, murder, torture, rape and kidnapping, now face hefty fines under the Criminal Code Amendment Act 2019 (Cth), up to 50,000 penalty units or 10% of annual turnover.

    Read more …

  • Use of competitor’s confidential information

    Use of competitor’s confidential information

    Many businesses try to increase market share by employing a competitor’s member of staff who may bring with them relationships and information acquired over the years.  Employees owe fiduciary duties to their employers meaning, among other things, that an employee cannot make a personal gain by using confidential information acquired in the course of their…

    Read more …

  • De-encryption Bill currently before Joint Committee

    De-encryption Bill currently before Joint Committee

    The much awaited Telecommunications and other Legislation Amendment (Assistance And Access) De-encryption Bill 2018 (De-encryption Bill) has been referred to the Parliamentary Joint Committee on Intelligence and Security (Joint Committee).  The Joint Committee has allowed three (3) weeks for submissions.  It is a very short time-frame for submissions considering the controversial nature of the Bill.…

    Read more …

  • De-encryption laws: compelling tech giants to cooperate with law enforcement

    De-encryption laws: compelling tech giants to cooperate with law enforcement

    The Australian Government is introducing encryption-related legislation that could have significant implications. Get the full scoop on what this Bill could mean for companies and citizens before it is officially announced.

    Read more …

  • Artificial intelligence – introductory thoughts on the legal issues

    Artificial intelligence – introductory thoughts on the legal issues

    Technology lawyers are grappling with the complex legal issues associated with Artificial Intelligence (AI), such as liability, competition, consumer issues, intellectual property, data ownership, security, and privacy. This article explores these topics and examines the approach taken in the European Union.

    Read more …

  • What is a data breach response plan and how do you obtain one?

    What is a data breach response plan and how do you obtain one?

    Organizations must now comply with the Notifiable Data Breaches Scheme. Learn how to create a Data Breach Response Plan and why it is so important for compliance.

    Read more …


Posted

in

Send this to a friend