privacy compliance

Privacy determination –Sensitive Information stored in garden shed

HomePrivate: BlogLegal insightsPrivacy determination –Sensitive Information stored in garden shed

by

reviewed by

Malcolm Burrows

The Privacy Commissioner, Timothy Pilgrim, has found that a Melbourne medical centre has breached the Privacy Act 1988 (Cth) (Privacy Act) in failing to provide adequate security to protect Sensitive Information contained in medical information. The breach occurred before the Australian Privacy Principles (APPs) took effect and therefore the medical centre was found to have breached the National Privacy Principles (NPPs).

The medical centre stored the files of around 960 patients in a locked garden shed. The security of the files was compromised when the shed was broken into. The files contained detailed personal information including individuals’ full name, address, date of birth, Medicare number, treatment details as well as patient’s discharge summaries.

Under section 6(1)(b) of the Privacy Act Sensitive Information includes Health information which under section 6(1)(a) includes, but it not limited to, information or an opinion about: the health or a disability (at any time) of an individual that is also personal information; or other personal information collected to provide, or in providing, a health service.

The Privacy Commissioner highlighted the insecure, temporary nature of a garden shed and its inadequacy to protect sensitive information from unauthorised access and misuse. The files belonged to many patients that existed prior to 2004. In these circumstances many of the patient files should have been destroyed or de-identified as they were no longer necessary for the purpose in which they were collected. The files could have been shredded or disposed of using another secure method. In failing to take these steps, the medical centre placed its patients at risk of identity fraud.

The Commissioner advised the medical center to undergo a privacy risk assessment, train staff and develop a privacy breach response plan.

The amendments

The Privacy Act now contains thirteen (13) new Australian Privacy Principles aimed at protecting Personal Information.   The APPs apply to business with an annual turnover of more than $3 million, as well as some small businesses including Health Service providers. The actions of the medical center breached the new APP 11 which requires businesses to take reasonable steps to secure Personal Information. The finding suggests that keeping Sensitive Information in a locked garden shed does not constitute “reasonable steps”.

Civil Penalty Provisions

Recent amendments to the Privacy Act have provided the privacy commissioner with the new powers. The Commissioner may apply to the Federal Court for civil penalties orders. The civil penalty provisions currently allow for penalties of up to:

  • $A340,000 for an individual; and
  • $A1.7 million for a company.

While the substance of the principles under the Privacy Act have not changed. The penalties and prescriptive requirements have become more onerous. Health Services providers and other small business should consider this finding when assessing the adequacy of their current security procedures.

Links and further references

Legislation

Privacy Act 1988 (Cth)

Privacy Amendment (Enhancing Privacy Protection) Act 2012

Other references

Office of the Australian Information Commissioner, APP Guidelines

Office of the Australian Information Commissioner, Australian Privacy Principles

Further information

If you need further information about complying with the Privacy Act 1988 (Cth), contact us for a confidential and obligation-free discussion:


Related insights about privacy compliance

  • What is the Meaning of Personal Information

    What is the Meaning of Personal Information

    Court discussed meaning of “personal info” and when identity can be ascertained. Didn’t define when metadata is personal info, but determined Section 6(1) of the Privacy Act 1988 (Cth) was substantial in making determination.

    Read more …

  • Data Breach Bill 2016 – key data security considerations

    Data Breach Bill 2016 – key data security considerations

    The Privacy Amendment (Notifiable Data Breaches) Bill 2016 has been passed, making notification of data breaches mandatory from 23 February 2018. Find out how this could affect you and what measures you can take to protect your data.

    Read more …

  • Data security – the increasing burden

    Data security – the increasing burden

    The consequences for an Australian business victim for a breach of cyber security are forecast to exponentially increase. In February 2015 the Parliamentary Joint Committee on Intelligence and Security (Committee) recommended the introduction of mandatory data breach notification scheme (Scheme) by the end of 2015.[1] Whilst the details of the incoming Scheme are currently scant,…

    Read more …

  • Revenge porn – legal options

    Revenge porn – legal options

    Revenge porn (Revenge Porn) refers to sexually explicit media that is distributed without the consent of the individual(s) involved.[1]  An act of Revenge Porn therefore involves the recording of video or still images of a person that is usually engaged in sexual acts (Revenge Content) and publishing or threatening to publish it.  A person’s participation…

    Read more …

  • Cupid Media risks privacy of the dateless

    Cupid Media risks privacy of the dateless

    The Privacy Act 1988 (Cth) (Privacy Act) requires entities to take reasonable steps to secure personal information.

    Read more …

  • Getting confidentiality agreements in place

    Getting confidentiality agreements in place

    Part 5 – Planning a business acquisition Confidentiality Agreements (Confidentiality Agreement or NDA’s) are essential in business Acquisitions, particularly if either the Target or Acquirer is subject to the ASX Listing Rules. Whilst generally an equitable obligation of confidence is applicable, a Confidentiality Agreement reduces the obligations of the parties to writing to ensure that…

    Read more …

  • Changes to the Privacy Act commence today!

    Changes to the Privacy Act commence today!

    Changes to the Privacy Act 1988 (Cth) included the introduction of thirteen Australian Privacy Principles (App’s). Learn more about potential civil penalty orders if you are a business with a turnover of over 3 million or more, a health care provider or a business that trades in personal information.

    Read more …

  • Are your privacy practices up to date with the amended Privacy Act 1988 (Cth)?

    Are your privacy practices up to date with the amended Privacy Act 1988 (Cth)?

    Organisations must act ensure compliance with the Privacy Act 1988 (Cth) reforms. Learn more about the thirteen new Australian Privacy Principles (APP’s) the penalties for non-compliance, and the steps you can take to protect your business.

    Read more …

  • Why is a Privacy Act Compliance Audit (PACA) necessary?

    Why is a Privacy Act Compliance Audit (PACA) necessary?

    Understand the implications of the Privacy Act 1988 (Cth) and national privacy principles with the upcoming legislative amendments. Find out what a Privacy Act Compliance Audit (PACA) involves, who should consider it, and the consequences of non-compliance.

    Read more …


Posted

in

Send this to a friend