Privacy Act reforms
and your practice

What has passed, what is signalled, and the practical steps an Australian practice can take now, including where an AI scribe fits.

The Privacy Act is being rebuilt in stages, and health information sits at the strict end of everything being proposed. The first tranche is already law, penalties have risen sharply, and stronger individual rights have been signalled for the next tranche. A practice does not need to predict the timetable to prepare well, because the direction is consistent and most of the preparation is worth doing under the current Act anyway.

An empty teal waiting room with two chairs and a potted plant

Where the reforms stand

The Privacy Act 1988 is partway through its largest overhaul since it was written. The Attorney-General's Department completed a full review of the Act in 2023, and the government agreed, or agreed in principle, to most of its proposals later that year. The first tranche of legislation, the Privacy and Other Legislation Amendment Act 2024, passed Parliament in late 2024, and further tranches have been signalled.

That first tranche already changed the landscape. A statutory tort for serious invasions of privacy has been in force since June 2025, giving individuals a direct path to court. The Office of the Australian Information Commissioner gained tiered civil penalties and infringement notices, so it can act on mid-level breaches without mounting a landmark case. The security obligation in Australian Privacy Principle 11 was clarified to expressly include technical and organisational measures. From December 2026, privacy policies must describe automated decisions that significantly affect people.

The proposals still to be legislated point in one direction: a fair and reasonable test for how personal information is collected and used, a direct right of action under the Act itself, a right to request erasure, and narrower exemptions. The timing of the next tranche is uncertain. The shape of the changes is settled enough to plan against.

Health data already sits at the strict end

Health information is classified as sensitive information under the Privacy Act, which means the stricter rules already apply to every practice. Collection generally requires consent, use is limited to the purpose of collection or a directly related secondary purpose, and APP 11 requires reasonable steps to protect the information from misuse, interference, loss and unauthorised access.

The Privacy Act's small business exemption, which excuses many businesses with annual turnover of three million dollars or less, has never covered health service providers. A solo psychologist holds the same obligations as a hospital group. On top of the federal Act, several states have their own health records legislation, and the My Health Records Act governs the national shared record separately.

This is the useful context for reading the reforms. Much of what is coming for the broader economy formalises what a well-run practice should already be doing with health information. Practices that treat the current rules seriously are closer to ready than most Australian businesses, and the work described below strengthens compliance under the Act as it stands today.

Stronger rights for individuals

The statutory tort is the change with immediate effect. Since June 2025 an individual can sue for a serious invasion of privacy, whether by intrusion into their seclusion or by misuse of information about them, where the fault and seriousness thresholds are met. A consultation recording made without proper consent, or health information disclosed carelessly, is exactly the kind of conduct the tort was written for.

The signalled second tranche goes further: a right to request erasure of personal information, a direct right of action for breaches of the Act, and stronger rights of access and objection. For clinical records themselves, an erasure right will have to sit alongside record-retention law. State health records legislation commonly requires clinical records to be kept for seven years from the last entry for an adult, and longer for children, so a signed note is unlikely to be deletable on demand.

The data around the record is a different matter. Audio recordings, interim transcripts, unsigned drafts and processing logs are not the clinical record and carry no retention mandate. These are the artefacts an erasure right reaches first. For every tool that touches a consultation, a practice should be able to say what is kept, where it is stored, how long it is retained, and how it is deleted when a patient asks.

Security duties and penalties are rising

The penalty ceiling moved first. Amendments passed in 2022 lifted the maximum penalty for a serious or repeated interference with privacy to the greater of fifty million dollars, three times the benefit obtained, or thirty per cent of adjusted turnover. The 2024 Act then filled in the middle of the enforcement pyramid with mid-tier and low-tier civil penalties and infringement notices, so regulatory action no longer waits for a catastrophe.

The clarified APP 11 obligation now expressly covers technical and organisational measures. In practice that reads as encryption, access controls, multi-factor authentication, audit logging, staff training and vendor governance. OAIC guidance has pointed this way for years; the amendment removes any argument that reasonable steps are about policy documents alone.

The Notifiable Data Breaches scheme shows why health is under particular scrutiny. Health service providers have been the most frequent reporters of breaches since the scheme began, according to the OAIC's periodic reports, and the causes are dominated by compromised credentials and human error. A practice's exposure includes every vendor that holds its patients' information, because APP 11 responsibility does not transfer to the supplier.

What this means for AI tools in the consult room

The new transparency requirement for automated decision-making starts in December 2026. It obliges organisations to describe, in their privacy policy, the kinds of decisions made by automated means that significantly affect individuals. An AI scribe used properly does not make such decisions: it drafts, and a clinician reviews, corrects and signs before anything becomes part of the record. The clinical and administrative decisions stay human. Even so, a practice adopting AI tools should revisit its privacy policy and collection notices, because the honest description of how information is handled has changed.

Consent sits underneath all of it. Recording a consultation is a collection of sensitive information, which already requires consent under the current Act, and a fair and reasonable test would additionally weigh whether the collection is necessary and proportionate. A short, plain consent script at the start of the consult, with the answer recorded, satisfies today's law and the signalled reforms at the same time.

Vendor selection is where the reforms concentrate risk. Whichever AI scribe a practice chooses, the questions are the same: where the audio and drafts are processed and stored, whether the data stays in Australia, how long each artefact is retained, whether patient data is used for any purpose beyond the practice's own documentation, how deletion requests are handled, and what support the vendor provides during a notifiable breach. These questions apply to any AI scribe, and every vendor should be willing to answer them in writing.

Practical steps to take now

None of this requires waiting for the next bill. The steps below strengthen compliance under the current Act, and each one also reduces the work when the second tranche arrives.

A realistic sequence for a practice looks like this:

  • Map every system that holds health information, including clinical software, the scribe, messaging, email and backups, and record where each stores data, for how long, and how it is deleted.
  • Update the privacy policy and collection notices to describe actual practice, including any AI tools in use, and diarise the December 2026 automated decision-making disclosure.
  • Agree a consent script for recorded consultations, train the whole team on it, and note consent in the record each time.
  • Put APP 11 questions to every vendor in writing: encryption, access controls, multi-factor authentication, audit logging, Australian data residency, retention, deletion and breach support.
  • Rehearse a data breach response, including the 30-day assessment window under the Notifiable Data Breaches scheme and who notifies the OAIC and affected patients.
  • Name one owner for privacy, usually the practice manager or a principal, and review the whole picture at least annually.

How aurii is built for this direction

This section is about our product. Everything above is not.

The reforms reward documentation tools that were designed for Australian health data from the start. With aurii, consultations are captured with the patient's consent, and everything is transcribed, drafted and stored in Australia, encrypted record by record. Nothing becomes a clinical record until the clinician has reviewed and signed it, which keeps the decisions that matter with a named human and keeps the practice's AHPRA and privacy positions aligned.

The artefacts around the note are governed deliberately. Retention is defined, deletion is supported, and a practice can answer the questions in this article about aurii specifically: where the data lives, what is kept, for how long, and how it is removed. That is the position the Privacy Act reforms assume a practice will be in, and choosing a tool that already provides it saves the practice from retrofitting it later.

Common questions

Yes. The small business exemption has never covered health service providers, so every practice holding health information is bound by the Australian Privacy Principles regardless of turnover. The reforms raise the penalties and the expectations for practices that were already covered.

Real law has passed. The statutory tort for serious invasions of privacy has been in force since June 2025, the OAIC holds tiered civil penalties and infringement notices, APP 11 expressly includes technical and organisational measures, and automated decision-making transparency starts in December 2026. The erasure right and the fair and reasonable test remain proposals for a later tranche.

Unlikely for the signed record, because state health records laws require clinical records to be retained, commonly for seven years from the last entry for adults and longer for children. An erasure right would bite first on data with no retention mandate, such as consultation audio, unsigned drafts and logs, so practices should know how each tool deletes those.

A properly used scribe drafts the note and a clinician reviews, corrects and signs it, so the decisions that significantly affect the patient remain human. The December 2026 requirement is aimed at decisions made by automation. Practices should still update their privacy policy to describe how AI tools handle patient information.

Map every system that holds health information and get vendor answers in writing on residency, retention, deletion and breach support. That inventory is the foundation for every other obligation, current and coming, and it makes the later steps much faster.

This is general information about the Privacy Act reforms. It is not clinical or legal advice. More guides sit on the resources hub. If your practice needs a question answered before it adopts AI documentation, tell us and we will write it: hello@aurii.com.au.

Read first.
Then see it on your own round.

You do not have to take any of this on faith. Request access, bring a real consult, and watch the note, letters and discharge come out the other end, yours to correct and sign.

hello@aurii.com.au

Stay in the loop.

Leave your email and we'll be in touch. No spam, unsubscribe any time.