Compliance

Patient Data Security for Dental Practices: What the Privacy Act Actually Requires

Patient data security is not optional for a dental practice. Health information carries the highest level of protection under the Privacy Act 1988, and the obligations sit with the practice — not with your IT provider.

Steeve10 min read

Most practices know they are meant to keep patient records secure. Fewer could say what the law actually requires, or what they would have to do in the first seventy-two hours after a breach.

That second gap is the expensive one.

Why the Privacy Act applies to your practice

The Privacy Act 1988 applies to businesses with an annual turnover above three million dollars — and, separately, to every organisation that provides a health service, regardless of size.

A dental practice provides a health service. So the Act applies, whether the practice has two chairs or twenty.

Health information is also classed as sensitive information, which carries stricter handling requirements than ordinary personal information. A patient record containing clinical notes and imaging sits in the most protected category the Act defines.

What the Act actually requires

The Australian Privacy Principles set out thirteen obligations. Four do most of the work for a practice.

APP 1 — manage privacy openly

You need a privacy policy that is current and available, and you need to actually run your practice the way it describes. A policy that does not reflect what you do is worse than no policy, because it becomes evidence.

APP 6 — use and disclosure

Patient information may be used for the purpose it was collected. Using it for something else — marketing, for instance — generally requires consent.

APP 11 — security

This is the one IT touches. You must take reasonable steps to protect information from misuse, interference, loss, unauthorised access, modification and disclosure. You must also destroy or de-identify it when it is no longer needed and you are not required to keep it.

"Reasonable steps" is deliberately not a checklist. It scales with the sensitivity of the information and the harm that would follow. For clinical records, the bar is high.

APP 12 — access

Patients can request their own records, and you generally have to provide them. Practically, this means you need to be able to find and export a single patient record without a major exercise.

What "reasonable steps" looks like in practice

The Act does not prescribe technology. These are the measures that a practice would be expected to have, and that we would look for in any review:

  • Multi-factor authentication on email and any system reachable from outside the practice
  • Individual logins — no shared reception account that four people use
  • Access limited to what each role needs
  • Encryption on laptops and any portable device holding patient data
  • Backups that are tested, with a copy that ransomware cannot reach
  • Supported, patched operating systems and practice software
  • Remote access that is controlled and logged, not open
  • A written record of who your IT provider is and what they can reach
  • Staff who can recognise a phishing email

The Australian Signals Directorate publishes the Essential Eight at cyber.gov.au, which is a reasonable baseline to measure yourself against.

The Notifiable Data Breaches scheme

This is the part most practices have not thought through, and it is where the obligations become concrete.

If personal information is lost or accessed without authorisation, and a reasonable person would conclude it is likely to result in serious harm, that is an eligible data breach. You must notify the Office of the Australian Information Commissioner and the affected individuals.

The sequence

The Notifiable Data Breaches sequenceFour stages. Contain the breach immediately. Assess within thirty days whether serious harm is likely. If it is an eligible breach, notify the Office of the Australian Information Commissioner and the affected patients as soon as practicable. Then review what allowed it.IF PATIENT DATA IS EXPOSEDContainImmediatelyStop further access.Disconnect the machine.AssessWithin 30 daysDecide whether seriousharm is likely.NotifyAs soon as practicableThe OAIC and theaffected patients.ReviewAfterClose the gap thatallowed it.The obligation to notify sits with the practice, not with your IT provider.
The four stages of the Notifiable Data Breaches scheme, and the timeframe attached to each.
  1. Contain it. Stop further access immediately.
  2. Assess. If you suspect an eligible breach, you have thirty days to complete a reasonable and expeditious assessment.
  3. Notify. If it is an eligible breach, notify the OAIC and the affected individuals as soon as practicable.
  4. Review. Work out what allowed it, and close that gap.

Notifying patients that their clinical records may have been accessed is a conversation no practice wants. Avoiding it is the real argument for the measures above.

The OAIC publishes detailed guidance on the scheme at oaic.gov.au, including what counts as serious harm.

How long you have to keep records

Retention is set by state health records legislation rather than by the Privacy Act. In Victoria, the Health Records Act 2001 sets the general position: seven years from the last entry for an adult, and for a patient who was a child, until they turn 25.

Two practical consequences. First, your backups and archives need to reach back that far and still be readable. Second, APP 11 requires you to destroy or de-identify records once you are no longer required to hold them — so indefinite retention is not the safe default it appears to be.

Your obligations do not stop at your own systems

If a third party holds or can reach your patient data — your IT provider, a cloud practice management vendor, an offsite backup service — you remain accountable for it.

Worth knowing for each: where the data is stored, whether it leaves Australia, who can access it, what happens if that provider fails, and how you would get your data back.

These are reasonable questions to ask, and any competent provider will answer them without hesitation.

The current threat is not theoretical

A phishing attack is moving through Victorian dental and medical practices now. It takes over a practice mailbox, then emails everyone in the address book from a genuine address. Antivirus does not detect it.

If it succeeds, an attacker has access to a mailbox containing patient correspondence and to passwords saved on that machine — which is precisely the scenario the Notifiable Data Breaches scheme exists for.

Our security advisory explains what it looks like and what to do.

For the wider picture of what practices get wrong operationally, see the five IT issues that disrupt dental clinics most.

Where to start

If you do nothing else after reading this, do these three:

  1. Turn on multi-factor authentication for every account, starting with email.
  2. Restore your patient database from backup and open it. Confirm it works and record how long it took.
  3. Decide now who makes the notification decision if patient data is exposed, and write it down.

The Australian Dental Association maintains guidance for practices on records and privacy. We work with practices across dental and medical IT support in Victoria, and the security review is free.

Common questions

Does the Privacy Act apply to a small dental practice?
Yes. The usual three million dollar turnover threshold does not apply to organisations providing a health service. A dental practice is covered regardless of size.
Is patient data treated differently from ordinary business data?
Yes. Health information is sensitive information under the Act, which is the most protected category. It carries stricter handling requirements and a higher expectation of security.
What is an eligible data breach?
Unauthorised access to or disclosure of personal information, or its loss, where a reasonable person would conclude it is likely to result in serious harm to an affected individual. If that test is met, you must notify the OAIC and those individuals.
How long do we have to report a data breach?
If you suspect an eligible breach, you have thirty days to complete a reasonable and expeditious assessment. If it is an eligible breach, you notify as soon as practicable — not at the end of the thirty days.
Is our IT provider responsible if patient data is exposed?
The legal obligation to notify sits with the practice. A provider can help you contain, assess and remediate, and a good one will. They cannot take on your duty under the Act.
How long must we keep dental records in Victoria?
Under the Health Records Act 2001, the general position is seven years from the last entry for an adult, and until the age of 25 for a patient who was a child. Confirm your own position with your adviser.
Does encryption alone make us compliant?
No. Encryption is one reasonable step among several. Access control, multi-factor authentication, tested backups, patching and staff awareness all form part of what APP 11 expects.
Can we store patient data overseas?
It is possible, but it brings additional obligations around disclosure to overseas recipients, and you remain accountable for the information. Know where your practice management vendor and backup provider actually store your data before you assume the answer.

Not sure where your practice stands?

We will review your setup and tell you what we find. Twenty minutes, no obligation, no disruption to clinic hours.