Notice of a Data Matching Program - Apunipima Cape York Health Council and Services Australia

Administered by Department of Social Services

Legislation au C2023G00339 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM - Apunipima Cape York Health Council and SERVICES AUSTRALIA

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Apunipima Cape York Health Council (Apunipima) about customers affected by the October 2022 data breach (Data Breach).

Where an Agency customer’s Medicare number or Centrelink Customer Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent available to Apunipima, has been provided by Apunipima to the Agency:

  • card number, expiry date and name appearing on Medicare
  • the CRN
  • customer’s date of birth.

The Agency will compare the data provided by Apunipima to Medicare and Centrelink customer records held by the Agency. This will assist the Agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

 https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:

 

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The notice of a data matching program published in Gazette C2023G00339 refers to a collaborative initiative between Services Australia and Apunipima Cape York Health Council aimed at addressing the consequences of the October 2022 data breach. Enacted to tackle the vulnerabilities exposed by the data breach, this program seeks to ensure that affected customers receive appropriate support and that their data is secured against future breaches. The data matching program involves Apunipima providing specific customer information, such as card numbers, expiry dates, names, and dates of birth, to Services Australia, which will then compare this data against its existing Medicare and Centrelink records. This comparison is intended to identify affected customers swiftly and implement proactive security measures. The initiative adheres to the guidelines set forth by the Office of the Australian Information Commissioner (OAIC) to safeguard individual privacy during data matching activities. By collaborating with Apunipima and following stringent privacy standards, Services Australia aims to mitigate the impact of the data breach and reinforce the security of customer data.

Scope and Application

The data matching program initiated by Services Australia in collaboration with Apunipima Cape York Health Council pertains specifically to customers whose Medicare number or Centrelink Customer Reference Number was disclosed during the October 2022 data breach. This program encompasses the comparison of the provided data, including card numbers, expiry dates, names on Medicare, CRNs, and dates of birth, against the Medicare and Centrelink customer records held by Services Australia. The primary objective is to identify affected customers and implement proactive security measures to safeguard their records. The scope of this Act is limited to the specific data breach incident and the subsequent need to mitigate its effects on affected individuals. The jurisdictional reach of this data matching program is primarily within the Commonwealth of Australia, as it involves federal entities such as Services Australia and the data provided by Apunipima, a regional health council. While the primary focus is on addressing the security implications of the disclosed data, the program adheres to the guidelines set by the Office of the Australian Information Commissioner to ensure the privacy and protection of individuals' information. There are no stated exclusions or exemptions in this program, and the data matching activities are conducted in strict compliance with the OAIC Guidelines on data matching and Services Australia's privacy policy.

Key Provisions

The primary sections of the notice (sections 1 to 3) outline the commencement of a data matching program by Services Australia (the Agency) in collaboration with Apunipima Cape York Health Council (Apunipima). This program follows the October 2022 data breach which exposed personal information of certain customers. Specifically, the notice highlights that Apunipima has provided the Agency with certain data elements, including card numbers, expiry dates, names appearing on Medicare, CRNs, and dates of birth, of customers affected by the data breach. The purpose of this data matching is to help the Agency identify affected customers and implement security measures to protect their records. The obligations and requirements imposed by the Act on the involved parties are detailed in sections 4 to 6. The Agency is mandated to compare the provided data with its existing Medicare and Centrelink customer records to identify individuals affected by the data breach. The data matching program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC), ensuring compliance with data matching guidelines designed to protect individual privacy. Apunipima is responsible for providing the necessary data to the Agency, which must be handled in accordance with the OAIC Guidelines on data matching and the Agency's privacy policy. Sections 7 to 9 of the notice detail the potential consequences of breaches and violations of the data matching program. Any breach of the privacy guidelines or misuse of personal information can result in both civil and criminal penalties. The maximum penalties for such breaches are determined by the Privacy Act 1988 and can include substantial fines for organisations and individuals involved in the mishandling of personal data. Additionally, there may be reputational damage and loss of trust from affected customers, further emphasising the importance of adhering to the outlined protocols and privacy standards. The notice ensures that all parties involved are aware of the stringent measures in place to protect the privacy and security of personal information.

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Definitions & Interpretation
Reporting & Disclosure Obligations
Enforcement Powers
Catchwords
Data Matching Program
Data Breach

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.