NOTICE OF A DATA MATCHING PROGRAM - MEDIBANK AND SERVICES AUSTRALIA
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Medibank Private Limited trading as Medibank or AHM (Medibank) about customers affected by the October 2022 data breach (Data Breach).
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by the Data Breach and available to Medibank, has been provided by Medibank to the Agency:
- card number, expiry date and name appearing on Medicare or Centrelink card
- customer’s date of birth
- customer’s home address
- customer’s telephone number.
The Agency will compare the data provided by Medibank to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy