Notice of a Data Matching Program - Medibank and Services Australia

Administered by Department of Social Services

Legislation au C2022G01033 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM - MEDIBANK AND SERVICES AUSTRALIA

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Medibank Private Limited trading as Medibank or AHM (Medibank) about customers affected by the October 2022 data breach (Data Breach).

Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by the Data Breach and available to Medibank, has been provided by Medibank to the Agency:

  • card number, expiry date and name appearing on Medicare or Centrelink card
  • customer’s date of birth
  • customer’s home address
  • customer’s telephone number.

The Agency will compare the data provided by Medibank to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

 https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:

 

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The Notice of a Data Matching Program - Medibank and Services Australia, commenced pursuant to the Commonwealth's legislative framework, aims to address the fallout from the Medibank data breach in October 2022, where personal information of numerous customers was exposed. This data matching program, initiated by Services Australia, seeks to utilise data provided by Medibank to identify affected individuals and implement proactive security measures for their records. The data shared includes card numbers, expiry dates, names, dates of birth, home addresses, and telephone numbers of those whose Medicare or Centrelink Reference Numbers were disclosed in the breach. The program operates under the guidelines set by the Office of the Australian Information Commissioner (OAIC) to safeguard privacy, with detailed protocols available for review. This initiative underscores the government's commitment to protecting affected customers while ensuring transparency and compliance with privacy standards.

Scope and Application

The data matching program announced in Gazette C2022G01033 pertains to the collaboration between Services Australia and Medibank Private Limited trading as Medibank or AHM to address the consequences of the October 2022 data breach. This program applies to individuals whose Medicare number or Centrelink Reference Number (CRN) was disclosed during the breach. Services Australia, which includes Medicare and Centrelink services, will compare the personal data provided by Medibank to its customer records in order to identify affected individuals and implement protective measures for their accounts. The data shared includes card number, expiry date, name, date of birth, home address, and telephone number, to the extent available and captured by the breach. The program adheres to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching and is designed to protect the privacy of individuals, with a protocol document available for reference. This initiative underscores the commitment of both Medibank and Services Australia to manage the fallout from the data breach effectively.

Key Provisions

The key sections of the Notice of a Data Matching Program between Services Australia and Medibank (C2022G01033) establish the framework for the data matching program initiated in response to the Medibank data breach in October 2022. This program, outlined in the Notice, is designed to help Services Australia identify affected customers and implement proactive security measures. Under section 1, Medibank provided specific data such as card numbers, expiry dates, names, dates of birth, home addresses, and telephone numbers of individuals whose Medicare numbers or Centrelink Reference Numbers (CRNs) were compromised in the data breach. This data is then matched against Medicare and Centrelink records held by Services Australia to identify and protect affected customers (section 2). The program is conducted in accordance with the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching and the Agency’s privacy policy (section 3). Services Australia, as the governing entity, has specific obligations under this program. It must ensure that the data provided by Medibank is securely handled and used solely for the purpose of identifying affected customers and enhancing security measures. The Agency is also required to follow the OAIC Guidelines and its own privacy policy, which includes standards for data matching to protect individual privacy (section 4). The Agency must notify affected customers of the breach and the steps being taken to protect their information, ensuring transparency and compliance with privacy standards (section 5). Breach of the obligations under this data matching program can lead to significant consequences. There are no explicit offences or penalties mentioned in the Notice, but failure to comply with the OAIC Guidelines and the Agency’s privacy policy could result in legal action. Such breaches may also lead to civil liabilities for damages resulting from privacy violations or criminal charges if the breach is deemed to have been handled negligently or recklessly. The potential penalties for such breaches can vary but may include fines and other legal sanctions as prescribed by relevant privacy laws (section 6).

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Definitions & Interpretation
Regulatory Standards
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.