NOTICE OF A DATA MATCHING PROGRAM
MEDLAB and SERVICES AUSTRALIA
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Clinical Laboratories Pty Ltd (Medlab) about customers affected by the 2022 data breach (Medlab Data Breach).
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Medlab Data Breach, the following data, to the extent captured by the Data Breach and available to Medlab, has been provided by Medlab to the Agency:
- card number, expiry date and name appearing on Medicare or Centrelink card
- customer’s date of birth
- customer’s home address
- customer’s telephone number.
The Agency will compare the data provided by Medlab to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/centrelink-data-matching-activities?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy
Overview
The Notice of a Data Matching Programmed issued under the Social Security (Administration) Act 1999 (the Act) relates to the use of data provided by Clinical Laboratories Pty Ltd (Medlab) following the 2022 data breach to identify affected customers of Services Australia (the Agency). This was enacted to address the problem of ensuring that customers whose personal information was compromised in the Medlab Data Breach could be swiftly identified and provided with appropriate security measures. The data matching program was developed in consultation with the Office of the Australian Information Commissioner (OAIC) to adhere to privacy standards and guidelines. The primary objective of the program is to proactively protect the affected customers' information by cross-referencing the compromised data with Medicare and Centrelink records held by the Agency. The Agency's privacy policy, which includes adherence to OAIC Guidelines on data matching, is available for reference to ensure transparency and accountability in the handling of personal information.
Scope and Application
The data matching program outlined in this notice applies to customers who have been affected by the 2022 data breach at Clinical Laboratories Pty Ltd (Medlab), a provider of pathology services. Specifically, the program pertains to those individuals whose Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the data breach. The Agency, Services Australia, will utilise the provided data to compare it against Medicare and Centrelink customer records held by the Agency. This comparison is intended to identify affected customers and enable the implementation of proactive security measures to safeguard their records. The geographic reach of this program is national, as it involves customers across Australia who have been impacted by the data breach. The program adheres to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching in Australian Government administration, which includes stringent standards designed to protect the privacy of individuals. This notice does not specify any exclusions, exemptions, or thresholds, and it is presumed that the program's application may be further defined or adjusted through subordinate instruments as necessary.
Key Provisions
The data matching program initiated by Services Australia under C2022G01061 (paragraphs 1-5) involves the use of specific information from Clinical Laboratories Pty Ltd (Medlab) regarding customers affected by the 2022 data breach. When an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed during the Medlab Data Breach, Medlab has provided certain personal details to the Agency. These details include the card number, expiry date and name appearing on the Medicare or Centrelink card, the customer’s date of birth, home address, and telephone number. The Agency intends to compare this data with the records it holds to identify affected customers and implement proactive security measures to safeguard these records.
The obligations imposed by this legislation on the parties involved are multifaceted. Medlab is required to furnish specific personal data of its customers to Services Australia. This data provision is a direct response to the data breach, aiming to assist Services Australia in identifying affected individuals. Services Australia, in turn, must ensure that the data matching process adheres to privacy standards as outlined by the Office of the Australian Information Commissioner (OAIC). This includes following the OAIC Guidelines on data matching in Australian Government administration, which are designed to protect the privacy of individuals. Furthermore, Services Australia must apply the information obtained to identify affected customers and implement necessary security measures to protect their records.
Breaches of the requirements set forth in the legislation could lead to significant consequences. While the specific penalties for non-compliance are not detailed in the text, the overarching legal framework within which this program operates suggests that serious repercussions may follow. Both Medlab and Services Australia must adhere strictly to the protocols and guidelines provided to avoid any civil or criminal liabilities that may arise from mishandling personal information or failing to implement adequate security measures. The potential penalties for such breaches could include fines, legal actions, or other sanctions as determined by the applicable laws and regulations governing data protection and privacy in Australia.