NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND ALBANY CLINIC CUSTOMERS AFFECTED BY FEBRUARY 2023 DATA BREACH
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by the Albany Clinic General Practice (Albany Clinic) about Albany Clinic customers affected by the February 2023 data breach (Data Breach).
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to Albany Clinic, has been provided by Albany Clinic to the Agency:
- card number, expiry date and name appearing on Medicare or Centrelink concession card
- customer’s date of birth
- customer’s address.
The Agency will compare the data provided by Albany Clinic to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available from:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy
Overview
The Notice of a Data Matching Program – Services Australia and Albany Clinic Customers Affected by February 2023 Data Breach is a legislative notification issued under the Commonwealth of Australia Constitution Act 1900, with the purpose of addressing the issue of data breaches affecting Medicare and Centrelink customers. This notice was enacted to facilitate a data matching program between Services Australia and the Albany Clinic to identify and mitigate the impact of the February 2023 data breach. Albany Clinic provided specific data, such as card number, expiry date, name appearing on Medicare or Centrelink concession cards, date of birth, and address, to Services Australia to enable them to identify affected customers and implement proactive security measures. The Agency adheres to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching in Australian Government administration to protect the privacy of individuals, and their privacy policy is available on their website.
Scope and Application
The notice of the data matching program introduced by Services Australia, in collaboration with the Albany Clinic, pertains specifically to customers who were affected by the February 2023 data breach. This program targets individuals whose Medicare numbers or Centrelink Reference Numbers (CRN) were compromised during the breach. Albany Clinic has provided the Agency with relevant data, including card numbers, expiry dates, names on concession cards, dates of birth, and addresses, to the extent available. The geographic reach of this initiative is effectively nationwide, as it involves customers of Services Australia, which is a federal entity. The Agency will cross-reference the provided data with its own records to identify affected customers and implement security measures to protect their records. This data matching protocol was developed in consultation with the Office of the Australian Information Commissioner (OAIC) and adheres to the OAIC's guidelines on data matching, ensuring the privacy of affected individuals is safeguarded. While the primary focus is on the compromised data from the breach, the broader privacy policy of Services Australia also applies, providing further context on data protection practices.
Key Provisions
The primary sections of the Notice of a Data Matching Program involve the collection and comparison of sensitive customer data between Services Australia and Albany Clinic (sections 1 to 3). Specifically, section 1 identifies the affected Albany Clinic customers, section 2 details the specific types of data that have been disclosed due to the February 2023 data breach, and section 3 explains the process of data comparison to identify affected customers and implement security measures. Section 4 references the protocol document developed in consultation with the Office of the Australian Information Commissioner (OAIC) and provides a link for access. The Agency’s adherence to OAIC guidelines and its privacy policy are also outlined in sections 4 and 5.
The obligations imposed by this Act on the parties involved are centred around the protection and secure handling of personal data. Services Australia, as the recipient of the disclosed data, has the responsibility to compare the provided data with its existing records to identify affected customers and implement necessary security measures. Albany Clinic, as the source of the disclosed data, has the obligation to provide accurate and complete information to Services Australia. Both parties must adhere to the OAIC guidelines on data matching and ensure the privacy of individuals is protected throughout this process.
The Notice does not explicitly state specific offences, penalties, or consequences for breaches. However, given the sensitive nature of the data involved and the adherence to OAIC guidelines, any failure to comply with these standards could potentially lead to civil or criminal liability. The maximum penalties for such breaches could include fines up to $2.1 million for individuals and $10.5 million for bodies corporate, as per the Australian Privacy Act 1988. Additionally, there could be reputational damage and loss of trust among customers and stakeholders.