NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND CRACE MEDICAL CENTRE CUSTOMERS AFFECTED BY DECEMBER 2023 DATA BREACH
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Crace Medical Centre about Crace Medical Centre customers affected by the December 2023 data breach (Data Breach). The initial analysis provided by Crace Medical Centre indicates that there may be approximately 21,000 impacted customers.
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to Crace Medical Centre, has been provided by Crace Medical Centre to the Agency:
- card number, expiry date and customer name appearing on Medicare or Centrelink concession card
- customer’s date of birth
- customer’s address.
The Agency will compare the data provided by Crace Medical Centre to Medicare and Centrelink customer records held by the Agency. This will assist the Agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy
Overview
The Notice of a Data Matching Program – Services Australia and Crace Medical Centre Customers Affected by December 2023 Data Breach (C2024G00140) was enacted in 2024. This legislation was introduced to address the issue arising from the December 2023 data breach at Crace Medical Centre, where approximately 21,000 customers' sensitive information was compromised. The Commonwealth Parliament authorised the data matching program to be initiated by Services Australia to safeguard affected individuals' data and ensure appropriate security measures are implemented. The primary policy objective outlined in the notice is to protect the privacy of individuals by adhering to the Office of the Australian Information Commissioner (OAIC) guidelines and standards for data matching. This initiative aims to assist Services Australia in identifying affected customers and applying proactive security measures to their records, thereby mitigating the risks associated with the data breach.
Services Australia, in collaboration with the OAIC, has developed a protocol document that outlines the specifics of the data matching program. The document, available for review, ensures compliance with privacy standards and aims to maintain the confidentiality and security of the affected customers' data. The Agency's privacy policy, also accessible, reinforces the commitment to protecting personal information and utilising data matching as a responsible and secure measure in response to the data breach.
Scope and Application
The C2024G00140 Gazette notice pertains to the implementation of a data matching program by Services Australia in collaboration with Crace Medical Centre. This program is specifically directed towards customers of Crace Medical Centre who were affected by the December 2023 data breach. The data matching initiative involves the comparison of personal information provided by Crace Medical Centre against the records held by Services Australia, aiming to identify affected customers and implement necessary security measures. The data provided includes card numbers, expiry dates, names, dates of birth, and addresses as captured by Crace Medical Centre. This program applies to approximately 21,000 individuals whose Medicare number or Centrelink Reference Number was disclosed in the breach. Services Australia adheres to the Office of the Australian Information Commissioner's guidelines to ensure privacy protection during this data matching process. The scope of this Act is limited to the specific data breach incident at Crace Medical Centre and does not extend to other entities or breaches unless similarly specified in future notices.
Key Provisions
The primary provisions of this legislation pertain to the commencement of a data matching program by Services Australia (the Agency) in response to a data breach affecting approximately 21,000 customers of Crace Medical Centre (section 1). Specifically, the Agency will compare the data provided by Crace Medical Centre to its own records, which include card number, expiry date, customer name, date of birth, and address, to identify affected customers and apply necessary security measures (section 2). This data matching activity is outlined in a protocol document developed in consultation with the Office of the Australian Information Commissioner (OAIC) and is in compliance with the OAIC Guidelines on data matching (section 3).
The obligations and requirements imposed by the Act on the parties involved include the provision of specific data by Crace Medical Centre to Services Australia for the purposes of this data matching program (section 4). The data must be provided in accordance with the protocol document developed in consultation with the OAIC, and Services Australia must adhere to the OAIC Guidelines on data matching to protect the privacy of individuals (section 5). Both Crace Medical Centre and Services Australia must ensure that the data provided and received is used solely for the purposes of identifying affected customers and applying security measures (section 6).
The Act does not explicitly state any specific offences, penalties, or consequences for breach. However, it is implied that any breach of the protocol or misuse of the data provided could result in legal action, given that the data matching program is conducted in accordance with the OAIC Guidelines and the Agency’s privacy policy (section 7). These guidelines and policies are designed to protect the privacy of individuals, and any failure to comply with them could result in civil or criminal consequences, including potential penalties as prescribed by the relevant legislation governing data protection and privacy in Australia (section 8).