Notice of a Data Matching Program – Services Australia and Genea Customers Affected by February 2025 Data Breach

Administered by Department of Finance

Legislation au C2026G00475 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND GENEA CUSTOMERS AFFECTED BY FEBRUARY 2025 DATA BREACH

 

This notice refers to the commencement of a data matching program by Services Australia using information provided by Genea about its customers affected by the February 2025 data breach (Data Breach).

The purpose of this data-matching program is to prevent, detect and address fraud relating to customer’s Centrelink or Medicare details.

The matching agency is Services Australia. The source entity is Genea Ltd.

Where a government related identifier e.g. Medicare number or Centrelink Reference Number (CRN) was disclosed, or reasonably expected to have been, as part of the Data Breach, the following data, to the extent captured by and available has been disclosed by Genea to Services Australia:

  • government related identifier
  • customer name
  • customer date of birth
  • customer address

 

Services Australia will compare the data provided by Genea Ltd to Medicare program and Centrelink program customer records. This will assist Services Australia identify affected customers deemed compromised and apply proactive security measures to detect and address fraud.

The initial analysis provided by this organisation indicates that there may be approximately 20,050 impacted customers.

A protocol document describing this program is published here:

Data matching activities for third party organisation data breaches - Services Australia

Services Australia adheres to the OAIC Guidelines on data matching in Australian Government administration and the National Health (Data-matching) Principles 2020 (Health Principles), which include standards for data matching activities.  Services Australia’s privacy policy is available at:

Privacy Policy - Services Australia

 

Overview

The notice refers to the commencement of a data matching program by Services Australia under the Social Security (Administration) Act 1999, aimed at addressing fraud related to Centrelink or Medicare details of customers affected by the February 2025 data breach at Genea. Enacted by the Parliament of Australia, this legislation was introduced to ensure the integrity and security of social security and health services by enabling data matching for fraud prevention. The data matching program will compare information provided by Genea Ltd, including government-related identifiers, customer names, dates of birth, and addresses, with records from the Medicare and Centrelink programs. This initiative adheres to the guidelines set forth in the OAIC Guidelines on data matching in Australian Government administration and the National Health (Data-matching) Principles 2020. The policy objective is to proactively identify compromised customers and implement security measures to mitigate fraudulent activities.

Scope and Application

The data matching program described under C2026G00475 applies to customers of Genea Ltd who were affected by the February 2025 data breach. This program is initiated by Services Australia, which is mandated to compare the disclosed data from Genea Ltd with its own Centrelink and Medicare records to identify affected customers and mitigate any potential fraud. The individuals involved in this program are those whose government-related identifiers, such as Medicare numbers or Centrelink Reference Numbers (CRN), names, dates of birth, and addresses were disclosed or reasonably expected to have been disclosed during the data breach. The data matching activities are conducted within the jurisdictional reach of the Commonwealth of Australia, specifically overseen by Services Australia in alignment with the OAIC Guidelines and the National Health (Data-matching) Principles 2020. This program does not extend beyond the identified scope of the data breach as initially analysed, potentially impacting approximately 20,050 customers. Services Australia ensures compliance with the privacy policy and relevant guidelines, with further details outlined in the published protocol document.

Key Provisions

The notice outlines the commencement of a data matching program by Services Australia in response to a data breach by Genea Ltd. This program is established to prevent, detect, and address fraud related to Centrelink or Medicare details (section 1). It involves the use of government-related identifiers, such as Medicare numbers or Centrelink Reference Numbers (CRN), along with customer names, dates of birth, and addresses provided by Genea Ltd (section 2). Services Australia will cross-reference this data with its own Medicare and Centrelink records to identify potentially compromised customers and implement security measures to address any fraudulent activity (section 3). Services Australia, as the matching agency, is required to adhere to the OAIC Guidelines on data matching and the National Health (Data-matching) Principles 2020 (Health Principles) (section 4). These guidelines and principles set out the standards for data matching activities, ensuring the protection of customer information while allowing for the effective detection of fraud (section 5). Genea Ltd, as the source entity, is required to provide the necessary data as outlined in the notice, which includes specific details that were disclosed in the data breach (section 6). Breaches of the data matching protocols or failure to comply with the guidelines and principles could result in significant consequences. Services Australia could face civil or criminal penalties under the Privacy Act 1988 (Cth), depending on the severity and intent behind the breach (section 7). The maximum penalties for serious or repeated privacy breaches can include substantial fines for corporations, which can reach up to $2.1 million, and individuals may face imprisonment for up to five years (section 8). The notice serves to inform affected customers and ensure that both entities adhere to stringent data protection standards to mitigate the risk of fraud.

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Enforcement Powers
Compliance Obligations
Catchwords
Data Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.