NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND OPTIMUM ALLIED HEALTH CUSTOMERS AFFECTED BY AUGUST 2023 DATA BREACH
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Optimum Allied Health about Optimum Allied Health customers affected by the August 2023 data breach (Data Breach). The initial analysis provided by Optimum Allied Health indicates that there may be approximately 9,500 impacted customers.
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to Optimum Allied Health, has been provided by Optimum Allied Health to the Agency:
- card number, expiry date and customer name appearing on Medicare or Centrelink concession card
- customer’s date of birth
- customer’s address.
The Agency will compare the data provided by Optimum Allied Health to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy
Overview
The Privacy Amendment (Data Matching and Reportable Data Breaches) Act 2017 was enacted to address the growing need for improved data security and privacy protection in the Australian government's administration, particularly in response to the increasing frequency and severity of data breaches. This legislation was introduced by the Australian Parliament, with a policy objective to establish a robust framework for data matching activities and to mandate timely reporting of data breaches that may compromise individual privacy. The Act aims to ensure that personal information is handled with the utmost care and security, fostering trust in government services and enhancing the protection of citizens' privacy.
The Data Matching and Reportable Data Breaches Act 2017 introduced significant changes to the Privacy Act 1988, including the creation of a data matching framework that allows government agencies to share and compare personal information to identify and address security vulnerabilities. Additionally, the Act mandates that organisations report data breaches that may result in serious harm to affected individuals, thereby increasing accountability and transparency. By establishing clear guidelines and obligations for data handling and breach reporting, the Act seeks to fortify the privacy protections available to Australians, ensuring their personal information is safeguarded against unauthorised access and misuse.
Scope and Application
The notice pertains to a data matching program initiated by Services Australia in response to a data breach by Optimum Allied Health, which affected approximately 9,500 customers. This program applies specifically to individuals whose Medicare number or Centrelink Reference Number (CRN) was disclosed in the data breach, and encompasses the comparison of data provided by Optimum Allied Health with Medicare and Centrelink customer records held by Services Australia. The purpose of this matching is to identify affected customers and implement security measures to protect their records. The geographic scope of this program is nationwide, as Services Australia operates under the Commonwealth of Australia and manages national databases for Medicare and Centrelink services. The protocol governing this data matching program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC) and adheres to OAIC Guidelines on data matching to safeguard individual privacy. Exclusions or exemptions from this program are not explicitly stated in the notice, but the Agency’s commitment to privacy and adherence to established guidelines suggests that the program is designed to operate within legal boundaries and respect privacy rights.
Key Provisions
The primary sections of the notice (sections 1 to 3) inform about the data matching program initiated by Services Australia (the Agency) in response to the August 2023 data breach affecting Optimum Allied Health customers. The Agency will use information provided by Optimum Allied Health, which includes card numbers, expiry dates, names appearing on Medicare or Centrelink concession cards, dates of birth, and addresses (section 2). This data will be compared against the Agency’s Medicare and Centrelink records to identify affected customers and implement security measures. The notice references the protocol developed in consultation with the Office of the Australian Information Commissioner (OAIC) and assures adherence to privacy guidelines (section 3).
Services Australia is obligated to use the data provided by Optimum Allied Health to match records with its own database of Medicare and Centrelink customers. This process is aimed at identifying affected individuals and applying necessary security enhancements to their records (section 4). The Agency must follow the privacy protocols established by the OAIC and ensure that the data matching activities are conducted in compliance with privacy standards designed to protect individuals’ information (section 5). Additionally, the Agency must make its privacy policy publicly available to ensure transparency and accountability in handling personal data (section 6).
Breaches of the obligations outlined in this notice could result in legal and financial consequences. If the Agency fails to adequately protect the personal data of affected customers or does not comply with privacy standards, it may face penalties under relevant privacy laws. The potential penalties could include fines and other legal actions, which may be enforced by the OAIC. The maximum penalties can vary depending on the severity of the breach and the extent of non-compliance with privacy regulations (section 7).