NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND PARTRIDGEGP CUSTOMERS AFFECTED BY SEPTEMBER 2023 DATA BREACH
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by PartridgeGP about PartridgeGP customers affected by the September 2023 data breach (Data Breach). The initial analysis provided by PartridgeGP indicates that there may be approximately 7,000 impacted customers.
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to PartridgeGP, has been provided by PartridgeGP to the Agency:
- card number, expiry date and customer name appearing on Medicare or Centrelink concession card
- customer’s date of birth
- customer’s address.
The Agency will compare the data provided by PartridgeGP to Medicare and Centrelink customer records held by the Agency. This will assist the Agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy
Overview
The notice of a data matching program concerning the September 2023 data breach affecting PartridgeGP customers was introduced to address the immediate need for identifying and protecting the data of approximately 7,000 customers whose personal information was compromised. The Privacy Act 1988, enacted by the Australian Parliament, provides the framework for data handling and protection, and the introduction of this data matching program aligns with its policy objective of ensuring that personal information is managed with appropriate security measures. Services Australia, the agency responsible for this initiative, has developed a protocol in consultation with the Office of the Australian Information Commissioner (OAIC) to adhere to the guidelines on data matching to safeguard individual privacy. This proactive approach is designed to mitigate any potential harm to affected customers by applying necessary security measures to their records, reflecting the commitment to privacy and data protection mandated by the Act.
Scope and Application
The data matching program initiated by Services Australia involves the use of specific personal information provided by PartridgeGP to identify customers affected by a recent data breach. This program applies to approximately 7,000 individuals whose Medicare numbers or Centrelink Reference Numbers were disclosed during the breach. The personal data provided by PartridgeGP includes card numbers, expiry dates, names appearing on concession cards, dates of birth, and addresses. Services Australia will compare this information with their existing Medicare and Centrelink records to identify affected customers and implement security measures. The program is conducted in accordance with the OAIC Guidelines on data matching, which are designed to protect individual privacy. The geographic reach of this program is effectively nationwide as Services Australia operates across Australia. The program does not explicitly mention any exclusions, exemptions, or thresholds, but it is designed to be compliant with privacy standards and is overseen by the OAIC. The application and further details of the program can be found in the protocol document available on the Services Australia website.
Key Provisions
The key provisions of the legislation, C2023G01243, revolve around the data matching program initiated by Services Australia, in collaboration with PartridgeGP, to address the data breach that occurred in September 2023. Section 2 outlines the data matching program, which involves comparing information provided by PartridgeGP regarding affected customers with the records held by Services Australia. The data provided includes Medicare or Centrelink concession card details, date of birth, and address. This comparison aims to identify affected customers and implement proactive security measures. Section 3 refers to the protocol document developed in consultation with the Office of the Australian Information Commissioner (OAIC), which details the data matching process and is available for review. Section 4 highlights the Agency's adherence to OAIC Guidelines on data matching, which includes privacy protection standards, and the Agency's privacy policy, which is accessible online.
The obligations and requirements imposed by this Act on Services Australia and PartridgeGP include the provision of specific customer data to Services Australia, as outlined in Section 2. PartridgeGP must furnish details of affected customers, such as card number, expiry date, customer name, date of birth, and address, to facilitate the data matching process. Services Australia, on the other hand, is obligated to compare this provided data with their existing customer records and to apply necessary security measures to protect the compromised records. Furthermore, both parties must ensure that the data matching program adheres to the OAIC Guidelines on data matching and privacy protection standards, as stipulated in Section 3.
In terms of offences, penalties, or consequences for breaches, the legislation does not explicitly detail specific sanctions within the provided text. However, the adherence to OAIC Guidelines implies a framework of compliance and accountability. Non-compliance with these guidelines or failure to properly handle customer data could potentially lead to civil or criminal consequences under broader privacy and data protection laws. Given the sensitivity of the data involved, any mishandling could result in significant repercussions, including legal action and penalties as prescribed under the Privacy Act 1988 or other relevant legislation. It is essential for both Services Australia and PartridgeGP to meticulously follow the outlined protocols to avoid any legal implications.