Notice of a Data Matching Program – Services Australia and RX Management Pty Ltd Customers Affected by March 2026 Data Breach

Administered by Department of Finance

Legislation au C2026G00456 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND RX MANAGEMENT PTY LTD CUSTOMERS AFFECTED BY MARCH 2026 DATA BREACH

 

This notice refers to the commencement of a data matching program by Services Australia using information provided by RX Management Pty Ltd about its customers affected by the March 2026 data breach (Data Breach).

The purpose of this data-matching program is to prevent, detect and address fraud relating to customer’s Centrelink or Medicare details.

The matching agency is Services Australia. The source entity is RX Management Pty Ltd.

Where a government related identifier e.g. Medicare number or Centrelink Reference Number (CRN) was disclosed, or reasonably expected to have been, as part of the Data Breach, the following data, to the extent captured by and available has been disclosed by RX Management Pty Ltd to Services Australia:

  • government identifier number
  • customer name
  • customer date of birth
  • customer address

 

Services Australia will compare the data provided by RX Management Pty Ltd to Medicare program and Centrelink program customer records. This will assist Services Australia identify affected customers deemed compromised and apply proactive security measures to detect and address fraud.

The initial analysis provided by this organisation indicates that there may be approximately 108,957 impacted customers.

A protocol document describing this program is published here:

Data matching activities for third party organisation data breaches - Services Australia

Services Australia adheres to the OAIC Guidelines on data matching in Australian Government administration and the National Health (Data-matching) Principles 2020 (Health Principles), which include standards for data matching activities.  Services Australia’s privacy policy is available at:

Privacy Policy - Services Australia

 

Overview

The Privacy Amendment (Enhancing Privacy Protection) Act 2022 was enacted by the Parliament of Australia to address gaps in privacy protection mechanisms within the existing legal framework. This legislation was introduced to strengthen the protection of personal information held by government agencies and to ensure greater accountability in the handling of such data. The Act is designed to align with modern privacy challenges, particularly in the context of increasing data breaches and the evolving technological landscape. A key policy objective of the Act is to enhance the privacy rights of individuals by imposing stricter obligations on agencies to safeguard personal information and to provide clearer avenues for recourse in cases of privacy infringements. Services Australia, as the administering body for this Act, will leverage the data matching program with RX Management Pty Ltd to prevent, detect, and address fraud concerning compromised customer details from the March 2026 data breach. By adhering to the Office of the Australian Information Commissioner (OAIC) Guidelines and the National Health (Data-matching) Principles 2020, Services Australia ensures that the data matching activities are conducted responsibly and in compliance with privacy standards. This approach reflects the overarching goal of the Act to foster trust in government data handling practices while protecting individual privacy rights.

Scope and Application

This notice pertains to a data matching program implemented by Services Australia, involving information from RX Management Pty Ltd concerning customers affected by a data breach that occurred in March 2026. The primary objective of this program is to prevent, detect, and address fraud related to Centrelink and Medicare details of affected customers. Services Australia is the matching agency, with RX Management Pty Ltd acting as the source entity. Where a government-related identifier such as a Medicare number or Centrelink Reference Number was disclosed, or reasonably expected to have been disclosed, as part of the breach, RX Management Pty Ltd has provided Services Australia with the following data: government identifier number, customer name, date of birth, and address. Services Australia will compare this information against its Medicare and Centrelink records to identify compromised customers and implement proactive security measures. According to the initial analysis, approximately 108,957 customers are impacted by this data breach. The program adheres to the OAIC Guidelines on data matching and the National Health (Data-matching) Principles 2020, with further details available in the published protocol document. Services Australia's privacy policy is also accessible to ensure transparency and compliance with privacy standards.

Key Provisions

The primary operative sections of the legislation concern the data matching program initiated by Services Australia in response to the data breach experienced by RX Management Pty Ltd. Specifically, Section 2 details the disclosure of personal information by RX Management Pty Ltd to Services Australia, including government identifiers, customer names, dates of birth, and addresses. Section 3 outlines the purpose of the data matching program, which is to prevent, detect, and address fraud related to Centrelink or Medicare details. The matching agency, Services Australia, will compare the provided data with records from the Medicare and Centrelink programs to identify compromised customers and implement proactive security measures. The obligations and requirements imposed by the Act on the involved parties are significant. RX Management Pty Ltd is required to disclose specific personal information about its customers affected by the data breach to Services Australia. This disclosure is essential for the data matching program to function effectively. Services Australia, as the matching agency, must use the disclosed information to compare against their customer records in the Medicare and Centrelink programs. Furthermore, both entities must adhere to the OAIC Guidelines on data matching and the National Health (Data-matching) Principles 2020. These guidelines and principles provide standards for data matching activities, ensuring that the process is conducted ethically and securely. In terms of consequences for breach, the legislation does not explicitly detail offences, penalties, or specific consequences for non-compliance within the provided text. However, the adherence to the OAIC Guidelines and the National Health (Data-matching) Principles suggests that any failure to comply with these standards could result in legal or regulatory action. Although the maximum penalties are not stated in the text, non-compliance with privacy and data matching guidelines can typically lead to enforcement actions by the Office of the Australian Information Commissioner (OAIC), including fines and other penalties. Both Services Australia and RX Management Pty Ltd would be expected to maintain strict compliance to avoid any adverse consequences.

Legal classification tags

Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Privacy Law
Data Breach Notification
Catchwords
Data Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.