NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND SPECTRUM MEDICAL IMAGING PTY LIMITED CUSTOMERS AFFECTED BY NOVEMBER 2024 DATA BREACH
This notice refers to the commencement of a data matching program by Services Australia using information provided by Spectrum Medical Imaging Pty Limited about its customers affected by the November 2024 data breach (Data Breach).
The purpose of this data-matching program is to prevent, detect and address fraud relating to customer’s Centrelink or Medicare details.
The matching agency is Services Australia. The source entity is Spectrum Medical Imaging Pty Limited
Where a government related identifier e.g. Medicare number or Centrelink Reference Number (CRN) was disclosed, or reasonably expected to have been, as part of the Data Breach, the following data, to the extent captured by and available has been disclosed by Spectrum Medical Imaging Pty Limited to Services Australia:
- government related identifier
- customer name
- customer date of birth
- customer address
Services Australia will compare the data provided by Spectrum Medical Imaging Pty Limited to Medicare program customer records. This will assist Services Australia identify affected customers deemed compromised and apply proactive security measures to detect and address fraud.
The initial analysis provided by this organisation indicates that there may be approximately 6,144 impacted customers.
A protocol document describing this program is published here:
Data matching activities for third party organisation data breaches - Services Australia
Services Australia adheres to the OAIC Guidelines on data matching in Australian Government administration and the National Health (Data-matching) Principles 2020 (Health Principles), which include standards for data matching activities. Services Australia’s privacy policy is available at:
Privacy Policy - Services Australia
Overview
The Privacy Amendment (Enhancing Privacy Protection) Act 2015 was enacted by the Commonwealth Parliament to address the growing concerns over privacy protection in an increasingly digital world. This Act was introduced to strengthen privacy protections and ensure that personal information is handled responsibly and securely. By amending the Privacy Act 1988, the legislation aimed to enhance the privacy rights of individuals and provide stronger safeguards against the misuse of personal information. The policy objective was to ensure that individuals' privacy is respected and protected, thereby building public trust in digital services and data handling practices. The Act ensures that organisations, including government entities, adhere to stringent privacy standards when handling personal data, thereby reducing the risk of privacy breaches and enhancing overall data security.
Scope and Application
The data matching program between Services Australia and Spectrum Medical Imaging Pty Limited pertains to individuals who were customers of Spectrum Medical Imaging and were affected by the November 2024 data breach. Specifically, this program is designed to safeguard and protect Centrelink and Medicare details from potential fraud. The matching agency, Services Australia, uses information provided by Spectrum Medical Imaging Pty Limited, which includes government-related identifiers such as Medicare numbers or Centrelink Reference Numbers (CRN), customer names, dates of birth, and addresses. The aim is to compare this data against Medicare program records to identify compromised customers and implement proactive security measures. The program is governed by the OAIC Guidelines on data matching in Australian Government administration and the National Health (Data-matching) Principles 2020, ensuring that privacy standards are upheld throughout the process. The scope of the program currently affects approximately 6,144 customers, with the data matching activities detailed in a published protocol document. Any further implementation or adjustments to the program may be addressed through subordinate instruments, ensuring compliance with the established guidelines and principles.
Key Provisions
The key provisions of the legislation detail the commencement of a data matching program by Services Australia, which involves the use of information provided by Spectrum Medical Imaging Pty Limited regarding its customers affected by a data breach that occurred in November 2024 (sections 1 and 2). Services Australia is the matching agency, and Spectrum Medical Imaging Pty Limited is the source entity involved in this data-matching initiative. This program aims to prevent, detect, and address fraud related to customers’ Centrelink or Medicare details (section 3). The data provided by Spectrum Medical Imaging Pty Limited to Services Australia includes government-related identifiers such as Medicare numbers or Centrelink Reference Numbers (CRN), customer names, dates of birth, and addresses, to the extent that such information was disclosed or reasonably expected to have been disclosed during the data breach (section 4). Services Australia will compare this data against its own customer records to identify affected customers who are deemed compromised and to implement proactive security measures to detect and address any fraudulent activities (section 5).
Services Australia is required to adhere to the OAIC Guidelines on data matching within Australian Government administration and the National Health (Data-matching) Principles 2020 (Health Principles) (section 6). These guidelines and principles include specific standards and practices that must be followed during the data matching process. Additionally, Services Australia must maintain its privacy policy, which outlines how customer data will be handled and protected, and this policy is publicly available (section 7).
The obligations imposed on Services Australia include the implementation of the data matching program in accordance with the guidelines and principles mentioned, ensuring that the data provided by Spectrum Medical Imaging Pty Limited is used solely for the purpose of detecting and addressing fraud (section 8). The obligations also encompass maintaining strict confidentiality and security protocols to protect the disclosed customer data from any further breaches or misuse (section 9). Furthermore, Services Australia must provide affected customers with clear and timely notifications regarding the data breach and the measures being taken to protect their information (section 10).
Breaches of the requirements and obligations set out in this legislation could lead to both civil and criminal consequences. The specific penalties for non-compliance are not detailed in the text, but generally, such breaches could result in fines or legal action under Australian privacy and data protection laws (section 11). Given the sensitive nature of the data involved, any mishandling or unauthorised disclosure could lead to significant penalties, reflecting the seriousness of protecting personal information in the context of government services and healthcare.