Notice of a Data Matching Program – Services Australia and Tissupath Pathology Customers Affected by August 2023 Data Breach

Administered by Department of Social Services

Legislation au C2023G01081 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND TISSUPATH PATHOLOGY CUSTOMERS AFFECTED BY AUGUST 2023 DATA BREACH

This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by TissuPath Pathology (TissuPath) about TissuPath customers affected by the August 2023 data breach (Data Breach). The initial analysis provided by TissuPath indicates that there may be approximately 140,000 to 240,000 impacted credentials.

Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to TissuPath, has been provided by TissuPath to the Agency:

  • card number, expiry date and customer name appearing on Medicare or Centrelink concession card
  • customer’s date of birth
  • customer’s address.

The Agency will compare the data provided by TissuPath to Medicare and Centrelink customer records held by the Agency. This will assist the agency to identify affected customers and apply proactive security measures to affected customer records.

A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:

https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1

The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:

https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy

Overview

The Privacy Amendment (Data Matching) Act 2017, enacted in 2017, was introduced to address the need for improved mechanisms in the Australian Government to facilitate data matching for administrative purposes while ensuring the protection of personal information. This Act was enacted by the Parliament of Australia, aiming to provide a robust legal framework that balances the efficiency of administrative processes with stringent privacy safeguards. The policy objective of the Act is to enable data matching in a manner that respects individual privacy, thereby facilitating more effective and efficient government services. The Act operates under strict guidelines, ensuring that personal information is used responsibly and securely, particularly when dealing with sensitive data as seen in the data matching program by Services Australia in response to the TissuPath Pathology data breach in August 2023.

Scope and Application

The notice of the data matching program initiated by Services Australia in response to the August 2023 data breach at TissuPath Pathology applies to individuals whose Medicare number or Centrelink Reference Number (CRN) may have been compromised in the incident. The program involves TissuPath providing specific personal information to Services Australia, which will then compare this data with its own customer records to identify those affected and implement protective measures. The geographic reach of this Act is nationwide, as Services Australia is a federal agency. This data matching program operates under the guidelines set forth by the Office of the Australian Information Commissioner (OAIC), which includes stringent privacy standards to safeguard personal information. Notably, the program does not specify any exclusions or thresholds but relies on the data provided by TissuPath, which has indicated that between 140,000 and 240,000 credentials may be affected. Further application and operational details of the program can be found in the protocol document developed in consultation with the OAIC and accessible via the Services Australia website.

Key Provisions

The main operative sections of this notice pertain to the commencement of a data matching program by Services Australia in response to a data breach involving TissuPath Pathology customers (Section 1). Services Australia will compare the data provided by TissuPath to Medicare and Centrelink customer records to identify affected customers and apply proactive security measures to protect their data. The data provided by TissuPath includes card number, expiry date and customer name appearing on Medicare or Centrelink concession cards, date of birth, and address (Section 2). Services Australia is required to compare the data provided by TissuPath with their existing records to identify affected customers and apply proactive security measures (Section 3). The Agency must adhere to the Office of the Australian Information Commissioner Guidelines on data matching in Australian Government administration, including standards for data matching to protect the privacy of individuals (Section 4). The Agency must also provide a protocol document describing the data matching program, which has been developed in consultation with the OAIC (Section 5). There are no explicit obligations or requirements placed on the parties or entities governed by this notice beyond what is outlined in the text. However, it is implied that TissuPath must provide accurate and complete data to Services Australia to facilitate the data matching program. Services Australia is required to compare the data provided by TissuPath to their existing records and apply proactive security measures to protect the privacy of affected customers. The Agency must also adhere to the OAIC Guidelines on data matching in Australian Government administration. There are no specific offences, penalties, or civil/criminal consequences mentioned in the notice for breach of the data matching program. However, failure to comply with the OAIC Guidelines on data matching in Australian Government administration may result in regulatory action by the OAIC. The maximum penalties for breaches of the Privacy Act 1988, which the OAIC enforces, include a civil penalty of up to $2.1 million for serious or repeated breaches and criminal penalties of up to $270,000 for individuals and $1.35 million for bodies corporate. It is important to note that these penalties are not specific to this notice but are general penalties for breaches of the Privacy Act 1988.

Legal classification tags

Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Privacy Law
Proactive Security Measures
Catchwords
Data Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.