NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND TOP HEALTH DOCTORS CUSTOMERS AFFECTED BY SEPTEMBER 2023 DATA BREACH
This notice refers to the commencement of a data matching program by Services Australia (the Agency) using information provided by Top Health Doctors about Top Health Doctors customers affected by the September 2023 data breach (Data Breach). The initial analysis provided by Top Health Doctors indicates that there may be approximately 5,500 impacted customers.
Where an Agency customer’s Medicare number or Centrelink Reference Number (CRN) was disclosed as part of the Data Breach, the following data, to the extent captured by and available to Top Health Doctors, has been provided by Top Health Doctors to the Agency:
- card number, expiry date and customer name appearing on Medicare or Centrelink concession card
- customer’s date of birth
- customer’s address.
The Agency will compare the data provided by Top Health Doctors to Medicare and Centrelink customer records held by the Agency. This will assist the Agency to identify affected customers and apply proactive security measures to affected customer records.
A protocol document describing this program has been developed in consultation with the Office of the Australian Information Commissioner (OAIC). Copies of the document are available from:
https://www.servicesaustralia.gov.au/data-matching-activities-for-third-party-organisation-data-breaches?context=1
The Agency adheres to the OAIC Guidelines on data matching in Australian Government administration which includes standards for data matching to protect the privacy of individuals. The Agency’s privacy policy is available at:
https://www.servicesaustralia.gov.au/organisations/about-us/publications-and-resources/privacy-policy
Overview
The notice pertains to the commencement of a data matching program by Services Australia, as announced in the 2023 Gazette. This initiative aims to address the issues arising from the September 2023 data breach involving Top Health Doctors, where approximately 5,500 customers were affected. The primary goal of this program is to ensure that customers whose Medicare number or Centrelink Reference Number was disclosed are identified and provided with necessary security measures. The data provided by Top Health Doctors includes card number, expiry date, customer name, date of birth, and address as they appear on Medicare or Centrelink concession cards. Services Australia intends to compare this information with its existing customer records to facilitate the identification of affected customers and to implement proactive security measures. The program has been developed in consultation with the Office of the Australian Information Commissioner, adhering to the OAIC Guidelines on data matching to ensure the protection of individual privacy.
Services Australia is committed to safeguarding customer data, as evidenced by its adherence to the OAIC Guidelines on data matching and its comprehensive privacy policy, which can be accessed online. This data matching program reflects the agency's dedication to addressing the consequences of the data breach efficiently and securely, thereby protecting the affected customers' personal information.
Scope and Application
The Data Matching Program Notice outlines a collaborative effort between Services Australia and Top Health Doctors to address the data breach that occurred in September 2023, affecting approximately 5,500 customers. This initiative applies to customers whose Medicare number or Centrelink Reference Number was disclosed in the breach, with data provided by Top Health Doctors including card number, expiry date, customer name, date of birth, and address. The program's jurisdiction encompasses the Commonwealth of Australia, with Services Australia being the administering body. It adheres strictly to the guidelines set forth by the Office of the Australian Information Commissioner to safeguard privacy. The protocol for this data matching program, developed in consultation with the OAIC, ensures that the process respects privacy standards and is available for review. Additionally, the Agency's privacy policy is accessible to ensure transparency and compliance with privacy regulations. The application of this data matching program is limited to the data provided by Top Health Doctors and is subject to the terms and conditions stipulated in the protocol document and privacy policy.
Key Provisions
The key provisions of the legislation commence with the establishment of a data matching program by Services Australia in response to a data breach that affected approximately 5,500 customers of Top Health Doctors in September 2023 (Section 1). This program involves the comparison of specific personal data provided by Top Health Doctors with the records held by Services Australia to identify affected customers and implement necessary security measures. The personal data shared includes card number, expiry date and customer name as it appears on Medicare or Centrelink concession cards, the customer’s date of birth and address (Section 2).
Services Australia is required to adhere to the Office of the Australian Information Commissioner (OAIC) Guidelines on data matching, which are designed to safeguard the privacy of individuals (Section 3). This adherence includes the use of standards that ensure the privacy of individuals is protected during the data matching process. Additionally, the Agency must ensure that any personal data provided by Top Health Doctors is used strictly for the purposes of identifying affected customers and applying proactive security measures (Section 4).
The legislation outlines the obligations of Services Australia to ensure that the data matching program is conducted in a manner that respects the privacy and security of the affected individuals (Section 5). This includes maintaining strict confidentiality of the personal data provided by Top Health Doctors and ensuring that the data is only used for the specified purpose of identifying and protecting affected customers. Any breach of these obligations could result in legal consequences (Section 6).
In the event of a breach of the obligations outlined in the legislation, the consequences can be severe. Specifically, individuals or entities found to have breached the privacy or security provisions may face both civil and criminal penalties (Section 7). The maximum penalties for such breaches can include substantial fines and, in cases of criminal offences, imprisonment. The exact penalties are determined by the severity and nature of the breach, but the legislation is clear in its intent to impose significant deterrents against non-compliance (Section 8).