Private Health Insurance (Data Provision) Rules 2017

Administered by Department of Health, Disability and Ageing

Legislation au F2017L00520 Rules Not in force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

 

Issued by the Authority of the Minister for Health

 

Private Health Insurance Act 2007

 

Private Health Insurance (Data Provision) Rules 2017

 

Section 333-20 of the Private Health Insurance Act 2007 (the Act) provides that the Minister may make Private Health Insurance (Data Provision) Rules 2017 providing for matters required or permitted by Part 4-5 of the Act, or necessary or convenient in order to carry out or give effect to Part 4-5 of the Act.

 

The Private Health Insurance (Data Provision) Rules 2017 (the Rules) revoke and remake the previous Private Health Insurance (Data Provision) Rules 2016 (No. 1).

 

The Rules specify the information, relating to the treatment of insured persons, that private health insurers must give to the Secretary of the Department of Health (the Department) under section 172-10 of the Act. 

 

The information required by the Rules is specified in the following documents, which were approved by the Assistant Secretary of the Health System Financing Branch of the Department on the dates indicated:

 

  •       GT-Dental Data from Insurers to the Department, approved 25 April 2015; and
  •       HCP2 Data from Insurers to the Department, approved 25 April 2015.

 

Also included is the following document which was approved by the Assistant Secretary of the Health Analytics Branch of the Department on the date indicated:

 

  •        HCP1 Data from Insurers to the Department, approved 30 March 2017.

 

These documents can be found on the Department’s website via the following link to the Hospital Casemix Protocol (HCP).

 

Consultation

 

The Department has consulted with the private health insurance and private hospital industry through existing working group arrangements.  The working groups are comprised of Department and industry stakeholder representatives.  Private health insurance and private hospital stakeholder representatives interested in developing the amendments participated in the process.  Industry is of the view that it is appropriate for amendments to be managed by this Working Group.  Previous amendments to the data specifications have been managed in this way.  The amended data specifications are distributed to industry via a Private Health Insurance Circular.

 

The Act does not specify any conditions that need to be met before the power to make the Rules may be exercised.

 

The Rules are a Legislative Instrument for the purposes of the Legislation Act 2003. 

 

The Rules commence on 1 July 2017.

   

Statement of Compatibility with Human Rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

 

Private Health Insurance (Data Provision) Rules 2017

This Legislative Instrument is compatible with the human rights and freedoms recognised                 or declared in the international instruments listed in section 3 of the                                                       Human Rights (Parliamentary Scrutiny) Act 2011.

 

Overview of the Legislative Instrument

The Private Health Insurance (Data Provision) Rules 2017 (the Rules) specify the information, relating to the treatment of insured persons, that private health insurers must give to the Secretary of the Department of Health (the Department) under section 172-10 of the Private Health Insurance Act 2007 (the Act).

The Rules revoke and replace the Private Health Insurance (Data Provision) Rules 2016 (No.1).

The Rules specify the information, relating to the treatment of insured persons, that private health insurers must give to the Secretary of the Department of Health (the Department) under section   172-10 of the Act. 

 

The information required by the Rules is specified in the following documents, which were approved by the Assistant Secretary of the Health System Financing Branch of the Department on the dates indicated:

 

  • GT-Dental Data from Insurers to the Department, approved 25 April 2015; and
  • HCP2 Data from Insurers to the Department, approved 25 April 2015.

 

Also included is the following document which was approved by the Assistant Secretary of the Health Analytics Branch of the Department on the date indicated:

 

  •    HCP1 Data from Insurers to the Department, approved 30 March 2017.

 

These documents can be found on the Department’s website via the following link to the Hospital Casemix Protocol (HCP).

 

The information which, under these Rules, private health insurers must give to the Secretary does not include personal information about patients (i.e. information from which individual patients could be identified).

 

Human rights implications

This Legislative Instrument will engage the human right of privacy but will not result in any limitation of that right.

Supply of the GT-Dental Data, HCP1 Data and HCP2 Data involves private health insurers disclosing to the Department de-identified information about the treatment of insured patients.  The Department would not be able to readily use this de-identified information to identify an individual patient.  Further, section 323-1 of the Act creates an offence for a person to disclose protected information to another person that the first person obtains in the course of performing a duty, function or power under the Act, unless the disclosure is an authorised disclosure.  The effect of this provision is to limit the way in which the Department deals with information about individuals.

The revisions to the documents are essentially mechanical in nature, and do not substantively alter any legislative requirements.

 

Conclusion

This Legislative Instrument is compatible with human rights as, although it engages the right of privacy in relation to personal information, it will not derogate from that right.

 

Ian Crettenden

Assistant Secretary

Health Analytics Branch

Department of Health

 

 

Overview

The Private Health Insurance (Data Provision) Rules 2017 were enacted to streamline and standardise the process of data provision from private health insurers to the Department of Health, as required under section 172-10 of the Private Health Insurance Act 2007. This Act was introduced to address the need for comprehensive data collection on private health insurance claims, facilitating better policy-making and healthcare service planning. The rules were made under the authority of the Minister for Health and are designed to ensure that the data collected is specific, relevant, and useful for health system analysis while maintaining the privacy of individuals. These rules revoke and replace the previous Private Health Insurance (Data Provision) Rules 2016 (No. 1), aiming to enhance the accuracy and timeliness of health data reporting. The Department of Health consulted with industry stakeholders through established working groups, ensuring that the amendments align with industry needs and operational realities. The data specifications outlined in the rules are intended to be de-identified, thereby protecting patient privacy while enabling the Department to perform its functions effectively.

Scope and Application

The Private Health Insurance (Data Provision) Rules 2017 are a legislative instrument that applies to private health insurers in Australia, requiring them to provide specific information relating to the treatment of insured persons to the Secretary of the Department of Health. These Rules, which revoke and replace the previous Private Health Insurance (Data Provision) Rules 2016, are necessary for carrying out and giving effect to Part 4-5 of the Private Health Insurance Act 2007. They outline the data specifications for three types of data: GT-Dental Data, HCP1 Data, and HCP2 Data, which have been approved by relevant branches of the Department of Health. Notably, the information required does not include personal details that could identify individual patients. While these Rules engage the human right of privacy, they do not result in any limitation of that right, as the information disclosed is de-identified and there are strict controls on the use of protected information. The Rules are compatible with human rights as they do not derogate from the right of privacy.

Key Provisions

The Private Health Insurance (Data Provision) Rules 2017, made under section 333-20 of the Private Health Insurance Act 2007 (the Act), specify the data that private health insurers must provide to the Secretary of the Department of Health (the Department) about the treatment of insured persons. These Rules revoke and replace the Private Health Insurance (Data Provision) Rules 2016 (No. 1), and they detail the types of information that insurers are required to submit, such as GT-Dental Data, HCP1 Data, and HCP2 Data. These documents, approved by the appropriate officials, outline the specific data elements and can be accessed via the Department's website through the Hospital Casemix Protocol (HCP) link. It is important to note that the information required under these Rules is de-identified, meaning it does not include personal information that could identify individual patients. This ensures that while the data is useful for policy and research purposes, patient privacy is maintained. Private health insurers subject to these Rules must ensure that the specified data is accurate, complete, and provided to the Department within the stipulated timeframes. This requirement is crucial for enabling the Department to monitor the performance and quality of health services provided under private health insurance arrangements. Insurers are also mandated to comply with section 323-1 of the Act, which prohibits the unauthorised disclosure of protected information obtained in the course of performing duties under the Act. This means that while insurers must supply the required data, they must do so in a manner that respects privacy and complies with the Act's provisions. Failure to comply with the data provision requirements under these Rules can result in various consequences. For instance, non-compliance may lead to enforcement actions by the Department, which could include fines or other penalties. Additionally, if an insurer knowingly or negligently discloses protected information in violation of section 323-1 of the Act, the insurer or its officers could face criminal penalties. The maximum penalties for such offences are specified in the Act and can include substantial fines and/or imprisonment, depending on the severity of the breach. These consequences underscore the importance of adhering to the Rules and ensuring that the required data is provided accurately and in a timely manner.

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Reporting & Disclosure Obligations
Compliance Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.