A patient list left in a car park: what the 30 days actually mean
A laptop goes missing from a car. A recall email goes to the whole list with every address in the To field. A former employee still has their login three months after leaving.
Each of those starts a clock, and the clock is shorter than most practices realise.
The scheme
Part IIIC of the Privacy Act 1988 creates the Notifiable Data Breaches scheme. It applies to health service providers regardless of turnover — the small business exemption that covers many companies under $3 million does not apply to you, because you handle health information.
That surprises a lot of practice owners. It should be the first thing you know about this scheme.
What has to happen, and when
If you suspect an eligible data breach, section 26WH(2) requires you to carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware of the grounds for suspicion.
Thirty days is the outer limit, not the target. It is also the part practices get wrong most often — not because they refuse to assess, but because nothing formally started. The laptop went missing, somebody mentioned it, everyone got busy, and no clock was ever set running.
If the assessment finds an eligible data breach, sections 26WK and 26WL require you to notify the Commissioner and the affected individuals as soon as practicable.
What "eligible" means
Three elements, all of which must be present:
- There is unauthorised access to, unauthorised disclosure of, or loss of, personal information the entity holds.
- That is likely to result in serious harm to one or more individuals.
- The entity has not been able to prevent the likely risk of serious harm through remedial action.
That third element matters and is frequently overlooked. A breach that you remediate before serious harm becomes likely is not notifiable. A laptop lost and then remotely wiped before anyone could access it may well fall outside the scheme — but you have to be able to show that, which means you have to have assessed it and recorded the reasoning.
"Serious harm" is not defined as a list. For a dental practice it is worth being honest about what your records actually contain: medical histories, conditions, and in some cases the fact of treatment that a patient would not want disclosed. Health information is treated as sensitive for a reason.
What a practice should have ready before it happens
None of this is expensive. All of it is much harder to assemble during an incident.
A register. Somewhere a suspected breach gets written down with a date. The date is the point — it is what starts the clock and what proves you started it. A conversation in the tea room is not a register.
One person who owns it. Not a committee. Somebody whose job it is to run the assessment and who knows that it is.
A known answer to "who has access to what". During an incident you will need to say who could have seen the affected records. If answering that means asking around, the assessment will take days it does not have.
An access log you can actually read. "Who opened this patient's file, and when" should be answerable from the system rather than by reconstruction. If your software cannot answer it, you will be writing "unable to determine" in a notification to the regulator.
A decision recorded, even when you decide not to notify. "We assessed it and concluded notification was not required because we remediated before serious harm was likely" is a legitimate outcome. It is only legitimate if it is written down at the time.
The most common failure
It is not a cover-up. It is that nobody ever started the assessment.
Somebody noticed something odd, mentioned it, and the practice moved on to a full Tuesday. There is no register entry, no date, no assessment and no decision — so if it later turns out to have mattered, the practice cannot show it did anything at all.
Thirty days is enough time. But only if day one is a day somebody wrote down.
This is general information about the Notifiable Data Breaches scheme, not legal advice. If you think you have had a breach, the OAIC publishes guidance, and it is worth a call to your indemnity insurer early rather than late.