Australian Privacy Foundation wants ‘privacy tort’ to protect health data
The Australian Privacy Foundation (APF) has requested that the federal government urgently reform existing laws and reconsider the administration of My Health Record, saying the recent Equifax data breach has highlighted the urgency of protecting citizen information.
In its submission to the Independent Review of Accessibility by Health Providers of Medicare Card Numbers, APF said that health records are just as valuable to hackers, and that the current system for storing and using health records in Australia is “hopelessly deficient”.
“With lousy data security, and a world where data breaches are a daily event, the Australian government’s reluctance to fix this problem is looking negligent,” APF chair David Vaile said.
Vaile called for the establishment of a “privacy tort”, such as a national law providing a right to compensation for anyone who has experienced a serious breach of privacy.
According to the APF, the tort has been recommended by Commonwealth, state, and territory law reform commissions and parliamentary committees over the last decade.
“A privacy tort is a common sense solution to a problem that will not go away,” the APF claimed. “A privacy tort exists in most major economies. Australians are now almost alone in remaining exposed to massive privacy breaches without any enforceable legal remedy. Australia is increasingly isolated by its failure to offer this basic self-help protection for citizens’ rights in the digital age.”
Similarly, the APF also called for strengthening the Office of the Australian Information Commissioner (OAIC), labelling the agency led by Timothy Pilgrim as being “underfed”.
“There needs to be greater transparency in disclosure by government of data breaches, particularly those relating to health records,” Vaile added. “We should not rely on journalists to discover that our privacy has been breached.”
The Australian government opened its review into the Health Professional Online Services (HPOS) system last month.
When announcing the HPOS review in July, the government admitted it was commissioned in response to reports originally made by The Guardianthat Medicare card details were being sold on the dark web.
The HPOS review is expected to consider the balance between allowing appropriate access to Medicare card numbers for health professionals to confirm patients’ Medicare eligibility and the security of patients’ Medicare card numbers.

