News

Information Commissioner report on My Health Record and notifiable data breaches

Data for the January-June 2022 reporting period has been released by the OAIC.

Data for the January-June 2022 reporting period has been released by the OAIC.

The Office of the Australian Information Commissioner (OAIC) published its final privacy assessment report for 2022. The privacy assessment reports contain information about the obligations, compliance, and privacy risks of healthcare provider organisations relating to having a written policy (referred to as a Security and Access policy) under Rule 42 of the My Health Records Rule 2016.

The OAIC was notified of 396 data breaches from January to June 2022. The Privacy Act 1988 requires entities to take reasonable steps to conduct a data breach assessment within 30 days of becoming aware that there are grounds to suspect they may have experienced an eligible data breach. Once the entity forms a reasonable belief that there has been an eligible data breach, they must notify the OAIC and affected individuals as soon as practicable.

The OAIC Report can be viewed here: https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-statistics/notifiable-data-breaches-report-january-june-2022

 

Related topics