Skip to content
Skip to content

Privacy Groundwork Before You Adopt AI

Health information is sensitive information under the Privacy Act 1988, and engaging a supplier does not transfer your accountability for it. This checklist covers what an Australian practice should settle before any AI system touches patient data.

General guidance to structure your own assessment, not legal advice. Your progress is saved in this browser so you can work through it over several sessions.

Privacy & Governance Checklist

Work through before any supplier touches health information.

0 of 32 complete0%

Your ticks are saved in this browser, so you can work through the list over several sessions.

01Scope: what data is involved

0/5

You cannot assess what you have not defined.

02Location and transfer

0/5

Cross-border disclosure carries specific obligations.

03Access and security

0/6

Who can reach the data, and is it logged.

04Retention and deletion

0/5

Balance minimisation against record-keeping obligations.

05Patients: notice and transparency

0/5

What patients are told, and when.

06Incidents and clinical boundaries

0/6

Decide these before you need them.

General guidance only: this is not legal advice and is not exhaustive. Australian privacy obligations, record retention requirements and surveillance devices laws vary by jurisdiction and change over time. Obtain professional advice for your specific circumstances and confirm the current position with the OAIC and relevant professional bodies.

The Principles Underneath the List

Every item here derives from three ideas that hold regardless of which product you are considering or how its marketing describes its security posture.

Accountability does not transfer

Under the Australian Privacy Principles, a practice that discloses personal information to a supplier remains responsible for how that information is handled. A contract allocates commercial risk between the parties; it does not move your obligations to your patients or to the regulator.

Health information attracts higher protection

Health information is a subset of sensitive information and carries stricter requirements around collection and use than ordinary personal information. Practices should assume the higher standard applies to anything a system captures during a patient interaction.

Written answers, not verbal assurance

Get the answers to the questions below in writing. A verbal assurance in a sales meeting is worth very little if a question arises later about where recordings were stored or whether call content was used to train a model.

The Six Areas to Work Through

Grouped so each section can be assigned to whoever in the practice is best placed to answer it.

1

Scope: what data is involved

Establish exactly what information the system will collect, see, store or transmit before assessing anything else.

2

Location and transfer

Where data is stored and processed, whether it leaves Australia, and what that means for your obligations.

3

Access and security

Who can reach the data, how access is controlled and logged, and how credentials are managed.

4

Retention and deletion

How long data is kept, whether you can require deletion, and how this squares with your record-keeping obligations.

5

Patients: notice and consent

What patients are told, when they are told it, and how your privacy policy and collection notices need to change.

6

Incidents and clinical boundaries

What happens if there is a breach, and what the system is explicitly prohibited from doing.

The Questions Practices Most Often Miss

Four issues that come up repeatedly and are considerably easier to address before adoption than afterwards.

Where the data actually goes

Many AI products process data through infrastructure located overseas, sometimes through several sub-processors. Cross-border disclosure carries specific obligations under the Australian Privacy Principles, and a vendor who cannot name the countries involved has not given you enough to assess it.

  • Ask which countries data is stored and processed in, including sub-processors
  • Ask whether any processing occurs outside Australia even transiently
  • Ask for the list of sub-processors and how you are notified of changes
  • Consider whether your patient communications need updating to reflect this

Whether your data trains their model

This is the single question most worth asking explicitly and getting in writing. Some providers use customer content to improve shared models by default, with opt-out available only on request or on higher tiers. For health information that is rarely acceptable, and it is not always disclosed prominently.

  • Ask directly whether content is used for model training or improvement
  • Ask whether the default is opt-in or opt-out, and get it confirmed in writing
  • Ask whether sub-processors have independent rights to the data
  • Ask what happens to data used in training if you later terminate

Retention versus your record-keeping obligations

Practices face two competing pressures: minimising retention of personal information, and meeting medical record retention requirements, which in Australia are commonly seven years from last contact for adults and, for children, until age twenty-five. Work out which category any AI-generated content falls into.

  • Determine whether transcripts and recordings form part of the medical record
  • Align vendor retention periods with your own retention policy
  • Confirm you can require deletion and how deletion is evidenced
  • Check what happens to backups after a deletion request

What patients are actually told

If a system records calls, generates transcripts, or captures health information in a new way, your collection notices and privacy policy likely need updating. Call recording notification obligations also arise under state and territory surveillance devices legislation, separately from privacy law.

  • Update the practice privacy policy to reflect the new processing
  • Include recording notification in the call greeting where calls are recorded
  • Review your collection statement for new categories of information
  • Consider signage and website updates for transparency

Next Steps

Healthcare AI Vendor Questions

Twenty-six commercial and technical questions to put to any vendor.

Open the questions

Practice AI Readiness Scorecard

Assess whether your practice has the foundations for a smooth adoption.

Score your practice

AI Healthcare Compliance Guide

The longer written guide to the Australian regulatory landscape.

Read the guide

Frequently Asked Questions

Sources and further reading

Want to Talk Through Your Requirements?

We are happy to answer every question on this list in writing before you commit to anything. That is the standard any practice should hold a supplier to.