Privacy Groundwork Before You Adopt AI
Health information is sensitive information under the Privacy Act 1988, and engaging a supplier does not transfer your accountability for it. This checklist covers what an Australian practice should settle before any AI system touches patient data.
General guidance to structure your own assessment, not legal advice. Your progress is saved in this browser so you can work through it over several sessions.
Privacy & Governance Checklist
Work through before any supplier touches health information.
Your ticks are saved in this browser, so you can work through the list over several sessions.
01Scope: what data is involved
0/5You cannot assess what you have not defined.
02Location and transfer
0/5Cross-border disclosure carries specific obligations.
03Access and security
0/6Who can reach the data, and is it logged.
04Retention and deletion
0/5Balance minimisation against record-keeping obligations.
05Patients: notice and transparency
0/5What patients are told, and when.
06Incidents and clinical boundaries
0/6Decide these before you need them.
General guidance only: this is not legal advice and is not exhaustive. Australian privacy obligations, record retention requirements and surveillance devices laws vary by jurisdiction and change over time. Obtain professional advice for your specific circumstances and confirm the current position with the OAIC and relevant professional bodies.
The Principles Underneath the List
Every item here derives from three ideas that hold regardless of which product you are considering or how its marketing describes its security posture.
Accountability does not transfer
Under the Australian Privacy Principles, a practice that discloses personal information to a supplier remains responsible for how that information is handled. A contract allocates commercial risk between the parties; it does not move your obligations to your patients or to the regulator.
Health information attracts higher protection
Health information is a subset of sensitive information and carries stricter requirements around collection and use than ordinary personal information. Practices should assume the higher standard applies to anything a system captures during a patient interaction.
Written answers, not verbal assurance
Get the answers to the questions below in writing. A verbal assurance in a sales meeting is worth very little if a question arises later about where recordings were stored or whether call content was used to train a model.
The Six Areas to Work Through
Grouped so each section can be assigned to whoever in the practice is best placed to answer it.
Scope: what data is involved
Establish exactly what information the system will collect, see, store or transmit before assessing anything else.
Location and transfer
Where data is stored and processed, whether it leaves Australia, and what that means for your obligations.
Access and security
Who can reach the data, how access is controlled and logged, and how credentials are managed.
Retention and deletion
How long data is kept, whether you can require deletion, and how this squares with your record-keeping obligations.
Patients: notice and consent
What patients are told, when they are told it, and how your privacy policy and collection notices need to change.
Incidents and clinical boundaries
What happens if there is a breach, and what the system is explicitly prohibited from doing.
The Questions Practices Most Often Miss
Four issues that come up repeatedly and are considerably easier to address before adoption than afterwards.
Where the data actually goes
Many AI products process data through infrastructure located overseas, sometimes through several sub-processors. Cross-border disclosure carries specific obligations under the Australian Privacy Principles, and a vendor who cannot name the countries involved has not given you enough to assess it.
- Ask which countries data is stored and processed in, including sub-processors
- Ask whether any processing occurs outside Australia even transiently
- Ask for the list of sub-processors and how you are notified of changes
- Consider whether your patient communications need updating to reflect this
Whether your data trains their model
This is the single question most worth asking explicitly and getting in writing. Some providers use customer content to improve shared models by default, with opt-out available only on request or on higher tiers. For health information that is rarely acceptable, and it is not always disclosed prominently.
- Ask directly whether content is used for model training or improvement
- Ask whether the default is opt-in or opt-out, and get it confirmed in writing
- Ask whether sub-processors have independent rights to the data
- Ask what happens to data used in training if you later terminate
Retention versus your record-keeping obligations
Practices face two competing pressures: minimising retention of personal information, and meeting medical record retention requirements, which in Australia are commonly seven years from last contact for adults and, for children, until age twenty-five. Work out which category any AI-generated content falls into.
- Determine whether transcripts and recordings form part of the medical record
- Align vendor retention periods with your own retention policy
- Confirm you can require deletion and how deletion is evidenced
- Check what happens to backups after a deletion request
What patients are actually told
If a system records calls, generates transcripts, or captures health information in a new way, your collection notices and privacy policy likely need updating. Call recording notification obligations also arise under state and territory surveillance devices legislation, separately from privacy law.
- Update the practice privacy policy to reflect the new processing
- Include recording notification in the call greeting where calls are recorded
- Review your collection statement for new categories of information
- Consider signage and website updates for transparency
Next Steps
Healthcare AI Vendor Questions
Twenty-six commercial and technical questions to put to any vendor.
Open the questions →Practice AI Readiness Scorecard
Assess whether your practice has the foundations for a smooth adoption.
Score your practice →AI Healthcare Compliance Guide
The longer written guide to the Australian regulatory landscape.
Read the guide →Frequently Asked Questions
Is health information treated differently from other personal information?
Yes. Under the Privacy Act 1988, health information falls within the category of sensitive information, which attracts stricter handling requirements than ordinary personal information, particularly around the circumstances in which it may be collected and the purposes for which it may be used or disclosed. Practically, this means a practice should apply a higher standard of diligence to any supplier that will see health information than it might apply to, say, an accounting package. This is general information rather than legal advice, and practices should seek advice on their specific circumstances.
Do we need patient consent to use an AI phone system?
The answer depends on what the system does with the information, and it is genuinely fact-specific rather than a simple yes or no. Where a system performs an administrative function a practice already performs (taking a booking, for example) and the information is used for the purpose it was collected for, the position is typically more straightforward than where new categories of information are captured or used for a secondary purpose. Separately, if calls are recorded, notification obligations arise under state and territory surveillance devices legislation regardless of the privacy analysis. Most practices address the practical side with a clear notification in the call greeting and an updated privacy policy, and take advice on anything beyond that.
What should we do about data stored overseas?
First establish the facts: which countries, which entities, and whether the transfer is storage, processing or both. The Australian Privacy Principles impose specific obligations on cross-border disclosure, including taking reasonable steps to ensure the overseas recipient handles the information consistently with the APPs. Some practices adopt a policy of requiring Australian data residency for anything touching health information, which is simpler to administer even if it narrows the supplier field. Whichever position you take, document the reasoning so the decision is defensible later.
How long should we keep AI-generated transcripts and recordings?
Start by determining whether the material forms part of the medical record, because that determines which retention rules apply. Australian medical record retention requirements commonly run to seven years from the date of last entry for adults, and until age twenty-five for records created while a patient was a child, with variations between states and territories and between practice types. Material that does not form part of the medical record should generally be retained only as long as it is needed for the purpose it was collected. Set the vendor’s retention configuration to match your documented policy rather than accepting their default.
What happens if the vendor has a data breach?
Australia’s Notifiable Data Breaches scheme requires notification to the OAIC and to affected individuals where an eligible data breach occurs and is likely to result in serious harm. Because accountability sits with the practice as well as the supplier, you need to know before you sign how quickly the vendor will inform you, what information they will provide, and who is responsible for notifying patients. Agree this in the contract, and make sure your own practice breach response plan accounts for a breach that occurs at a supplier rather than internally.
Is this checklist legal advice?
No. It is a practical prompt list to help a practice structure its own assessment and ask better questions of suppliers, drawn from general Australian privacy principles. It is not legal advice, it is not exhaustive, and it cannot account for your specific circumstances, jurisdiction, practice type or the particular product you are considering. Obligations also change over time. For decisions with real consequence, and adopting a system that handles health information is one, obtain advice from a qualified professional and confirm the current position with the OAIC and any relevant professional body.
Sources and further reading
- Australian Privacy Principles (Office of the Australian Information Commissioner)
- The Privacy Act 1988 (Office of the Australian Information Commissioner)
- Notifiable Data Breaches scheme (Office of the Australian Information Commissioner)
- My Health Record and the Australian Digital Health Agency (Australian Digital Health Agency)
Want to Talk Through Your Requirements?
We are happy to answer every question on this list in writing before you commit to anything. That is the standard any practice should hold a supplier to.