Skip to content
Skip to content

Privacy Groundwork Before You Adopt AI

Health information is sensitive information under the Privacy Act 1988, and engaging a supplier does not transfer your accountability for it. This checklist covers what an Australian practice should settle before any AI system touches patient data.

General guidance to structure your own assessment, not legal advice. Your progress is saved in this browser so you can work through it over several sessions.

Privacy & Governance Checklist

Work through before any supplier touches health information.

0 of 32 complete0%

Your ticks are saved in this browser, so you can work through the list over several sessions.

01Scope: what data is involved

0/5

You cannot assess what you have not defined.

02Location and transfer

0/5

Cross-border disclosure carries specific obligations.

03Access and security

0/6

Who can reach the data, and is it logged.

04Retention and deletion

0/5

Balance minimisation against record-keeping obligations.

05Patients: notice and transparency

0/5

What patients are told, and when.

06Incidents and clinical boundaries

0/6

Decide these before you need them.

General guidance only: this is not legal advice and is not exhaustive. Australian privacy obligations, record retention requirements and surveillance devices laws vary by jurisdiction and change over time. Obtain professional advice for your specific circumstances and confirm the current position with the OAIC and relevant professional bodies.

The Principles Underneath the List

Every item here derives from three ideas that hold regardless of which product you are considering or how its marketing describes its security posture.

Accountability does not transfer

Under the Australian Privacy Principles, a practice that discloses personal information to a supplier remains responsible for how that information is handled. A contract allocates commercial risk between the parties; it does not move your obligations to your patients or to the regulator.

Health information attracts higher protection

Health information is a subset of sensitive information and carries stricter requirements around collection and use than ordinary personal information. Practices should assume the higher standard applies to anything a system captures during a patient interaction.

Written answers, not verbal assurance

Get the answers to the questions below in writing. A verbal assurance in a sales meeting is worth very little if a question arises later about where recordings were stored or whether call content was used to train a model.

The Six Areas to Work Through

Grouped so each section can be assigned to whoever in the practice is best placed to answer it.

1

Scope: what data is involved

Establish exactly what information the system will collect, see, store or transmit before assessing anything else.

2

Location and transfer

Where data is stored and processed, whether it leaves Australia, and what that means for your obligations.

3

Access and security

Who can reach the data, how access is controlled and logged, and how credentials are managed.

4

Retention and deletion

How long data is kept, whether you can require deletion, and how this squares with your record-keeping obligations.

5

Patients: notice and consent

What patients are told, when they are told it, and how your privacy policy and collection notices need to change.

6

Incidents and clinical boundaries

What happens if there is a breach, and what the system is explicitly prohibited from doing.

The Questions Practices Most Often Miss

Four issues that come up repeatedly and are considerably easier to address before adoption than afterwards.

Where the data actually goes

Many AI products process data through infrastructure located overseas, sometimes through several sub-processors. Cross-border disclosure carries specific obligations under the Australian Privacy Principles, and a vendor who cannot name the countries involved has not given you enough to assess it.

  • Ask which countries data is stored and processed in, including sub-processors
  • Ask whether any processing occurs outside Australia even transiently
  • Ask for the list of sub-processors and how you are notified of changes
  • Consider whether your patient communications need updating to reflect this

Whether your data trains their model

This is the single question most worth asking explicitly and getting in writing. Some providers use customer content to improve shared models by default, with opt-out available only on request or on higher tiers. For health information that is rarely acceptable, and it is not always disclosed prominently.

  • Ask directly whether content is used for model training or improvement
  • Ask whether the default is opt-in or opt-out, and get it confirmed in writing
  • Ask whether sub-processors have independent rights to the data
  • Ask what happens to data used in training if you later terminate

Retention versus your record-keeping obligations

Practices face two competing pressures: minimising retention of personal information, and meeting medical record retention requirements, which in Australia are commonly seven years from last contact for adults and, for children, until age twenty-five. Work out which category any AI-generated content falls into.

  • Determine whether transcripts and recordings form part of the medical record
  • Align vendor retention periods with your own retention policy
  • Confirm you can require deletion and how deletion is evidenced
  • Check what happens to backups after a deletion request

What patients are actually told

If a system records calls, generates transcripts, or captures health information in a new way, your collection notices and privacy policy likely need updating. Call recording notification obligations also arise under state and territory surveillance devices legislation, separately from privacy law.

  • Update the practice privacy policy to reflect the new processing
  • Include recording notification in the call greeting where calls are recorded
  • Review your collection statement for new categories of information
  • Consider signage and website updates for transparency

Next Steps

Healthcare AI Vendor Questions

Twenty-six commercial and technical questions to put to any vendor.

Open the questions

Practice AI Readiness Scorecard

Assess whether your practice has the foundations for a smooth adoption.

Score your practice

AI Healthcare Compliance Guide

The longer written guide to the Australian regulatory landscape.

Read the guide

Frequently Asked Questions

Is health information treated differently from other personal information?

Yes. Under the Privacy Act 1988, health information falls within the category of sensitive information, which attracts stricter handling requirements than ordinary personal information, particularly around the circumstances in which it may be collected and the purposes for which it may be used or disclosed. Practically, this means a practice should apply a higher standard of diligence to any supplier that will see health information than it might apply to, say, an accounting package. This is general information rather than legal advice, and practices should seek advice on their specific circumstances.

Do we need patient consent to use an AI phone system?

The answer depends on what the system does with the information, and it is genuinely fact-specific rather than a simple yes or no. Where a system performs an administrative function a practice already performs (taking a booking, for example) and the information is used for the purpose it was collected for, the position is typically more straightforward than where new categories of information are captured or used for a secondary purpose. Separately, if calls are recorded, notification obligations arise under state and territory surveillance devices legislation regardless of the privacy analysis. Most practices address the practical side with a clear notification in the call greeting and an updated privacy policy, and take advice on anything beyond that.

What should we do about data stored overseas?

First establish the facts: which countries, which entities, and whether the transfer is storage, processing or both. The Australian Privacy Principles impose specific obligations on cross-border disclosure, including taking reasonable steps to ensure the overseas recipient handles the information consistently with the APPs. Some practices adopt a policy of requiring Australian data residency for anything touching health information, which is simpler to administer even if it narrows the supplier field. Whichever position you take, document the reasoning so the decision is defensible later.

How long should we keep AI-generated transcripts and recordings?

Start by determining whether the material forms part of the medical record, because that determines which retention rules apply. Australian medical record retention requirements commonly run to seven years from the date of last entry for adults, and until age twenty-five for records created while a patient was a child, with variations between states and territories and between practice types. Material that does not form part of the medical record should generally be retained only as long as it is needed for the purpose it was collected. Set the vendor’s retention configuration to match your documented policy rather than accepting their default.

What happens if the vendor has a data breach?

Australia’s Notifiable Data Breaches scheme requires notification to the OAIC and to affected individuals where an eligible data breach occurs and is likely to result in serious harm. Because accountability sits with the practice as well as the supplier, you need to know before you sign how quickly the vendor will inform you, what information they will provide, and who is responsible for notifying patients. Agree this in the contract, and make sure your own practice breach response plan accounts for a breach that occurs at a supplier rather than internally.

Is this checklist legal advice?

No. It is a practical prompt list to help a practice structure its own assessment and ask better questions of suppliers, drawn from general Australian privacy principles. It is not legal advice, it is not exhaustive, and it cannot account for your specific circumstances, jurisdiction, practice type or the particular product you are considering. Obligations also change over time. For decisions with real consequence, and adopting a system that handles health information is one, obtain advice from a qualified professional and confirm the current position with the OAIC and any relevant professional body.

Sources and further reading

Want to Talk Through Your Requirements?

We are happy to answer every question on this list in writing before you commit to anything. That is the standard any practice should hold a supplier to.