A structured reference to federal legislation, state and territory regimes, sector-specific rules, and current reform timelines governing health information in Australia.
The Privacy Act 1988 (Cth) is the principal federal instrument. Health information is classified as sensitive information and receives the highest level of protection under the Australian Privacy Principles.
A parallel legislative stack governs the My Health Record system, healthcare identifiers, and digital health infrastructure — largely separate from the Privacy Act but interoperating with it.
The Privacy Act does not apply to state and territory public sector health service providers — public hospitals, state health departments. This creates a patchwork. NSW, Victoria, and ACT have the most comprehensive parallel health privacy regimes.
Healthcare is consistently the most-breached sector in Australia. In January–June 2025, health entities accounted for 18% of all Notifiable Data Breach notifications — the highest of any sector.
Research and secondary use of health data is permitted under specific conditions — ethics approval, de-identification, and data governance arrangements. AI and machine learning add an emerging regulatory layer.
Australian health data law is in its most active reform period in decades. The following timeline shows enacted and pending changes relevant to healthcare and medtech.
Where health data physically lives — and who has legal access to it — is one of the most operationally consequential compliance questions for cloud-hosted medtech, SaMD, and hospital systems. Three distinct concepts apply simultaneously.
The most common compliance failures in Australian healthcare data are: using health data for a secondary purpose without consent or a permitted health situation; delayed or absent NDB notifications (now attracting civil penalties — see Australian Clinical Labs); inadequate data security under APP 11, particularly in cloud-hosted systems; and cloud procurement that satisfies data residency but not data sovereignty — choosing a US hyperscaler's Sydney region for MHR-adjacent workloads is the most common example. For medtech and SaMD companies, the convergence of Privacy Act obligations, TGA cybersecurity requirements, PSPF flow-down in government contracts, and OAIC scrutiny of AI systems means that privacy, sovereignty, and regulatory compliance cannot be treated as separate workstreams. A Privacy Impact Assessment — including a cloud provider sovereignty assessment — should be initiated at the same time as TGA classification is determined, not after product launch.