Australia

Last reviewed: 2026-09-26

Australian health-service providers need to assess the Privacy Act and relevant state or territory rules. Small size does not by itself exempt a private health-service provider. The review covers collection, use, disclosure and the handling of health information.

Where PHI Mask fits

Your file is masked in your browser and never sent to us. The Compliance page explains the masking workflow, browser storage and the separate handling of website and support information.

The service you send a masked copy to has its own purposes, settings, contracts and storage locations. Assess that service as part of your workflow.

Identify the rules for the provider

The federal Privacy Act applies to private-sector health-service providers even when they are small businesses. Public-sector services and some health-information handling also involve state or territory rules.

Record the organisation, location and type of health service before deciding which requirements apply.

Establish the basis for collection and use

Health information is sensitive information. Collection generally requires consent and a reasonably necessary purpose unless an exception applies.

Assess the proposed use and disclosure separately. Explain the workflow through the applicable collection notice and privacy policy.

Review overseas recipients

Determine whether sending information to the selected service is an overseas disclosure. APP 8 can require reasonable steps concerning the recipient's handling and can leave the Australian entity accountable for it.

Check the recipient, locations, contract and any exception being relied on. Masking in a local browser is not an Australian-hosting commitment for the entire workflow.

Plan security and retention

Assess reasonable security measures for the devices, browser records and services in use. APP 11 also addresses destruction or de-identification when information is no longer needed, subject to applicable exceptions.

Reversible masking alone does not establish de-identification. Consider recovery information and the likelihood of identification from the remaining context.

Compliance and security