Australia’s Health Data Protection Framework

Australia doesn’t have a direct equivalent of the United States’ HIPAA (Health Insurance Portability and Accountability Act), but it does have a robust framework of laws and standards that govern the handling of health information, including its destruction. For Australian healthcare organisations and their IT service providers, understanding these requirements is essential when disposing of equipment that has held patient or health data.

The Australian framework is arguably more integrated than HIPAA, with health data protection woven into broader privacy legislation rather than existing as a standalone health-specific law. This means the obligations are sometimes less prescriptive but no less binding.

The Privacy Act and Health Information

The Privacy Act 1988 treats health information as a special category of “sensitive information” that receives enhanced protection. Under the Australian Privacy Principles (APPs), health information includes information about a person’s health or disability, health services provided to them, their wishes about future health services, and genetic information.

APP 11 requires organisations to take “reasonable steps” to protect personal information, and the standard for what constitutes “reasonable” is higher for sensitive information like health data. When it comes to disposal, this means the data destruction methods used for health data need to be more rigorous than those for general business data.

The Notifiable Data Breaches scheme adds further weight. A breach involving health information is almost automatically considered likely to cause “serious harm,” making notification to the OAIC and affected individuals virtually mandatory. This makes the stakes of improper disposal particularly high for healthcare data.

My Health Records Act 2012

The My Health Records Act governs Australia’s national digital health record system. While it primarily covers the electronic health record system itself, it has implications for IT disposal in healthcare settings.

Organisations that participate in the My Health Records system must maintain the security of any systems that access or interact with the record system. When decommissioning equipment that has been used to access My Health Records, the data destruction process must ensure that any cached, stored, or locally saved health record data is completely removed.

The Act includes specific penalties for unauthorised access to or disclosure of health information in the system. Improper disposal that leads to unauthorised access could trigger these penalties in addition to Privacy Act obligations.

Key Australian health data legislation:

  • Privacy Act 1988 – Health information as sensitive information (APPs)
  • My Health Records Act 2012 – Digital health records system
  • State/territory health records legislation – Additional state-level requirements
  • Healthcare Identifiers Act 2010 – Protection of healthcare identifiers
  • Aged Care Act 1997 – Resident information protection

State and Territory Health Records Laws

Several Australian states and territories have their own health records legislation that adds requirements beyond the federal Privacy Act. These state laws can impose stricter obligations on healthcare providers operating in those jurisdictions.

Victoria’s Health Records Act 2001 is one of the most comprehensive. It establishes Health Privacy Principles (HPPs) that apply to health service providers in Victoria regardless of their size. HPP 4 specifically addresses data security, and HPP 2 covers the use and disclosure of health information. When Victorian health service providers dispose of IT equipment, both the federal Privacy Act and the Victorian Health Records Act apply.

New South Wales’ Health Records and Information Privacy Act 2002 similarly creates additional obligations for NSW health service providers. Other states rely primarily on the federal Privacy Act, supplemented by sector-specific guidelines.

For organisations operating across multiple states, the safest approach is to apply the most stringent standard across all operations rather than maintaining state-specific disposal procedures.

What Equipment Holds Health Data

Healthcare environments contain a wider range of data-bearing devices than most people expect. Beyond the obvious computers and servers, health data can reside on:

Clinical workstations and point-of-care terminals. Medical imaging equipment (MRI, CT, X-ray, ultrasound machines store patient images locally). Patient monitoring systems (ICU monitors, telemetry systems). Electronic health record (EHR) system terminals. Pharmacy dispensing systems. Pathology laboratory information systems. Dictation and transcription equipment. Mobile devices used by clinicians (tablets, smartphones). Printers and multifunction devices (which store printed documents including prescriptions and reports). Backup storage media (tapes, external drives). Portable diagnostic equipment. Video conferencing systems used for telehealth consultations.

Medical devices are particularly challenging because they may run specialised operating systems, have limited or no user-accessible storage management, and may require manufacturer involvement for data destruction.

Destruction Standards for Health Data

Given the sensitivity of health information, the destruction standard for healthcare IT equipment should be at the higher end of available methods.

For storage media that can be software-wiped, use tools that comply with NIST 800-88 guidelines, specifically the “Purge” level rather than just “Clear.” Purge-level sanitisation applies physical or logical techniques that render data recovery infeasible using state-of-the-art laboratory techniques. For health data, the Clear level (which protects against simple, non-invasive recovery) is generally insufficient.

For SSDs and flash-based storage, cryptographic erasure (destroying the encryption keys on a self-encrypting drive) or physical destruction is recommended. The complexities of SSD architecture mean that software overwriting may not reach all data due to wear levelling and over-provisioned areas.

For devices where software-based destruction isn’t possible (damaged drives, medical devices with inaccessible storage), physical destruction through shredding, disintegration, or incineration is the appropriate method.

For a complete comparison of methods, see our guide to hard drive destruction methods.

Medical Device Disposal Challenges

Medical devices present unique disposal challenges that don’t exist with standard IT equipment.

Many medical devices are classified as therapeutic goods under the Therapeutic Goods Act 1989 and may have specific disposal requirements set by the manufacturer or the Therapeutic Goods Administration (TGA). Some devices contain radioactive materials or biohazardous components that need specialist handling beyond data destruction.

The data on medical devices is often stored in proprietary formats on embedded storage that can’t be easily removed or wiped using standard tools. Manufacturers may need to be involved in the data destruction process, or the entire device may need to be physically destroyed to ensure data is unrecoverable.

Leased medical equipment creates additional complexity. The lessor typically requires the equipment back, but the lessee has obligations to ensure patient data is removed before return. The lease agreement should specify data destruction responsibilities and methods.

Documentation for Healthcare Disposal

Documentation requirements for health data destruction are more demanding than for general business data, reflecting the higher sensitivity classification and the regulatory environment.

Each disposal event should be documented with the asset identity and type (including medical device classification if applicable), the nature of health data stored on the device, the destruction method applied, verification that destruction was successful, the date and time of destruction, the identity of the person or organisation performing the destruction, a certificate of destruction with the asset’s serial number, and sign-off from an authorised person (typically the privacy officer or IT security lead).

Healthcare organisations should retain disposal records for a minimum of 7 years, aligning with general medical record retention requirements. Some organisations retain them longer based on specific state requirements or internal policy.

Healthcare IT disposal checklist:

  • Identify all devices containing health data (including medical devices)
  • Apply Purge-level or higher destruction to all storage media
  • Handle medical devices according to manufacturer and TGA guidance
  • Document destruction with asset-level detail
  • Obtain certificates of destruction from any third-party providers
  • Retain records for minimum 7 years
  • Ensure disposal providers have appropriate certifications and insurance
  • Report any suspected data exposure through the NDB scheme

Choosing a Disposal Provider for Healthcare

When selecting a disposal provider for healthcare IT equipment, look for experience specifically in the healthcare sector. Healthcare disposal involves regulatory requirements, device types, and data sensitivity levels that general IT recyclers may not be equipped to handle.

Key provider qualifications include ISO 27001 certification, ADISA certification for data destruction verification, experience with medical device disposal, understanding of Australian health privacy legislation, comprehensive insurance coverage including professional indemnity, and willingness to provide detailed, asset-level certificates of destruction.

Some healthcare organisations require disposal providers to sign specific confidentiality agreements and to undergo security assessments before engagement. This is good practice given the sensitivity of health data.

For broader guidance on data destruction compliance, see our complete guide to data destruction for Australian businesses.

EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.