Australian Privacy Watchdog Finds Health Firms Track Patient Searches Without Consent
Australian Privacy Commissioner finds health firms track patient searches without consent.
Why it matters: Health data privacy compliance is now under closer scrutiny in Australia, with legal risks rising for firms handling patient information.
- The Australian Privacy Commissioner found health firms tracked patient online searches without consent.
- The Privacy Act 1988 and Australian Privacy Principles require explicit consent for sensitive health data collection.
- A 2025 amendment enables legal action for serious invasions of privacy under the Privacy Act.
- The Office of the Australian Information Commissioner enforces privacy laws and investigates breaches.
The Australian Privacy Commissioner has determined that certain health firms tracked patients' online search activity without obtaining their consent, in breach of the Privacy Act 1988 and the Australian Privacy Principles (APPs).
Under Australian law, the Privacy Act regulates the handling of personal information, including sensitive health data. The APPs require organizations to notify individuals and obtain their consent before collecting and using such sensitive information.
The Office of the Australian Information Commissioner (OAIC) oversees enforcement of the Privacy Act and investigates potential breaches. This ruling reflects the OAIC's increased scrutiny of privacy compliance within the health sector.
In June 2025, a significant amendment to the Privacy Act introduced a statutory cause of action, allowing individuals to bring legal proceedings for serious invasions of privacy. This expands the legal remedies available and raises accountability for organizations that fail to protect patient data.
Though the specific firms involved and exact tracking techniques were not disclosed, the decision emphasizes the obligation of health entities to uphold patient privacy in digital interactions.
Legal and compliance professionals in the health sector should review data collection practices to ensure compliance with consent requirements and prepare for stronger enforcement and potential litigation under evolving privacy standards.
By the numbers:
- 1988 — Year Privacy Act was enacted governing sensitive health data
- June 10, 2025 — When statutory cause of action for serious privacy invasions became effective
What's next: Health firms can expect increased OAIC audits and enforcement actions following this ruling.