The Australian healthcare sector has just received a $5.8 million wake-up call about its handling of patient data.
In the first civil penalty ever imposed under the Privacy Act 1988 (Cth), the Federal Court ruled that Australian Clinical Labs (ACL) had failed to take reasonable steps to protect personal information or to promptly investigate a cyberattack that exposed the data of more than 223,000 patients.
The decision sends a clear message: data protection is no longer a technical issue – it’s a governance obligation.
By contrast, I-MED Radiology was recently commended for its transparent handling of data used in artificial-intelligence training. Its proactive de-identification of patient information and early disclosure to regulators show what good governance looks like when privacy is treated as a board-level issue rather than a back-end IT problem.
Both cases underline one truth: careful stewardship of patient data is now a leadership responsibility for every healthcare organisation.
To explore how healthcare leaders can strengthen governance in the face of rising cyber risk, Veri Health spoke with Ashwin Pal, Partner in Risk Advisory (Privacy & Security) at RSM Australia. Pal is a recognised leader in cyber security and privacy governance with more than two decades’ experience advising organisations across health, government and critical infrastructure.
The realities of protecting patient data
Healthcare leaders face a unique set of pressures when it comes to protecting data, according to Pal.
“Budgets will always be too tight and it’s hard to prioritise a stronger IT system over more ER beds. The consequences of a malware attack are potentially fatal if patient care is compromised. And then there’s the nature of healthcare data itself. It’s deeply personal and sensitive and it can’t be erased. You can cancel your driver’s licence or passport but you can’t cancel your health record.”
When working with healthcare organisations, Pal’s approach is calm and pragmatic: acknowledge the realities, prioritise the must-haves, and build a roadmap that fits within an organisation’s risk appetite.
“The risks are real. But my role is to help organisations see that there are practical steps they can take to protect their patients and themselves.”
Education before technology
In Pal’s experience, it’s common for organisations to assume they need an expensive IT overhaul. “They think the answer to every cyber problem is more technology,” he says. “But most breaches begin with people – someone clicking a phishing link or using a weak password. That’s why education and awareness come first.”
The post-pandemic shift to remote work has implications for data security too. As Pal explains, “Every home Wi-Fi network connected to a corporate system becomes an entry point. Home networks are now part of the organisation’s ecosystem and they need to be robust.”
Data stewardship, not ownership
ƒ“Healthcare organisations don’t own patient data – they’re custodians of it,” Pal says. “From the age of 18, patients legally own their records. Anyone holding that data has obligations under the Privacy Act and the APPs.”
That mindset reframes responsibility: it’s not about data storage, but stewardship. Custodianship demands leadership, policy, education and controls that ensure data is collected, used, retained and destroyed lawfully and ethically.
The Australian Privacy Principles and healthcare
For healthcare providers, the Australian Privacy Principles (APPs) are the foundation of lawful data handling. They dictate how personal and sensitive information (including health data) must be collected, stored, used, disclosed and secured.
“The Privacy Act and the Australian Privacy Principles aren’t new but too few organisations actually understand them,” says Pal. “That lack of awareness is where most problems start. Once you know what your obligations are, it’s not complicated. The APPs are clear, practical, and they give you a framework to measure yourself against.”
Among the 13 APPs, several are particularly critical for healthcare leaders:
- APP 6: governs how and when personal information can be used or disclosed
- APP 11: requires entities to take reasonable steps to protect information from misuse, interference and loss
- APP 12 & 13: provide for patient access and correction rights.
While the Privacy Act applies to most organisations earning over $3 million annually, health service providers are covered regardless of turnover, reflecting the sensitivity of health data. Yet, as Pal notes, few in the sector realise this.
“The Privacy Act actually sets the threshold for health organisations at zero,” he says. “That means anyone handling patient data has full legal obligations, from a large hospital to a small solo provider.”
He encourages leaders to audit their policies and practices against the APPs:
“Once you know your obligations and where your gaps are, you can start fixing them.”
The Board and leadership imperative
Understanding the APPs clarifies that cyber security is not primarily an IT issue.
“This is risk management,” he explains. “Data protection involves regulatory risk, financial risk and reputational risk. Mitigating those risks is a Board-level responsibility. Boards need to understand their risk appetite, quantify the risk, and work out what needs to be done to bring it within tolerance.”
The ACL case demonstrates the cost of poor governance; the I-MED case shows how transparency and compliance protect both patients and reputation.
Budget pressures mean priorities must be clear: start with governance, education and process before investing in technology.
The data governance checklist
To help healthcare boards and executives strengthen oversight, Pal recommends asking these five essential questions:
Who has access to patient data, and how is that access controlled?
- Enforce role-based access and grant people only the minimum level of access necessary to perform their role (the principle of least privilege).
- Require multi-factor authentication and maintain audit trails.
How is patient data stored and transmitted?
- Encrypt data both at rest and in transit.
- Use secure channels such as HTTPS/TLS or VPNs.
Are we compliant with privacy laws (APPs, state legislation)?
- Review policies for data handling, consent and breach notification.
- Verify that vendors and partners also comply.
What safeguards and monitoring systems detect unauthorised access?
- Implement and regularly review intrusion detection, logging and alert systems.
How are backups, retention and disposal managed?
- Maintain regular encrypted backups.
- Securely delete old or unnecessary data in line with policy.
A final word
“The sky isn’t falling,” Pal concludes. “Yes, the risks are serious, but they can be mitigated – just like other forms of risk.”
Protecting patient data is not just about compliance or avoiding fines – it’s about leadership, trust and patient safety.
With informed governance, continuous education and robust controls, healthcare organisations can protect both their reputation and the people behind the data.
Sources:



Building pressure: what’s straining Australia’s hospitals and how to build resilience