AHPRA privacy breach leaves doctors distressed

Lynnette Hoffman

writer

Lynnette Hoffman

Managing Editor

Lynnette Hoffman

A mass email sent by AHPRA last week unwittingly disclosed the identities of 136 health professionals invited to a webinar on addiction and recovery – and the regulator repeated the same mistake in a follow up email it sent to apologise, with the private email addresses of all those were invited to attend appearing yet again for all recipients to see, a source told Healthed.

“We appreciate that involvement in our regulatory processes can be challenging for practitioners,” the initial email stated. It went on to emphasise that if participants were concerned about privacy, they could join using a different name or email address and type questions anonymously.

A spokesperson for AHPRA said the agency apologised for the error on the same day it was made.

“Ahpra took immediate steps to respond to the privacy breach as soon as it was detected, in accordance with established policies and protocols. This included alerting those affected, requesting deletion of the email, apologising to them directly and providing information on how to raise a formal complaint with Ahpra or the National Health Practitioner Ombudsman,” the spokesperson said, adding that it had also notified the NHPO.

Doctors caught up in the breach ‘scared’ and ‘vulnerable’

Dr Mukesh Haikerwal, deputy chair of the Australian GP Alliance, said some of the doctors impacted by the privacy breach had sought advice from him about what to do in response – with many afraid to speak up.

“It’s the big policing body that takes your license away, so people are reluctant to raise a fuss, because they don’t want even more opprobrium to come over them by saying anything to these people,” Dr Haikerwal said.

“They are Darth Vader, they can say and do what they want. But, in reality, it’s a breach of privacy,” he said of AHPRA.

“It’s like they don’t care. There is no care about the privacy, the welfare, the decent courtesy they would expect from us as providers,” Dr Haikerwal observed.

“These people can make a massive breach, and they are not answerable,” he said.

Who is regulating the regulator?

Dr Aniello Iannuzzi, chair of the Australian Doctors Federation (ADF) also noted this discrepancy.

“A privacy breach of this magnitude would likely end the career of any health professional and result in being dragged through the system for months or years. But who is regulating the regulator?” Dr Iannuzzi said.

“It is a labyrinth of plausible deniability that suits the senior health bureaucracy and ministers. Do they really think that a report to the ombudsman and an apology email is sufficient accountability?”

David Gardner, a lawyer and former AHPRA investigator who is now director of AHPD, also pointed to the glaring lack of accountability.

“It’s a massive mistake and I think it’s very damaging to those practitioners, but also more broadly,” he said, noting AHPRA’s recent efforts to encourage practitioners to participate in its health program. “This kind of thing really sets that back.”

“There just isn’t the kind of accountability you would expect,” Mr Gardner said.

“If this was a Department of Health that had done this, the next day, there’d be questions of the Minister. It would be, ‘what are you doing to fix this? What steps are you taking to ensure this doesn’t happen again? But when it’s AHPRA, there isn’t that same kind of accountability, because there isn’t any minister that’s responsible for it,” Mr Gardner said.

“It’s a group of ministers. And, there’s no kind of direct line to any particular person who sits outside of AHPRA, who is actually responsible or accountable,” he added.

What should happen next?

Dr Iannuzzi said the ADF is advocating for a return to state and territory boards with ministerial oversight and accountability.

“This is a reminder to AHPRA that human errors occur at all levels and is a reminder to handle such errors with more humanity,” he added.

Dr Haikerwal said every affected individual should receive a personal apology, and every staff member at AHPRA should be subject to the same type of mandatory education that AHPRA imposes on health professionals.

What recourse do doctors have when a privacy breach occurs?

Healthed reached out to the NHPO, and received a reply from the National Health Practitioner Privacy Commissioner. It explained that the Commissioner is empowered to “accept privacy complaints about how personal information is handled by organisations in the National Registration and Accreditation Scheme (National Scheme), including the Australian Health Practitioner Regulation Agency” as well as to receive notifications from AHPRA and other bodies about data breaches.

“When a privacy complaint is made, the Commissioner, Richelle McCausland, and her office seek to address the concerns raised as early and informally as possible, including through conciliation or preliminary inquiries. Possible complaint outcomes can include, for example, the organisation taking steps to address the matter, making changes to a process or policy or providing an apology or compensation,” the Commissioner’s office said.

“If a privacy complaint is investigated, and it is found the complainant’s privacy was interfered with, the Commissioner may make a determination. This can include, for example, declaring that specific steps must be taken to prevent further breaches. Other enforcement action, such as seeking a civil penalty, may also be considered where required.”

Generally, the Commissioner’s powers come from the Privacy Act and are akin to the Office of the Australian Information Commissioner’s powers.

The Commissioner’s office said that they have been notified by AHPRA of the privacy breach and are “currently managing privacy complaints related to this privacy breach.”

“Individuals who are concerned about an interference with their privacy can make a written complaint. We encourage individuals to first make a complaint directly to Ahpra for a response if possible,” the Commissioner said.

More information

The National Scheme’s legislation and regulation set out the Commissioner’s role and powers, modifying the Privacy Act to make it suitable for the scheme.

You can read more about the Scheme and the Commissioner’s role on its website.

Icon 2

NEXT LIVE Webcast

:
Days
:
Hours
:
Minutes
Seconds
Prof Gary Wittert

Prof Gary Wittert

The Peptide Craze – What You Need to Know

Prof Andrew Sindone AM

Prof Andrew Sindone AM

Managing Acute Heart Failure After Discharge: A Practical Guide for GPs

A/Prof Gino Pecoraro OAM

A/Prof Gino Pecoraro OAM

Oral Contraceptives on the PBS – A Practical Guide for GPs

Dr Terri Foran

Dr Terri Foran

The Impact of PFAS & Other Endocrine Disrupting Chemicals on Fertility

Join us for the next free webcast for GPs and healthcare professionals

High quality lectures delivered by leading independent experts

Once you confirm you’ve read this article you can complete a Patient Case Review to earn 0.5 hours CPD in the Reviewing Performance (RP) category.

Select ‘Confirm & learn‘ when you have read this article in its entirety and you will be taken to begin your Patient Case Review.

Upcoming Healthed Webcast

New Brain Health Guidelines – What GPs Can Do

Tuesday 4th August, 7pm - 9pm AEST

Speaker

Scientia Prof Kaarin Anstey

Psychologist; Director, UNSW Ageing Futures Institute; ARC Laureate Fellow; Senior Principal Research Scientist, NeuRA

Scientia Prof Kaarin Anstey translates the WHO's updated 2026 dementia risk-reduction guidelines changes into concrete actions for opportunistic risk assessment and targeted advice in everyday general practice.