Compliance & Governance
Notifiable Data Breach
Detect, assess, and notify — before the deadline expires.
Data breach detection, risk assessment, OAIC notification management, affected individual communications, and remediation tracking.
Residential care · Home care
In practice
The work behind notifiable data breach.
Aged care providers hold highly sensitive personal and health information. Under the Notifiable Data Breaches (NDB) scheme, providers must assess suspected breaches, determine whether they are likely to result in serious harm, and notify the Office of the Australian Information Commissioner (OAIC) and affected individuals. Statura Care’s Data Breach module structures this process from detection through to remediation.
A data breach involving resident health records, financial information, or staff screening data can have severe consequences — regulatory action, reputational damage, and harm to individuals. Without a structured response process, providers risk missing the mandatory notification timeline or failing to communicate effectively with affected individuals.
Breach Detection & Logging
Log suspected data breaches with classification by type (unauthorised access, disclosure, loss), data categories affected (health, financial, personal), and number of individuals impacted.
Risk Assessment Workflow
Structured assessment of whether a breach is likely to result in serious harm — the threshold that triggers mandatory notification. Considers sensitivity of data, protective measures in place, and nature of the breach.
OAIC Notification Management
Auto-generate OAIC notification forms with breach details pre-populated. Track submission status, OAIC correspondence, and response deadlines.
Affected Individual Communications
Manage notifications to affected individuals with templates, delivery tracking, and response management. Track who has been notified and any follow-up actions.
Remediation Tracking
Document containment actions taken, root cause analysis, systemic changes implemented, and ongoing monitoring. Every action is audit-trailed.
Breach Register & Reporting
Maintain a register of all suspected and confirmed breaches with outcomes, timelines, and lessons learned. Generate reports for governing body oversight.
The wider workflow
Where notifiable data breach connects.
Review roles, access boundaries and activity history alongside published security information. Agree the evidence your procurement team needs.
A workflow illustration showing the broader operating context.
Explore the product tourEvaluation
What to inspect with your team.
Bring a representative notifiable data breach scenario and use these questions to guide your demonstration.
Book a demo with this scenario- Walk through breach detection & logging using a representative example.
- Check the permissions and review steps for risk assessment workflow.
- Inspect the records and outputs available for oaic notification management.
Requirements and responsibilities
The requirements behind the workflow.
Review how these requirements apply to your services and the responsibilities your team retains.
Reference area: Privacy Act 1988, Part IIIC
Mandatory Notification
Eligible data breaches likely to result in serious harm must be notified to the OAIC and affected individuals as soon as practicable.
Breach Assessment
Providers must conduct a reasonable and expeditious assessment of suspected breaches within 30 days.
Record Keeping
Providers must maintain records of all data breaches and assessments, whether or not they meet the notification threshold.
Related workflows.
Explore the records and responsibilities that connect notifiable data breach with the wider platform.
Quality Standards
Data breach incidents feed into Quality Standard 2 (The Organisation) as evidence of information governance.
Whistleblower & Disclosures
Data breaches may be reported through whistleblower channels — the modules cross-reference to prevent duplicate handling.
Responsible Persons
Governing body notification requirements are tracked when breaches affect responsible person data.
Questions about notifiable data breach.
When is a data breach 'notifiable'?
A data breach is notifiable when it is likely to result in serious harm to any individual whose personal information is involved. The assessment considers the sensitivity of the information (health data is always considered sensitive), whether protective measures like encryption were in place, and the nature and extent of the breach.
What is the notification timeline?
Once you determine a breach is notifiable, you must notify the OAIC and affected individuals as soon as practicable. The initial assessment of a suspected breach must be completed within 30 days.
Does this replace our privacy officer's role?
No. The module structures and tracks the response process, but your privacy officer (or equivalent) still makes the assessment decisions. The module ensures nothing is missed, deadlines are tracked, and every action is documented for regulatory review.
See Notifiable Data Breach in action.
Bring a notifiable data breach scenario. We’ll walk through the relevant records, review steps and scope for your organisation.