Compliance & Governance

Notifiable Data Breach

Detect, assess, and notify — before the deadline expires.

Data breach detection, risk assessment, OAIC notification management, affected individual communications, and remediation tracking.

Residential care · Home care

In practice

The work behind notifiable data breach.

Aged care providers hold highly sensitive personal and health information. Under the Notifiable Data Breaches (NDB) scheme, providers must assess suspected breaches, determine whether they are likely to result in serious harm, and notify the Office of the Australian Information Commissioner (OAIC) and affected individuals. Statura Care’s Data Breach module structures this process from detection through to remediation.

A data breach involving resident health records, financial information, or staff screening data can have severe consequences — regulatory action, reputational damage, and harm to individuals. Without a structured response process, providers risk missing the mandatory notification timeline or failing to communicate effectively with affected individuals.

Breach Detection & Logging

Log suspected data breaches with classification by type (unauthorised access, disclosure, loss), data categories affected (health, financial, personal), and number of individuals impacted.

Risk Assessment Workflow

Structured assessment of whether a breach is likely to result in serious harm — the threshold that triggers mandatory notification. Considers sensitivity of data, protective measures in place, and nature of the breach.

OAIC Notification Management

Auto-generate OAIC notification forms with breach details pre-populated. Track submission status, OAIC correspondence, and response deadlines.

Affected Individual Communications

Manage notifications to affected individuals with templates, delivery tracking, and response management. Track who has been notified and any follow-up actions.

Remediation Tracking

Document containment actions taken, root cause analysis, systemic changes implemented, and ongoing monitoring. Every action is audit-trailed.

Breach Register & Reporting

Maintain a register of all suspected and confirmed breaches with outcomes, timelines, and lessons learned. Generate reports for governing body oversight.

The wider workflow

Where notifiable data breach connects.

Review roles, access boundaries and activity history alongside published security information. Agree the evidence your procurement team needs.

A workflow illustration showing the broader operating context.

Explore the product tour
Workflow illustration: an access review covering roles, records, permitted actions and activity history.

Evaluation

What to inspect with your team.

Bring a representative notifiable data breach scenario and use these questions to guide your demonstration.

Book a demo with this scenario
  • Walk through breach detection & logging using a representative example.
  • Check the permissions and review steps for risk assessment workflow.
  • Inspect the records and outputs available for oaic notification management.

Requirements and responsibilities

The requirements behind the workflow.

Review how these requirements apply to your services and the responsibilities your team retains.

Reference area: Privacy Act 1988, Part IIIC

Mandatory Notification

Eligible data breaches likely to result in serious harm must be notified to the OAIC and affected individuals as soon as practicable.

Breach Assessment

Providers must conduct a reasonable and expeditious assessment of suspected breaches within 30 days.

Record Keeping

Providers must maintain records of all data breaches and assessments, whether or not they meet the notification threshold.

Questions about notifiable data breach.

When is a data breach 'notifiable'?

A data breach is notifiable when it is likely to result in serious harm to any individual whose personal information is involved. The assessment considers the sensitivity of the information (health data is always considered sensitive), whether protective measures like encryption were in place, and the nature and extent of the breach.

What is the notification timeline?

Once you determine a breach is notifiable, you must notify the OAIC and affected individuals as soon as practicable. The initial assessment of a suspected breach must be completed within 30 days.

Does this replace our privacy officer's role?

No. The module structures and tracks the response process, but your privacy officer (or equivalent) still makes the assessment decisions. The module ensures nothing is missed, deadlines are tracked, and every action is documented for regulatory review.

See Notifiable Data Breach in action.

Bring a notifiable data breach scenario. We’ll walk through the relevant records, review steps and scope for your organisation.