AI scribes and patient confidentiality — what Australian practices need to check
The $3 million small business exemption does not apply to health service providers. A solo practice carries close to the same obligations as a hospital.
Published 26 July 2026
Clinical documentation is the most obvious candidate for AI assistance in any practice. It is repetitive, time-consuming, and structurally predictable — exactly the work AI handles well. The productivity gain is real and clinicians are right to want it.
The obligations attached to the underlying information are also unusually strict, and several of them surprise practice owners.
The exemption you probably do not have
Most Australian businesses with annual turnover of $3 million or less are exempt from the Privacy Act 1988. It is a widely known threshold and a widely misapplied one.
Health service providers are covered regardless of turnover. The exemption specifically does not extend to organisations providing a health service that hold health information. A single-practitioner physiotherapy clinic carries essentially the same obligations under the Act as a large hospital group.
If your compliance position has ever rested on “we are too small for the Privacy Act”, it does not apply here.
Health information is sensitive information
The APPs treat sensitive information as requiring a higher standard of protection than ordinary personal information, and health information is squarely within that category.
Practically, this raises the bar on what counts as “reasonable steps” under APP 11 (security) and APP 8 (cross-border disclosure). Steps that might be adequate for a mailing list are not adequate for clinical records. Sensitivity scales the obligation.
The layers above the Privacy Act
Federal privacy law is the floor, not the ceiling.
My Health Record. Where My Health Record data is involved, the My Health Records Act 2012 applies a distinct regime with criminal penalties attached to unauthorised collection, use or disclosure. This is a materially different consequence from a civil penalty, and it is worth knowing exactly whether your workflows touch that data.
State legislation. Some jurisdictions layer their own health records legislation on top of the federal Act — New South Wales, Victoria and the ACT each have specific health privacy statutes. Western Australia does not have equivalent standalone health records privacy legislation, which means WA private practices rely primarily on the federal Privacy Act. That is a simpler position, not a lighter one.
Professional obligations. Registration standards and codes of conduct impose confidentiality duties independent of privacy legislation. A privacy regulator is not the only body that can take an interest.
The NDB scheme. An eligible data breach involving health information will very often meet the “serious harm” threshold, given the sensitivity involved. Notification obligations follow.
Where the exposure actually occurs
Consult note generation. Dictated or typed detail submitted to produce a structured note. Contains presenting complaint, history, and enough identifying detail to be useful — which is exactly what makes it health information.
Referral and specialist letters. Often the richest single document the practice holds about a patient, because the letter is only useful if the clinical picture is complete.
Discharge and progress summaries. Condensing longitudinal records means transmitting months or years of history in a single request.
Coding and billing queries. Procedure and diagnosis detail pasted in to resolve item numbers, linking clinical facts to an identifiable episode of care.
The informal one. A clinician describing a difficult presentation to a chatbot to think it through. No name attached — but with enough clinical and demographic detail that the patient may well be identifiable, particularly in a small community. De-identification is harder than it looks, and rare conditions in regional towns are not de-identified by removing a name.
Purpose-built scribes versus general chatbots
It would be wrong to treat these as equivalent.
Several AI scribe products are built specifically for Australian healthcare and make explicit commitments about onshore processing, retention limits, and not training on clinical data. Some are used at scale by large health services that have conducted their own privacy assessments. These are serious products, and for many practices they are the appropriate answer.
If you are evaluating one, the questions worth pressing on are:
- Where is audio and text processed, specifically — which country, which provider?
- Is any part of the pipeline subcontracted to an overseas model provider? This is the one that most often surprises people.
- How long is data retained, and can you configure it?
- Is patient consent obtained, and is that documented in a way that satisfies your obligations?
- What happens to your data if the vendor is acquired or ceases trading?
- Will they provide their answers in writing?
Question 2 matters disproportionately. A number of products with Australian branding and Australian hosting still route the actual inference to a large overseas model provider. The hosting being local does not mean the processing is.
The general-purpose chatbot case is much simpler to assess, and much worse. Consumer terms, offshore processing, no clinical-specific commitments, no consent framework. That is the usage most practices have and least visibility of.
The consent problem
Even where a vendor’s arrangements are sound, patient consent remains your obligation.
Patients should generally be informed that an AI tool is used in documenting their care and be able to decline. This needs to be genuine — a poster in the waiting room is a weaker position than a documented conversation, particularly for a patient who did not see the poster.
Note the asymmetry: the vendor’s compliance does not discharge your consent obligation. Those are separate requirements, and only one of them is outsourced.
What on-premise changes, and what it does not
If the AI runs on hardware physically inside the practice, the cross-border analysis disappears. There is no overseas recipient, no third-party disclosure, and no vendor whose retention policy you need to audit. Question 2 above has a trivial answer.
It also keeps working when the internet does not, which matters more in regional and remote practice than most metropolitan vendors appreciate.
It does not make you compliant on its own, and we would rather say so plainly:
- APP 11 still requires you to secure the system physically and on your network.
- Patient consent obligations are unchanged.
- Clinical responsibility for the accuracy of the record is unchanged. AI-generated notes must be reviewed by the clinician. Every AI system produces confident errors, and an unreviewed AI note in a clinical record is a liability regardless of where it was generated.
- Your record-keeping and retention obligations are unchanged.
What it removes is one specific risk — the transmission of health information to third parties you cannot audit — which happens to be the risk that is hardest to control by policy alone, because it depends on individual behaviour under time pressure.
Where to start
Before evaluating any product, establish what is already happening. Ask your clinicians directly, without consequence attached, whether they have used AI tools with patient information.
Practice owners are routinely surprised by the answer. You cannot assess an exposure you have not measured, and the measurement is a conversation, not an audit.
This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.