Health information and the Privacy Act: what to ask a software vendor
A Privacy Act health information checklist for vetting software vendors: questions on APPs 1, 5, 6, 8, 11, 12 and 13, and what good answers look like.
On this page
When a software vendor will store, host or access health information for you, the Privacy Act still treats that information as yours to protect. Health information is sensitive information, the Act covers health service providers whatever their size, and your vendor's practices become your risk. The quickest way to test a vendor is to ask questions tied to the Australian Privacy Principles (APPs) and compare the answers with what good looks like.
This post is part of our guide to healthcare software development in Australia. This article is general information, not legal advice.
How the Privacy Act treats health information#
Five points shape every vendor conversation.
- Health information is sensitive information. The OAIC's key concepts guidance lists health information among the categories of sensitive information, which the APPs protect more strictly than other personal information, for example when it comes to secondary use.
- Size does not exempt health providers. The Act generally covers organisations with annual turnover above A$3 million, but it also covers private sector health service providers regardless of turnover.
- Outsourcing does not end your obligations. You "hold" information if you have possession or control of it, and the OAIC says an organisation that outsources storage but keeps the right to access and amend the information still holds it. Your APP 11 security duties continue.
- Your vendor may not be bound directly. A small software business may fall outside the Act, so the contract must carry the protections you need.
- Overseas access makes you accountable. Under APP 8 and section 16C, if you disclose personal information to an overseas recipient you generally remain accountable for how it is handled.
In NSW, Victoria and the ACT, private sector health service providers also have state or territory health records laws to comply with, so include those in your review.
The vendor due-diligence questionnaire#
Send these questions in writing before a demo turns into a contract, and ask for evidence rather than a sales call. Each row links a question to an APP.
APP | Question to ask | Why it matters | A good answer |
|---|---|---|---|
1 | What privacy practices, procedures and systems do you run, and who is accountable? | APP 1.2 expects practices and systems that ensure compliance | A named contact, written policies, staff training, a complaints process |
1 | Does the product make automated decisions about people? | From 10 December 2026, privacy policies must describe certain automated decisions | A list of automated features, the data each uses, and how humans review them |
5 | Can the product show our collection notice when information is collected? | Notice is due at or before collection, or as soon as practicable | Configurable notices on forms and apps, with a record of what was shown |
6 | Will you use our data for anything other than serving us? | Secondary use of health information is tightly limited | No, in writing, covering analytics, product improvement and AI training |
8 | Where is data stored, and from which countries can staff or subcontractors access it? | You are generally accountable for overseas recipients | A list of locations, subcontractors and countries, plus access controls |
11 | How is access controlled, and can we see the logs? | Reasonable steps include technical and organisational measures | MFA, least privilege, audit logs you can view, regular access reviews |
11 | How do you handle encryption, backups and patching? | Loss and unauthorised access are both APP 11 risks | Encryption in transit and at rest, tested restores, stated patch timeframes |
11 | How do you destroy or de-identify our data at the end? | Unneeded information must generally be destroyed or de-identified, unless the law requires you to keep it | A documented process that covers backups, with written confirmation |
11 | How fast will you tell us about a suspected breach? | You may have 30 days to assess and must notify eligible breaches promptly | A committed window in hours, a named contact, help with the assessment |
12 | Can we find and export everything about one person quickly? | Access requests need a response within a reasonable period; the OAIC's guide is 30 days | Search across all records, export in readable formats |
13 | Can we correct records and attach a statement if we refuse a correction? | People can ask you to associate a statement with their record | Edits with an audit trail, and a visible statement field |
All | Which certifications are yours, and which belong to your hosting provider? | An infrastructure certificate does not cover the vendor's own practices | A clear scope for each certificate, with evidence you can check |
A few rows deserve more explanation.
- APP 1 and automated decisions. From 10 December 2026, if a computer program makes, or does something substantially and directly related to making, a decision that could reasonably be expected to significantly affect someone's rights or interests, your privacy policy must describe the kinds of personal information used and the kinds of decisions made. You cannot write that without the vendor's help.
- APP 5 notices. Collection notices must cover matters such as your identity, usual disclosures, and whether you are likely to disclose information overseas and to which countries. The vendor's answer to the APP 8 question feeds straight into your notice.
- APP 6 and AI. For sensitive information, a secondary use generally needs consent, or a directly related purpose the person would reasonably expect, unless another exception applies. The OAIC's guidance on commercially available AI products recommends checking whether a provider's terms let it use your inputs for further AI training.
- APPs 12 and 13. The OAIC treats 30 calendar days as a general guide for responding to access and correction requests. If the vendor's export takes a support ticket and a week, your timeframe is already under pressure.
Red flags in vendor answers#
Treat these as reasons to slow down:
- Reassurance without detail, such as "we take privacy seriously", with no policies, logs or architecture to show.
- No clear answer about which countries support staff or subcontractors work from.
- A plan to "anonymise" your data for the vendor's own use, with no detail on method or purpose.
- No breach notification commitment in the contract, or a commitment measured in weeks.
- Exports only as PDFs, only on request, or only for a fee.
- Data centre certificates presented as if they were the vendor's own.
Put the answers into the contract#
Good answers only protect you if they end up in the contract. Ask your lawyer to cover at least these points:
- The purposes for which the vendor may handle your information, and a ban on other uses, including AI training, without your written agreement.
- Where data may be stored and accessed, the approved subcontractors, and notice before either changes.
- The security measures promised in the questionnaire, and your right to evidence of them.
- A breach notification window, cooperation with your assessment, and who notifies individuals and the OAIC.
- Support for access and correction requests within agreed timeframes.
- Return and deletion of data, including backups, when the contract ends.
The NDB scheme lets one entity assess and notify on behalf of all entities that jointly hold the affected information, so decide in advance which of you will do it. Our data breach response plan guide covers what the first hours and days should look like.
Written instructions may matter even more in future. The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, released on 31 August 2026, proposes "controller" and "processor" roles: a processor acting on a controller's documented written instructions would generally not itself breach the APPs (other than APPs 1 and 11), and the controller would be treated as having done the act. It is a draft and may change, but documenting your instructions to vendors is good practice either way.
How to run a vendor privacy review#
- Map the data. List the health information involved, whose it is, where it comes from and which systems it passes through.
- Send the questionnaire early. Ask for written answers before the final demo, not after the contract is drafted.
- Ask for evidence. Policies, a data-flow or architecture diagram, a summary of recent security testing, and the list of subcontractors.
- Check the contract matches. Every promise in the answers should appear in the agreement.
- Update your own documents. Your privacy policy and collection notices may need new overseas countries or automated decision details.
- Review each year. Re-ask the key questions annually and whenever the vendor changes subcontractors or hosting.
If the vendor will access data from outside Australia, read our explainer on APP 8 and offshore developers before you finalise the contract.
What to do next#
We expect to be asked these questions ourselves; our trust page sets out how we approach security and access. If you are weighing up a build or a vendor for health information, our healthcare page explains how we work with care providers.
Frequently asked questions
Is my software vendor covered by the Privacy Act?
Not necessarily. The Act generally covers organisations with annual turnover above A$3 million, plus certain smaller businesses such as private sector health service providers and contracted service providers for Australian Government contracts. A small software company may fall outside it. You remain responsible for health information you hold, so write the protections you need into the contract rather than assuming the law binds your vendor directly.
Who notifies if a vendor causes a data breach?
If you and your vendor both hold the affected information, the NDB scheme allows one of you to carry out the assessment and notification for both. The OAIC suggests that the entity with the most direct relationship with the affected individuals should usually notify, which is often the provider rather than the vendor. Agree the arrangement, and the vendor's reporting timeframe, in the contract before an incident.
Can a vendor use our health data to improve its product or train AI?
Only within APP 6, which for sensitive information such as health information generally requires consent, or a directly related purpose the person would reasonably expect, unless another exception applies. The OAIC also recommends that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools. Ask the vendor directly and record the answer in the contract.
How quickly must we respond to a request for someone's records?
Organisations must respond to access and correction requests within a reasonable period, and the OAIC treats 30 calendar days as a general guide. You cannot charge for making an access request, any charge for giving access must not be excessive, and corrections are free. Choose software that can find and export one person's records quickly, or meeting that timeframe becomes a manual scramble.
Sources
- Rights and responsibilities — Office of the Australian Information Commissioner — accessed 18 September 2026
- Chapter B: Key concepts (APP guidelines) — OAIC — accessed 18 September 2026
- Chapter 1: APP 1 Open and transparent management of personal information — OAIC — accessed 18 September 2026
- Chapter 5: APP 5 Notification of the collection of personal information — OAIC — accessed 18 September 2026
- Chapter 6: APP 6 Use or disclosure of personal information — OAIC — accessed 18 September 2026
- Chapter 8: APP 8 Cross-border disclosure of personal information — OAIC — accessed 18 September 2026
- Chapter 11: APP 11 Security of personal information — OAIC — accessed 18 September 2026
- Chapter 12: APP 12 Access to personal information — OAIC — accessed 18 September 2026
- Chapter 13: APP 13 Correction of personal information — OAIC — accessed 18 September 2026
- State and territory privacy legislation — OAIC — accessed 18 September 2026
- Part 4: Notifiable Data Breach (NDB) Scheme — OAIC — accessed 18 September 2026
- Guidance on privacy and the use of commercially available AI products — OAIC — accessed 18 September 2026
- Privacy reform: consultation on exposure draft legislation — Attorney-General's Department — accessed 18 September 2026
- Exposure draft: Privacy Amendment (Personal Data Protection) Bill 2026, Schedule 6 — Attorney-General's Department — accessed 18 September 2026
Facts in this article were last checked on 18 September 2026.
Inventure Engineering Team
Engineers at Inventure Technologies who build, host and run software for clients in Nepal and Australia. We write about what we do every day.
Keep reading
Healthcare software development in Australia: privacy, data residency, integrations and cost
Healthcare software development in Australia explained: Privacy Act, data residency, security, FHIR integrations, cost drivers and a vendor checklist.
Read articleNDIS software: off-the-shelf (ShiftCare, Lumary, Brevity…) vs custom — how to decide
Compare NDIS software such as ShiftCare, Lumary and Brevity with a custom build, and use a simple framework to decide whether to buy, extend or build.
Read articleOffshore developers and Australian health data: APP 8 cross-border disclosure explained
APP 8 cross-border disclosure explained for health data: when offshore access counts, who stays accountable, and controls that keep access rare and logged.
Read articleWant engineers who handle this for you?
We build, host and run software for teams in Nepal and Australia — with dedicated support on every plan.