Healthcare — GPs, Dental, Allied HealthPatient records, Medicare data, clinical systems
Healthcare providers handle some of the most sensitive personal information in Australia. Under the My Health Records Act 2012, all data within the My Health Records system — including backups — must never be processed, held, taken, or handled outside of Australia (Section 77). This is one of the strictest data residency mandates in Australian law, with zero exceptions for identifiable data.
Beyond My Health Records, general practice, dental, and allied health data falls under the Privacy Act 1988 and specifically the handling of "health information," which is classified as sensitive information under APP 3. Health service providers have always been covered by the Privacy Act regardless of turnover — the small business exemption has never applied to health services.
The Australian Dental Association (ADA) mandates that dental records be securely stored and protected from unauthorised access. Computer systems must be password-protected, screen visibility limited to staff, and security software kept current. Under APP 8, cross-border disclosure of health information requires the disclosing entity to take reasonable steps to ensure the overseas recipient complies with the APPs — a much harder bar to clear than simply hosting in-country.
My Health Records Act 2012 (s.77)
All My Health Record data, including backups, must never be processed, held, or handled outside Australia. No exceptions for identifiable data.
Privacy Act 1988 — Health Services
Health service providers are exempt from the small business exemption. All practices handling health information must comply with the APPs, regardless of turnover.
ADA Data Privacy Guidelines
Dental practices must implement technical and physical security measures, restrict access, maintain security software, and have data breach response plans.
My Health Records Rules 2026
Non-compliant registered organisations may have their My Health Record registration revoked. OAIC is the privacy regulator for the system.
How WattleDB Helps
WattleDB stores all data — including backups and replicas — on Australian-owned infrastructure in Sydney and Canberra. No US parent entity means no CLOUD Act exposure for patient records. Row-level security enforces access control at the database layer, and Australian-only SMTP ensures appointment confirmations and password resets never traverse offshore relays.