Federal privacy law imposes no general obligation to store health information in Australia, and it holds a practice accountable for what any recipient of a disclosure does with the information. Victoria, New South Wales and the Australian Capital Territory add a health-records statute of their own.
The federal position
The Privacy Act 1988 (Cth) classifies health information as sensitive information, and a practice that discloses it to a vendor stays accountable for how that vendor handles it. An eligible data breach is notifiable under the Notifiable Data Breaches scheme in Part IIIC, to the affected individuals and to the Office of the Australian Information Commissioner, and an entity that suspects one has 30 days to assess it.
State health-records law
Three jurisdictions add a health-records statute on top of the Privacy Act: the Health Records Act 2001 (Vic), the Health Records and Information Privacy Act 2002 (NSW), and the Health Records (Privacy and Access) Act 1997 (ACT).
In Victoria and New South Wales a private health record is kept for seven years from the last occasion of service, and until the patient turns 25 where the record was made while they were a child. Elsewhere the Privacy Act applies alone.
My Health Record
The My Health Records Act 2012 (Cth) prohibits the System Operator and registered repository operators from holding or taking records included in a My Health Record outside Australia. It does not reach a practice's own clinical records or the software used to write them.
Questions for a vendor
Reasonable steps under the Privacy Act are assessed on what the practice did before it disclosed, so these answers belong in writing.
- The country holding the primary copy, and the country holding each backup and replica.
- The entity the practice contracts with, its country of incorporation, and its ultimate parent.
- The sub-processors that touch clinical content, the country each operates from, and how changes to that list are notified.
- Which contractual terms bind each recipient, and whether the vendor carries liability for their breaches.
- Who notifies the Office of the Australian Information Commissioner and the affected patients if the breach occurs at a sub-processor.
- The retention period, whether it can be set to match the practice's state legislation, and what is deleted when the practice leaves.
- Whether clinical content is used to train or improve any model, and whether that is a contractual term or a setting.
aurii's position
Hosting and backups are in Australian regions. Where the data sits.
Australia East, in Sydney, holds the primary copy. Australia Southeast, in Melbourne, holds the geo-redundant backups and runs no compute. Your content is not used to train models.
A point-in-time restore was run on 5 September 2026 and the restored audit chains were verified end to end. The verification output is available on request to hello@aurii.com.au. Backup and recovery.
This article is general information about Australian privacy law and data residency. It is not legal advice for a particular practice.