If a technical flaw or an attack on Mediref’s servers leads to personal information being accessed, disclosed or lost, Mediref follows the process below, based on the OAIC’s guidance on data breach preparation and response.
- This covers breaches of Mediref’s own systems. If someone at your practice sent correspondence to the wrong person, see I sent to the wrong recipient.
- Mediref may be required to notify affected practices, their recipients and the Australian Information Commissioner under the Notifiable Data Breaches (NDB) scheme.
Our process
- Identify and contain. Work out the scope of the breach and stop it spreading — for example by disconnecting affected systems or revoking access for compromised accounts.
- Notify. Assess the likely harm and whether the breach is an eligible data breach under the NDB scheme, then tell those who need to know: affected practices and individuals, the Commissioner, and law enforcement where relevant.
- Investigate. Find the root cause and assess the impact, using logs, evidence and outside experts or law enforcement as needed.
- Fix and recover. Put measures in place to close the cause and prevent it happening again.
- Review. Assess how the response went and update the process, training or security controls with what was learned.
A breach is eligible under the NDB scheme when personal information is accessed, disclosed or lost, this is likely to cause someone serious harm, and remedial action can’t prevent that harm. Serious harm can be physical, psychological, financial or to someone’s reputation — for example identity theft, fraud, family violence or intimidation.
To prepare your own practice, the OAIC’s Data breach preparation and response guide is a good place to start.