How Mediref handles a data breach

What Mediref does if a flaw or attack on its own systems exposes personal information.

If a technical flaw or an attack on Mediref’s servers leads to personal information being accessed, disclosed or lost, Mediref follows the process below, based on the OAIC’s guidance on data breach preparation and response.

Our process

  1. Identify and contain. Work out the scope of the breach and stop it spreading — for example by disconnecting affected systems or revoking access for compromised accounts.
  2. Notify. Assess the likely harm and whether the breach is an eligible data breach under the NDB scheme, then tell those who need to know: affected practices and individuals, the Commissioner, and law enforcement where relevant.
  3. Investigate. Find the root cause and assess the impact, using logs, evidence and outside experts or law enforcement as needed.
  4. Fix and recover. Put measures in place to close the cause and prevent it happening again.
  5. Review. Assess how the response went and update the process, training or security controls with what was learned.

A breach is eligible under the NDB scheme when personal information is accessed, disclosed or lost, this is likely to cause someone serious harm, and remedial action can’t prevent that harm. Serious harm can be physical, psychological, financial or to someone’s reputation — for example identity theft, fraud, family violence or intimidation.

To prepare your own practice, the OAIC’s Data breach preparation and response guide is a good place to start.

Mediref Help Centre · https://mediref.com.au/support/how-mediref-handles-a-data-breach

Helpful?

Still need a hand?

Search for another article, or contact us.