What is a Notifiable Data Breach?

Australia has recorded the highest number of data breaches in more than three years, with the government sector being one of the greatest targets, according to a new report.

 

A data breach happens when personal information is accessed or disclosed without authorisation or is lost.

 

The Office of the Australian Information Commissioner (OAIC) published the data last week, revealing it recorded 527 breaches from January to June this year (2024). That figure was up nine per cent from the six months prior and the highest reported since the second half of 2020.

The top five sectors to notify the regulator of a breach were; health service providers, the Australian government, finance, education and retail.

The Australian government reported 63 breaches in the first six months this year.

A total of 67 per cent of all breaches were found to be malicious or criminal attacks, while 30 per cent were chalked up to human error and three per cent were system faults. Cyber criminals were able to hack into systems through phishing, ransomware or using compromised or stolen credentials.

Check out the article link here for more information.

 

 

Notifiable Data Breach

 

Australian Government agencies and organisations with an annual turnover of more than $3 million, (as well as some other organisations) must follow the Privacy Act 1988 and other laws when handling personal information. If the Privacy Act 1988 covers your organisation or agency, you must notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach involving personal information is likely to result in serious harm.

The notification to individuals must include recommendations about the steps they should take in response to the data breach.

The OAIC has more information on notifiable data breaches including;

  • Further info on the Notifiable Data Breaches Scheme
  • When to report a data breach
  • Report a data breach
  • Data breach preparation and response
  • Preventing data breaches: advice from the Australian Cyber Security Centre
  • Notifiable data breaches statistics

For more information head here.

 

The top 5 industries most affected by Privacy Data Breaches are;

  • Health service providers
  • Finance (including superannuation)
  • Legal, accounting & management services
  • Australian Government
  • Insurance

NOTE: Malicious or criminal attacks remain the leading source of data breaches with contact information remaining the most common type of personal information involved in data breaches.

A throwback pic to when the team from Hume Bank Albury popped into our office in 2022 to give us a seminar on Financial Crimes. A big thank you to Elaine, Talia and Ainslea!

 

 

Privacy Law Reforms

In September 2023, the OAIC welcomed the Australian Government’s response to the Attorney-General’s Department’s (AGD) review of the Privacy Act 1988 as a crucial step in ensuring Australia’s privacy framework is strengthened for the future. The Government is committed to introducing the legislative amendments this year.

Check out our latest blog article where we share more on the Privacy Law reforms: https://littonlegal.com.au/blog/privacy-law-reforms/

Data breaches have always been big news. In 2022 Optus was the victim of a massive data breach that saw over 9 million current or former customers’ personal data hacked with Medibank also a victim of a huge data breach.

More recently e-script provider MediSecure has been at the centre of a large-scale ransomware data breach announced by the national cyber security coordinator last week. The government continues to investigate the widespread breach.

A MediSecure spokesperson said at the time it was too early to respond to detailed questions about the nature and extent of the incident but added that “a lot of investigation work is being conducted.”

The OAIC routinely reports that health services suffer the most breaches of any sector mainly through malicious or criminal attacks.

Check out this article from The Conversation on why health records are so appealing for hackers to target. Cybercrime is very lucrative for hackers and with health records increasingly digitised, this industry will always be targeted:

“Patients are now taking steps against companies who don’t protect their data. In the case of Medibank, affected customers have launched several class actions with the national privacy regulator and under Australian corporations and consumer law. The introduction of a right to sue for serious invasions of privacy under an amended Privacy Act is an important, impending, change.”

At Litton Legal, we can assist your business with understanding cyber security risks, your obligations around this and what you should do in the event of a data breach. Send our friendly team an email here for more information.