HIPAA Doesn’t Apply in Australia: Here’s What Actually Does
One of the most common misconceptions in Australian healthcare is that clinics need to be “HIPAA compliant.” They almost never do. HIPAA is a United States law, and it has no legal standing in Australia. Yet the belief persists, partly because HIPAA is so widely referenced online, and it leads Australian clinics to worry about the wrong framework while sometimes overlooking the ones that actually bind them. Byteway helps Australian healthcare businesses get their real obligations right, so let us clear this up: HIPAA does not apply here, and here is what actually does. First, The Correction: HIPAA is US law HIPAA, the Health Insurance Portability and Accountability Act, is an American law governing how US healthcare entities handle protected health information. It applies to US health plans, providers and their business associates. It does not apply to an Australian clinic treating Australian patients, any more than Australian road rules apply in California. So a Melbourne dental practice or an allied health clinic serving local patients is not, and does not need to be, “HIPAA compliant.” The confusion is understandable given how much US content dominates online, but chasing HIPAA for a domestic Australian practice is solving the wrong problem. That does not mean Australian healthcare is unregulated. Far from it. It means the rules that apply have different names, and knowing them is what actually matters. What Actually Applies: the Privacy Act 1988 and the APPs The main law governing patient data in Australia is the Privacy Act 1988 and the Australian Privacy Principles (APPs) within it. This is the framework that genuinely binds Australian healthcare providers, and it has a critical feature: while many small businesses under $3 million turnover are exempt from the Privacy Act, health service providers are covered regardless of turnover. A solo practitioner is bound by it just as a large hospital is. Under the Privacy Act, health information is classified as sensitive information, which attracts the highest level of protection. In practice this means a healthcare provider must collect health information fairly and generally with consent, tell patients how it will be used, keep it secure by taking reasonable steps to protect it, use it only for the purpose it was collected unless the patient consents otherwise, and give patients access to their own records. These are the Australian Privacy Principles, and they are what a clinic should actually be complying with. The Notifiable Data Breaches Scheme Also under the Privacy Act is the Notifiable Data Breaches scheme, which requires organisations to assess and notify eligible data breaches likely to cause serious harm. Note the difference from HIPAA here, because it trips people up: HIPAA runs to a fixed notification clock, while Australia’s scheme requires notification “as soon as practicable” after assessing, with an assessment window rather than a single hard deadline. A clinic worried about “HIPAA breach notification” should instead understand its obligations under Australia’s NDB scheme, which is what actually governs a breach here. The My Health Record Framework On top of the Privacy Act sits legislation specific to the national digital health system: the My Health Records Act 2012, which governs the My Health Record system, along with associated rules, including the recent Share by Default rules requiring pathology and diagnostic imaging reports to be uploaded to My Health Record by default. There is also the Healthcare Identifiers regime. Clinics interacting with My Health Record have obligations under this framework, none of which has anything to do with HIPAA. State and Territory Health Records Laws Here is the layer many providers miss entirely: several states and territories have their own health records legislation, and private healthcare providers in those jurisdictions may need to comply with both the federal Privacy Act and the state law. Examples include the Health Records Act 2001 in Victoria, the Health Records and Information Privacy Act 2002 in New South Wales, and equivalent legislation in the ACT. So a Victorian or NSW clinic is potentially subject to two sets of privacy obligations, federal and state, which impose broadly similar but distinct requirements. This is genuinely more complex than a single “HIPAA compliant” box, and it is what actually applies. So When Does HIPAA Ever Matter for an Australian Business? There is one real scenario, and it is worth being precise about. HIPAA can matter to an Australian business if it handles US patients’ health data or provides services to US healthcare organisations, for example, an Australian health tech company with US clients, or a business that processes protected health information on behalf of a US covered entity. In those cases, HIPAA obligations can flow through by contract, and the business genuinely does need to meet them, alongside its Australian obligations. This is exactly where a service like HIPAA compliance implementation is relevant, not for domestic Australian care, but for Australian businesses doing US-facing healthcare work. If that is not you, HIPAA is not your framework. What to Actually Do? For an Australian healthcare provider serving Australian patients, the practical path is to stop worrying about HIPAA and get your real obligations right: comply with the Privacy Act and the APPs, treat health information as the sensitive data it is, secure it with reasonable steps, understand your NDB breach obligations, meet your My Health Record duties, and check whether your state imposes additional health records requirements. That is what a regulator would actually hold you to, and it is what protects your patients. If you also do US-facing healthcare work, then HIPAA is added on top, for that work specifically. Getting the framework right is the first step to getting compliance right, and for most Australian clinics that framework is Australian, not American. FAQs Does HIPAA apply in Australia? No. HIPAA is a United States law with no legal standing in Australia, so an Australian clinic treating Australian patients does not need to be “HIPAA compliant.” What applies is the Privacy Act 1988 and related Australian laws. Byteway helps Australian healthcare providers meet their actual obligations.









