What the OAIC requires when Australian healthcare practices use AI: every AI tool that processes patient health information is covered by the Privacy Act 1988, regardless of where the vendor is based. APP 8 makes your practice accountable for what overseas AI vendors do with patient data. Two dated changes land first: the TGA's decision support exemption changes on 1 November 2026, and privacy policies must disclose automated decision-making from 10 December 2026. Each section below links to the page that covers its question in full.
Key Takeaways
- The Privacy Act 1988 covers every AI tool that processes patient health information, wherever the vendor is. APP 8 makes the practice accountable for what an overseas vendor does with patient data.
- The OAIC's October 2024 guidance recommends practices "do not enter personal information" into publicly available generative AI tools.
- The account tier decides training. OpenAI "may use your content to train our models" on services for individuals, and by default does not on ChatGPT Business, Enterprise, Edu or the API.
- The TGA test turns on what the tool does. A scribe that only transcribes is not a device; one that suggests a diagnosis or treatment not stated by the practitioner is. The decision support exemption changes on 1 November 2026.
- RACGP criterion F11 was published on 26 August 2026 and applies only if the practice uses AI. It is not assessable until the ACSQHC announces arrangements.
- From 10 December 2026, privacy policies must disclose automated decision-making (APPs 1.7 to 1.9). OAIC guidance followed on 30 September 2026. Tranche 2 is a 31 August 2026 exposure draft, not law.
AI clinical scribes are transcribing consultations, AI-assisted diagnostic tools are analysing pathology results, patient-facing chatbots are triaging symptoms, and general-purpose tools like ChatGPT are being used by reception and administration staff to draft correspondence, summarise notes and generate letters. Each of these involves health information and is governed by the Privacy Act 1988. According to the OAIC, healthcare providers remain accountable for what happens to patient data once it reaches an AI system, wherever that system runs.
How many Australian practices use AI scribes?
Somewhere between one in five GPs and two in five practices, depending on the question. The RACGP's newsGP poll, reported on 12 December 2025 in "GPs' AI scribe use doubles in one year: Poll", found that "in August 2024, just 22% of poll respondents were currently using AI scribes in their general practice. However, by November 2025, that percentage almost doubled to 40%". The same article reported 88% of GPs said most patients are happy for them to use a scribe.
The Healthed / HSD survey, reported in Health Services Daily on 14 May 2026, asked a different question: "Do you use an AI scribe for consulting?" Of 1,535 GPs, "just 18.7% said they personally use an AI scribe for consulting". As that article notes, the RACGP's wording "potentially captures practice-level use".
Both figures are right. One counts practices where a scribe is in use, the other counts GPs who use one themselves, and the samples differ. In the same Healthed / HSD survey, "Only 25.0% of respondents said their practice had an AI governance policy". The AI scribe governance pack is built for the other 75%.
What does the OAIC's AI guidance say?
The OAIC published two guides on 21 October 2024: one on using commercially available AI products (updated 17 January 2025), and one on developing and training generative AI models. The first is the one most practices need. Its opening takeaway says: "Privacy obligations will apply to any personal information input into an AI system, as well as the output data generated by AI (where it contains personal information)."
It also says: "As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools, due to the significant and complex privacy risks involved."
The guidance does not prohibit AI in healthcare. It says practices must assess the tools they use, understand how those tools handle health data, and document that assessment.
Under APP 6, if a vendor trains a model on what your practice types in, that is a secondary use of your patients' information.
Which Privacy Act obligations apply to AI?
Four Australian Privacy Principles do most of the work when a practice adopts an AI tool.
APP 1: Transparency About AI in Your Privacy Policy
APP 1 requires organisations to have a clearly expressed and up-to-date privacy policy. A policy drafted before your practice started using an AI scribe or patient chatbot is already out of date. It needs to explain what AI tools you use, what health information they process, where that information is stored and by whom, and what rights patients have. The automated decision-making duty that takes effect on 10 December 2026 adds to APP 1 (see below).
APP 6: Health Information Can Only Be Used for Its Primary Purpose
APP 6 limits use of personal information to the primary purpose of collection, subject to limited exceptions: patient consent, a secondary use directly related to the primary purpose that the patient would reasonably expect, or a law or court order. AI vendor model training is a secondary purpose and needs its own basis. Removing a patient's name from a consultation transcript does not de-identify it if the transcript holds enough clinical detail to identify the person in context. If your vendor's terms allow training on your inputs, APP 6 is engaged.
APP 8: Cross-Border Disclosure Rules Apply to Overseas AI Vendors
When your practice sends patient data to an overseas AI system, that is a cross-border disclosure of health information subject to APP 8. The practice must take reasonable steps to ensure the overseas recipient handles the information in compliance with the Australian Privacy Principles, or rely on the patient's express consent. Using a foreign AI tool without reviewing its data terms does not satisfy APP 8. The AI scribe assessment guide sets out the data location checks step by step.
APP 11: Reasonable Steps to Protect Health Information
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. The Federal Court's October 2025 judgment in the Australian Clinical Labs case established that this is an objective standard assessed across your systems, policies and procedures as a whole. A free-tier or consumer AI product processing patient records almost certainly fails it.
Can staff put patient information into ChatGPT or Copilot?
No, not on a personal or free account. Pasting a patient's name, date of birth and history into a consumer chatbot is a disclosure of identifiable health information to the vendor. The OAIC's best-practice line applies directly: do not enter personal information, and particularly sensitive information, into publicly available generative AI tools.
The vendors' own pages draw the line at the account tier. OpenAI's help centre says services for individuals may train on content unless you opt out under Settings > Data controls, and even then, feedback you submit may still be used to train.
| Personal or free account | Business or work account | |
|---|---|---|
| OpenAI (ChatGPT) | "we may use your content to train our models" (help centre); opt-out available | "By default, we don't use inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, or our API to improve our models" (help centre); DPA available (enterprise privacy page) |
| Microsoft (Copilot) | "uses prompts and related data to provide and improve services, including relevant advertising" | "aren't used to train foundation models"; covered by the DPA with Microsoft "acting as a data processor" |
| Source and date | OpenAI help centre (read 6 October 2026); OpenAI privacy policy (6 February 2026); Microsoft privacy statement (September 2026) | OpenAI enterprise privacy page (8 January 2026); Microsoft Learn enterprise data protection page (18 August 2026) |
Vendor terms change; these are the pages as read on 6 October 2026.
Microsoft 365 Copilot is now named Microsoft Copilot, so the product name no longer tells you which terms apply. The sign-in does: a work or school Microsoft Entra account lands under the enterprise terms; a personal account lands under the consumer privacy statement.
A no-training default answers APP 6's training question only. Where the data is stored and processed is still an APP 8 and APP 11 question for the contract, along with a documented decision on which tools are permitted, in which tier. The AI acceptable use policy template approves tools by plan.
What does a practice need before using an AI scribe?
Six questions, answered before the first consultation is recorded. Does the patient know their consultation is being recorded and processed by AI? Is there a disclosure in your practice's privacy policy and on the patient registration or consent form? Does the vendor store transcripts, and for how long? Is data stored in Australia or overseas? Has the vendor provided a data processing agreement that addresses APP 8? Is model training switched off on your plan?
Ahpra's guidance says: "Practitioners must apply human judgment to any output of AI." On consent, Ahpra says to "make sure you obtain informed consent from your patient, and ideally note the patient's response in the health record".
The procedure for answering those questions is in how to assess an AI scribe for privacy compliance. The AI scribe patient consent form covers the disclosure, and the AI scribe governance pack keeps the whole file in one place.
Is our AI scribe a medical device?
No, not if it only transcribes and summarises. The TGA's digital scribes page (30 January 2026) says: "Digital scribes intended only to transcribe and translate clinical conversations into written records without performing analysis or interpretation are not considered medical devices." But "if a digital scribe analyses or interprets clinical conversations, for example by generating a diagnosis, differential diagnosis or treatment recommendation not explicitly stated by the healthcare practitioner, it is considered a medical device", and such products must "be included in the ARTG before they can be imported, exported, or supplied in Australia".
The RACGP's AI scribes fact sheet (October 2025) says scribes "do not require regulation by the TGA as they do not have a therapeutic use and therefore do not meet the definition of a medical device". F11 says some AI tools "may be classified as medical devices under the Therapeutic Goods Act 1989".
From 1 November 2026, the TGA's amended clinical decision support exemption applies: decision support software keeps its exemption only if it is not intended to make a diagnosis or treatment decision and shows the health professional the logic behind its recommendations. Software that gives decision support directly to patients does not qualify.
The AI scribe glossary entry, the clinical decision support system entry and the TGA 1 November 2026 post carry the tests in full.
Do patients have to be told when an AI answers the phone or the chat?
Yes, in practice. Practices using patient-facing chatbots for appointment booking, symptom triage or pre-consultation questionnaires are collecting health information through those tools, and the Privacy Act's transparency rules apply to that collection. A disclaimer buried in terms of service is unlikely to satisfy the OAIC's transparency expectations for health information.
A triage or routing tool may also fall under the automated decision-making disclosure duty that takes effect on 10 December 2026, if it makes decisions that could significantly affect individuals. The OAIC's fact sheet on the duty lists programs used to prioritise the provision of health or disability services among the decisions generally in scope.
The step-by-step procedure, including the greeting and privacy notice, the recording law, and sending anything clinical to a person, is in how to deploy an AI phone receptionist.
What should an AI vendor contract cover?
Six things.
Data use. The vendor uses patient information only for the contracted service, with no model training without your opt-in.
Data residency. The contract states where data is stored and where it is processed.
Breach notification. The vendor notifies you in time to meet your own Notifiable Data Breaches obligations.
Sub-processors. All sub-processors are disclosed and bound to the same protections.
Deletion and return. You get confirmed deletion or return of patient data at exit.
Security certifications. The vendor holds recognised certifications such as ISO 27001 or SOC 2 Type II.
If a vendor cannot provide a data processing agreement that addresses these points, or declines to negotiate on data use terms, that is a signal the tool is not designed for healthcare use. The AI scribe governance pack includes a vendor questionnaire, and the assessment guide walks the contract checks.
Do we need an AI acceptable use policy?
Yes, if anyone in the practice uses AI. The policy names the approved tools and the tier or plan for each, bans patient identifiable information (names, dates of birth, Medicare numbers, clinical details) in unapproved tools, sets out patient disclosure, covers de-identification, says who assesses new tools before they are used, and requires staff training with a record of who was trained and when. The AI acceptable use policy template is written for a healthcare practice and approves tools by plan.
Do the RACGP Standards cover AI?
Yes, from 26 August 2026, when the RACGP published the Standards for general practices (6th edition), the first edition to name AI directly. F11 is the artificial intelligence criterion: "F11.A Where the practice uses artificial intelligence, it does so safely and securely and consistent with existing standards." and "F11.B The practice assesses and evaluates its use of artificial intelligence." Neither has a 5th edition equivalent.
F11 applies only to practices that use AI, administrative AI included, alongside new F10 (governance of digital health technologies) and strengthened F8 and F9 privacy and security expectations.
F11 is not yet assessable. The Commission's page for the 6th edition (26 August 2026) says: "Accreditation under the NGPA Scheme currently uses the 5th edition of the Standards. Information about arrangements for the 6th edition of the Standards will be provided in due course."
The AI acceptable use policy, vendor assessment and patient disclosure work above are the evidence a surveyor will ask to see under F11. The F11 evidence checklist guide and what the 6th edition changes cover the rest.
What about day hospitals?
The ACSQHC's 2026 National Model for Clinical Governance is "for public and private health services in the acute sector, including day hospitals". It makes boards accountable for "the safe and ethical use of automated systems, such as artificial intelligence, in clinical decision-making and patient care", and expects that "a risk management plan is used to assess and mitigate risks before introducing digital tools and technologies". Its foundations will shape the NSQHS Standards third edition, for which no date is published.
What changes on 10 December 2026?
From 10 December 2026, under the Privacy and Other Legislation Amendment Act 2024 (the first tranche of reform), privacy policies must disclose automated decision-making that could significantly affect individuals (APPs 1.7 to 1.9). Systems that may be caught include billing software that automatically applies or declines Medicare item eligibility, AI-assisted triage tools that route patients to different appointment types, clinical decision support tools that recommend (or flag against) specific clinical actions, and patient risk stratification systems that determine follow-up frequency. Under APP 1.8, the policy has to say what kinds of personal information those programs use and what kinds of decisions they make or substantially assist.
The OAIC published its guidance on 30 September 2026, announced in the statement "New resources on transparency for use of AI and automated decision-making". Chapter 1 of the APP guidelines, now version 2.0, has a new section, "Information relating to decisions made by a computer program" (paragraphs 1.35 to 1.78). The OAIC's fact sheet lists "computer programs used to prioritise the provision of health or disability services to individuals" among the decisions generally in scope. The second tranche of reform is a separate exposure draft released on 31 August 2026 and is not yet law. The automated decision-making post and the automated decision-making glossary entry carry the detail.
What happened in July to September 2026?
Eight dated events fell in those three months, and each has its own page.
| Date | What happened | Primary source | Our page |
|---|---|---|---|
| 5 July 2026 | Guardian Australia reports a February 2026 Senate Estimates brief released under FOI: scribes have "little oversight"; some suppliers "may be unaware their cloud platforms send data outside Australia"; some advertise "a 30% revenue increase" | FOI 26-3154 | AI scribe assessment guide |
| 14 August 2026 | ABC reports a specialist's AI-drafted letter to a GP that wrongly said the patient had micro-dosed mushrooms; Ahpra restates that clinicians must check all scribe output | ABC News | AI scribe glossary entry |
| 26 August 2026 | RACGP 6th edition published with F11; not yet assessable | ACSQHC 6th edition page | F11 evidence checklist guide |
| 31 August 2026 | Privacy Act tranche 2 exposure draft released; not law | Exposure draft, 31 August 2026 | automated decision-making post |
| 8 September 2026 | TGA amends the decision support exemption, effective 1 November 2026 | TGA news | TGA 1 November post |
| 15 and 17 September 2026 | Information Commissioner: ADM guidance "on the verge" | OAIC speech | automated decision-making glossary entry |
| 21 September 2026 | ANAO Report No. 5 of 2026-27: about one-fifth of software websites refer to AI; one suggests "the most lucrative combination of MBS item numbers" | ANAO report | ANAO AI billing post |
| 30 September 2026 | OAIC publishes its ADM guidance: APP guidelines chapter 1 version 2.0 (paragraphs 1.35 to 1.78), a fact sheet and a flowchart, reflecting "90 written submissions" | OAIC statement | automated decision-making post |
The next dated events are 1 November 2026 (the TGA change) and 10 December 2026 (the privacy policy duty). The map of every body that sets AI rules for a practice, from Ahpra to Medicare, is AI in healthcare compliance.
Frequently Asked Questions
Can Australian healthcare practices use AI tools like ChatGPT for patient information?
No, not on a personal or free account. The OAIC's October 2024 guidance recommends organisations "do not enter personal information, and particularly sensitive information, into publicly available generative AI tools". OpenAI may train on individual accounts unless opted out, and by default does not on ChatGPT Business, Enterprise, Edu or the API. A business plan still needs its contract checked against APP 8 and 11.
Does Australia's Privacy Act apply to overseas AI vendors used by healthcare practices?
Yes. Sending patient health information to an overseas AI vendor is a cross-border disclosure under APP 8 of the Privacy Act 1988. The practice must take reasonable steps to ensure the overseas recipient handles the information in compliance with the Australian Privacy Principles, or obtain the patient's express consent to the transfer.
What is the automated decision-making privacy disclosure deadline for healthcare practices?
10 December 2026. From that date, under the Privacy and Other Legislation Amendment Act 2024, privacy policies must disclose automated decision-making that could significantly affect individuals (APPs 1.7 to 1.9). Billing, triage, decision support and risk stratification systems may qualify. The OAIC published its guidance on 30 September 2026, and its fact sheet lists computer programs used to prioritise the provision of health or disability services among the decisions generally in scope.
What are the privacy risks of AI clinical scribes in Australian healthcare?
Four, mapped to the APPs. APP 1: a policy that does not mention the scribe is out of date. APP 8: transcripts sent overseas are cross-border disclosures. APP 6: vendor model training on consultation content is a secondary use. APP 11: a consumer-tier product is unlikely to meet the reasonable steps standard. Confirm training is off and the contract addresses each point.
What should be in an AI acceptable use policy for a healthcare practice?
The approved AI tools and tier for each, a ban on patient identifiable information in unapproved tools, how patients are told AI is used, de-identification rules, who assesses new tools, and staff training with a record. The AI acceptable use policy template sets these out.
Do the RACGP Standards now cover AI?
Yes. The 6th edition, published 26 August 2026, contains criterion F11: "F11.A Where the practice uses artificial intelligence, it does so safely and securely and consistent with existing standards." and "F11.B The practice assesses and evaluates its use of artificial intelligence." It applies only if the practice uses AI, administrative AI included, and is not yet assessable.
Is a patient's consent required before using AI to process their health information?
Yes, in practice. Ahpra says to "obtain informed consent from your patient, and ideally note the patient's response in the health record". Under APP 6 of the Privacy Act, using health information for its primary purpose, the patient's care, needs no separate consent; a secondary use such as vendor model training needs its own basis, usually consent. The consent form is the mechanism.