Allied Health NDIS Audit Checklist
PrivacyPrivacy Act: the Australian Privacy Principles and notifiable data breachesprivacy-act--privacy-act-health-service-providers
Requirement

Does the Privacy Act apply to an allied health practice?

A business with an annual turnover of 3 million dollars or less is usually a small business operator outside the Act, but not if it provides a health service and holds health information other than in an employee record. Assessing, treating, managing or recording a person's physical or psychological health is a health service, and so is that activity in disability care. An allied health practice of any size is therefore covered.

Clause

Privacy Act s 6D(1), (3) to s 6(1) health information, sensitive information

Regulator

Office of the Australian Information Commissioner

Edition held

Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)

Checked current

6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026

Who it applies to

Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.

Under review, not in force

From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

s 6D(1), (3)A small business is one with an annual turnover of 3,000,000 dollars or less for the
Requirement, our statement of the clause

A small business is one with an annual turnover of 3,000,000 dollars or less for the previous financial year; a small business operator carries on only small businesses.

Evidence an auditor or the regulator asks for
  • The practice's turnover for the previous financial year, if the practice relies on any part of the small business test for other activities
Common gap to check
  • Assuming the practice is exempt because its turnover is under 3 million dollars
s 6D(4)(b)An entity is not a small business operator if it provides a health service to another
Requirement, our statement of the clause

An entity is not a small business operator if it provides a health service to another individual and holds any health information except in an employee record. Such an entity is an organisation bound by the Australian Privacy Principles whatever its turnover.

Evidence an auditor or the regulator asks for
  • A written note, kept with the privacy policy, that the practice provides health services and holds health information, so the Australian Privacy Principles apply
Common gap to check
  • No one in the practice has recorded which privacy obligations apply
  • Treating client notes as exempt because the practice is small
s 6FB(1), (3)A health service is an activity intended or claimed to assess, maintain, improve or
Requirement, our statement of the clause

A health service is an activity intended or claimed to assess, maintain, improve or manage a person's health, diagnose or treat an illness, disability or injury, or record a person's health for those purposes; health includes physical and psychological health, and such an activity in aged care, palliative care or disability care is a health service.

Evidence an auditor or the regulator asks for
  • A list of the services the practice provides (assessment, therapy, reports) mapped to the health service definition
Common gap to check
  • Non-clinical services (for example NDIS support coordination or reports) assumed to fall outside the Act
s 6(1) health information, sensitive informationHealth information, including information about a person's health or disability and
Requirement, our statement of the clause

Health information, including information about a person's health or disability and personal information collected to provide a health service, is sensitive information, which the Australian Privacy Principles protect more strictly (for example APP 3.3 and APP 6.2(a)(i)).

Evidence an auditor or the regulator asks for
  • A data inventory listing where health information is held: client records, referral letters, NDIS plans and reports, email and messaging
Common gap to check
  • Health information held in email, text messages or personal devices left out of the inventory
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
s 6D(1), (3)
s 6D(4)(b)
s 6FB(1), (3)
s 6(1) health information, sensitive information

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

Privacy Act: the Australian Privacy Principles and notifiable data breaches

The same topic in other instruments (privacy and records)

See every requirement for your practiceSee the specimen practice