APP 9: NDIS numbers, Medicare numbers and other government identifiers
A practice must not adopt a government related identifier (such as a Medicare number or an NDIS number) as its own client identifier, and may use or disclose one only where that is reasonably necessary to verify identity, to meet its obligations to an agency, or is required or authorised by law, or another listed exception applies.
Privacy Act APP 9.1, APP 9.2
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Do not adopt a government related identifier as the practice's own identifier for a client, unless required or authorised by law or prescribed by regulations.
- Practice software configured to use its own client numbers
- Medicare or NDIS numbers used as the client ID in files and file names
Use or disclose a government related identifier only where reasonably necessary to verify identity for the practice's activities, to fulfil obligations to an agency or a State or Territory authority (for example claiming), where required or authorised by law, or another listed exception applies.
- A note of where identifiers are used (claims, NDIA requests) and the basis
- Identifiers printed on documents that do not need them
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| APP 9.1 | |||||
| APP 9.2 |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- APP 8.1, APP 8.2(a), (b), APP 8.2(c), (d)APP 8: client information that goes overseas
- APP 10.1, APP 10.2APP 10: keeping client information accurate and up to date
- APP 7.1, 7.4 to APP 7.8APP 7: newsletters and marketing to clients
- APP 11.1, APP 11.3, APP 11.2APP 11: securing client records and destroying them when no longer needed
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- APP 12.1, 12.4 to APP 13.3 to 13.5APP 12 and 13: client requests to see or correct their records
- APP 5.1 to APP 5.2(g) to (j)APP 5: the collection notice for clients
- s 26WE(2) to s 26WHNotifiable data breaches: the 30-day assessment of a suspected breach
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice