Company: Audri Pty Ltd
Effective Date: 16 February 2026
Responsible Officer: CTO
1. Purpose
The purpose of this plan is to ensure Audri Pty Ltd ("Audri") can contain, assess, and manage data breaches effectively. As a medical application handling sensitive health information, Audri has a heightened responsibility to protect patient trust and safety. This plan outlines the steps to minimise harm to affected individuals and ensure compliance with the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme.
2. What is a Data Breach?
A data breach occurs when personal or sensitive health information held by Audri is:
- Accessed without authorisation (e.g., an employee viewing patient records they shouldn't, or an external hack).
- Disclosed without authorisation (e.g., sending a medical report to the wrong email address, or accidental publication of data).
- Lost (e.g., loss of a laptop or USB drive containing unencrypted patient data).
3. Data Breach Response Team (DBRT)
For a medical app company, speed is critical. The DBRT should be convened immediately upon suspicion of a breach.
| Role | Responsibility | Contact |
|---|---|---|
| Team Leader / Privacy Officer | Oversees the response, makes the final decision on notification, liaises with the OAIC. | On File |
| Technical Lead (CTO/IT) | Secures systems, identifies the technical cause, executes containment (e.g., resetting passwords, patching). | On File |
| Communications / Support | Manages communication with affected users (doctors/patients) and media if necessary. | On File |
| Legal Advisor | Advises on regulatory obligations and liability. | On File |
4. Response Process: The 4 Steps
Audri Pty Ltd follows the OAIC's four-step process. These steps often happen continuously or simultaneously.
Step 1: Contain the Breach (Immediate Action: 0-24 Hours)
Objective: Stop the data leak and limit further access.
- Immediate Trigger: Any staff member who suspects a breach must notify the Privacy Officer immediately.
-
Technical Containment:
- Take affected systems offline or suspend access to the specific accounts involved.
- Revoke access privileges or reset passwords for compromised accounts.
- Remote wipe lost devices (if applicable).
- If a coding error caused the leak, deploy a hotfix immediately.
-
Non-Technical Containment:
- If data was sent to the wrong recipient, contact them immediately to ask them to delete it and confirm destruction in writing.
- Secure physical areas if physical files are involved.
Step 2: Assess the Risks (Assess within 30 days)
Objective: Determine if this is an "Eligible Data Breach" that requires mandatory notification.
The Privacy Officer must answer: Is this breach likely to result in serious harm to any of the individuals to whom the information relates?
- Consider the Data: Is it sensitive medical history, Medicare numbers, or demographic information? (Health data almost always carries a higher risk of "serious harm").
- Consider the Cause: Was it malicious (hack) or accidental? Malicious breaches generally carry higher risk.
- Consider the Protection: Was the data encrypted? If yes, and the key is secure, the risk of harm may be low.
Assessment Framework:
- Initiate: Gather facts (what data, who is affected, how long it was exposed).
- Evaluate: Use the "Reasonable Person" test. Would a reasonable person conclude that serious harm (physical, psychological, emotional, financial, or reputational) is likely?
- Conclusion: Document the decision. (See Appendix A: Assessment Template).
Step 3: Notify (If Required)
Objective: Inform affected parties so they can protect themselves.
If "Serious Harm" is likely (and cannot be remediated), you MUST notify:
-
The Individuals:
- Notify all affected users OR only those at risk of serious harm.
- Method: Email, push notification, or phone call (most direct method preferred).
-
Content:
- Audri Pty Ltd contact details.
- Description of the breach.
- Type of information involved (e.g., "Your name and pathology results").
- Steps Audri has taken to fix it.
- Crucial: Steps the individual should take (e.g., "Change your password," "Check bank statements").
-
The Regulator (OAIC):
- Submit the Notifiable Data Breach Form via the OAIC website.
-
Other Bodies (If Applicable):
- Cybersecurity: If it is a cybercrime (ransomware/hacking), report to the Australian Cyber Security Centre (ACSC) via ReportCyber.
- Police: If theft is involved.
- Insurers: Contact Audri's cyber insurance provider.
Step 4: Review and Prevent
Objective: Learn from the incident.
- Post-Incident Review: Conduct a "lessons learned" meeting within 7 days of resolving the breach.
- Update Security: Implement Multi-Factor Authentication (MFA), update encryption standards, or patch software vulnerabilities found during the breach.
- Training: Retrain staff on the specific error that led to the breach.
- Audit: Review this Response Plan and update it based on what worked and what didn't.
5. Specific Scenarios for Medical Apps
| Scenario | Specific Action |
|---|---|
| Accidental Email/Share | If a patient's report is sent to the wrong doctor: Contact the recipient immediately. If they are a trusted medical professional who confirms deletion, "Serious Harm" might be avoided, and notification may not be required. |
| Ransomware Attack | Do not pay. Disconnect backups immediately to prevent encryption of backup files. Contact ACSC. Assume data has been exfiltrated (stolen) even if just locked. |
| Lost Device | If a mobile device or laptop with app access is lost, initiate remote wipe immediately via Mobile Device Management (MDM) software. |
6. Testing and Maintenance
- Testing: This plan will be tested annually using a "tabletop exercise" (a hypothetical breach scenario, e.g., "A doctor's iPad with the Audri app is stolen").
- Availability: All staff must know where to find this document.
Appendix A: Breach Assessment Checklist
- ☐ Date/Time Discovered: __________________
-
☐ Type of Data:
- ☐ Name/Contact/Demographics
- ☐ Medical/Clinical
- ☐ Medicare/Financial
- ☐ Passwords
- ☐ Number of People Affected: __________________
-
☐ Risk of Serious Harm:
- ☐ Physical/Safety: (e.g., domestic violence concerns if address revealed?)
- ☐ Financial: (e.g., credit card or Medicare fraud?)
- ☐ Emotional: (e.g., embarrassment from sensitive diagnosis leak?)
-
☐ Can we remediate? (e.g., Can we remote wipe the device before access? Can we recall the email?)
- ☐ Yes. If so, how? __________________
- ☐ No
-
☐ Decision:
- ☐ Notify OAIC & Users
- ☐ Do Not Notify (Document Reason) __________________
Key Links for the Response Team:
- OAIC NDB Form: https://www.oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach
- ReportCyber (ACSC): https://www.cyber.gov.au/report-and-recover/report