Healthcare Providers
A GP, psychologist, or hospital staff member may disclose a diagnosis, treatment history, or mental health record to a patient's family member, employer, or insurer without the patient's consent. Under the Australian Privacy Principles (APPs), health service providers are APP entities regardless of their turnover, which means a complaint to the OAIC is available in these cases. However, where the disclosure was intentional or reckless and sufficiently serious, the statutory tort provides a direct path to civil privacy damages, including compensation well beyond what the OAIC typically awards.
Employers and Workplace Disclosure
Employers sometimes obtain medical information through pre-employment checks, workers compensation claims, or fitness-for-duty assessments. The disclosure of that information to managers, colleagues, or third parties who have no legitimate need to know it can constitute a serious invasion of privacy. The APPs contain an employee records exemption: acts and practices of an employer that relate to an employee record are exempt from the APPs. The statutory tort contains no equivalent exemption. If your employer disclosed your health information to people who had no proper reason to receive it, the statutory tort may be the only viable civil remedy.
Insurers
Health and life insurers hold detailed medical information provided during the underwriting process. Unauthorised disclosure of that information, whether to third-party assessors, affiliated companies, or former partners in the context of a disputed claim, may give rise to liability under both the APPs and the statutory tort.
Former Partners and Associates
In relationship breakdowns, former partners sometimes disclose sensitive health information (mental health diagnoses, substance use history, sexual health records) to mutual acquaintances or family members. The OAIC has no jurisdiction over individuals acting in a personal capacity. The statutory tort addresses this gap. Where the disclosure involves publication online, the principles regarding private information published without consent apply.
Evidence You Should Preserve
If you believe your medical records have been disclosed without your consent, preserving evidence is critical. Take screenshots of any online posts before they are removed. Keep copies of text messages, emails, or letters in which the information was communicated. Record the date you first became aware of the disclosure: this is when the limitation period begins to run. If you received the information verbally, make a file note of the conversation as soon as possible, including the date, time, who was present, and what was said. Do not confront the person who disclosed the information before obtaining legal advice, as this may compromise your position.
The Seriousness Threshold
Not every unauthorised disclosure of medical information will meet the threshold for the statutory tort. The invasion must be serious, and the defendant's conduct must have been intentional or reckless. An accidental inclusion of medical details in a misdirected email, while distressing, is unlikely to satisfy the fault element. However, a deliberate disclosure of a patient's HIV status to their workplace, or a former partner's calculated revelation of a mental health diagnosis on social media, is within the scope of the tort. The court considers specific factors to determine if the seriousness threshold is met.