30 días de prueba de riesgos de IA generativa -Empezar ahora
Ir al contenido principal
AI Governance · Healthcare Australia · 2026

AI Governance forAustralian Healthcare

A practical guide for healthcare CIOs and privacy officers navigating the My Health Records Act, Privacy Act, TGA medical device regulations, and the risks of clinical and administrative AI in hospitals, clinics, and aged care facilities.

My Health Records Act
health data obligations
TGA SaMD
clinical AI regulation
Privacy Act APPs
sensitive health info
NDB Scheme
assessment and notification
En esta guía
Illustrative Risk Scenario

The Nurse & ChatGPT: A Privacy Breach Waiting to Happen

A registered nurse on a busy hospital ward needs to complete a discharge summary before end of shift. Short on time, she opens ChatGPT and types:

Prompt: "Write a discharge summary for John Smith, 67, admitted 14 March with acute MI. Medications: aspirin 100mg, atorvastatin 40mg, metoprolol 25mg BD. Treating cardiologist Dr. A. Nguyen. Patient to follow up in 6 weeks. Home to wife, independent ADLs."

What just happened: Identifiable health information has been entered into an unapproved external AI service. Assess the authority for disclosure, service settings, processing location and applicable privacy obligations. The prompt alone does not establish whether consent or another legal basis existed.

Privacy Risk
Assess APP 6 use and disclosure, and APP 8 where overseas disclosure is involved
NDB Obligation
Take reasonable steps to assess within 30 days; notify as soon as practicable when required
Governance Gap
Clear policies, staff training and approved tools support safer handling of patient information

Clinical AI Risks

AI in clinical settings introduces patient safety, regulatory, and liability risks that administrative AI governance frameworks alone cannot address.

Diagnostic AI & Clinical Decision Support

AI tools used in radiology, pathology and clinical decision-making may meet the definition of a medical device depending on their intended purpose and functionality. Unless excluded or exempt, a medical device generally needs inclusion in the ARTG before supply. Clinical validation and applicable post-market responsibilities remain important to patient safety.

TGA non-compliance + patient harm liability if AI diagnostic errors are not governed.

AI Treatment Recommendations

Generative AI used to suggest treatment protocols, medication dosages, or care pathways without appropriate clinical oversight creates accountability gaps. When a clinician acts on an AI recommendation that results in patient harm, questions of responsibility, and insurance coverage, become complex without clear governance documentation.

Unvalidated AI treatment recommendations create uninsurable clinical liability gaps.

Autonomous AI in Care Coordination

AI agents increasingly assist appointment scheduling, patient triage, discharge planning and referral coordination. Assess uses in aged care and mental health against clinical safety and duty-of-care obligations. From 10 December 2026, qualifying automated decisions also require privacy-policy transparency under APP 1.

Assess care-coordination AI for clinical safety and applicable ADM transparency obligations.

Administrative AI Risks

The greatest volume of AI-related health privacy breaches comes not from clinical AI, but from staff using general-purpose AI tools in their daily workflows.

The nurse + ChatGPT scenarioHigh, assess privacy impact and notification obligations

ChatGPT for Patient Notes & Discharge Summaries

A nurse in a busy ward uses an unapproved public ChatGPT service to draft a discharge summary, entering the patient’s name, date of birth, diagnosis, medications and treating physician details. This creates serious health-information risks. The hospital should contain the incident and assess the service arrangements, authority for disclosure, applicable privacy laws and any data-breach notification obligations.

Ambient AI recording consultationsHigh, assess overseas disclosure and health-privacy obligations

AI Medical Scribes & Clinical Documentation

Ambient AI scribes listen to patient-clinician consultations and generate clinical notes. Providers should assess consent, data handling, vendor arrangements and applicable health-privacy obligations, including where recordings are processed. My Health Records Act requirements depend on whether and how the system’s information is involved.

Clinical research via ChatGPT/ClaudeMedium, data minimisation obligations under APP 3 may be breached

Medical Staff Using Consumer AI for Research

Medical staff searching for treatment evidence, drug interactions, or clinical guidelines using general-purpose AI tools may inadvertently include patient-specific context in their queries, e.g., 'my patient has condition X and is on medication Y, what dose adjustment is appropriate?' This patient-identifiable query is processed by an external AI service not covered by any BAA or data processing agreement.

Patient billing and insurance claimsMedium, Medicare numbers are sensitive data under expanded Privacy Act

Administration Staff & Billing AI Tools

Administrative staff at hospitals and clinics are adopting AI tools to process insurance claims, manage Medicare billing, and draft correspondence. These tools often require patient health and financial data as input. Without data classification controls, staff may use unapproved AI tools that expose Medicare numbers, private health insurance details, and sensitive diagnosis codes.

Australian Healthcare AI Regulatory Framework

Healthcare AI in Australia sits at the intersection of multiple regulatory regimes. Understanding each obligation is the first step to effective governance.

My Health Records Act 2012All Healthcare Providers

Health Data Sovereignty

The My Health Records Act governs collection, use and disclosure within the My Health Record system. Authorised access and handling are required. OAIC explains that, after lawful download to a provider’s local system, most My Health Records Act rules no longer govern subsequent handling; the Privacy Act, state or territory privacy laws and professional obligations apply instead.

Privacy Act 1988, Health RecordsAll Organisations

Sensitive Information & APP Compliance

Health information is sensitive information under the Privacy Act. Relevant obligations include APP 3 collection requirements, APP 6 use and disclosure, APP 8 overseas disclosure and APP 11 security. From 10 December 2026, qualifying automated decisions using personal information also require privacy-policy transparency about the relevant information and decision types.

TGA, Software as a Medical DeviceClinical AI Tools

AI Medical Device Regulation

The TGA regulates software that meets the medical-device definition unless it is excluded. Medical-image analysis, diagnosis support, treatment recommendations and clinical-outcome prediction should be assessed by intended purpose and functionality. ARTG inclusion is generally required before supply unless an exclusion or exemption applies, with applicable assessment and post-market obligations.

Aged Care Act 2024Aged Care Providers

Aged Care AI Obligations

The Aged Care Act 2024 commenced on 1 November 2025, alongside strengthened Aged Care Quality Standards. Providers using falls prediction, care-planning or medication-management AI should assess its role in safe, person-centred care, with appropriate human oversight and consent processes.

Learn more about AI governance and compliance frameworks

Healthcare AI Governance Framework

A practical five-step framework for hospitals, clinics, and aged care providers building AI governance programs that satisfy the OAIC, TGA, and accreditation bodies.

01

AI Tool Inventory & Risk Classification

Map every AI tool in use across your health service, clinical, administrative, and research. Classify each by risk level: clinical AI (TGA obligations), tools processing health records (Privacy Act/My Health Records Act), and general productivity AI used by staff. Shadow AI discovery is essential, most hospitals significantly underestimate AI tool adoption.

Aona discovers observed AI activity on supported, deployed endpoints
02

Patient Data Protection Policies

Implement controls that prevent patient-identifiable health information from entering unapproved AI tools. This includes technical controls (DLP policies that detect health identifiers, Medicare numbers, diagnosis codes), staff policies, and approved-tool lists. Prevention is far less costly than NDB notification and OAIC investigation.

Block patient data from reaching unapproved AI, automatically
03

Clinical AI Governance Committee

Establish a governance committee including CMO/CNO, privacy officer, IT security, legal counsel, and clinical leads. This committee approves clinical AI tools, reviews TGA compliance, oversees incident response, and provides the board-level accountability that regulators increasingly expect from health services.

Document governance to support privacy, clinical safety and accreditation reviews
04

Staff Training & Consent Frameworks

Train all clinical and administrative staff on what health information can and cannot be shared with AI tools. Establish patient consent processes for any AI use that affects care decisions. Document consent in clinical records. Training logs and policy attestations are critical evidence in any regulatory investigation.

Training records + policy attestations reduce regulatory risk significantly
05

Incident Response & NDB Procedures

Document an AI-specific incident response procedure covering containment, assessment, notification and evidence preservation. Under the Privacy Act NDB scheme, take all reasonable steps to assess a suspected eligible breach within 30 days. Notify the OAIC and individuals at risk of serious harm as soon as practicable when an eligible breach requires notification.

Assess promptly; notify as soon as practicable when required

How Aona Protects Australian Healthcare Organisations

Secure clinical and administrative staff’s AI use with visibility, sensitive-data controls and evidence for your governance program.

Shadow AI Discovery in Healthcare Settings

Discover observed staff AI activity on supported browsers and desktop paths, including unapproved tools. Aona’s browser extension or native app must be deployed on the relevant endpoints.

Patient Data Protection Controls

Apply policies to detect and block sensitive patient information in prompts and files on supported AI paths. Configure and validate the controls for your health service’s requirements.

Audit Trails for OAIC & Accreditation

Use observed activity and policy-event records to support privacy investigations, governance reviews and accreditation work. These records complement the health service’s wider evidence and obligations.

Policy Enforcement Across Clinical Workflows

Roll out employee AI-use policies across clinical and administrative teams on supported, managed endpoints. Apply approved-tool access and sensitive-data controls with clear staff guidance.

Sources and further reading

FAQ

Frequently Asked Questions

Does the My Health Records Act apply to AI tools used at our hospital?
The Act restricts collection, use and disclosure of information within the My Health Record system. Its application depends on how information is accessed and handled. OAIC guidance explains that, after information is lawfully downloaded to a provider’s local system, most My Health Records Act rules no longer apply to its subsequent handling; the Privacy Act, relevant state or territory laws and professional obligations apply instead. Assess the proposed AI use and its legal authority before sharing health information.
What happens if a nurse uses ChatGPT to write a patient's discharge summary?
Entering identifiable patient information into an unapproved public AI service creates serious privacy risks. Whether it breaches a legal obligation depends on the information, authority for its use or disclosure, service arrangements and applicable laws. OAIC recommends not entering personal information, especially sensitive information, into publicly available generative AI tools. If an incident occurs, contain it and assess the applicable data-breach notification requirements.
When does AI used in healthcare need TGA registration?
AI software that meets the definition of a medical device generally needs inclusion in the Australian Register of Therapeutic Goods before supply, unless an exclusion or exemption applies. Intended purpose and functionality matter; general administrative software is not automatically a medical device. Examples to assess include medical-image analysis, diagnosis and treatment recommendations, and clinical-outcome prediction. If in doubt, seek TGA regulatory advice before deploying clinical AI.
How does the Privacy Act's automated decision-making requirement affect healthcare AI?
From 10 December 2026, APP entities must add information to their privacy policies where a computer program uses personal information to make, or substantially and directly assist, decisions reasonably expected to significantly affect an individual’s rights or interests. The policy must describe the relevant kinds of personal information and decisions. Healthcare organisations should assess uses such as triage or eligibility decisions against these criteria. These amendments introduce transparency obligations, not a general new right to contest every AI-generated decision.
What governance does Aona provide for healthcare AI compliance?
Aona helps health services secure employees’ AI use through visibility, policy enforcement and sensitive-data protection on supported browser and desktop paths. Policy events, audit records and board-ready reports support privacy and governance reviews. Coverage depends on deployed endpoints, supported tools and configuration. These controls complement clinical governance, legal assessment and accreditation work.

Protect Patient Privacy Before the Next AI Breach

Understand staff AI use, apply patient-data protection controls and build evidence for governance reviews with Aona’s supported browser and desktop coverage.

AI Governance for Healthcare Australia (2026) | My Health Records Act, TGA & Privacy Act | Aona AI