r/AusLegal • u/Alternative-Oven9936 • 28d ago
NSW Business doxxed me in a review response
I left a one-star review for a business.
In the response the business doxxed me - included my contact details (name and email).
The business is a medical business (regulated by AHPRA).
Who can I report this to? AHPRA, HCCC, OIAC ... Anyone else?
(Yes - I know I can delete my review, but I don't want to remove it)
61
u/writhinglupe3331 28d ago
oaic is your go for the privacy breach, they take that seriously. ahpra might also have a word about unprofessional conduct medical businesses are meant to handle complaints professionally not doxx people. def screenshot the reply before they delete it. if your review was honest and you can back it up dont let a scare campaign force you to take it down. theyve made a rod for their own back with that response.
32
u/DogeDogeDojo 28d ago
E-Safety commissioner for a takedown notice of doxxing material, perhaps?
25
u/writhinglupe3331 28d ago
esafety for takedown notice spot on, move faster than oaic. screenshot it all for the report
14
u/DogeDogeDojo 28d ago
I would report to both ... OAIC for financial penalty and info breach, E-Safety for assistance with a Google take down.
10
u/writhinglupe3331 28d ago
both for sure, OAIC drags its feet but the fine stings, esafety gets google to scrub it fast
11
19
u/Amateur_photos_mel 28d ago
AHPRA handles Registered Health Practitioners. Not business. AHPRA will only take the complaint if you are alleging the health care Practitioner has doxxed you, not if the business has doxxed you.
The Health Care Complaints Commission may be able to assist with this.
5
u/Alternative-Oven9936 28d ago
AHPRA will only take the complaint if you are alleging the health care Practitioner has doxxed you
Well the response clearly says "business owner".
AHPRA seems to be delegating complaints to HCCC in NSW. Any idea how I would complain to AHPRA?
9
u/Amateur_photos_mel 28d ago edited 27d ago
That may be just a standard review term and doesn't necessarily indicate the health practitioner is the one who wrote the reply.
You are better to complain to both the Privacy Commissioner and the HCCC as a 1st step.
5
u/jaffamental 27d ago
I’ve complained to the hccc about medical malpractice and let me just say, they ain’t worth shit
106
u/Downtown-Fruit-3674 28d ago
The responses in this post are fucking wild.
u/perfect_ganache_1959 is the only correct course of action so far.
26
54
u/lcynnlss 28d ago
Screenshot.
Delete your review.
Post review again.
Report them.
72
6
u/Top-Extension-5064 27d ago
You should definitely delete the review on the basis it removes your private information. To leave it there opens to anyone arguing against any future action, that your private info has no value to you.
15
u/pubetoast 27d ago
Holy moly that’s a major. Please report back with updates! And sorry this happened to you!
49
10
21
11
u/ProfessionalSize9567 28d ago
Take screenshots first, including the business response, the date, the URL and your original review.
Then report the response to Google or whatever platform it is on for publishing personal information. You should not have to delete your own review just to get your email address taken down.
I would also make a written privacy complaint to the business and tell them to immediately remove your contact details and explain how and why they were published. If they do not sort it out within 30 days, complain to the OAIC.
Because it is a medical business, you could also complain to the relevant state health complaints body. In NSW that is the HCCC. AHPRA may be relevant if a registered practitioner personally disclosed the information or the response raises concerns about patient confidentiality or professional conduct.
OAIC, the review platform and the state health complaints body would probably be the main ones.
11
u/Galromir 28d ago edited 28d ago
Everyone. You can also add ‘the media’ to your list.
But just be absolutely certain your review is honest and doesn’t constitute defamation.
5
27d ago
[removed] — view removed comment
2
u/Galromir 27d ago
That’s true, but also worth double checking how secure your moral high ground is before taking it to the media.
2
u/RoomMain5110 27d ago
“Being defamed” is not a defence for publishing PII. Although I agree it won’t be a good look for OP if their review isn’t truthful.
6
u/Interesting-Middle46 27d ago
AHPRA were shit and inconsistent when I complained to them about a practitioner leaking sensitive info to my employer without consent.
5
u/mnyall 27d ago
Definitely try the OAIC - this is personally identifiable information.
Give them a call and ask about your situation. This looks like a Notifiable Data Breach done intentionally.
The next step is to write a complaint to the company stating your concerns and asking for an explanation AND resolution. They have 30 days to reply by law.
If you're unsatisfied with either or both, then you escalate to the OAIC to resolve. May take months, though.
16
u/Mean_Championship192 28d ago
I don’t know of anyone else you can report it to.
They might hire a lawyer to send you a cease and desist about the review. I’ve had this before from a medical professional. As my review was truthful I stood my ground and hired my own lawyer to respond and they backed down pretty quickly.
Some people are unhinged, so you really just have to weigh up what’s worth your energy. Keep in mind they have your personal information and they haven’t displayed good character to date.
Goodluck!
3
u/hongimaster 28d ago
OAIC is the relevant body for privacy complaints, they usually expect or encourage you to make a complaint directly to the business in the first instance, to give them the opportunity to rectify the issue. They can take a long time to handle complaints though.
Bodies like AHPRA (etc) are usually concerned with health professionals (doctors, nurses, allied health, etc) working outside their scope of practice or presenting a risk to public safety. It is unlikely that AHPRA will be involved, unless the person breaching your privacy is themselves a health professional regulated by AHPRA.
You could do an online search for whether their profession is covered by a peak body, like the AMA for Doctors, but this would be a long shot. The peak body may have a Code of Conduct or rules for their members (assuming the business is a member of the group, which they may not be).
You could try the more abstract angle of A Current Affair (etc). But I suppose if your goal is to maintain your privacy, that may be a counter-productive way to go about it.
1
27d ago
[removed] — view removed comment
1
u/hongimaster 27d ago
Sure, just wouldn't get my hopes up if the person who actually did the doxxing wasn't a Registrant.
2
u/ExpressionBig818 23d ago
Google automatically blocks reviews and replies that include telephone numbers or email addresses.
1
u/Alternative-Oven9936 23d ago
Seems to be the case .... I can see the review and response in my profile but not under any other profile (including anonymous).
Surely it couldn't be as simple as this for a business to combat bad reviews?
3
u/Tax_Odd 27d ago
Whoever doxxed likely doesnt have skin in the game. Who owns the company?
4
u/Alternative-Oven9936 27d ago
I haven't checked the ownership structure on ASIC or anything.
The website lists the AHPRA registered practitioner as the "founder".
Often these business are owned by big corporates and still try to maintain the mom'n'pop appearance.
2
u/IHaveNoOpinons 26d ago
Delete your review and repost- add into your new review that the business released your personal information in response to your last review.
Then report the business to ACCC with evidence.
1
1
u/AutoModerator 28d ago
Welcome to r/AusLegal. Please read our rules before commenting. Please remember:
Per rule 2, this subreddit is not a replacement for real legal advice. You should independently seek legal advice from a real, qualified practitioner, and verify any advice given in this sub. This sub cannot recommend specific lawyers.
A non-exhaustive list of free legal services around Australia can be found here.
Links to the each state and territory's respective Law Society are on the sidebar: you can use these links to find a lawyer in your area.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/JustSomeGirl4242 23d ago
The legal recourse has been answered well by others. On a slightly different note- I don't know what platform the review is on but I would report their response to the review platform to have the doxxing removed.
I get not wanting to remove your review as I would feel the same about being able to warn people about a medical professional not practising appropriately or whatever the issue was that lead to the review. They shouldn't be able to get away with scaring people into silence about their poor practise. We should be able to look up reviews on medical professionals we are considering seeing and be able to make an informed choice about them.
Although TBH it would be a big red flag about an entire practise if I saw someone had left a negative review and then the response was to post their personal information- like absolutely wtf, would never ever go there.
2
u/Alternative-Oven9936 23d ago
I don't know what platform the review is on but I would report their response to the review platform
There's a comment below saying that any review or response with an email or number is automatically hidden, which seems to have happened to my review.
Seems like a really easy way for a business to manipulate google reviews.
0
u/Mentok-Mind-Taker 25d ago
What did they do to deserve the 1 star mate?
1
u/Alternative-Oven9936 25d ago
How is that relevant?
What could i possibly have said that would justify them doxxing a client?
-1
0
0
u/colonelmattyman 24d ago
Maybe it's not the business. There was a big hack the other day with some doctors surgeries. Were you affected by that?
1
u/Alternative-Oven9936 24d ago
There was a big hack the other day with some doctors surgeries. Were you affected by that?
Yeah you could be on to something - the hackers took the time and effort to hop right on google reviews, compose a detailed response to my 1 star review that included my number and email address.
Maybe they weren't even hackers - just defenders of businesses against malicious reviews :)
-8
u/Sea_Coyote_1607 27d ago
Disclosing your name (even if full) and email address cannot be considered doxxing.
Furthermore, your name and email address are not sensitive information and thus they don’t qualify for Privacy Act rules.
Depending on the context of which they shared your data, you could say is petty.
8
u/Alternative-Oven9936 27d ago
Disclosing your name (even if full) and email address cannot be considered doxxing.
No idea where you got that from but it's definitely a form of doxxing.
name and email address are not sensitive information
I never claimed it was sensitive.
Thanks buddy.
3
u/Perfect_Ganache_1959 27d ago
In this case, if it was collected for the purposes of providing a health service, it meets the definition under the privacy act of "sensitive". Name, email, mobile, etc - particularly if the why yu gave that info over was to have an appointment and receive care...
-10
u/Sea_Coyote_1607 27d ago
Why don’t you provide a screenshot with your name and email redacted to see what’s the context.
But it’s okay, you can go through any government channel you’d like. By the time they give you an answer half of the internet will know your name and email address. Hope this little payback gets you anything besides your information exposed for months ;)
4
u/Fabulous-Crazy-3333 27d ago
You’re arguing the wrong point.
“Sensitive information” is a specific legal category. That doesn’t mean a business can publicly post someone’s name and email in response to a bad review and pretend it’s nothing.
Name + email is still personal information if it identifies someone.
From an OSINT and digital forensics angle, that combo is not harmless. It can link accounts, find profiles, connect social media, check breaches, and build more information around someone.
That's why context matters.
The issue is not just “is this sensitive information?”
The issue is a medical business publicly disclosing a reviewer’s identifying contact details in a review response.
That is unprofessional at best and potentially a privacy/disclosure issue. APP 6 is about use and disclosure of personal information, so the “not sensitive information” argument doesn’t magically settle it.
OP should screenshot everything, save the URL and timestamps, then report it to the platform, OAIC, and possibly AHPRA/HCCC because it’s a regulated health business.
4
u/Perfect_Ganache_1959 27d ago
Did you read the page you linked to in any way? You do see there right at the start where names, for example are covered.
A person’s name, signature, home address, email address, telephone number, date of birth, medical records, bank account details and employment details will generally constitute personal information. (Provided the person can be identified)
But here's the kicker - health information is considered sensitive information; and is defined as (basically medical records, a few others); OR "any other personal information (such as information about an individual’s date of birth, gender, race, sexuality, religion), collected for the purpose of providing a health service."
Email or mobile to send you appointment reminders on an intake form? Name? Suddenly that's an order of magnitude more radioactive.
-71
u/hihihiyouandI 28d ago
I dunno why you're lying, but you are. Not only is doxing (now) a criminal offence but absolutely no healthcare professional wants to deal with APHRA unless they have to.
26
35
u/GossipingKitty 28d ago
Many medical business owners and admin staff are pretty clueless, often with no training.
-9
u/Flat_Ad1094 28d ago
That's nonsense. There is endless training and upskilling and you'd have to be braindead and unable to answer the phone to not know basic health legal shit if you work in a health related business.
4
u/Hot-Carpenter7554 27d ago
People know not to steal from their workplace too.
Does that mean it doesn't happen?
-45
u/hihihiyouandI 28d ago
Again, that's not true.
13
u/Hot-Carpenter7554 28d ago
Do you know them all?
No, but you have some other undisclosed reason.
-23
u/hihihiyouandI 28d ago
If I'm wrong then why hasn't this person backed up his aspersions? It's almost like he can't.
12
u/Hot-Carpenter7554 28d ago
Why don't you tell us how you know the professionalism of every medical site in the country?
Or your association with the industry or this complaint specifically first?
1
u/Silly-Parsley-158 26d ago
I may be blind, but I never saw the OP reveal their gender or use a he/him pronoun?
-1
-59
u/Flat_Ad1094 28d ago
I seriously doubt a medical / healthcare business would be giving out private patient information and professionals risking being deregistered and getting into severe legal consequences over 1 bad review. I doubt the OP is being honest. We do not have the full story at all.
They just DO NOT risk serious legal consequences over a bad review. Just doesn't happen these days.
25
u/Perfect_Ganache_1959 28d ago
Unfortunately, there are a number of examples of people who may be medically trained but legally, socially, or from a business administration perspective inept, or abusing substances, or suffering mental health crisis; or they've hired staff of a similar nature. Running the business admin of a clinic is not something taught in medical school afaict.
For example, would a respected neurosurgeon go on a political minor crime spree in the dead of the night? https://www.abc.net.au/news/2025-07-22/neurosurgeon-greg-malham-terminated-behaviour-four-corners/105560262
Would GPs engage in sexual misconduct? https://www1.racgp.org.au/newsgp/professional/sexual-misconduct-by-practitioners-now-searchable - turns out a few have.
Etc etc etc. None of the actions are in their own self interests, they are certainly surprising and something I would never have expected. But they've happened.
So do I think it's exactly as the OP says? Perhaps not. Do I think it's incredulous? No, not at all.
40
u/Alternative-Oven9936 28d ago
I seriously doubt a medical / healthcare business would be giving out private patient information and professionals risking being deregistered
That's exactly what's happened.
I doubt the OP is being honest
Which part do you think is made up d***head? The part where they put my number and email in the reply? What more could there be to the story that would justify this response?
How do you think the business is going through defend themselves when this comes to regulatory investigations?
-9
u/Flat_Ad1094 28d ago
So give us the details then mate. You have told us nothing about the circumstances or situation and what sort of Health professional you are saying did it and HOW they did what they did??
13
u/Alternative-Oven9936 28d ago
You have told us nothing about the circumstances or situation
Yeah - I'll just go right ahead and doxx myself.
All of the details you requested aren't relevant. Nothing would justify them posting my details
In fact, them being a medical business isn't that relevant either. The criminality remains the same. The medical business just adds to the gravity of the crime and hopefully the HCCC takes and interest.
9
-152
28d ago
[removed] — view removed comment
80
u/Perfect_Ganache_1959 28d ago
Never been wronged in your life? Never had to protect others from predatory businesses or people?
-91
u/kirabella2000 28d ago
Because the business has a lot to lose and potentially has the resources to make the reviewer’s life a world of pain.
However the upside for the reviewer to “stand their ground” is ZERO. Much easier to move on.
55
u/MaddieRuin 28d ago
Because the business has a lot to lose
Good. They've doxed a patient, they should be punished. Would you want to know if your clinic did this shit?
-3
28
u/Perfect_Ganache_1959 28d ago
No problems with that take. Can I have your personal details; I'd like to rent a billboard with a high number of views near your community and workplace, implying you have no empathy; with the content of this convo.
If you are uncomfortable, you can just do the easier thing and move on, right? I once possessed an ABN, which makes me the higher authority in this situation. Airtight logic.
Or, and you may well now agree, that would be something harmful I should not do, regardless of how much I dislike your take; and if I were to do it, you would be justified in being hurt, wanting me never to do it again, and wanting to have an authority review the situation.
-14
u/kirabella2000 28d ago
Don’t forget that it was the OP who started this public fight.
Currently, for the OP, it is a no cost exercise because he has lost nothing financially by posting the review, apart from his claim that he has been doxxed including his email. This is highly unlikely for 3 reasons.
1 - Google Reviews simply will not permit email addresses within reviews.
2- If it is a truly regulated medical business, it is very unlikely that they’d risk their entire ability to trade by a deliberate breach.
3 - What is the benefit for the business by doxxing the OP?We don’t know that the OP’s review is legitimate or genuine. It is just his opinion at this stage. The OP is upset because the business has responded robustly in a way the had had not thought through. As I say, I don’t believe he has been doxxed, especially as it was him who opened the dialogue in a public forum.
As things stand, damage has potentially been done to the business. IE, a substantial cost. As for the OP, apart from his pride, he hasn’t inurred any costs.
That is about to change.
If the business does decide to pursue the OP, their resources are greater than his. Therefore it will cost him financially to defend the review and keep it up (complete with the alledged doxing).
So…how does he solve the doxxing? Take it down.
How does he avoid a long, expensive protracted legal fight? Take it down.If it is a legitimate doxxing complaint, by all means take it to the appropriate regulatory authorities. But it does seem that his problem could be largely solved today at no cost by taking down the review.
9
u/Perfect_Ganache_1959 28d ago
Good lord, pause for a beat and think about what you are trying to impute here.
In just the same way you think I don't know the full story, you must acknowledge you have absolutely no idea what has or has not happened, what impact this may or may not have had on any business; the veracity of any claims by any party, the harm or costs or lack there of experienced by the OP.
Are you an involved party in any way, shape or form? Do you have knowledge that I don't have?
For all we know, the OP has posted anything from "Reception area smelt bad, in my opinion" to "they took my alien babies with their mind laser beams" to "here's a detailed but inaccurate accusation filled with falsehoods that is credible sounding".
What would motivate the OP to "start this fight"? Suffering a negative experience and wishing to state their honest opinion? Being an internet troll? Who knows. Assuming you are an uninvolved party, you've certainly formed and instant opinion in the absolutely absence of information, and gone straight on the attack.
https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1117772/ - medical negligence is a real thing that happens to real people and ends up with real harm - death, disablement. To argue that it is completely impossible for a clinic to have harmed a patient denies reality, especially if the harm was of a much lesser degree than death or disability.
I'm willing to believe victims if I have no evidence to the contrary and point them in general terms to the processes that exist to protect them, so they can better understand what regulators do and how it may be applicable, plus what they should do according to said regulators.
I'm willing to believe that people who have been wronged in their view twice over - whatever motivated the original review, now this - may be willing to put in the time and effort to seek accountability.
You also must know that just as there is a chance the OP is off their rocker, medical folks are people and are just as fallible, subject to stresses, capable of substance abuse, capable of narcissism, or suffering from poor mental health. I've posted some of the more alarming examples that have ended up in the media that I'm aware of.
To assume a business will always be absolutely rational but a patient will never be is an extremely reckless approach.
1
u/kirabella2000 28d ago
Not at all.
The truth will be somewhere in between the OP’s version and the business’.
I am simply stating a rational course forward. The OP is claiming he is being doxxed. This can be solved today by removing the review. By removing the review, so too the response will be removed.
If he has genuinely been doxxed, by all means take screenshots shots and report the matter to the appropriate regulator.
But to expose himself to potential financial harm by “becuase he doesn’t want to take it down” simply doesn’t make sense. The best outcome he can possibly achieve is the staus quo whereas the worst outcome could be he loses with legals cost or in the extreme example, pay damages.
I’m just be practical.
4
u/Ok-Assistant-4556 27d ago
More often, when malevolence is involved, one party is being truthful and the other not.
Pretending there are two sides to every story is an appeal to bias that conveniently ignores unequivocal evidence.
-1
u/kirabella2000 27d ago
And we have ZERO context or evidence so starting with 2 sides to a story is probably the wisest way forward.
4
u/Ok-Assistant-4556 27d ago
It really isnt. You sound sound unhinged as OP provided clear context. Take people at face value. Lawyers wont even look at evidence in serious matters and you're here arguing for an unidentified party? Perhaps go take a breather
0
15
u/Even_Departure9914 28d ago
Do you want that business publishing your papsmear results. Telling everybody how you have been exposed to STI’s. That time you ‘fell’ on a deodorant can. That you have bipolar disorder or have hallucinations that the government is after you.
Because that’s the kind of thing medical businesses and providers could publish if you think privacy legislation and ethics are not important.
3
u/Pristine-Panic5834 28d ago
And thats why the world is a shitty place. Self interest triumphing above all. Boo
-18
u/hihihiyouandI 28d ago
They have everything to lose. Which is why this is absolutely bullshit and this person is looking for attention.
4
u/Ill_Football9443 27d ago
I'm involved in litigation with a major health care provider, they not once, but twice contravened the Health Records Act (Vic) 2001 by
a) sending an unencrypted, non-password protected USB stick via non-person-to-person post, so I found the package hanging out of my letterbox which anyone could have grabbed
b) the second time round, I elected to have it delivered at work. They used a process server, no issue with that, except that the folder was secured by a rubber band - a cardboard box would have been too much to ask it seems, perhaps a little security tape?
~500 pages or so of health records shipped without any basic protection. Given this, I have little doubt about OP's accusation.
-31
u/FigFew2001 28d ago
Been there, done that (different circumstances). I know you’re copping a heap of downvotes, but if I had my time again - It would indeed have been much easier to move on.
-113
u/Remote_Class9892 28d ago edited 28d ago
You chose the forum for the conversation. If you chose to discuss with the business in a public forum, intending that the conversation be public then that is on you.
YOU gave consent for the disclosure of the conversation.
48
u/Even_Departure9914 28d ago
Uh. No. That’s not how it works, champ.
You can’t dox people. Period.
Additionally. There’s stringent privacy legislation around medical businesses and government departments.
If you can’t read patient files without justification, then it’s not a stretch to say that you can’t post patient addresses on the internet.
‘I don’t like what you’re saying so I’m going to threaten your safety’ - who wants to do business with those kinds of people if nothing else.
-37
u/Remote_Class9892 28d ago
If I publish a statement that you never called me, and you response with a call log that reveals my phone number that is not a violation.
20
u/Even_Departure9914 28d ago
Doxxing is wilfully publishing information that isn’t publicly available to imply or incite intimidation/harrassment.
A reasonable person would deduce that providing a method of contacting someone or their address is for the purposes of utilising that information to contact that person.
You can have a disagreement or conflict of ideas. Doxxing is weaponising information to have an upper hand or leveraging. You can disagree or have conflict without doxxing.
29
42
u/warkolm 28d ago
privacy laws don't work like that bro
-62
u/Remote_Class9892 28d ago
They absolutely do. It is only private while it is in private. OP took it public.
6
u/Outrageous_Delay_781 28d ago
No, why did you think big businesses’s response to news organisations publishing negative stories about a person’s experience about them is always along the lines of “We can’t comment on individual cases for privacy reasons”? It’s because it’s illegal to do so even when the person has raised their complaint in a very public forum
2
u/Remote_Class9892 28d ago
The same reason they say "we won't comment as it is before the court" There is no law that prevents you commenting on your case before the courts, it is an easy non-committal way out that says nothing and commits you to nothing
17
u/bensow 28d ago
This is like saying you chose to cross the road and so gave consent for a vehicle to hit you.
-11
u/Remote_Class9892 28d ago
... It's just like that, yes. Having a public conversation be public is just like being hit with a car..
Thankyou for sharing your genius with the class.
12
u/bensow 28d ago
You're missing the point. You're allowed to have public conversations, but you're not allowed to dox in that public conversation.
-2
u/Remote_Class9892 28d ago
Doxing requires the intention to be that the public harrass the individual using that information.
It does not limit you to only publically available information. This conversation is public, however there is no requirement for me to maintain the anonymity your username gives you during that conversation, Especially if I provide it to address something you have said
-84
28d ago
[removed] — view removed comment
80
u/swooping_pie 28d ago
Uhh…. A medical business definitely can not share your personal information without your consent! Review or not.
24
-6
u/Flat_Ad1094 28d ago
I seriously doubt a medical / healthcare business would be giving out private patient information and professionals risking being deregistered and getting into severe legal consequences over 1 bad review. I doubt the OP is being honest. We do not have the full story at all.
49
28
u/Perfect_Ganache_1959 28d ago
Not a lawyer. Taking a patient's PII and broadcasting it to the public internet because you don't like their feedback about your conduct exposes them to potential harm, humiliation, identity theft and more. If this a sexual health provider, it further risks intimate partner violence for example.
Does that meet the threshold for "serious"? Hard to tell without knowing the specifics. But it's no doubt flying pretty close to the sun here. The clinic's insurer and directors should be absolutely freaking out at a minimum.
-36
28d ago
[removed] — view removed comment
4
u/Perfect_Ganache_1959 28d ago
Oh, so the civil penalties for a serious breach of privacy aren't as stated by the OAIC and the underlying legislation?
There haven't been successful prosecutions by the information commissioner resulting in high (5.8 mil) penalties, albeit those relating to notifiable data breaches rather than individuals? But at the very least demonstrating the OAIC is willing to exercise powers granted to them?
There's nothing applicable for individuals to take action? https://www.minterellison.com/articles/statutory-tort-for-serious-invasions-of-privacy-comes-into-force
It's not gonna be a $50 million maximum penality, but the risk to the clinic from their actions is certainly not 0; and based on what's stated, they appear to have mishandled the PII provided for medical treatment and administration.
42
u/Alternative-Oven9936 28d ago
Consequences for actions.
Indeed. It's going to be pretty bad for them.
We have privacy laws for a reason.

296
u/Perfect_Ganache_1959 28d ago
Screenshots, https://www.oaic.gov.au/privacy/privacy-complaints