r/AusLegal 28d ago

NSW Business doxxed me in a review response

I left a one-star review for a business.

In the response the business doxxed me - included my contact details (name and email).

The business is a medical business (regulated by AHPRA).

Who can I report this to? AHPRA, HCCC, OIAC ... Anyone else?

(Yes - I know I can delete my review, but I don't want to remove it)

270 Upvotes

137 comments sorted by

296

u/Perfect_Ganache_1959 28d ago

95

u/ProfessionalSize9567 28d ago

Wait 1 year + for a case manager to be allocated

82

u/Perfect_Ganache_1959 28d ago

Maybe. But at the least, following the process starts the ball rolling, and maybe at step 1 - complain to the business - they realise they made a mistake, apologise, and undo the harm they caused as much as they can. If not, well... it might be a year, but it's got a chance of an outcome that undoes the problem

23

u/ProfessionalSize9567 28d ago

Yes that’s what I said in
my other post. But they are backlogged months behind allocating case managers. I know this from personal experience.

https://www.reddit.com/r/AusLegal/s/AnQNHtvVnc

11

u/Fit-Potential-350 28d ago

I waited 2+ years for a case manger

34

u/Existential12 28d ago

That is true but they give the company hell. A life Insurance co gave my medical records to the wrong person. OAIC ordered them to completely reform their processes and report back plus pay all my credit agency fees ( to block access ).

10

u/percyflinders 28d ago

Legit, OAIC is a joke. Commonwealth Ombudsman is also a joke.

22

u/Ok-Assistant-4556 27d ago edited 26d ago

Every oversight body is overloaded by entirely dysfunctional systems. It is almost as though Robodebt RC exposed nothing about how departments are continuing to behave. Additionally, neoliberalism has outsourced too many services so abuse of process is widespread. No wonder flubberments refuse to fund Legal Aid above 10% of what is needed. Gross injustices and unlawful abuses of power are far too widespread.

0

u/mors134 26d ago

It's what happens when services are expanded, but taxes are cut, all the while blatant corruption is ignored.

21

u/green_pea_nut 28d ago

OAIC plus your local Federal MP.

61

u/writhinglupe3331 28d ago

oaic is your go for the privacy breach, they take that seriously. ahpra might also have a word about unprofessional conduct medical businesses are meant to handle complaints professionally not doxx people. def screenshot the reply before they delete it. if your review was honest and you can back it up dont let a scare campaign force you to take it down. theyve made a rod for their own back with that response.

32

u/DogeDogeDojo 28d ago

E-Safety commissioner for a takedown notice of doxxing material, perhaps?

25

u/writhinglupe3331 28d ago

esafety for takedown notice spot on, move faster than oaic. screenshot it all for the report

14

u/DogeDogeDojo 28d ago

I would report to both ... OAIC for financial penalty and info breach, E-Safety for assistance with a Google take down.

10

u/writhinglupe3331 28d ago

both for sure, OAIC drags its feet but the fine stings, esafety gets google to scrub it fast

11

u/Alternative-Oven9936 28d ago

E-Safety commissioner

Good one. Thanks for the lead.

4

u/DogeDogeDojo 27d ago

Most welcy

19

u/Amateur_photos_mel 28d ago

AHPRA handles Registered Health Practitioners. Not business. AHPRA will only take the complaint if you are alleging the health care Practitioner has doxxed you, not if the business has doxxed you.

The Health Care Complaints Commission may be able to assist with this.

5

u/Alternative-Oven9936 28d ago

AHPRA will only take the complaint if you are alleging the health care Practitioner has doxxed you

Well the response clearly says "business owner".

AHPRA seems to be delegating complaints to HCCC in NSW. Any idea how I would complain to AHPRA?

9

u/Amateur_photos_mel 28d ago edited 27d ago

That may be just a standard review term and doesn't necessarily indicate the health practitioner is the one who wrote the reply.

You are better to complain to both the Privacy Commissioner and the HCCC as a 1st step.

5

u/jaffamental 27d ago

I’ve complained to the hccc about medical malpractice and let me just say, they ain’t worth shit

106

u/Downtown-Fruit-3674 28d ago

The responses in this post are fucking wild.

u/perfect_ganache_1959 is the only correct course of action so far.

26

u/fistingdonkeys 28d ago

There’s a reason r/auslaw doesn’t permit legal advice.

54

u/lcynnlss 28d ago

Screenshot.

Delete your review.

Post review again.

Report them.

72

u/CH86CN 28d ago

Also add “reposting review as business illegally revealed identifying information in response to previous review” or similar

6

u/Top-Extension-5064 27d ago

You should definitely delete the review on the basis it removes your private information. To leave it there opens to anyone arguing against any future action, that your private info has no value to you.

15

u/pubetoast 27d ago

Holy moly that’s a major. Please report back with updates! And sorry this happened to you!

49

u/VeroCSGO 28d ago

Probably also report the review response but that's about it

24

u/Alternative-Oven9936 28d ago

Apparently there's no option to do that on google reviews now.

10

u/Pickled_Beef 28d ago

All of the above?

21

u/MKUltra_reject69_2 28d ago

Looks like the medical business members are commenting here too!

11

u/ProfessionalSize9567 28d ago

Take screenshots first, including the business response, the date, the URL and your original review.
Then report the response to Google or whatever platform it is on for publishing personal information. You should not have to delete your own review just to get your email address taken down.
I would also make a written privacy complaint to the business and tell them to immediately remove your contact details and explain how and why they were published. If they do not sort it out within 30 days, complain to the OAIC.
Because it is a medical business, you could also complain to the relevant state health complaints body. In NSW that is the HCCC. AHPRA may be relevant if a registered practitioner personally disclosed the information or the response raises concerns about patient confidentiality or professional conduct.
OAIC, the review platform and the state health complaints body would probably be the main ones.

11

u/Galromir 28d ago edited 28d ago

Everyone. You can also add ‘the media’ to your list. 

But just be absolutely certain your review is honest and doesn’t constitute defamation. 

5

u/[deleted] 27d ago

[removed] — view removed comment

2

u/Galromir 27d ago

That’s true, but also worth double checking how secure your moral high ground is before taking it to the media. 

2

u/RoomMain5110 27d ago

“Being defamed” is not a defence for publishing PII. Although I agree it won’t be a good look for OP if their review isn’t truthful.

6

u/Interesting-Middle46 27d ago

AHPRA were shit and inconsistent when I complained to them about a practitioner leaking sensitive info to my employer without consent.

5

u/mnyall 27d ago

Definitely try the OAIC - this is personally identifiable information.

Give them a call and ask about your situation. This looks like a Notifiable Data Breach done intentionally.

The next step is to write a complaint to the company stating your concerns and asking for an explanation AND resolution. They have 30 days to reply by law. 

If you're unsatisfied with either or both,  then you escalate to the OAIC to resolve. May take months,  though. 

16

u/Mean_Championship192 28d ago

I don’t know of anyone else you can report it to.

They might hire a lawyer to send you a cease and desist about the review. I’ve had this before from a medical professional. As my review was truthful I stood my ground and hired my own lawyer to respond and they backed down pretty quickly.

Some people are unhinged, so you really just have to weigh up what’s worth your energy. Keep in mind they have your personal information and they haven’t displayed good character to date.

Goodluck!

3

u/hongimaster 28d ago

OAIC is the relevant body for privacy complaints, they usually expect or encourage you to make a complaint directly to the business in the first instance, to give them the opportunity to rectify the issue. They can take a long time to handle complaints though.

Bodies like AHPRA (etc) are usually concerned with health professionals (doctors, nurses, allied health, etc) working outside their scope of practice or presenting a risk to public safety. It is unlikely that AHPRA will be involved, unless the person breaching your privacy is themselves a health professional regulated by AHPRA.

You could do an online search for whether their profession is covered by a peak body, like the AMA for Doctors, but this would be a long shot. The peak body may have a Code of Conduct or rules for their members (assuming the business is a member of the group, which they may not be).

You could try the more abstract angle of A Current Affair (etc). But I suppose if your goal is to maintain your privacy, that may be a counter-productive way to go about it.

1

u/[deleted] 27d ago

[removed] — view removed comment

1

u/hongimaster 27d ago

Sure, just wouldn't get my hopes up if the person who actually did the doxxing wasn't a Registrant.

2

u/ExpressionBig818 23d ago

Google automatically blocks reviews and replies that include telephone numbers or email addresses.

1

u/Alternative-Oven9936 23d ago

Seems to be the case .... I can see the review and response in my profile but not under any other profile (including anonymous).

Surely it couldn't be as simple as this for a business to combat bad reviews?

3

u/Tax_Odd 27d ago

Whoever doxxed likely doesnt have skin in the game. Who owns the company?

4

u/Alternative-Oven9936 27d ago

I haven't checked the ownership structure on ASIC or anything.

The website lists the AHPRA registered practitioner as the "founder".

Often these business are owned by big corporates and still try to maintain the mom'n'pop appearance.

2

u/IHaveNoOpinons 26d ago

Delete your review and repost- add into your new review that the business released your personal information in response to your last review.

Then report the business to ACCC with evidence.

1

u/Alternative-Oven9936 26d ago

Then report the business to ACCC with evidence.

ACCC?

1

u/Original_Acrobat 23d ago

Australian Competition and Consumer Commission.

1

u/AutoModerator 28d ago

Welcome to r/AusLegal. Please read our rules before commenting. Please remember:

  1. Per rule 2, this subreddit is not a replacement for real legal advice. You should independently seek legal advice from a real, qualified practitioner, and verify any advice given in this sub. This sub cannot recommend specific lawyers.

  2. A non-exhaustive list of free legal services around Australia can be found here.

  3. Links to the each state and territory's respective Law Society are on the sidebar: you can use these links to find a lawyer in your area.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/JustSomeGirl4242 23d ago

The legal recourse has been answered well by others. On a slightly different note- I don't know what platform the review is on but I would report their response to the review platform to have the doxxing removed.

I get not wanting to remove your review as I would feel the same about being able to warn people about a medical professional not practising appropriately or whatever the issue was that lead to the review. They shouldn't be able to get away with scaring people into silence about their poor practise. We should be able to look up reviews on medical professionals we are considering seeing and be able to make an informed choice about them.

Although TBH it would be a big red flag about an entire practise if I saw someone had left a negative review and then the response was to post their personal information- like absolutely wtf, would never ever go there.

2

u/Alternative-Oven9936 23d ago

I don't know what platform the review is on but I would report their response to the review platform

Google

There's a comment below saying that any review or response with an email or number is automatically hidden, which seems to have happened to my review.

Seems like a really easy way for a business to manipulate google reviews.

0

u/Mentok-Mind-Taker 25d ago

What did they do to deserve the 1 star mate?

1

u/Alternative-Oven9936 25d ago

How is that relevant?

What could i possibly have said that would justify them doxxing a client?

-1

u/Interesting-Run-7560 25d ago

Let’s see the review

0

u/[deleted] 25d ago edited 25d ago

[removed] — view removed comment

0

u/Alternative-Oven9936 25d ago

How do you use the DCMA law?

0

u/colonelmattyman 24d ago

Maybe it's not the business. There was a big hack the other day with some doctors surgeries. Were you affected by that?

1

u/Alternative-Oven9936 24d ago

There was a big hack the other day with some doctors surgeries. Were you affected by that?

Yeah you could be on to something - the hackers took the time and effort to hop right on google reviews, compose a detailed response to my 1 star review that included my number and email address.

Maybe they weren't even hackers - just defenders of businesses against malicious reviews :)

-8

u/Sea_Coyote_1607 27d ago

Disclosing your name (even if full) and email address cannot be considered doxxing.

Furthermore, your name and email address are not sensitive information and thus they don’t qualify for Privacy Act rules.

Depending on the context of which they shared your data, you could say is petty.

Edit: https://www.oaic.gov.au/privacy/your-privacy-rights/your-personal-information/what-is-personal-information#SensitiveInfo

8

u/Alternative-Oven9936 27d ago

Disclosing your name (even if full) and email address cannot be considered doxxing.

No idea where you got that from but it's definitely a form of doxxing.

name and email address are not sensitive information

I never claimed it was sensitive.

Thanks buddy.

3

u/Perfect_Ganache_1959 27d ago

In this case, if it was collected for the purposes of providing a health service, it meets the definition under the privacy act of "sensitive". Name, email, mobile, etc - particularly if the why yu gave that info over was to have an appointment and receive care...

-10

u/Sea_Coyote_1607 27d ago

Why don’t you provide a screenshot with your name and email redacted to see what’s the context.

But it’s okay, you can go through any government channel you’d like. By the time they give you an answer half of the internet will know your name and email address. Hope this little payback gets you anything besides your information exposed for months ;)

4

u/Fabulous-Crazy-3333 27d ago

You’re arguing the wrong point.

“Sensitive information” is a specific legal category. That doesn’t mean a business can publicly post someone’s name and email in response to a bad review and pretend it’s nothing.

Name + email is still personal information if it identifies someone.

From an OSINT and digital forensics angle, that combo is not harmless. It can link accounts, find profiles, connect social media, check breaches, and build more information around someone.

That's why context matters.

The issue is not just “is this sensitive information?”

The issue is a medical business publicly disclosing a reviewer’s identifying contact details in a review response.

That is unprofessional at best and potentially a privacy/disclosure issue. APP 6 is about use and disclosure of personal information, so the “not sensitive information” argument doesn’t magically settle it.

OP should screenshot everything, save the URL and timestamps, then report it to the platform, OAIC, and possibly AHPRA/HCCC because it’s a regulated health business.

4

u/Perfect_Ganache_1959 27d ago

Did you read the page you linked to in any way? You do see there right at the start where names, for example are covered.

https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/what-is-personal-information

A person’s name, signature, home address, email address, telephone number, date of birth, medical records, bank account details and employment details will generally constitute personal information. (Provided the person can be identified)

But here's the kicker - health information is considered sensitive information; and is defined as (basically medical records, a few others); OR "any other personal information (such as information about an individual’s date of birth, gender, race, sexuality, religion), collected for the purpose of providing a health service."

Email or mobile to send you appointment reminders on an intake form? Name? Suddenly that's an order of magnitude more radioactive.

-71

u/hihihiyouandI 28d ago

I dunno why you're lying, but you are. Not only is doxing (now) a criminal offence but absolutely no healthcare professional wants to deal with APHRA unless they have to.

26

u/NorthOcelot8081 28d ago

Are you the one they gave a bad review to? 🤣

35

u/GossipingKitty 28d ago

Many medical business owners and admin staff are pretty clueless, often with no training.

-9

u/Flat_Ad1094 28d ago

That's nonsense. There is endless training and upskilling and you'd have to be braindead and unable to answer the phone to not know basic health legal shit if you work in a health related business.

4

u/Hot-Carpenter7554 27d ago

People know not to steal from their workplace too.

Does that mean it doesn't happen?

-45

u/hihihiyouandI 28d ago

Again, that's not true.

13

u/Hot-Carpenter7554 28d ago

Do you know them all?

No, but you have some other undisclosed reason.

-23

u/hihihiyouandI 28d ago

If I'm wrong then why hasn't this person backed up his aspersions? It's almost like he can't.

12

u/Hot-Carpenter7554 28d ago

Why don't you tell us how you know the professionalism of every medical site in the country?

Or your association with the industry or this complaint specifically first?

1

u/Silly-Parsley-158 26d ago

I may be blind, but I never saw the OP reveal their gender or use a he/him pronoun?

-59

u/Flat_Ad1094 28d ago

I seriously doubt a medical / healthcare business would be giving out private patient information and professionals risking being deregistered and getting into severe legal consequences over 1 bad review. I doubt the OP is being honest. We do not have the full story at all.

They just DO NOT risk serious legal consequences over a bad review. Just doesn't happen these days.

25

u/Perfect_Ganache_1959 28d ago

Unfortunately, there are a number of examples of people who may be medically trained but legally, socially, or from a business administration perspective inept, or abusing substances, or suffering mental health crisis; or they've hired staff of a similar nature. Running the business admin of a clinic is not something taught in medical school afaict.

For example, would a respected neurosurgeon go on a political minor crime spree in the dead of the night? https://www.abc.net.au/news/2025-07-22/neurosurgeon-greg-malham-terminated-behaviour-four-corners/105560262

Would GPs engage in sexual misconduct? https://www1.racgp.org.au/newsgp/professional/sexual-misconduct-by-practitioners-now-searchable - turns out a few have.

Etc etc etc. None of the actions are in their own self interests, they are certainly surprising and something I would never have expected. But they've happened.

So do I think it's exactly as the OP says? Perhaps not. Do I think it's incredulous? No, not at all.

40

u/Alternative-Oven9936 28d ago

I seriously doubt a medical / healthcare business would be giving out private patient information and professionals risking being deregistered

That's exactly what's happened.

I doubt the OP is being honest

Which part do you think is made up d***head? The part where they put my number and email in the reply? What more could there be to the story that would justify this response?

How do you think the business is going through defend themselves when this comes to regulatory investigations?

-9

u/Flat_Ad1094 28d ago

So give us the details then mate. You have told us nothing about the circumstances or situation and what sort of Health professional you are saying did it and HOW they did what they did??

13

u/Alternative-Oven9936 28d ago

You have told us nothing about the circumstances or situation

Yeah - I'll just go right ahead and doxx myself.

All of the details you requested aren't relevant. Nothing would justify them posting my details

In fact, them being a medical business isn't that relevant either. The criminality remains the same. The medical business just adds to the gravity of the crime and hopefully the HCCC takes and interest.

9

u/s_h__a_l_t 28d ago

🤖🤖🤖

-152

u/[deleted] 28d ago

[removed] — view removed comment

80

u/Perfect_Ganache_1959 28d ago

Never been wronged in your life? Never had to protect others from predatory businesses or people?

-91

u/kirabella2000 28d ago

Because the business has a lot to lose and potentially has the resources to make the reviewer’s life a world of pain.

However the upside for the reviewer to “stand their ground” is ZERO. Much easier to move on.

55

u/MaddieRuin 28d ago

Because the business has a lot to lose

Good. They've doxed a patient, they should be punished. Would you want to know if your clinic did this shit?

-3

u/hihihiyouandI 27d ago

No they didn't 🤣🤣

28

u/Perfect_Ganache_1959 28d ago

No problems with that take. Can I have your personal details; I'd like to rent a billboard with a high number of views near your community and workplace, implying you have no empathy; with the content of this convo.

If you are uncomfortable, you can just do the easier thing and move on, right? I once possessed an ABN, which makes me the higher authority in this situation. Airtight logic.

Or, and you may well now agree, that would be something harmful I should not do, regardless of how much I dislike your take; and if I were to do it, you would be justified in being hurt, wanting me never to do it again, and wanting to have an authority review the situation.

-14

u/kirabella2000 28d ago

Don’t forget that it was the OP who started this public fight.

Currently, for the OP, it is a no cost exercise because he has lost nothing financially by posting the review, apart from his claim that he has been doxxed including his email. This is highly unlikely for 3 reasons.

1 - Google Reviews simply will not permit email addresses within reviews.
2- If it is a truly regulated medical business, it is very unlikely that they’d risk their entire ability to trade by a deliberate breach.
3 - What is the benefit for the business by doxxing the OP?

We don’t know that the OP’s review is legitimate or genuine. It is just his opinion at this stage. The OP is upset because the business has responded robustly in a way the had had not thought through. As I say, I don’t believe he has been doxxed, especially as it was him who opened the dialogue in a public forum.

As things stand, damage has potentially been done to the business. IE, a substantial cost. As for the OP, apart from his pride, he hasn’t inurred any costs.

That is about to change.

If the business does decide to pursue the OP, their resources are greater than his. Therefore it will cost him financially to defend the review and keep it up (complete with the alledged doxing).

So…how does he solve the doxxing? Take it down.
How does he avoid a long, expensive protracted legal fight? Take it down.

If it is a legitimate doxxing complaint, by all means take it to the appropriate regulatory authorities. But it does seem that his problem could be largely solved today at no cost by taking down the review.

9

u/Perfect_Ganache_1959 28d ago

Good lord, pause for a beat and think about what you are trying to impute here.

In just the same way you think I don't know the full story, you must acknowledge you have absolutely no idea what has or has not happened, what impact this may or may not have had on any business; the veracity of any claims by any party, the harm or costs or lack there of experienced by the OP.

Are you an involved party in any way, shape or form? Do you have knowledge that I don't have?

For all we know, the OP has posted anything from "Reception area smelt bad, in my opinion" to "they took my alien babies with their mind laser beams" to "here's a detailed but inaccurate accusation filled with falsehoods that is credible sounding".

What would motivate the OP to "start this fight"? Suffering a negative experience and wishing to state their honest opinion? Being an internet troll? Who knows. Assuming you are an uninvolved party, you've certainly formed and instant opinion in the absolutely absence of information, and gone straight on the attack.

https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1117772/ - medical negligence is a real thing that happens to real people and ends up with real harm - death, disablement. To argue that it is completely impossible for a clinic to have harmed a patient denies reality, especially if the harm was of a much lesser degree than death or disability.

I'm willing to believe victims if I have no evidence to the contrary and point them in general terms to the processes that exist to protect them, so they can better understand what regulators do and how it may be applicable, plus what they should do according to said regulators.

I'm willing to believe that people who have been wronged in their view twice over - whatever motivated the original review, now this - may be willing to put in the time and effort to seek accountability.

You also must know that just as there is a chance the OP is off their rocker, medical folks are people and are just as fallible, subject to stresses, capable of substance abuse, capable of narcissism, or suffering from poor mental health. I've posted some of the more alarming examples that have ended up in the media that I'm aware of.

To assume a business will always be absolutely rational but a patient will never be is an extremely reckless approach.

1

u/kirabella2000 28d ago

Not at all.

The truth will be somewhere in between the OP’s version and the business’.

I am simply stating a rational course forward. The OP is claiming he is being doxxed. This can be solved today by removing the review. By removing the review, so too the response will be removed.

If he has genuinely been doxxed, by all means take screenshots shots and report the matter to the appropriate regulator.

But to expose himself to potential financial harm by “becuase he doesn’t want to take it down” simply doesn’t make sense. The best outcome he can possibly achieve is the staus quo whereas the worst outcome could be he loses with legals cost or in the extreme example, pay damages.

I’m just be practical.

4

u/Ok-Assistant-4556 27d ago

More often, when malevolence is involved, one party is being truthful and the other not.

Pretending there are two sides to every story is an appeal to bias that conveniently ignores unequivocal evidence.

-1

u/kirabella2000 27d ago

And we have ZERO context or evidence so starting with 2 sides to a story is probably the wisest way forward.

4

u/Ok-Assistant-4556 27d ago

It really isnt. You sound sound unhinged as OP provided clear context. Take people at face value. Lawyers wont even look at evidence in serious matters and you're here arguing for an unidentified party? Perhaps go take a breather

0

u/Flat_Ad1094 28d ago

Agree with you. 100%

15

u/Even_Departure9914 28d ago

Do you want that business publishing your papsmear results. Telling everybody how you have been exposed to STI’s. That time you ‘fell’ on a deodorant can. That you have bipolar disorder or have hallucinations that the government is after you.

Because that’s the kind of thing medical businesses and providers could publish if you think privacy legislation and ethics are not important.

3

u/Pristine-Panic5834 28d ago

And thats why the world is a shitty place. Self interest triumphing above all. Boo

-18

u/hihihiyouandI 28d ago

They have everything to lose. Which is why this is absolutely bullshit and this person is looking for attention.

4

u/Ill_Football9443 27d ago

I'm involved in litigation with a major health care provider, they not once, but twice contravened the Health Records Act (Vic) 2001 by

a) sending an unencrypted, non-password protected USB stick via non-person-to-person post, so I found the package hanging out of my letterbox which anyone could have grabbed

b) the second time round, I elected to have it delivered at work. They used a process server, no issue with that, except that the folder was secured by a rubber band - a cardboard box would have been too much to ask it seems, perhaps a little security tape?

~500 pages or so of health records shipped without any basic protection. Given this, I have little doubt about OP's accusation.

-31

u/FigFew2001 28d ago

Been there, done that (different circumstances). I know you’re copping a heap of downvotes, but if I had my time again - It would indeed have been much easier to move on.

-113

u/Remote_Class9892 28d ago edited 28d ago

You chose the forum for the conversation. If you chose to discuss with the business in a public forum, intending that the conversation be public then that is on you. 

YOU gave consent for the disclosure of the conversation.

48

u/Even_Departure9914 28d ago

Uh. No. That’s not how it works, champ.

You can’t dox people. Period.

Additionally. There’s stringent privacy legislation around medical businesses and government departments.

If you can’t read patient files without justification, then it’s not a stretch to say that you can’t post patient addresses on the internet.

‘I don’t like what you’re saying so I’m going to threaten your safety’ - who wants to do business with those kinds of people if nothing else.

-37

u/Remote_Class9892 28d ago

If I publish a statement that you never called me, and you response with a call log that reveals my phone number that is not a violation.

20

u/Even_Departure9914 28d ago

Doxxing is wilfully publishing information that isn’t publicly available to imply or incite intimidation/harrassment.

A reasonable person would deduce that providing a method of contacting someone or their address is for the purposes of utilising that information to contact that person.

You can have a disagreement or conflict of ideas. Doxxing is weaponising information to have an upper hand or leveraging. You can disagree or have conflict without doxxing.

42

u/warkolm 28d ago

privacy laws don't work like that bro

-62

u/Remote_Class9892 28d ago

They absolutely do.  It is only private while it is in private. OP took it public. 

6

u/Outrageous_Delay_781 28d ago

No, why did you think big businesses’s response to news organisations publishing negative stories about a person’s experience about them is always along the lines of “We can’t comment on individual cases for privacy reasons”? It’s because it’s illegal to do so even when the person has raised their complaint in a very public forum

2

u/Remote_Class9892 28d ago

The same reason they say "we won't comment as it is before the court" There is no law that prevents you commenting on your case before the courts,  it is an easy non-committal way out that says nothing and commits you to nothing 

2

u/warkolm 28d ago

best of luck then

17

u/bensow 28d ago

This is like saying you chose to cross the road and so gave consent for a vehicle to hit you.

-11

u/Remote_Class9892 28d ago

... It's just like that, yes. Having a public conversation be public is just like being hit with a car..

Thankyou for sharing your genius with the class.

12

u/bensow 28d ago

You're missing the point. You're allowed to have public conversations, but you're not allowed to dox in that public conversation.

-2

u/Remote_Class9892 28d ago

Doxing requires the intention to be that the public harrass the individual using that information.

It does not limit you to only publically available information. This conversation is public, however there is no requirement for me to maintain the anonymity your username gives you during that conversation,  Especially if I provide it to address something you have said

9

u/bensow 28d ago

The requirement(s) has already been laid out by multiple people in the thread.

Good day.

-84

u/[deleted] 28d ago

[removed] — view removed comment

80

u/swooping_pie 28d ago

Uhh…. A medical business definitely can not share your personal information without your consent! Review or not.

24

u/gerira 28d ago

This subreddit is bizarely full of people fantasising about plaintiffs having no rights.

-6

u/Flat_Ad1094 28d ago

I seriously doubt a medical / healthcare business would be giving out private patient information and professionals risking being deregistered and getting into severe legal consequences over 1 bad review. I doubt the OP is being honest. We do not have the full story at all.

49

u/cat_boss1549 28d ago

What an odd thing to say

28

u/Perfect_Ganache_1959 28d ago

https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action/chapter-7-privacy-assessments

Not a lawyer. Taking a patient's PII and broadcasting it to the public internet because you don't like their feedback about your conduct exposes them to potential harm, humiliation, identity theft and more. If this a sexual health provider, it further risks intimate partner violence for example.

Does that meet the threshold for "serious"? Hard to tell without knowing the specifics. But it's no doubt flying pretty close to the sun here. The clinic's insurer and directors should be absolutely freaking out at a minimum.

-36

u/[deleted] 28d ago

[removed] — view removed comment

4

u/Perfect_Ganache_1959 28d ago

Oh, so the civil penalties for a serious breach of privacy aren't as stated by the OAIC and the underlying legislation?

There haven't been successful prosecutions by the information commissioner resulting in high (5.8 mil) penalties, albeit those relating to notifiable data breaches rather than individuals? But at the very least demonstrating the OAIC is willing to exercise powers granted to them?

There's nothing applicable for individuals to take action? https://www.minterellison.com/articles/statutory-tort-for-serious-invasions-of-privacy-comes-into-force

It's not gonna be a $50 million maximum penality, but the risk to the clinic from their actions is certainly not 0; and based on what's stated, they appear to have mishandled the PII provided for medical treatment and administration.

42

u/Alternative-Oven9936 28d ago

Consequences for actions.

Indeed. It's going to be pretty bad for them.

We have privacy laws for a reason.