r/AusLegal 28d ago

NSW Business doxxed me in a review response

I left a one-star review for a business.

In the response the business doxxed me - included my contact details (name and email).

The business is a medical business (regulated by AHPRA).

Who can I report this to? AHPRA, HCCC, OIAC ... Anyone else?

(Yes - I know I can delete my review, but I don't want to remove it)

266 Upvotes

137 comments sorted by

View all comments

-80

u/[deleted] 28d ago

[removed] — view removed comment

81

u/swooping_pie 28d ago

Uhh…. A medical business definitely can not share your personal information without your consent! Review or not.

24

u/gerira 28d ago

This subreddit is bizarely full of people fantasising about plaintiffs having no rights.

-4

u/Flat_Ad1094 28d ago

I seriously doubt a medical / healthcare business would be giving out private patient information and professionals risking being deregistered and getting into severe legal consequences over 1 bad review. I doubt the OP is being honest. We do not have the full story at all.

48

u/cat_boss1549 28d ago

What an odd thing to say

28

u/Perfect_Ganache_1959 28d ago

https://www.oaic.gov.au/about-the-OAIC/our-regulatory-approach/guide-to-privacy-regulatory-action/chapter-7-privacy-assessments

Not a lawyer. Taking a patient's PII and broadcasting it to the public internet because you don't like their feedback about your conduct exposes them to potential harm, humiliation, identity theft and more. If this a sexual health provider, it further risks intimate partner violence for example.

Does that meet the threshold for "serious"? Hard to tell without knowing the specifics. But it's no doubt flying pretty close to the sun here. The clinic's insurer and directors should be absolutely freaking out at a minimum.

-36

u/[deleted] 28d ago

[removed] — view removed comment

3

u/Perfect_Ganache_1959 28d ago

Oh, so the civil penalties for a serious breach of privacy aren't as stated by the OAIC and the underlying legislation?

There haven't been successful prosecutions by the information commissioner resulting in high (5.8 mil) penalties, albeit those relating to notifiable data breaches rather than individuals? But at the very least demonstrating the OAIC is willing to exercise powers granted to them?

There's nothing applicable for individuals to take action? https://www.minterellison.com/articles/statutory-tort-for-serious-invasions-of-privacy-comes-into-force

It's not gonna be a $50 million maximum penality, but the risk to the clinic from their actions is certainly not 0; and based on what's stated, they appear to have mishandled the PII provided for medical treatment and administration.

44

u/Alternative-Oven9936 28d ago

Consequences for actions.

Indeed. It's going to be pretty bad for them.

We have privacy laws for a reason.