Ahpra notification · All 15 National Boards
Confidentiality in Healthcare Practice for Health Practitioners facing an Ahpra notification, complaint or allegation
The allegation concerns patient information — disclosed, opened, overheard, sent or posted where it should not have been.
- Disclosed — information shared outside the care team without consent
- Impairment — a breach while fatigue, illness, alcohol or drugs affected you
- Accessed — a record opened with no clinical reason, a colleague’s included
- Overheard — at a bedside, a desk, in a corridor or on a telehealth call
- Misdirected — an email, a letter or a result sent to the wrong person
- Online — a post or a photograph from which a patient could be recognised
- Family — a relative or a carer told what the patient had not agreed to
- Any other — confidentiality or privacy concern, or allegation of a breach
Facing an allegation of a confidentiality or privacy breach like these — from your National Board, Ahpra, a panel or a tribunal?
Help with an Ahpra notification, complaint or allegation starts here. This CPD course helps you remediate — and demonstrate the remediation, with a dated certificate for your written response, your portfolio or a Board, panel or tribunal direction.
Immediate access · certificate on completion · twelve months' access
- 2 CPD hours
- Self-paced
- Every registered profession
- CPD certificate
- Bulk buy: any 5 for A$850 · any 10 for A$1,400
At a glance
- Who it is for
- Any registered practitioner facing an Ahpra notification, complaint or allegation, a National Board investigation, a panel or a tribunal hearing about patient confidentiality or privacy — information disclosed without consent, a record opened without a reason, a conversation overheard, an email to the wrong person, a post, or a relative told
- Also covers
- The Privacy Act 1988 and the Australian Privacy Principles, and state and territory health records law
- Regulators covered
- Ahpra and all fifteen National Boards, plus the NSW Councils, the HCCC and the OHO
- Length
- 9 sections, 72 lessons, 2 CPD hours
- Format
- Self-paced, online, immediate access, twelve months from purchase
- Certificate
- Issued by Healthcare Ethics Courses on completion, dated, with the course title and 2 CPD hours
- Price
- A$200 · any 5 for A$850 · any 10 for A$1,400
Certificate issued by Healthcare Ethics CoursesRemediation courses for regulatory processes.
Who this course is for
Facing an allegation of a confidentiality or privacy breach
Ahpra’s letter says information was disclosed without consent, a record was opened without a reason, a conversation was overheard, an email went to the wrong person or something was posted. Clause 3.3 of the shared Code of conduct sets nine lettered obligations, and opening a record is a breach whether or not anything was passed on; this course is how you account for how the information travelled — and show what now stops it.
Dealing with an Ahpra notification or complaint
A patient, a relative, a colleague, your employer or a mandatory notifier has told Ahpra, and you have been asked for a written response. In 2024/25 Ahpra received 13,327 notifications across the 16 professions. What was shared, with whom and when is recorded somewhere — the mail server, the record system, the platform — and the course teaches the account that answers it: clear, without minimising, with the change since.
An access audit or a log has found something
A record opened without a clinical reason — a neighbour, a colleague, a relative, a name in the news — and the system logged it, or an email trail shows where a result went. An account given before the audit is put to you, with the reason stated plainly and the permissions now reviewed, reads very differently from one the log contradicts; the course covers access, boundaries and responding to a breach once it has happened.
Under investigation, or under immediate action
Ahpra is investigating, or your Board has suspended your registration or imposed conditions while it does. An investigator reads the audit log, the email trail or the post beside your account, and reads for the sequence: what travelled, to whom, what you did in the hour you knew, and what has changed about the room, the list or the permissions since.
Facing a panel or a tribunal hearing
A panel has been convened, or your Board has referred you to the tribunal in your state or territory. A panel of your own profession weighs whether the insight in the response is the same in the room; a tribunal reaches confidentiality where access was deliberate or repeated, or the account of it was untrue. Remediation completed before the hearing — dated and documented — is weighed every time.
Directed to complete CPD on confidentiality
Conditions on your registration, an undertaking, a panel or tribunal order, or a supervisor’s advice require education in confidentiality and privacy. The certificate records two dated CPD hours written to clause 3.3 of the shared code, the professions’ own codes and the Australian Privacy Principles.
The concerns this course speaks to
Information disclosed without consent
A diagnosis mentioned to a colleague not involved in the care, a letter copied to someone who did not need it, a report released without authority, a detail shared in a group chat. Clause 3.3 asks for informed consent before disclosing, and a record of it; information is held in confidence unless its release is required or authorised by law, or needed for emergency care. The course sets out consent, the lawful exceptions — a mandatory notification, a reporting duty, a court order — and how each is justified in the record.
Impairment — fatigue, health and the breach you did not notice
The email sent at the end of a shift that was too long, the record opened while distracted, the conversation started in a corridor; illness, alcohol or drugs behind a lapse. Impairment is one of the four grounds for a mandatory notification under the National Law, and clause 9.1 of the shared code asks a practitioner with a condition that could affect their judgement to seek help rather than rely on their own assessment of the risk. A condition raised early, with a plan attached, is read as insight.
A record opened without a reason
A neighbour, a former partner, a colleague. Clause 3.3 point c says never to access records when you are not professionally involved or authorised, and the access is the breach whether or not anything was passed on; systems log it and employers audit it. A practitioner who opened a colleague’s records 14 times was suspended by the Board and later reprimanded by the tribunal. Looking someone up out of curiosity is a boundaries breach with a patient or a colleague before it is a privacy one (4.9).
A conversation overheard, in the room or on a telehealth call
A bedside on a four-bed ward, a reception desk, a corridor; a telehealth consultation heard at the other end by someone the patient did not name, or held on a platform the practice does not control. Clause 3.3 point b asks for surroundings that allow a private discussion, and clause 4.10 asks whether confidentiality can be provided before treating more than one patient at a time. The surroundings are the breach, so the remediation is concrete: the room changed, a telehealth protocol adopted, each dated.
An email, a letter or a result sent to the wrong person
A mistyped address, an auto-complete, an attachment meant for another patient, a letter in the wrong envelope. Clause 8.3 requires records held securely and not subject to unauthorised access, and clause 3.3 asks you to apply your state or territory’s privacy and health records law in every format. A reader looks first at the hour afterwards — the recall, the recipient contacted, the patient told — and then at what changed about the mailing list. The course’s first worked case is an accidental email disclosure.
Social media and identifiability
A case discussed without a name, a photograph with a corner of a screen in it, a comment in a closed group, a patient messaged from a personal account. Clause 3.3 point g says never to post any person’s information or images, even unnamed, without written informed consent, and Ahpra’s social media guidance applies the code online without change. De-identification is not a defence if the person is recognisable, and in a small community the threshold is lower than many assume; the course’s social media case turns on it.
A relative, a carer or an employer told
A relative told about an adult patient, a partner given a result, a worried family reassured, an employer told why someone was away. Clause 4.4 asks you to be responsive to those close to the patient only with appropriate consent or where otherwise permitted, and the qualifier is the whole obligation: refusing where the law required disclosure is a concern too. The course’s two family-request cases turn on that qualifier, and the course gives the words for the conversation with the relative — respectful, explained and recorded — as well as the rule.
Probity: the account of the breach, and any other concern
An account of the disclosure that the audit log contradicts, an access explained as clinical when the roster says otherwise, a post taken down and then denied. An account that does not match the log turns a confidentiality matter into a probity one: a tribunal described a doctor’s denials — to his employer, the Board and the tribunal — as a significant breach of his professional obligations of candour and honesty. Any allegation is measured against your own Board’s code; the course puts acknowledging the breach first, before reflection, the plan and the evidence of change.
Facing an Ahpra notification, complaint or allegation? This course helps you remediate — and demonstrate it.
Buy this course — A$200.00What the course covers
Nine sections and 72 lessons, with a reflective quiz closing each of the first eight and a post-course assessment at the end.
Overview and relevance to Australian practice
Why confidentiality is fundamental, how it breaks down in real settings, what a breach costs the patient and the practitioner, and why this is scrutinised so closely here.
Core concepts and definitions
Ten lessons separating confidentiality from privacy, defining personal health information, setting out the legal frameworks, and covering the treating team, telehealth, families, substitute decision-makers and boundaries.
Regulatory expectations in Australia
Ahpra's mandate, the National Board codes, the legal requirements, mandatory reporting, team-based care, documentation, digital records, cultural safety, and what regulators expect when a breach happens.
Ethical and professional challenges
Ten lessons on the hard cases: patient safety against confidentiality, family requests, shared spaces, digital risk, multidisciplinary collaboration and conflicting legal duties.
Case studies in the Australian context
Five worked cases — accidental email disclosure, a shared ward space, a family demanding information, a relative’s request for information, and social media identification.
Insight, reflection and professional growth
What insight looks like in a confidentiality matter specifically, and how to develop reflective habits that hold under pressure rather than only in hindsight.
Remediation and preventing recurrence
Root cause analysis, targeted remediation plans, system-level improvements, monitoring change over time, and demonstrating it to Ahpra.
Applying principles to daily practice
Ten practical habits — confirming privacy at the start of a consultation, discreet communication, secure handover, environmental awareness.
Conclusion and assessment
Key takeaways, then the post-course assessment. Your certificate is issued on completion and carries the date.
Show every lesson title
- Section 01 · Overview and Relevance to Australian Healthcare Practice
- Why Confidentiality Is Fundamental in Healthcare; Confidentiality in the Australian Regulatory Context; How Confidentiality Breaks Down in Healthcare Practice; The Impact of Confidentiality Breaches; Why This Course Matters for Practitioners in Australia.
- Section 02 · Core Concepts and Definitions
- The Ethical Principle of Confidentiality; Privacy vs Confidentiality: Understanding the Difference; Personal Health Information: What Must Be Protected; Legal Frameworks Governing Confidentiality in Australia; When Confidentiality Must Be Maintained; When Confidentiality May Be Lawfully Breached; Confidentiality and the Treating Team; Confidentiality in Telehealth, Email, and Digital Communication; Working With Families, Carers, and Substitute Decision-Makers; Confidentiality and Professional Boundaries.
- Section 03 · Regulatory Expectations in Australia
- Ahpra’s Mandate: Protecting Public Safety Through Confidentiality Compliance; National Board Codes of Conduct and Professional Standards; Legal Requirements Governing Confidentiality and Disclosure; Confidentiality in the Context of Mandatory Reporting; Confidentiality and Team-Based Care: What Is Permitted; Documentation Requirements Relating to Confidentiality; Confidentiality in Telehealth, Digital Records, and Electronic Communication; Cultural Safety and Confidentiality Expectations; Responding to Confidentiality Breaches: Regulator Expectations; Demonstrating Trustworthiness Through Behaviour.
- Section 04 · Ethical and Professional Challenges in Confidentiality
- Balancing Confidentiality With Patient Safety; Navigating Confidentiality When Families Request Information; Confidentiality When Capacity Is in Doubt: Consent, Disclosure, and Substitute Decision-Makers; Confidentiality in Shared or Public Clinical Spaces; Digital Confidentiality: Technology, Telehealth, and Social Media Risks; Confidentiality vs Multidisciplinary Collaboration; Cultural Safety and Confidentiality Challenges; Managing Accidental Breaches: Responding Safely and Professionally; Boundary Drift and Confidentiality Risks; Ethical Tension When Confidentiality Conflicts With Legal Duties.
- Section 05 · Case Studies in the Australian Context
- Case Study 1: Accidental Digital Disclosure via Email; Case Study 2: Confidentiality Breach in a Shared Ward Space; Case Study 3: Family Demanding Information Without Consent; Case Study 4: Confidentiality and a Relative’s Request for Information; Case Study 5: Inappropriate Use of Social Media Leading to Identification.
- Section 06 · Insight, Reflection, and Professional Growth
- Understanding Insight as a Core Competency in Confidentiality; Developing Reflective Practice to Strengthen Confidentiality Habits; Using Feedback Constructively to Improve Confidentiality Awareness; Strengthening Emotional Regulation to Prevent Privacy Errors; Strengthening Communication Skills to Support Confidentiality; Building a Culture of Confidentiality Through Team Collaboration; Enhancing Cultural Safety to Protect Patient Privacy; Learning From Confidentiality Breaches Without Becoming Discouraged; Using Supervision and Mentoring to Support Growth; Embedding Long-Term Growth and Continuous Improvement.
- Section 07 · Remediation, Improvement, and Preventing Recurrence
- Understanding the Purpose of Remediation in Confidentiality Concerns; Conducting a Root Cause Analysis of the Confidentiality Breach; Designing a Targeted and Meaningful Remediation Plan; Improving Communication to Strengthen Privacy Protection; Enhancing Documentation to Improve Accountability and Transparency; Using System-Level Improvements to Prevent Recurrence; Strengthening Boundary Awareness and Professional Conduct; Improving Cultural Safety and Confidentiality Practices; Monitoring Behavioural Change Over Time; Demonstrating Remediation and Trustworthiness to Ahpra.
- Section 08 · Applying Principles to Daily Practice
- Confirming Privacy at the Start of Every Consultation; Using Discreet, Respectful Communication in Shared Environments; Practising Secure Digital and Telehealth Confidentiality; Ensuring Confidentiality During Handover and Team Communication; Managing Family and Carer Requests With Sensitivity and Clarity; Maintaining Confidentiality With Vulnerable Adults; Demonstrating Cultural Safety in Confidentiality Practices; Strengthening Documentation to Support Privacy Decisions; Preventing Accidental Breaches Through Environmental Awareness; Embedding Continuous Improvement and Professional Growth.
- Section 09 · Conclusion and Key Takeaways
- Conclusion; Key Takeaways.
How to respond to an Ahpra notification, complaint or allegation
Ahpra, your National Board, a panel and a tribunal all read a confidentiality response as the route the information took: what travelled, to whom, how, and what has changed. Ahpra says it needs to understand how you responded to the event — recognising and assessing the risk, responding promptly in the patient’s interests, accepting accountability, declaring what happened, actively reflecting and updating your knowledge and skills, and being able to say how you would respond in similar circumstances in future. The course teaches each part.
What you did in the hour you knew is read before what you knew.
- How the information travelledWhat was disclosed, opened, overheard or posted; to whom, and how they could identify the patient; and why — the address that auto-completed, the ward with no private room, the concern for someone you knew — in order and in the first person, with the log beside it.The course’s five worked cases — an email, a shared ward, two family requests, a post — each set out what went wrong, the insight and the remediation.
- What you did in the hour you knewThe recall, the recipient contacted, the patient told, the practice told so that any notification the Privacy Act requires is made, the access stopped — all of it with times, or, if not, why not and what has been done since.The course gives responding to an accidental breach a lesson of its own.
- The clause, and the effect on the patientThe clause named by number from your own Board’s code — 3.3 of the shared code, 4.4 of Good medical practice, 3.5 of the NMBA codes — and the effect in the patient’s terms: the exposure, the trust, the people who now know, the decision taken out of their hands.The course names the code each Board uses, reads them side by side, and sets out what a breach does to a patient.
- What has changed, with evidenceThe room, the mailing list, the access permissions or the telehealth protocol, each changed and dated; an audit of your own record access, repeated; a confidentiality self-audit against the nine points of 3.3.This course is the dated item you attach — and it names the other tools.
Confidentiality protects against recognition, not only against naming.
Take advice from your indemnity insurer or defence organisation, your union or professional association, or a lawyer before you respond to anyone.
Facing an Ahpra notification, complaint or allegation? This course helps you remediate — and demonstrate it.
Buy this course — A$200.00How this course helps with an Ahpra notification
The Board reads for how the information travelled before it reads for the harm
Confidentiality matters differ from many others in one respect: the remediation is systemic as well as personal. What a Board looks for beside the apology is what changed about the room, the mailing list, the handover and the access permissions — and, before that, an account that matches the log. Every code is a numbered document: a shared-space breach engages 3.3 point b with 4.10, a record opened without a reason 3.3 point c, an email to the wrong recipient 3.3 with 8.3 on secure records, a post 3.3 point g. A response that names the clause and answers it reads very differently from one written about the importance of privacy in general. Practitioners who show insight, take responsibility and engage in remediation are treated differently from those who deflect blame or repeat the behaviour.
Reflection has a structure, and the Board can tell when it is absent
The course sets out five components of high-quality reflection: description, analysis, impact, learning and action. On a confidentiality matter the description is the route the information took, told without minimising, and the impact is the part a response can leave out: the psychological and relational effect on the patient — who could now identify them, and what that meant. The analysis is where the auto-complete, the four-bed ward, the shared screen or the long shift belongs — environmental, emotional and systemic factors a plan can change, never a defence — and curiosity about someone you know is named there plainly. The course names the weak version too: “it wasn’t that serious” is minimisation. A statement such as “I will be more careful with patient information” will not satisfy a Board; a permissions review and an access audit, dated and repeated, will.
Remediation that stands up
Confidentiality remediation is unusually concrete, because a breach has a route: the room, the list, the screen, the platform and the access rule can each be changed and shown to have changed — and the Board, a panel and a tribunal all weigh it the same way. Counts: a reflective statement that cites your Board’s confidentiality clause by number; CPD targeted to the lapse, this course’s dated certificate among it; an audit of your own record access and a confidentiality self-audit against the nine points of 3.3, repeated after an interval; supervision or mentoring with written reports; feedback from patients and colleagues gathered on purpose. Counts for little: an apology followed by “but”, a character reference in place of an account, CPD hours on another subject, a reflection written by someone else, a promise where evidence should be. For the stages from the first letter to a tribunal, see the Ahpra investigation process, explained.
Read the primary sources
Who wrote it
In short
Confidentiality in Healthcare Practice is a self-paced remediation course of 2 hours for practitioners registered with any of Australia's fifteen National Boards facing an Ahpra notification, complaint or allegation. The duty is clause 3.3 of the shared Code of conduct, and the equivalent clause in each Board's own code — 4.4 for doctors, 3.5 for nurses and midwives, 3.3 for psychologists. It covers disclosure and consent, unauthorised access to records, shared clinical spaces, email and telehealth, social media and identifiability, families and carers. It is not accredited by Ahpra or any National Board, and no course determines the outcome of a notification.
Which code of conduct applies to you
There is no single code covering every registered practitioner, and the confidentiality clause is numbered differently in each. The shared Code of conduct, developed by twelve National Boards under section 39 of the National Law, puts it at clause 3.3, Confidentiality and privacy: nine lettered obligations, from consent before disclosing and surroundings that allow a private discussion (point b) to never opening a record you are not professionally involved with (point c) and never posting a person’s information or images, even unnamed, without written consent (point g). Doctors cite Good medical practice at 4.4, nurses and midwives the NMBA codes at 3.5, and psychologists the Psychology Board’s own code, in force since 1 December 2025, at 3.3. The duty is the same in substance: information is held in confidence unless its release is required or authorised by law, or needed for emergency care.
Three things are Australian. The first is the second system: the Privacy Act 1988 and its thirteen Australian Privacy Principles, with state and territory health records law beside them, govern how health information is collected, held, used and disclosed — and the code says it is no substitute for that law, and that the law prevails where the two conflict, so one breach can bring a notification and a privacy complaint to the OAIC or a state privacy body at the same time. The second is the National Law: under section 41 a Board may use its code to evaluate your conduct, and a confidentiality concern travels the same route as any notification — assessment, immediate action where the risk is current, investigation, a panel or a tribunal — with the HCCC and your profession’s Council of NSW, or the Office of the Health Ombudsman, holding the file first in New South Wales and Queensland. The third is the log: record systems, mail servers and telehealth platforms record who opened, sent or saw what, so a response is read against the system before it is read for anything else. Cite the clause your own Board uses, say how the information travelled and what you did in the hour you knew, and attach the dated evidence of what has changed. The Board reads for the last part.
What these words mean
The four terms that matter most here, and the other words on this page.
- Notification
- The formal term for a concern raised with Ahpra about a health practitioner. Anyone may make one, and in some circumstances practitioners and employers are required to.
- Immediate action
- The step a National Board may take at any stage under section 156 of the National Law where it believes a practitioner poses a serious risk: suspending registration or imposing conditions while the matter continues. A protective step, not a finding, and reviewable.
- The Australian Privacy Principles
- Thirteen principles under the Privacy Act 1988 governing the handling of personal information, including health information as a category of sensitive information. The shared Code of conduct points to them directly.
- The four National Law grounds
- Fitness to practise is the phrase practitioners use for the whole process. The National Law names four grounds on which a Board acts: impairment (a health matter, not a conduct finding), unsatisfactory professional performance (knowledge, skill, judgement or care below the standard of a peer), unprofessional conduct (conduct below what peers and the public reasonably expect) and professional misconduct (substantially below that standard, found only by a tribunal). Which one your letter uses tells you how the matter is being treated.
Confidentiality, privacy, mandatory notification, insight, remediation and the other terms the course uses
- The shared Code of conduct
- The Code of conduct issued by twelve National Boards under section 39 of the National Law. Section 3.3 is the confidentiality clause. It does not cover doctors, nurses, midwives or psychologists, who have codes of their own.
- Confidentiality
- The professional and ethical duty not to disclose what a patient tells you or what you learn in the course of caring for them. It is owed to the patient and it survives the end of the therapeutic relationship.
- Privacy
- The legal framework governing how personal and health information is collected, held, used and disclosed. Confidentiality is the duty; privacy law is the statutory machinery around it. The two overlap but are not the same thing.
- Mandatory notification
- A report a practitioner is required by the National Law to make in defined circumstances. It is one of the situations in which the duty of confidentiality gives way to a legal obligation.
- Insight
- Understanding what happened, why it happened, and the effect on the patient and on public confidence. In a confidentiality matter this means understanding how the information travelled, not simply regretting that it did.
- Remediation
- The concrete steps taken so the same breach does not recur, with evidence that they happened and were sustained. In confidentiality matters this is often systemic as much as personal.
The clauses a confidentiality notification engages
Read off the shared Code of conduct, which twelve National Boards use; if you are a doctor, a nurse, a midwife or a psychologist, your own code covers the same ground under different numbers — Good medical practice at 4.4, the NMBA codes at 3.5, the Psychology Board’s code at 3.3 — and the course reads them side by side. The clause a confidentiality notification starts on, then the three it reaches once the matter is examined; the rest are below.
3.3 — Confidentiality and privacy
The clause this course sits on. Seek informed consent before disclosing, and document it; provide surroundings that allow a private discussion (point b); never access a record when you are not professionally involved or authorised (point c); apply your state or territory’s privacy and health records law in every format; and never transmit, share, reproduce or post a person’s information or images, even unnamed, without written informed consent (point g). Information is held in confidence unless its release is required or authorised by law, or needed for emergency care.
For this course: its five worked cases sit under this clause — consent before disclosing (point a) in the two family-request cases, private surroundings (point b) on the shared ward, posting (point g) in the social media case, and secure handling in the misdirected email — and the remediation it names is concrete: secure messaging, a double-check before sending, staff training and a review of access controls.
8.3 — Health records
Records held securely and not subject to unauthorised access, the privacy and integrity of electronic records protected, and no demeaning or derogatory remarks in them. An email sent to the wrong address, a result left on an open screen, a file kept where the practice does not control it and a record opened without a reason all reach here, beside 3.3; an audit of your own record access, repeated after an interval, shows the change held.
For this course: telehealth, digital records and electronic communication have a lesson of their own; secure messaging, a double-check before anything is sent, and a review of password protection and access controls are the system changes it names.
4.4 — Relatives, carers and partners
Be considerate of those close to the patient and respectful of their role — but provide information only with appropriate consent, or where otherwise permitted. The qualifier is the whole obligation: a relative told about an adult patient, a partner given a result or an employer told why someone was away engages it, and so does a refusal where the law required disclosure. Explain the position to the relative respectfully rather than simply refusing, and record the exchange.
For this course: the two family-request worked cases turn on the qualifier in this clause — appropriate consent, or otherwise permitted — and the course gives the words for the conversation with the relative as well as the rule.
4.5 — Adverse events and open disclosure
Where a breach has harmed someone the clause applies as it does to any adverse event: recognise what has happened, act to rectify it, explain to the patient as promptly and fully as possible, acknowledge their distress, and review the event to reduce the risk of recurrence. What you did in the hour you knew — the recall, the recipient contacted, the patient told, the practice told — is read before anything else in a confidentiality response.
For this course: its lessons on responding to a breach set out the same steps: acknowledge it promptly, assess the harm, tell the patient (open disclosure), report it internally, document it, and change the system that let it happen.
Also engaged: 4.10 — working with multiple patients: whether confidentiality can be provided before treating more than one patient at a time, the shared-ward case · 3.2 — effective communication: information to colleagues within the bounds of privacy, and no non-professional remark about a patient in a message or a note · 4.9 — professional boundaries: a record opened out of curiosity about a patient or a colleague is a boundary question before it is a privacy one · 7.1 — risk management: the system component of a breach, and the root cause analysis that answers it · 8.1 — reporting obligations: a mandatory notification is one of the places confidentiality gives way to a legal duty · 4.6 — complaints: a prompt, open and constructive answer to a confidentiality complaint, with what happened and what changed · 4.11 — closing or relocating a practice: records transferred or managed under the privacy and health records law that applies.
What happens after a confidentiality notification reaches Ahpra
The same stages as any notification, set by the National Law, whichever Board registers you — and at every one the reader asks the same question: how did the information travel, what did you do in the hour you knew, and what now stops it happening again? It answers from the log and the dated evidence.
Assessment: how did the information travel, and what has changed?
Ahpra and the Board assess every notification for risk to the public, tell you about it and ask for your written response. The first reading is of the account against the log; a breach owned, the patient told, the room, the list or the permissions changed and dated remediation attached can end a confidentiality matter here, with no further action or advice.
Immediate action, where the risk is current
At any stage, where the Board believes a practitioner poses a serious risk, it may suspend registration or impose conditions while the matter continues (section 156). A protective step, not a finding, and reviewable — and the response to it is read like any other. On a confidentiality matter immediate action is rare on its own; it follows where access or disclosure is continuing, deliberate or part of a pattern, and a response that shows access already controlled is read as the risk controlled.
Investigation: does the account hold against the log?
Where more is needed, Ahpra investigates (section 160): some information is gathered through a case discussion at which you may be represented, some under compulsory powers. The investigator reads the audit log, the email trail, the platform record or the post beside your account; an account the log does not support becomes a probity question of its own.
Health or performance assessment: was there something beneath it?
Where the concern is about health or about performance rather than conduct, the Board may require a health assessment or a performance assessment (sections 169 and 170) instead of an investigation. Impairment is a health matter under the National Law, dealt with under its own route with support, and a condition declared early, with a plan behind it, is read as insight. An email sent at the end of a shift that was too long, or a record opened while distracted, can point to fatigue or illness beneath a confidentiality matter, and the course names fatigue, stress and burnout among the human factors behind a breach.
A panel: does the practitioner understand what the disclosure meant for the patient?
The Board may refer a matter to a performance and professional standards panel or a health panel (sections 181 and 182), which meets you and can caution, impose conditions or refer the matter on — it cannot cancel registration. On a confidentiality matter it asks whether you understand how the information travelled and what its reach meant to the patient — and it can impose conditions, supervision or education itself.
The tribunal: what should follow?
The most serious matters go to the tribunal in your state or territory (section 193), which can reprimand, impose conditions, fine up to A$30,000, suspend, cancel registration and disqualify (section 196). In 2024/25, 94.3% of the matters closed after a tribunal referral ended in disciplinary action. The tribunals weigh insight, remediation and conduct since the events in every decision, and their orders — education, mentoring, audits, supervision — are made of the same instruments a remediation portfolio holds. A confidentiality matter reaches a tribunal where access was deliberate or repeated, or where the account given of it was untrue — and a denial the log contradicts is weighed as a matter of honesty in its own right.
Who investigates in New South Wales and Queensland
Two states run their own arrangements in every one of the sixteen professions. A New South Wales conduct matter does not go to Ahpra: your profession’s Council of NSW manages standards and conditions and the Health Care Complaints Commission (HCCC) investigates and prosecutes. In Queensland every complaint goes first to the Office of the Health Ombudsman (OHO), which keeps what it keeps and refers the rest to Ahpra and your Board. Ahpra sets both out at reporting concerns in New South Wales or Queensland. A privacy breach may also engage the OAIC or a state privacy body separately; the letterhead tells you which body holds which file.
Facing an Ahpra notification, complaint or allegation? This course helps you remediate — and demonstrate it.
Buy this course — A$200.00Whatever your profession: Ahpra and the National Boards regulate 16 professions under the National Law, and the process is the same for all — courses for every registered profession →
Frequently asked questions
What does my Board want in a response to a confidentiality notification?
The route the information took, and what now closes it. What was disclosed, opened, overheard or posted; to whom, and how they could identify the patient; why it happened; what you did in the hour you knew — the recall, the recipient contacted, the patient told; the clause named by number from your own code — 3.3 point b with 4.10 for a shared space, 3.3 point c for a record opened without a reason, 3.3 with 8.3 for an email to the wrong recipient, 3.3 point g for a post; and the change, systemic as well as personal, each part dated. The course’s five components of reflection — description, analysis, impact, learning and action — are the structure.
Should I take advice before I respond to Ahpra?
Yes — before you answer, and before you contact the patient or the recipient about the breach, because how that is done is part of the answer. Your indemnity insurer or defence organisation is the first call, and a lawyer should read the response before it goes to Ahpra, your National Board, your profession’s Council of NSW or the HCCC, the OHO, a privacy body, your employer, or a panel or tribunal. Nothing on this page is legal advice, and no course determines the outcome of a notification.
Can a confidentiality breach be remediated — and will Ahpra or my Board accept this course as part of it?
Yes, concretely: the patient told; the room, the list or the permissions changed and dated; your own record access audited, then audited again. No provider is accredited by Ahpra or any National Board, and no course decides a matter. What the Board, a panel and a tribunal weigh is dated, targeted remediation with reflection that engages the standard — and this course is written to clause 3.3 and the professions’ own codes, so the connection is plain on the certificate and in your reflective account. Check the wording of any condition, undertaking or direction with your indemnity insurer or defence organisation, your union or professional association or a lawyer before you rely on it.
What can my Board do about a confidentiality concern?
After an assessment or an investigation your Board may take no further action, caution you, accept an undertaking or impose conditions — supervision, an audit of your record access, education (section 178) — refer you to a panel, or refer the most serious matters to a tribunal (section 193), which can reprimand, impose conditions, fine, suspend, cancel registration and disqualify (section 196). Deliberate or repeated access, and an account of it that was not true, are what take a confidentiality matter towards a tribunal; in 2024/25, 94.3% of the matters closed after a tribunal referral ended in disciplinary action. The honest account and the change since are weighed every time.
Who investigates a confidentiality complaint in New South Wales or Queensland?
Not Ahpra, in either case. In New South Wales your profession’s Council of NSW and the Health Care Complaints Commission manage conduct, health and performance matters between them, and Ahpra does not investigate registered practitioners there. In Queensland every complaint goes first to the Office of the Health Ombudsman, which decides what it keeps and what it refers on to Ahpra and the Board. The letterhead tells you which body has your file, and the same response — the reasoning, the standard, the remediation — is what each of them reads for. A privacy breach may also engage the OAIC or a state or territory privacy body separately.
Which code of conduct actually applies to me?
It depends on your profession. The shared Code of conduct is issued by twelve National Boards — Aboriginal and Torres Strait Islander Health Practice, Chinese medicine, chiropractic, dental, medical radiation practice, occupational therapy, optometry, osteopathy, paramedicine, pharmacy, physiotherapy and podiatry — and there the confidentiality clause is 3.3. It does not apply to doctors, nurses, midwives or psychologists, each of whom has a separate code with the same duty under different numbering: Good medical practice at 4.4, the NMBA codes at 3.5, and the Psychology Board’s code, in force since 1 December 2025, at 3.3. Check which code covers you before you cite one.
When can I lawfully disclose without consent?
The code puts it narrowly: information is held in confidence unless its release is required or authorised by law, or is needed to facilitate emergency care. A mandatory notification under the National Law and a reporting duty under state or territory law sit inside that exception, as do a court order and a lawful request from a regulator. Everything else needs consent, and the code asks you to document it where possible. Then share only the relevant information, and record the reasoning — disclosing more than was needed is a breach even where some disclosure was justified. If you are unsure, take advice before you disclose, not after.
The information I shared did not name anyone. Does that still count?
Yes. Clause 3.3 point g is explicit: do not transmit, share, reproduce or post any person’s information or images, even if the person is not directly named or identified, without first getting written and informed consent. Confidentiality protects against recognition, not only against naming: a role, a place, an event or an unusual presentation can identify a patient, and in a small or remote community that threshold is much lower than many practitioners assume. De-identification is not a defence if the person is recognisable from the detail, and the course’s social media case is written on exactly this point.
Someone else looked at the record. Is that still my problem?
It may be. Clause 3.3 asks you to make sure staff are aware of the need to respect confidentiality and do not discuss patients in a non-professional context, and clause 7.1 asks you to take reasonable steps where patient safety may be compromised. If you had responsibility for the room, the team or the system, the question will include what you had put in place — the access rules, the induction, the reminder after the last near miss. That is also why confidentiality remediation is so often systemic as well as personal, and why a response names the system change beside your own.
Is a privacy breach the same as a confidentiality breach?
Not quite, and the distinction matters. Confidentiality is the professional duty you owe the patient, set by your Board’s code; privacy law is the statutory framework — the Privacy Act 1988 and its thirteen Australian Privacy Principles, with state and territory health records law beside them. One incident can bring a notification to Ahpra and a privacy complaint to the OAIC at the same time, and the code says the law prevails where the two conflict. The course makes the distinction in its own terms: privacy as the patient’s right to personal space, bodily modesty and freedom from intrusion, confidentiality as your duty to protect their information — and either can be breached without the other.
Should I do a course before or after I respond to Ahpra?
Ask your adviser about the order, but the pattern is clear: remediation begun before the response is evidence you can describe in it, and remediation promised for later is an intention. A dated certificate showing you worked through the standard before the outcome was known reads differently from one dated afterwards, and the systemic changes — the room, the mailing list, the access permissions — are worth making and dating at once. The course is 2 CPD hours and self-paced, so it can sit beside the response rather than after it.
How is this different from the Privacy, Consent and Chaperone course?
They overlap on consent to share information, and they are often taken together. This course works from the information outwards: what was disclosed, opened, overheard or posted, to whom, the duty in your Board’s code and the privacy law beneath it, and the system change that answers it. The Privacy, Consent and Chaperone course works from the consultation inwards: consent as a process, privacy and dignity during an examination, and the question of a third person in the room. If the letter is about where information went, start here; if it is about what happened in the room, start there.
Does this count towards my CPD?
Each National Board sets its own continuing professional development registration standard, and targeted CPD on the subject of a notification is among the remediation the Board and the tribunals recognise. The certificate records the course, the 2 CPD hours and the date, which is what a CPD portfolio needs; how the hours count towards your requirement depends on the standard’s categories, so check them.
How long does it take, and how long do I have access?
The course is 2 CPD hours, self-paced, with twelve months’ access from purchase. The certificate is issued on completion, dated, with the course title and the CPD hours, for a response, a portfolio or your CPD record.
Courses that work alongside this one
A notification can raise more than one issue. These are the courses that pair with this one.
Documentation for Healthcare Professionals
Records in daily practice: stored securely, never opened without a clinical reason, and free of judgemental labels.
Social Media Professionalism and Boundaries
Confidentiality online: why a “de-identified” post can still identify a patient, and why closed groups are not private.
Privacy, Consent and Chaperone in Healthcare Practice
The consent side of the same duty, and the practical arrangements that keep a consultation private.
Dealing with a Complaint or Investigation Professionally
How to conduct yourself through the process without making the matter worse.
Insight for Fitness to Practise
The element a Board weighs in every decision, and the one often described as lacking.
Remediation for Fitness to Practise
Turning insight into evidenced change: CPD on confidentiality, an audit of your own records, and a supervisor’s letter.
Professional Boundaries Course
Boundary drift and confidentiality failure can go together, through a dual relationship or a post that identifies a patient.
Confidentiality in Healthcare Practice
This course. Disclosure and consent, a record opened without a reason, shared spaces, email and telehealth, social media, families and carers, and the evidenced remediation that answers a notification.
See all CPD courses for healthcare professionals in Australia →
Start today, finish at your own pace
Immediate access on purchase. Twelve months' access, a dated certificate on completion, and 2 CPD hours issued by Healthcare Ethics Courses.