Aged Care Privacy Breach Documentation: What to Record After a Data Incident

Learn how aged-care providers can document suspected privacy incidents, containment, affected information, preserved audit evidence, notification assessment, remediation, and review.

Published by Privacy & Compliance Specialist

Open a Restricted Incident Record Without Pre-Judging the Outcome

Create a role-restricted privacy incident record when a suspected loss, unauthorised access, disclosure, alteration, or system event is discovered. Record the initial facts and classification as suspected unless and until an authorised assessment confirms what occurred. A suspected privacy incident is not automatically a confirmed eligible data breach under the Notifiable Data Breaches scheme.

Keep sensitive investigation material out of general progress notes, email chains, and broad-access registers. A resident record may need a minimal factual entry where care or communication was affected, but it should link to the restricted incident process rather than reproduce exposed information.

Record Discovery, Source and Immediate Reporting

Document when and how the issue was detected, who detected it, the system or process involved, and when the authorised privacy or incident lead was notified. Preserve the reporter's factual account, screenshots or messages through approved secure methods, and distinguish observed facts from assumptions.

Use the Privacy Act and health information documentation guide to identify handling principles while the incident is assessed. Record only information necessary to understand and manage the event.

Document Containment and Preserve Evidence

Containment may include recalling a message, disabling credentials, isolating a device, restricting a record, securing paper files, or asking an unintended recipient to preserve and not use information. Actions should be directed by authorised roles so that containment does not destroy evidence or interrupt essential care.

Record each containment action, time, actor, result, and unresolved risk. Preserve relevant audit logs, access records, file versions, email metadata, device information, and vendor records under approved evidence controls. Do not edit original logs or rely on screenshots alone when authoritative system evidence is available.

Define the Affected Records, People and Systems Carefully

Build a verified inventory of affected systems, data sets, documents, users, recipients, and people. Note the type and sensitivity of information, whether it was encrypted or otherwise protected, access permissions, exposure pathway, likely access or use, and what remains unknown. Avoid placing the affected data itself into the incident summary unless necessary and authorised.

Reconcile system evidence with manual records and third-party reports. Correct the inventory as facts emerge while retaining a traceable history of who changed the assessment and why.

Separate Risk and Notification Assessment From Communications

An authorised privacy, legal, governance, or executive role should assess the event against current Privacy Act, Australian Privacy Principles, NDB scheme, applicable health-record laws, contracts, aged-care obligations, and provider policy. Record the criteria considered, evidence, uncertainties, advice obtained, decision-maker, decision, and review trigger. Do not assume a universal notification deadline or claim that one framework covers every organisation or incident.

Keep draft assessment work separate from authorised communications. Record which residents, representatives, regulators, partners, insurers, law enforcement bodies, or other parties were approved for contact, by whom, through what secure channel, and what version was sent. The aged care privacy compliance guide provides wider governance context.

Privacy Incident Documentation Checklist

  • Restricted incident identifier, discovery details, factual initial report, and current classification.
  • Privacy lead notification, authority, access controls, and confidentiality instructions.
  • Containment actions, timestamps, accountable people, outcomes, and service impacts.
  • Affected systems, records, information types, individuals, recipients, and unknowns.
  • Original audit logs and digital or paper evidence preserved with source and integrity recorded.
  • Risk and notification criteria, applicable frameworks, advice, decision-maker, and rationale.
  • Authorised communication plan, approved wording, recipients, delivery, and questions raised.
  • Corrections, access restoration, resident support, vendor actions, and operational remediation.
  • Root contributors, improvement owners, effectiveness measures, and review outcome.
  • Links to related incident, complaint, care, workforce, or regulatory records without unnecessary duplication.

Example of a De-Identified Restricted Breach Record

"09:12 — Staff member C reported that a care summary for Resident D was attached to an email sent to an unintended external address. Incident logged as a suspected privacy incident; no NDB conclusion made. Privacy lead assumed control at 09:19. The recipient was contacted using the approved script and confirmed the message was unopened and deleted, subject to verification. IT preserved mail-gateway, access, and recall logs before account changes were made. The affected document version and fields are listed in the restricted evidence schedule, not this summary. Privacy lead will complete the applicable risk and notification assessment with legal input. Resident communication is deferred to the authorised communication decision and will not be made through general email."

Remediate, Review Effectiveness and Maintain Record Integrity

Remediation may address access configuration, recipient selection, printing, disposal, identity verification, staff support, vendor controls, templates, or workflow design. Assign each action, preserve the reason for change, and later test whether the control worked in practice. A policy update or training attendance record alone does not establish effectiveness.

Use the late entries and corrections guide if the incident record needs amendment: preserve the original, date and attribute the correction, and explain why it was made. Close the incident only through the authorised process, with remaining risks, communications, linked actions, and review outcomes visible. Complete documentation supports accountability but does not guarantee compliance or a regulatory outcome.


This article provides general documentation education, not legal advice. Apply current privacy, NDB, health-record, contractual, aged-care, and organisational requirements to each incident.