AI and patient data: what practices can and cannot do.

Health information sits at the top of Australia's privacy hierarchy, and AI vendors' generic assurances are least persuasive exactly here. This guide maps the instruments that apply when a practice considers AI, and the distinction that keeps the analysis manageable: administrative use versus clinical use.

General information only. This guide is not legal advice and is not a substitute for advice about your specific obligations. Verify positions against the primary sources linked throughout, and take professional advice where it matters.

Health information is sensitive information

Under the Privacy Act 1988, health information is sensitive information, attracting the strictest APP handling requirements: tighter collection rules, tighter use and disclosure limits, and the same APP 8 cross-border analysis that applies to any offshore processing, now with the least forgiving category of data (OAIC, health information). A prompt containing a patient's name and condition is a disclosure of health information; where that prompt travels is the whole question.

My Health Records and state regimes

The My Health Records Act 2012 imposes its own controls on record information, with civil and criminal penalties for unauthorised use and disclosure (My Health Records Act 2012). State instruments add further layers: the Health Records and Information Privacy Act 2002 in NSW and the Health Records Act 2001 in Victoria both regulate health information held by private sector providers in those states. A practice using cloud AI needs its data flows to be defensible under each regime that applies to it; a practice processing on-site largely avoids engaging them.

De-identification is harder than it sounds

The tempting workaround is stripping names before pasting into a cloud tool. In a clinical context, de-identification that actually defeats re-identification is genuinely difficult: rare conditions, dates, locations and referral chains re-identify patients with unsettling ease, and information is only outside these regimes if re-identification is no longer reasonably possible. Relying on ad-hoc de-identification by busy staff is a policy that audits badly.

The administrative and clinical distinction

The defensible frame for AI in a practice today is administrative and documentation assistance: drafting referral letters and correspondence for practitioner review, summarising incoming documents for verification, maintaining policies and templates. Diagnostic or clinical decision support is different regulatory territory, engaging therapeutic goods regulation of software as a medical device. Ermos units are built for the first category only, and say so on our healthcare page: documentation help with clinical judgement staying entirely with practitioners.

The practical takeaway

For patient data, the deployment posture question is at its sharpest: every regime above is engaged by transmission and quiet about processing that never leaves the practice. Our four-postures comparison sets out the options side by side.

Common questions

Can a GP practice use ChatGPT for patient letters?
Putting identifiable patient information into a public cloud AI tool is a disclosure of sensitive information and very hard to defend across the Privacy Act, My Health Records and state regimes. Practices wanting AI drafting either enforce strict no-patient-data rules or move the processing on-site.
Is de-identified patient data safe to use with cloud AI?
Only if re-identification is no longer reasonably possible, which is a high bar for clinical information. Rare conditions, dates and referral details re-identify readily. Treat ad-hoc de-identification by staff as a risk, not a control.
Can AI be used for clinical decisions?
Software intended for diagnosis or clinical decision support can be regulated as a medical device, which is different territory from administrative assistance. Ermos units are positioned strictly as documentation and administrative help, with clinical judgement remaining with practitioners.

See Dominion answering from your own documents.

A demonstration takes 30 minutes, uses no client data, and comes with no obligation.

Book a demo