EQH v Health Administration Corporation (No. 2) [2022] NSWCATAD 45

EQH v Health Administration Corporation (No. 2) [2022] NSWCATAD 45

The Respondent was not responsible for M's unauthorised access because M accessed EQH's health information for purposes extraneous to her employment and contrary to the Respondent's policies. The Respondent had taken reasonable safeguards as a whole, including restricting access to staff with work need, password and login controls, audit capability, privacy policies, mandatory privacy training, staff communications, warnings about monitoring and consequences, and disciplinary responses. Accordingly, the Respondent did not contravene HPP 5(1)(c), M's conduct was not attributable to the Respondent, and there was no use by the Respondent for HPP 10 purposes.

Jurisdiction
Australia
Judgment Date
09 February 2022
Procedural Posture
Application for Review of Conduct Alleging Contraventions of Privacy Obligations Under the Health Records and Information Privacy Act 2002 (nsw) and Privacy and Personal Information Protection Act 1998 / Hearing to Determine Whether the Respondent Had Liability for the Conduct of Employee M Under the HRIP Act
Outcome
The Respondent's decision made on 26 February 2021 was affirmed and no further action was taken.
Legal Topics
['health Privacy Principle 5(1)(c)' 'reasonable Security Safeguards' 'unauthorised Access to Health Information' 'rogue Employee' 'vicarious Liability' 'health Records and Information Privacy Act 2002 (nsw)']

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 1 Authorities cited 2 Party arguments 2 Amounts and remedies 1
Sign in to unlock

Procedural Posture

Application for Review of Conduct Alleging Contraventions of Privacy Obligations Under the Health Records and Information Privacy Act 2002 (nsw) and Privacy and Personal Information Protection Act 1998 / Hearing to Determine Whether the Respondent Had Liability for the Conduct of Employee M Under the HRIP Act

  1. 1 ["Whether the Respondent was responsible for M accessing the Applicant's personal and health information other than as required in the exercise of M's duties." "Whether the Respondent contravened HPP 5(1)(c) by failing to take reasonable security safeguards against unauthorised access, use, modification, disclosure or misuse of the Applicant's health information." "Whether principles of vicarious liability should attribute M's conduct to the Respondent in the privacy context." "Whether there was any breach of HPP 10 arising from M viewing the Applicant's health information."]

Ratio Decidendi

The Respondent was not responsible for M's unauthorised access because M accessed EQH's health information for purposes extraneous to her employment and contrary to the Respondent's policies. The Respondent had taken reasonable safeguards as a whole, including restricting access to staff with work need, password and login controls, audit capability, privacy policies, mandatory privacy training, staff communications, warnings about monitoring and consequences, and disciplinary responses. Accordingly, the Respondent did not contravene HPP 5(1)(c), M's conduct was not attributable to the Respondent, and there was no use by the Respondent for HPP 10 purposes.

Court Disposition

The Respondent's decision made on 26 February 2021 was affirmed and no further action was taken.

Orders

  • ['The decision of the Respondent made on 26 February 2021 is affirmed.' 'No further action is taken.']