EQH v Health Administration Corporation (No. 2) [2022] NSWCATAD 45
The Respondent was not responsible for M's unauthorised access because M accessed EQH's health information for purposes extraneous to her employment and contrary to the Respondent's policies. The Respondent had taken reasonable safeguards as a whole, including restricting access to staff with work need, password and login controls, audit capability, privacy policies, mandatory privacy training, staff communications, warnings about monitoring and consequences, and disciplinary responses. Accordingly, the Respondent did not contravene HPP 5(1)(c), M's conduct was not attributable to the Respondent, and there was no use by the Respondent for HPP 10 purposes.
- Jurisdiction
- Australia
- Judgment Date
- 09 February 2022
- Procedural Posture
- Application for Review of Conduct Alleging Contraventions of Privacy Obligations Under the Health Records and Information Privacy Act 2002 (nsw) and Privacy and Personal Information Protection Act 1998 / Hearing to Determine Whether the Respondent Had Liability for the Conduct of Employee M Under the HRIP Act
- Outcome
- The Respondent's decision made on 26 February 2021 was affirmed and no further action was taken.
- Legal Topics
- ['health Privacy Principle 5(1)(c)' 'reasonable Security Safeguards' 'unauthorised Access to Health Information' 'rogue Employee' 'vicarious Liability' 'health Records and Information Privacy Act 2002 (nsw)']
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Procedural Posture
Application for Review of Conduct Alleging Contraventions of Privacy Obligations Under the Health Records and Information Privacy Act 2002 (nsw) and Privacy and Personal Information Protection Act 1998 / Hearing to Determine Whether the Respondent Had Liability for the Conduct of Employee M Under the HRIP Act
Legal Issues
- 1 ["Whether the Respondent was responsible for M accessing the Applicant's personal and health information other than as required in the exercise of M's duties." "Whether the Respondent contravened HPP 5(1)(c) by failing to take reasonable security safeguards against unauthorised access, use, modification, disclosure or misuse of the Applicant's health information." "Whether principles of vicarious liability should attribute M's conduct to the Respondent in the privacy context." "Whether there was any breach of HPP 10 arising from M viewing the Applicant's health information."]
Ratio Decidendi
The Respondent was not responsible for M's unauthorised access because M accessed EQH's health information for purposes extraneous to her employment and contrary to the Respondent's policies. The Respondent had taken reasonable safeguards as a whole, including restricting access to staff with work need, password and login controls, audit capability, privacy policies, mandatory privacy training, staff communications, warnings about monitoring and consequences, and disciplinary responses. Accordingly, the Respondent did not contravene HPP 5(1)(c), M's conduct was not attributable to the Respondent, and there was no use by the Respondent for HPP 10 purposes.
Court Disposition
The Respondent's decision made on 26 February 2021 was affirmed and no further action was taken.
Orders
- ['The decision of the Respondent made on 26 February 2021 is affirmed.' 'No further action is taken.']
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment