AI Receptionist Privacy Rules: Australian Dental Clinics - Zian AI

AI Receptionist Privacy Rules: Australian Dental Clinics

AI Receptionist Privacy Rules: Australian Dental Clinics

A dental or medical practice running an AI phone agent is an APP entity under the Privacy Act 1988 (Cth) at any size. The A$3,000,000 small-business threshold in s 6D(1) is switched off by s 6D(4)(b) for a health service provider holding health information. That information is sensitive information under s 6(1), so APP 3.3 governs every call.

  • Turnover does not save you. The A$3,000,000 threshold in s 6D(1) is switched off by s 6D(4)(b).
  • APP 3.3 requires consent and reasonable necessity, not either — unless one of the APP 3.4 exceptions applies.
  • “Australian hosted” is an APP 8 and s 16C question. Where APP 8.1 applies, s 16C makes the practice answerable for an offshore recipient.
  • From 10 December 2026, APP 1.7 adds an automated-decision disclosure — the threshold is contested.

Your practice is covered even at two chairs

Most Australian small businesses sit outside the Privacy Act. Health practices do not. Section 6D(1) of the Privacy Act 1988 (Cth) defines a small business by annual turnover of “$3,000,000 or less” (Australian dollars). Section 6D(4)(b) then says an entity is not a small business operator if it “provides a health service to another individual and holds any health information except in an employee record” — both limbs, not just the first (compilation No. 104, in force 4 June 2026, checked 4 September 2026). The OAIC agrees: “Regardless of turnover, the Privacy Act covers any business that is: a health service provider” (OAIC, checked 4 September 2026).

Section 6FB defines “health service” broadly: an activity intended or claimed “to assess, maintain or improve the individual’s health”, to manage, diagnose or treat. Section 6FB(3)(b) extends it to activities in the course of aged care, palliative care and care for a person with a disability. A single-dentist practice and a two-room GP clinic are inside.

Health information is sensitive information, so APP 3.3 applies

Section 6(1) defines sensitive information to include, at paragraph (b), “health information about an individual”, and s 6FA extends that to “other personal information collected to provide, or in providing, a health service to an individual”.

APP 3.3 reads: “An APP entity must not collect sensitive information about an individual unless: (a) the individual consents to the collection of the information and … (ii) if the entity is an organisation—the information is reasonably necessary for one or more of the entity’s functions or activities”. The OAIC is explicit that both limbs must be met unless an exception applies (APP Guidelines chapter 3, paragraph 3.31, checked 4 September 2026). The exceptions live in APP 3.4 — collection required by law, a permitted general situation under s 16A, or a permitted health situation under s 16B — and they are worth reading before you assume consent is the only route. That still favours a narrow agent: one offering a short list of visit reasons is easier to defend as reasonably necessary than one recording free text. See consent language on AI calls.

APP 8 and section 16C: hosting location is a legal question

Before disclosing personal information to an overseas recipient, APP 8.1 requires the entity to “take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles”. APP 8.2 carries exceptions — chiefly where the entity reasonably believes the recipient is subject to a substantially similar law or binding scheme the individual can enforce. Where APP 8.1 does apply, s 16C does the real work: an offshore recipient’s APP-breaching act “is taken … to have been done, or engaged in, by the APP entity”. The OAIC restates this at paragraph 8.60 of APP Guidelines chapter 8 (checked 4 September 2026). That is why data location is on every vendor page in this category: the practice inherits the vendor’s mistakes. See AI data sovereignty in Australia.

What changes on 10 December 2026

Schedule 1, Part 15 of the Privacy and Other Legislation Amendment Act 2024 inserts new APP 1.7–1.9. Item 7 of the commencement table sets it at “the day after the end of the period of 24 months beginning on the day this Act receives the Royal Assent” — column 3 gives 10 December 2026. The same Part inserts APP 1.7 into s 13K(1)(b), the civil penalty provision that infringement notices attach to, capped by s 13K(4) at 200 penalty units.

APP 1.7 bites where an entity “has arranged for a computer program to make … a decision” and “the decision could reasonably be expected to significantly affect the rights or interests of an individual”. Does routine booking clear that? APP 1.9(d)(iii) gives as an example “a decision that affects the individual’s access to a significant service or support”, and the OAIC’s ADM Transparency Obligation issues paper (18 May 2026) glosses that as one that “may include access to healthcare services” — while adding that the “effects must be more than trivial, and must have the potential to significantly influence the circumstances of the individual concerned”. An agent writing a slot into a diary is arguably trivial; one deciding who gets an urgent slot is not. No regulator statement addressing whether appointment booking specifically meets the APP 1.7 threshold was found on oaic.gov.au, checked 4 September 2026. That paper is a consultation document, not final guidance — submissions closed 15 June 2026, and no submissions and no final guidance were listed on the consultation page as at 4 September 2026. Mechanics: ADM transparency statement guide.

What buyers inflate, and what they miss

Inflated: the My Health Records Act 2012, and certification. Section 59(1) of the My Health Records Act 2012 provides that “a person must not collect from the My Health Record system health information included in a healthcare recipient’s My Health Record” without authorisation, the fault-based offence in s 59(3) carrying “Imprisonment for 5 years or 300 penalty units, or both”. The trigger is collection from, or access to, that system; a booking agent that never touches it does not engage s 59 (compilation No. 18, in force 1 July 2026, checked 4 September 2026). And neither that Act nor the Privacy Act 1988 (Cth) names a health-specific privacy certification as a requirement for a phone vendor — HIPAA is a US statute and does not bind an Australian practice.

Missed: the TGA line between booking and advice. Software “intended by its manufacturer to be used for the administration or management of health processes or facilities (including financial records, claims, billing, appointments, operating theatre management, hospital bed management, schedules, business analytics, admissions, inventory and workflow)” is an excluded good under item 14G of Schedule 1 to the Therapeutic Goods (Excluded Goods) Determination 2018 — but only where it is also “not intended by its manufacturer to be used for the purpose of diagnosis, screening, prevention, monitoring, prediction, prognosis, alleviation, treatment, or making a recommendation or decision about the treatment, of a disease, condition, ailment or defect” (compilation No. 11, 8 August 2024, checked 4 September 2026). Booking reads as sitting inside that exclusion; symptom guidance is the limb that can take software out of it and towards the medical device definition in s 41BD of the Therapeutic Goods Act 1989.

The clinical decision support carve-out does not obviously rescue a patient-facing agent either. The TGA’s current guidance states: “If your software provides decision support directly to patients (or any non-health professional user) it also does not qualify for the exemption”, and separately that “an AI-enabled CDSS will not meet the exemption criteria” (TGA, Understanding clinical decision support system software regulation, last updated 29 January 2026, checked 4 September 2026). Note who this falls on: under s 41BD(2) the intended purpose is the manufacturer’s, read from labelling, instructions, advertising material and technical documentation — so it is a question for your vendor and your own regulatory adviser, not something a practice settles in a configuration screen. It is also the plainest reason to keep triage out of scope.

What to configure before the agent takes a call

  • Recording notice first, collection second. Announce recording and the practice’s identity before any clinical detail is captured — the OAIC’s Guide to health privacy, chapter 2 lists the matters a privacy notice should include (checked 4 September 2026).
  • No clinical advice, no triage, no medication questions. Deny-list those intents.
  • A hard escalation path. Your clinicians — not your vendor, and not this page — set the escalation triggers. The agent’s job is to stop and hand the call to a human or the on-call number, not to assess it.
  • A written retention period for audio. APP 11.2 requires reasonable steps “to destroy the information or to ensure that the information is de-identified” once it is no longer needed and no Australian law or court order requires retention. Audio outlives its purpose long before the clinical record does; check your state health-records rules with your adviser first.
  • Name the APP entity in the contract. The same guide is direct: you ‘hold’ health information if you have possession or control of a record, and that this “includes information that a third party stores on your behalf but you retain the right to deal with the information” (chapter 4, checked 4 September 2026).
  • Separate recalls from bookings. The guide again: “You can only use or disclose a patient’s health information for direct marketing if the patient has provided consent” (chapter 3, checked 4 September 2026).

None of this is legal advice, and none of it is clinical advice. It is a list to put in front of your own adviser, section numbers attached.

Obligation, phone agent impact, artefact to ask for

Obligation What it means for a phone agent Artefact to ask the vendor for
s 6D(4)(b) — no small-business exemption for health providers holding health information The practice is an APP entity from the first call Confirmation of whether the vendor is itself an APP entity
s 6EA — voluntary opt-in to organisation status A vendor under A$3m turnover may carry no APP obligations unless it opts in, though the other limbs of s 6D(4) can still catch it Its entry on the Commissioner’s register of opted-in operators (s 6EA(3), (6))
APP 3.3 — consent plus reasonable necessity, subject to the APP 3.4 exceptions Consent before sensitive detail; no over-collection The opening script, consent wording, and fields written to practice software
APP 8.1 and s 16C — cross-border accountability Where APP 8.1 applies, the practice answers for an offshore recipient’s APP breach Every processing location and sub-processor named, model and speech-to-text included
Part IIIC — notifiable data breaches All reasonable steps to complete the assessment within 30 days (s 26WH(2)(b)) A contractual breach-notification window shorter than 30 days
Item 14G, Excluded Goods Determination 2018, and s 41BD Therapeutic Goods Act 1989 Booking is excluded; symptom guidance is the limb that can take it out of the exclusion The manufacturer’s written intended purpose, plus the guardrail configuration

Where Zian sits: Zian AI builds autonomous phone, SMS, email and WhatsApp agents, with SmartReach AI™ orchestrating channel and timing and PrecisionPitch AI™ split-testing scripts. Zian is in partnership-application beta and holds no SOC 2, ISO/IEC 27001, HIPAA or health-sector certification of its own. Ask us these questions as you would anyone else — Apply For Partnership.

Frequently asked questions

Is a small dental practice really covered by the Privacy Act?

Yes. Section 6D(4)(b) of the Privacy Act 1988 (Cth) says an entity is not a small business operator if it “provides a health service to another individual and holds any health information except in an employee record”. A practice meets both limbs, so the A$3,000,000 test in s 6D(1) is irrelevant, as the OAIC confirms.

Does the practice or the vendor answer to the OAIC?

The practice, in almost every case. The OAIC’s Guide to health privacy says you ‘hold’ health information if you have possession or control of a record, and that this “includes information that a third party stores on your behalf but you retain the right to deal with the information”. A vendor under the A$3m threshold that has not opted in under s 6EA may carry no APP obligations of its own.

What is the penalty if this goes wrong?

Section 13G(2) caps a serious interference with privacy at A$2,500,000 for a person other than a body corporate; s 13G(3) sets the corporate maximum at the greatest of A$50,000,000, three times the value of the benefit obtained, or 30% of adjusted turnover. Section 13G(1B)(b) makes “the sensitivity of the personal information of the individual” a factor a court may weigh.

Do we have to disclose the AI agent as automated decision-making?

Possibly, from 10 December 2026, and only if the decision “could reasonably be expected to significantly affect the rights or interests of an individual” under new APP 1.7(b). The OAIC’s ADM issues paper cites “access to healthcare services” as an example, but says the “effects must be more than trivial”. No final guidance was published on oaic.gov.au as at 4 September 2026. Disclose if the agent decides urgency or allocation, and take advice if you are unsure.

Does the My Health Records Act apply to an AI phone agent?

Not unless the agent touches the My Health Record system. Section 59 of the My Health Records Act 2012 is triggered by collecting information “from the My Health Record system”, or by using or disclosing information obtained through it. A booking agent reading a practice diary does not.

Can the agent tell a caller whether their symptom is urgent?

Treat it as out of scope and take advice before doing anything else. The TGA’s clinical decision support guidance says that “If your software provides decision support directly to patients (or any non-health professional user) it also does not qualify for the exemption”, and that “an AI-enabled CDSS will not meet the exemption criteria”. Whether any given agent is a medical device under s 41BD turns on the manufacturer’s stated intended purpose. Escalate, do not assess.

Next step

Take the table into your next vendor call and ask for the artefacts by name. If a supplier cannot produce a sub-processor list or a retention default, you have your answer without a lawyer. To run it against Zian, Apply For Partnership. See also AI sales agents in regulated industries.

Related Blogs

Related from Zian AI