Implemented correctly, a data minimisation strategy would mean that clinics hold fewer sensitive details about patients.
GP clinic cyber-attacks and data breaches would be a whole lot less disastrous if the clinic didn’t hold so much sensitive personal, patient-identifying information – or at least that’s the opportunity that the RACGP sees in digital ID technology.
Several jurisdictions across Australia have now rolled out digital driver’s licenses, the underlying technology for which is known as “verifiable credentials” (VC).
VC use has become popular enough that the Commonwealth is currently developing a range of policies, frameworks and strategies for the technology.
Part of the use case, according to Department of Finance consultation documents, is that VCs can reduce the economic impact of data breaches by “constraining the amount of data that needs to be shared, and driving down the prevalence with which copies of physical credentials are stored”.
In its submission to the Department of Finance consultation, the RACGP seized on this idea of “data minimisation”.
“Rather than requiring patients to present an entire document containing information that is not relevant to the transaction, a VC could enable an individual to prove a specific attribute—such as Medicare eligibility, concession status, age eligibility, or another entitlement—without disclosing additional personal information,” the college wrote.
“This data-minimisation approach reduces the amount of sensitive information collected, handled, and potentially exposed by healthcare providers, while still providing confidence in the validity of the claim being made.”
The forthcoming sixth edition of the RACGP’s Standards for General Practice, the college noted, will note that copies of patients’ identity documents must not be stored in their health record due to the security risk it represents.
Data breaches in healthcare have become increasingly common over the last several years; there was an 84% rise in reported cybersecurity incidents in Australia’s healthcare sector between 2019 and 2020 alone.
Partnered Health, one of Australia’s largest corporate GP chains, announced last week that 21 clinics had been subject to a large-scale cyber-attack in June.
The criminals were able to access patients’ personal details and health information.
This includes information such as names, dates of birth, addresses, contact details, Medicare numbers, private health insurance details, veteran card numbers and concession card numbers.
Related
The other big opportunity that the RACGP espied within the Department of Finance consultation was for GPs themselves.
“GPs are frequently required to demonstrate their identity, AHPRA registration status, prescribing authority and eligibility to access government services,” the college wrote.
“Verifiable credentials could enable these attributes to be validated in real time, reducing administrative burden and supporting more seamless access to systems such as PRODA.”
This enthusiasm came with the caveat that VC technology would only work to increase GP efficiency if it was suitably interoperable with existing system.
While the RACGP said it would support policy settings which minimised the unnecessary capture and storage of personal information, it also said that physical credentials should remain valid.
Doing so would be essential to ensuring access for older patients, people with low digital literacy, vulnerable or marginalised populations and patients in rural areas, the college said.



