The same day that news of AHPRA accidentally breaching the privacy of more than 100 doctors went live, the regulator has sent out reminders that registration is due.
In what federal health minister Mark Butler has described as a “totally unacceptable” lapse, AHPRA has confirmed that it failed to conceal the identities of 136 practitioners invited to a webinar on the process of being investigated for a health impairment notification.
Whether the affected parties will be able to secure more than an apology, however, is unclear.
The email in question was sent on Wednesday, 29 July. Recipients of the email weren’t blinded, meaning that each recipient could see the personal email addresses of every other recipient.
All 136 recipients – according to the ABC, the email was sent to “doctors, nurses, radiologists and other health workers” – were being invited to attend an upcoming webinar titled Addiction and recover: process, support and experiencing a health notification.
The email notes that while the webinar is open to all practitioners, the material will focus specifically on the experience of practitioners who have a health-related notification or a restriction on their practice related to substance misuse.
“If you’re concerned about privacy, you’re welcome to join the webinar using another name or email address,” the email read.
“Your name will not be visible to other participants or to AHPRA during the webinar.
“All participants will be able to type anonymous questions during the webinar. We ask that questions avoid sharing information that could identify a notification or person.”
It is unclear how AHPRA selected the 136 recipients of the invitation, given that it regulates close to one million health practitioners.
While it appears that some recipients were subject to health impairment notifications, the ABC said it was aware of at least who one claimed to have no history of an addiction or impairment-related notification.
For its part, AHPRA told The Medical Republic that it “apologised” to the affected clinicians and that it had taken “immediate steps” to respond to the breach on the same day it occurred.
These steps included notifying the affected practitioners, requesting deletion of the email, apologising to each person directly and advising them on how to raise a formal complaint with AHPRA or the National Health Practitioner Ombudsman.
AHPRA also notified the National Health Practitioner Ombudsman itself.
Mr Butler told TMR that anyone seeking help or support “has the right to expect their sensitive information will be treated in the strictest of confidence”.
“It is totally unacceptable that health professionals have had their privacy breached in this manner,” he said.
“I note that AHPRA has apologised and referred the matter to the National Health Practitioner Ombudsman on the day the error was made.
“It is important to now allow the process of investigation to take place.”
Related
Outrage in the medical community has been palpable.
“A regulator that demands the highest standards of privacy and professionalism from health practitioners should probably start by meeting them itself,” NSW GP Dr Max Mollenkopf told TMR.
“AHPRA wields extraordinary power over clinicians, and once a doctor’s professional reputation is smeared, undoing that damage is almost impossible.”
Medical forums like Reddit’s r/AusJDocs and Australian Doctor have been alight with doctors questioning whether those affected by AHPRA’s blunder may have grounds to sue for defamation, breach of privacy or negligence.
David Gardner, a lawyer whose practice focusses on assisting health practitioners going through regulatory processes, told TMR that the chances of a successful case on any of those fronts would be slim.
Referring to the few clinicians who appeared to have no history of an addiction-related health impairment notification but received the email nonetheless, Mr Gardner said there was a “potential … defamation pathway”.
“But defamation is such a complex technical area that I certainly wouldn’t be saying that they have [a certain case],” he said.
“If they’ve been sort of tarred with the brush of having an addiction issue when they don’t, that’s something you might look at exploring with a lawyer.
“On the privacy side, it’s interesting because we don’t have great privacy protections in terms of actually bringing proceedings for loss.”
As for the negligence angle, Mr Gardner said case law generally tended to indicate that because of its role as a protective regulator, health regulators do not owe a duty of care to those under its purview.
While there is a new statutory tort covering serious invasions of privacy, it relies on being able to prove that the breach was either deliberate or reckless.
These standards would be relatively hard to prove, legally, given that the email error appears to have been a genuine accident.
The health practitioner ombudsman is responsible for regulating privacy breaches related to medical colleges, AHPRA, the national board and other health accreditation authorities.
Mr Gardner said he suspected the main remedy which the ombudsman will suggest is that AHPRA use a more sophisticated customer relationship management [CRM] strategy.
“I don’t think there’s any doubt that they didn’t mean to do this,” he said.
“I think generally the way AHPRA’s tried to handle health matters over the last few years has been an improvement. They’ve tried to be a lot kinder and more sensitive.
“I think probably the main thing, from my perspective, that’s the problem here is that AHPRA doesn’t seem to have [protocols] in their CRM where they can send out a really sensitive message like this.
“It seems like someone’s copying and pasting into Outlook, and probably put [the addresses] in the CC field instead of the BCC field.”
In Mr Gardner’s experience, bringing legal action against AHPRA is difficult at best.
“I have a lot of people who approach me to sue AHPRA, and it would only be in the most extreme circumstances [that I would advise it go ahead],” he said.
“I’ve had a couple of very extreme matters, and even then, it’s incredibly hard. It’s very difficult to bring proceedings against the regulator for loss.”



