Where Is Your Patient Data Hosted? A Clinic Residency Checklist
Under APP 8 and section 16C, a clinic stays accountable for what an overseas provider does with patient data, even after taking reasonable steps. Most clinics cannot name the country their booking data sits in. Here is how to find out and what to do about it.

Key Takeaways
- APP 8 does not ban offshore hosting. It requires reasonable steps before disclosure to an overseas recipient
- Section 16C makes you accountable for the overseas recipient’s acts, and that can apply even where you took reasonable steps and even where a subcontractor was the one who breached
- The substantially similar law exception (APP 8.2(a)) has two limbs: comparable protection, and enforcement mechanisms your patient can actually access
- Most clinics cannot name the country their booking data sits in, which means the reasonable steps were never taken
- My Health Record data is a separate regime with its own Australian-residency restrictions
- This is in force, and has been since the APPs commenced in March 2014
Ask your booking platform which country your patient data is stored in. Not which cloud provider: which country. Then ask whether their support team, or any subcontractor, can access it from a third country.
Most clinics have never asked, and the answer usually takes a vendor several days to produce. That gap is the whole issue, because APP 8 does not ask whether your data went offshore. It asks what steps you took before it did.
What APP 8 Actually Requires
The obligation is specific. Before an APP entity discloses personal information to an overseas recipient, it must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles, other than APP 1, in relation to the information.
Then comes the part clinics consistently miss. Section 16C makes an APP entity accountable for an act or practice of an overseas recipient that would breach the APPs. Accountable means the act is taken to have been done by the APP entity and to be a breach by that entity.
The OAIC’s guidance is explicit that this accountability can bite even where the entity has taken reasonable steps and the recipient subsequently breached anyway, and even where the recipient passed the information to a subcontractor and the subcontractor breached. You do not discharge the obligation by choosing a reputable vendor and looking away.
| Question | APP 8 answer |
|---|---|
| Can I host patient data overseas? | Yes, subject to reasonable steps |
| Am I liable if the overseas provider breaches? | Generally yes, under s 16C |
| Does taking reasonable steps end my exposure? | No, accountability can still apply |
| Is there a way out? | Yes, the APP 8.2 exceptions |
The Exceptions, and Their Limits
APP 8.2(a) is the one clinics rely on most, usually without checking it. It applies where the entity reasonably believes that the overseas recipient is subject to a law or binding scheme with an effect that, overall, is at least substantially similar to the way the APPs protect the information, and that mechanisms can be accessed by the individual to enforce that protection.
The OAIC lists the factors that indicate substantial similarity: a comparable definition of personal information, comparable regulation of collection, a notification requirement, use and disclosure limited to authorised purposes, comparable data quality and security standards, and a right to access and seek correction.
Note the second limb. A jurisdiction can have an excellent privacy statute and still fail the exception if your patient in Rockingham has no accessible route to enforce it.
The APP baseline is definitional. The second series is an illustrative pattern of where offshore assessments most often fall short, not a measurement of any specific jurisdiction. Notification and access-and-correction are consistently the weakest points.
What That Means for the Build
Map every destination first. You cannot take reasonable steps toward a recipient you have not identified. Produce a written list of every system that receives patient personal information: booking platform, form handler, email host, CRM, SMS gateway, analytics, backup provider, and any support tooling.
Ask three questions of each vendor, in writing. Which country is data stored in at rest. Which countries can staff or subcontractors access it from. Which subprocessors do you use, and where are they. Written answers are the evidence that reasonable steps were taken.
Prefer contractual commitments over marketing pages. A vendor’s website saying “hosted in Australia” is not a commitment. A clause in your agreement is.
Treat support access as disclosure. Data at rest in Sydney that a support engineer reads from another country has still gone to an overseas recipient. This is the single most common gap in clinic vendor stacks, because the hosting question gets asked and the support question does not.
This is a build-experience model of where the mapping gap sits, not survey data. The consistent finding behind it is that clinics map the booking platform and stop.
A Worked Example
Cosmetic clinic. A clinic’s booking vendor confirmed Australian data residency. The same vendor’s support desk operated from two offshore locations with production read access, and its SMS provider was a US company. Two overseas recipients existed that the clinic’s privacy policy did not mention and its risk assessment had never considered.
Dental practice. A practice used an offshore transcription tool for clinical notes. The vendor’s terms permitted use of submitted content for model improvement. That is a disclosure to an overseas recipient plus a secondary use, and neither had been assessed. The practice moved to an onshore alternative rather than attempt to rely on an exception.
What to Check on Your Own Site
- List every system that receives a patient’s name, contact details or treatment interest. Include analytics.
- For each, get a written answer on data-at-rest country, support-access countries, and subprocessors.
- Check whether your privacy policy names offshore disclosure at all, and whether it matches the list you just built.
- Check your booking widget’s network requests for third-country endpoints.
- Confirm separately whether any My Health Record data is involved, because that is a different regime.
- Diarise a re-check. Vendors change subprocessors without telling customers.
The Enforcement Anchor
The OAIC maintains a determinations register covering health service providers, and cross-border disclosure sits squarely within its remit under s 16C. What does not exist, at the time of writing, is a published Australian determination against a cosmetic or dental clinic specifically for an offshore booking-data disclosure.
Stating that plainly is more useful than implying a precedent that is not there. The accountability provision is enacted law and the OAIC’s own guidance spells out how far it reaches; the sector-specific case has not yet been published.
Where This Gets Hard
Subprocessors. You can assess your booking vendor thoroughly and still not know that their SMS provider changed to a company in another jurisdiction last quarter. Contractual notification of subprocessor changes is the only practical control, and most small-clinic contracts do not have it because most small clinics sign the vendor’s standard terms.
The regulator says you must take reasonable steps before disclosing to an overseas recipient and remain accountable for their acts; the build consequence is a written vendor map with country-level answers and contractual commitments; whether your particular arrangement satisfies APP 8 in your circumstances is a question for your medical defence organisation or your lawyer.
Status
In force. APP 8 and section 16C have applied since the Australian Privacy Principles commenced on 12 March 2014. The My Health Records Act restrictions are also current law. Nothing in this post depends on the proposed second tranche of Privacy Act reform, which has not passed and has no commencement date.
Frequently Asked Questions
Is it illegal for an Australian clinic to store patient data overseas?
No. APP 8 does not prohibit offshore storage. It requires that before disclosing personal information to an overseas recipient you take such steps as are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles in relation to that information. Offshore hosting is permitted; unexamined offshore hosting is the problem.
If my overseas provider mishandles patient data, am I liable?
Generally yes. Section 16C makes an APP entity accountable for an act or practice of an overseas recipient that would breach the APPs, and that accountability can apply even where you took reasonable steps and even where the overseas recipient passed the data to a subcontractor who breached. Accountability means the act is taken to have been done by you.
Does using a provider in a country with strong privacy law remove the obligation?
It can, under an exception. APP 8.2(a) applies where you reasonably believe the recipient is subject to a law or binding scheme that overall protects the information in a way at least substantially similar to the APPs, and that the individual can access mechanisms to enforce that protection. Both limbs matter. A strong law with no accessible enforcement route for your patient does not satisfy it.
Does My Health Record data have different rules?
Yes. The My Health Records Act contains its own restrictions on holding records outside Australia, which sit separately from and in addition to APP 8. Do not reason from your general hosting arrangements to your My Health Record obligations; they are different regimes.
Get Your Vendor Map Built
RockingWeb can help you build the written list this post starts with: every system on your site that receives patient information, and what each one transmits.
Sources
- OAIC - APP Guidelines Chapter 8, cross-border disclosure, including s 16C accountability at 8.60 to 8.62 and the APP 8.2(a) exception at 8.20 to 8.25. Checked 10 August 2026.
- OAIC - Australian Privacy Principles. Checked 10 August 2026.
- Federal Register of Legislation - My Health Records Act 2012. Checked 10 August 2026.
Last reviewed: 10 August 2026.

Vikas Thakur
Founder of RockingWeb. 16 years building for companies like TPG, iiNet and Monadelphous, now focused on websites and marketing that comply with AHPRA's advertising guidelines and still book patients.




