![]()

Disability & Mental Health Care Pty Ltd · ABN 19 658 578 575 · registered NDIS provider 4-LO5XNY0
A procedure of Disability and Mental Health Care Pty Ltd, the registered NDIS provider that runs The Care Web. Published for the people we support and the people who work with us.
This procedure sets out what Disability and Mental Health Care Pty Ltd (DMHC) does when personal information it holds is lost, accessed, used or disclosed without authorisation. It sits under the Privacy and Information Management Policy and gives effect to the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). DMHC's commitment is that a suspected breach is contained and assessed within one business day, and that the people affected hear about it from DMHC first.
This procedure applies to all personal information DMHC holds about participants, their families and nominees, workers, applicants and anyone else — whether on The Care Web, in email, on paper, on a phone, or held on DMHC's behalf by a supplier. It applies to everyone who works for or with DMHC.
A data breach is unauthorised access to, or unauthorised disclosure of, personal information, or the loss of personal information in circumstances where unauthorised access or disclosure is likely. Examples: a phone or notebook with participant details is lost; an email with a support plan goes to the wrong address; a worker looks up a participant they do not support; a Care Web account is accessed by someone else; a supplier reports a security incident.
An eligible data breach is one that is likely to result in serious harm to any of the individuals concerned, and which DMHC has not been able to prevent through remedial action. Serious harm includes physical, psychological, emotional, financial or reputational harm, and is more likely where health and disability information, identity documents or financial details are involved.
1. Report it at once. Anyone who knows or suspects a breach tells the Director immediately, by phone, and within 24 hours at the latest — the same day is expected. Do not investigate alone, do not delete anything, and do not contact the affected person before the Director has been told. Record what you know: what information, whose, how, when, and who else knows.
2. Contain it. The Director, on the same day, takes whatever step stops the breach continuing: revoking a Care Web session or resetting a password, recalling or asking for the deletion of a misdirected email, remotely wiping a lost device, retrieving papers, suspending a worker's access, or asking a supplier to isolate a system. Every containment step is written down with the time.
3. Assess it, within one business day. The Director assesses, and records, what information was involved and how sensitive it is; who is affected and how many people; who has had, or could have, access to it; whether it has been recovered or made unusable; and what harm could reasonably follow. Where the assessment cannot be finished in one business day, it is completed as quickly as practicable and in any case within 30 days, and the reason for the delay is recorded.
4. Decide whether it is an eligible data breach. If the assessment finds that serious harm is likely and has not been prevented, the breach is notifiable. If in doubt, DMHC treats it as notifiable. The Director records the decision and the reasons.
5. Notify. For an eligible data breach, DMHC prepares a statement containing DMHC's name and contact details, a description of the breach, the kinds of information involved, and the steps affected people should take. DMHC gives the statement to the Office of the Australian Information Commissioner (OAIC) through its online form as soon as practicable, and tells each affected individual directly wherever it can — by phone or in person for participants, in words they understand, with an interpreter or their nominee or advocate involved where that is how they are usually supported. Where a breach involves a participant's NDIS information, DMHC also considers its obligations to the NDIS Commission under the Incident Management Policy, and notifies the police where a crime may have been committed.
6. Support the people affected. DMHC tells affected people what it has done, what it recommends they do, and who to contact, and offers practical help — for example changing passwords, replacing identity documents, or arranging additional support where a participant is distressed. Complaints about the breach are handled under the Feedback and Complaints Policy.
7. Record and learn. Every breach and suspected breach, whether or not notifiable, is entered in the Incident Management Register and the assessment, the decision and every action are filed with it. Within 30 days the Director reviews what allowed the breach and records the improvement in the Continuous Improvement Register — a change to a process, a system setting, training, or a supplier arrangement.
| Approval Authority | Supriya Thapa, Director |
|---|---|
| Version | 1 |
| Approval Date | September 2026 |
| Review Date | September 2027 |
Disability & Mental Health Care Pty Ltd · ABN 19 658 578 575 · NDIS provider 4-LO5XNY0 · 0488 114 368 · hello@thecareweb.com.au
Data Breach Response Procedure. Published on The Care Web from the office’s document set; the office keeps it current.