When an Insurer Asks for Full Patient Records: A Practice Manager’s Guide
Private health insurers are asking practices for far more clinical detail than the claim under audit requires. Here is what the Privacy Act expects, and how a practice manager handles the request.
Post Author:
TalentMed

An email lands on a Tuesday morning. A private health insurer is auditing claims your practice has submitted, and it wants clinical records. Not the notes for one disputed episode, but the full history for a list of patients. The contract you signed says you will co-operate with audits. The Privacy Act says a patient’s health information does not go to a third party without that patient’s consent. Those two things point in opposite directions, and someone has to decide what happens next. In most Australian practices, that someone is the practice manager.
In August 2026 the ABC reported that hospitals, dentists, physiotherapists and specialists have been asked for far more clinical detail than the claim under audit would seem to require. If you are considering a career in practice management, this is a good example of what the job actually involves.
What the law expects before a record leaves the practice
Health information is treated as sensitive information under the Privacy Act 1988. That gives it stronger protection than an address or a phone number, and the rules about sharing it are stricter.
Australian Privacy Principle 6 covers use and disclosure. Broadly, a practice can use health information for the reason it was collected, which is providing care. Sending it somewhere else is a disclosure, and that generally needs either the patient’s consent or a specific exception written into the law. The Office of the Australian Information Commissioner puts it plainly in its health privacy guidance: where a request for records comes from a third party, the practice should only release the information if the patient has consented.
Consent also has to be worth something. For sensitive information it needs to be express rather than assumed, and the patient needs to understand what is being released and to whom. A signature collected years ago at new-patient registration is thin ground to stand on.
The point that catches practices out is the relationship between a contract and a statute. A provider agreement can oblige a practice to co-operate with a reasonable audit. It cannot rewrite the Privacy Act. Dr Bashi Kumar-Hazard of the University of Sydney Law School told the ABC that a contract cannot contain terms which contravene existing law, and that requesting patient notes outside the episode of care without consent should void it. Our guide to the Privacy Act for Australian medical practices covers the obligations in more detail.
Who in the practice actually handles the request
The worst outcome is the one where nobody owns it. A request arrives, it gets forwarded to whoever is at the front desk that day, and files go out because the sender sounded official and impatient.
A practice that handles this well has decided in advance who receives these requests, and the answer is usually the practice manager, working with the principal or owner. From there the sequence is consistent:
- Get it in writing. A phone call is not a request. Ask for it in writing, naming the specific claims it relates to and the basis being relied on.
- Log it. Date received, who sent it, what was asked for, and what was provided. This log is your evidence if the request is later disputed.
- Check the scope against the claim. If the audit concerns three item numbers billed in March, work out what an auditor would reasonably need to verify them.
- Deal with consent properly. Contact the affected patients, explain in plain terms what is being requested and by whom, and record their answer. A refusal is a valid answer, and the practice needs a process for what follows.
- Release only what was agreed, and record it. Note what was sent, when, in what format, and to whom.
None of that is glamorous. All of it is what lets a practice explain its decisions later.
How to narrow a request without refusing to co-operate
Audits are a normal part of a system that pays out large sums. Private Healthcare Australia chief executive Rachel David has defended audit activity as responsible management of roughly 27 billion dollars in annual healthcare payments, and noted that audits do find incorrect claiming. Refusing outright is not realistic.
The productive move is to narrow rather than refuse. A written reply that says the practice will co-operate, sets out what it can release for the claims in question, and asks the auditor to explain why anything beyond that is needed, is a co-operative response. It is also a written record that the practice took its privacy obligations seriously.
Practical questions are fair too. Who will receive the records, and are they qualified to assess the clinical decisions being reviewed? Merv Saultry of the Independent Dentist Network told the ABC about a case where auditors did not hold the dental qualifications needed to assess complex work. How will the records be stored and destroyed once the audit closes?
The Australian Private Hospitals Association has been blunt about the pattern, with chief executive Brett Heffernan describing some audit conduct as rogue behaviour, and in March 2026 the association joined Catholic Health Australia in calling for a mandatory code of conduct covering insurer contracting. Whether that arrives or not, the practice still has to answer the email sitting in the inbox today.
When to stop and escalate
A practice manager runs the process but does not carry the legal risk alone.
Escalate when the request goes well beyond the episodes under audit, when patients have declined consent and the requester keeps pressing, when there is a threat of a repayment demand or removal from a provider network, or when you are not confident of the right answer. Go to the principal or owner first, then the practice’s professional indemnity insurer or medico-legal adviser, the relevant association, and a lawyer with health privacy experience. Patients who believe their information was mishandled can complain to the Office of the Australian Information Commissioner, and practices can seek guidance from the same office.
Knowing where your authority ends is part of the skill, not a gap in it. Handling private billing, WorkCover and DVA claims takes the same instinct: resolve what you can, and route the rest.
This article is general information, not legal advice. A practice facing an audit dispute should get advice about its own circumstances.
Why this lands on the practice manager’s desk
People still picture practice management as rosters and reception. The insurer audit story shows what it has become. One request can involve privacy law, a commercial contract, patient communication, records governance, revenue, and a relationship with a funder the practice depends on.
That is why the role is a serious career with a serious skillset behind it. The HLT57715 Diploma of Practice Management covers the operational, financial, legal and people-management side of running a healthcare practice, including managing information and working within legal and ethical frameworks. It is 100 percent online and self-paced over 12 months with daily intakes, and it suits people already working in reception, administration or nursing, as well as managers moving into health from other industries.
Frequently asked questions
Interested in the role that answers the hard email? Explore the HLT57715 Diploma of Practice Management or read the practice management career guide.
TalentMed Pty Ltd, RTO 22151. Nationally recognised training delivered online across Australia.
HLT57715
Diploma of Practice Management
100% online and self-paced over 12 months. Start any time.
Prefer to talk it through?
Book a free, no-obligation call with a TalentMed course adviser about the Diploma of Practice Management.
More for practice managers
Healthcare practice news
Monthly insights for GP, specialist, and allied health teams.



