Today’s correspondent asks about the:

… complex and rapidly evolving legal scenario regarding new police data extraction powers and their conflict with medical confidentiality.

Specifically, I am concerned about the legal ramifications when police seize and copy a mobile device—either a personal device (BYOD) or an employer-issued work device—that a healthcare practitioner uses to access and manage Electronic Health Records (EHR) while actively looking after clients.

With the introduction and expansion of Digital Evidence Access Orders (DEAOs) and expanded warrantless seizure powers across various Australian jurisdictions, forensic extraction tools (like Cellebrite) allow law enforcement to copy a device’s entire drive en masse. This means non-relevant, highly sensitive clinical notes, patient histories, and medical photographs are invariably ingested into police databases.

I would be incredibly grateful for your perspective on the following questions:

Conflict of Statutory Duties: How do the statutory powers of police to seize devices and compel access (via DEAOs or warrantless provisions based on ‘reasonable suspicion’) interact with a practitioner’s strict legal obligations under the Privacy Act 1988 (Cth) and Section 65 of the My Health Records Act 2012 (Cth) Does law enforcement power entirely extinguish medical confidentiality in these moments?

Professional and Civil Liability: If a practitioner complies with a police demand to unlock a device containing EHR data, or if a work device is copied without a warrant, what is the practitioner’s exposure to AHPRA disciplinary action for professional misconduct? Furthermore, could the practitioner or their healthcare organization face civil liability or Notifiable Data Breach (NDB) penalties if patient data is compromised as a collateral result of a police investigation?

Work-Issued vs. Personal Devices: Does the legal landscape or the protective framework shift significantly if the device is owned and managed by a healthcare organization (subject to Mobile Device Management) rather than being a practitioner’s personal phone? What rights do healthcare employers have to legally challenge a broad or warrantless data download to protect their broader patient database?

Admissibility and Data Retention: If police copy a device’s contents without a traditional warrant and sweep up hundreds of unrelated patient records, what legal remedies exist to force the deletion of that confidential medical data from law enforcement servers?

The lawyers who write legislation, as well as the courts, try their best to make sure legislation can work together.  Where, by some oversight, there is a complete incompatibility, that is t is just not possible to comply with both Acts, then the presumption is that the later or more recent Act overrides the earlier Act to the extent of the inconsistency. 

I’m going to use NSW as my example – and here I refer readers to the following articles which give details that relate to the question posed:

I cannot find a bill that would allow police to access digital information without judicial oversight. The Crimes and Other Legislation Amendment (Further Organised Crimes Reforms) Bill 2026 provides for ‘digital evidence access orders (organised crime)’ but they still require an application to be made and a court to approve the application. Assuming this is the Bill he was referring to, as far as I can see Sainsbury is wrong when he says this Legislation ‘will allow police to extract mobile phone data without a warrant’.  

The Crimes Act 1914 (Cth) ss 3K-3Q provides for access to electronic equipment but again it refers to equipment seized under a warrant and the need for an officer to get an order from a Magistrate to compel the person to reveal access details

The law in this area is rapidly developing and still depends on judicial interpretation – see https://newsouthlawyers.com.au/can-the-police-search-my-phone-without-a-warrant/. That article says:

Under laws such as the Law Enforcement (Powers and Responsibilities) Act 2002 (NSW), police can search a person after arrest if they suspect it is necessary to prevent evidence being destroyed, protect safety, or locate evidence related to the offence.

However, whether this automatically extends to detailed digital data searches is a developing area in Australian Criminal Law.

Police can seize your phone if you are arrested but I cannot see that without a digital access order they can compel you to unlock it. 

Assuming police have a warrant or access order, the Health Records and Information Privacy Act 2002 (NSW) Sch 1 cl 11(f) says that health information may be disclosed if it ‘is reasonably necessary for the exercise of law enforcement functions by law enforcement agencies in circumstances where there are reasonable grounds to believe that an offence may have been, or may be, committed’. If the police have a warrant to access the materials, then they have satisfied a judge access to the information is ‘reasonably necessary’ (Law Enforcement (Powers and Responsibilities) Act 2002(NSW) s 76AF(1)(d)).   Privacy Principle 6 in the Privacy Act 1988 (Cth) says information must not be disclosed unless ‘the use or disclosure of the information is required or authorised by or under an Australian law or a court/tribunal order’.

Just as medical records must be produced in response to a subpoena and police can search a medical practice if they have a search warrant, the production of a Digital Access Order would override any duty to protect the information. Medical confidentiality does not survive the use of law enforcement powers.

A complaint may be made if a Practitioner is convicted of a criminal offence (Health Practitioner Regulation National Law (NSW) s 144). Failure to comply with a digital access order is a crime.  A practitioner is more likely to face a complaint of they don’t comply, rather than if they do.  A ‘Notifiable Data Breach’ ‘happens when personal information is accessed or disclosed without authorisation’ (https://www.oaic.gov.au/privacy/notifiable-data-breaches) but as noted, the privacy legislation provides that the release of information in response to a warrant is authorised. 

To protect oneself a health care practitioner would want to insist that the police get an order or warrant.  On TV police dramas the police threaten ‘we’ll come back with a warrant’ and the person says ‘oh ok then’ not ‘ok, go get a warrant’.  A health care practitioner may be in breach of various provisions if they give access to their computer simply because the police ask for it, so the best answer is ‘I’ll unlock it if you can show me your authority’.  In that case the police must indeed show that they have the relevant order (Law Enforcement (Powers and Responsibilities) Act 2002 (NSW) s 76AN). 

If a computer is seized and an access order is sought, a person would be entitled to challenge that decision eg by seeking an injunction arguing that the conditions for the making of the order were not established or that the information provided in the application was false.  Such a remedy would not be easy, but it would be an option. If for example police were investigating an individual and wanted to access his or her work computer the employer could apply to have an access order set aside. 

I do not know the answer to the questions on data retention by police, but it also has to be retained pending the final judicial outcome.  Property that has been seized must be returned (Law Enforcement (Powers and Responsibilities) Act 2000 (NSW) s 218 but that is not the same as requiring data to be deleted. 

Conclusion

Whilst police may seize items without a warrant, I cannot see that they can compel a person to provide access to a computer without a judicial warrant.  If someone can identify legislation that allows that I’d be happy to consider it.

Where the police have a Digital Evidence Access Order (in NSW), a magistrate’s order (Commonwealth) or the equivalent in another jurisdiction, then a person, including a health practitioner has to comply with the terms of that order.  Complying with the order will be a defence to any alleged breach of professional obligation or privacy legislation.

This blog is a general discussion of legal principles only.  It is not legal advice. Do not rely on the information here to make decisions regarding your legal position or to make decisions that affect your legal rights or responsibilities. For advice on your particular circumstances always consult an admitted legal practitioner in your state or territory.