The news that potentially sensitive health data of up to 30,000 ACT public servants has been online for more than three years has been labelled “deeply troubling” by the Community and Public Sector Union (CPSU).
CPSU ACT regional secretary and UnionsACT president, Maddy Northam, said she is astonished and concerned that private data was publicly available for so long before the government was made aware of it.
A spreadsheet that contained the details of thousands of workers’ compensation claims dating back to the beginning of self-government in July 1989 was uploaded to the ACT Government’s tender website in 2018 before it was deleted earlier this week.
It is understood the information disclosed includes claimants’ birth year, gender, occupation, types and dates of injuries, and the directorate where a person worked.
The exact birth dates and names of claimants had been removed in an effort to deidentify the data, ACT Special Minister of State Chris Steel told the Assembly on Thursday, 25 November.
However, it is Ms Northam’s belief that “the data that has been available is of a highly personal nature, and it has been troubling for our members who have had a claim”.
She noted union members were blindsided by the breach, having not been notified before the report appeared in the media earlier this week.
Ms Northam said a significant number of union members had already made contact with her to express concerns about their sensitive data.
She is concerned the matter could be triggering for people who’d previously been involved in workers’ compensation claims as they are often stressful.
“A lot of people had put it behind them, and now this has come up,” said Ms Northam.
She has been seeking to remind people who are affected that they can access the ACT Government’s Employee Assistance Program (EAP) if support is needed.
The CPSU was briefed by the ACT Government on Thursday, 25 November, at a meeting Ms Northam said was productive.
During the course of the meeting, some of her and the union’s members’ concerns were alleviated.
For example, initial reporting of the breach had said an individual’s position title was included in the spreadsheet, but Ms Northam said upon further analysis, this was not the case.
“A position title would have been much more identifiable,” she said.
The CPSU was also able to secure a commitment from the ACT Government that the data will be vigorously tested against other publicly available information to check whether or not people can be identified.
During Thursday’s Question Time, which was dominated by the potential data breach, Mr Steel announced an internal review would be conducted into the matter
He said affected individuals have not yet been contacted. However, it is Ms Northam’s understanding that people whose data was included in the spreadsheet will now receive some correspondence from the government.
Mr Steel told the Assembly the government is not yet aware of a particular breach of private information, but an internal review will now be conducted.
He would not give a time frame for the review and the government also would not commit to releasing its findings in advance.
Mr Steel said future government policy will be informed by the review.
“We look forward to that review being undertaken and any recommendations that may come out of that review about whether there has been a breach of privacy in this particular case, and whether there are any further measures we can put in place to protect the privacy of individuals in procurements going forward,” he said.
The ACT Opposition has called for an independent investigation into the matter.
At this point, unless a breach is determined, the government will not refer the matter to the Office of the Australian Information Commissioner.
Mr Steel said the “heavily redacted” spreadsheet was uploaded to the tender website to provide potential tenderers with information about the costs associated with managing workers’ compensation claims in the Territory.
He said it was part of an ACT Government push towards being a self-insurer as it moves away from Comcare as an assessor of workers’ compensation claims of ACT public servants.