AI and Patient Data: Privacy and Compliance for Pharmacies
Using AI in a pharmacy means handling patient data under Australian privacy law. What the Privacy Act requires, and what to check before you adopt AI.


small-business turnover exemption from the Privacy Act that does NOT cover health providers
Source: OAICpharmacies must report eligible data breaches under the Notifiable Data Breaches scheme
Source: OAICIn this article
This article is general information, not legal advice. Privacy law is detailed and changes over time. For decisions about your pharmacy, get advice specific to your situation.
Any AI that touches your pharmacy phone or records is handling patient information, and in Australia that brings clear legal obligations. The good news is the rules are knowable, and choosing the right AI makes them easier to meet, not harder.
This guide explains why privacy matters more for pharmacy AI, what Australian law actually requires, and what to check before you adopt any AI tool.
Why privacy matters more for pharmacy AI
A pharmacy handles some of the most sensitive information a person has: their medicines, conditions, and history. When you add AI to the phone or the workflow, that information may be collected, transmitted, or processed by software. Getting the privacy settings right is not optional, and it is a fair question to ask any vendor.
Pharmacies are covered, regardless of size
Many small businesses assume privacy law does not apply to them. In general, businesses with an annual turnover of 3 million dollars or less are exempt from the Privacy Act. But that exemption specifically does not apply to health service providers, and pharmacies are health service providers.
The practical result is simple: a pharmacy of any size must comply with the Privacy Act and all 13 Australian Privacy Principles. Size is not an out.
Health information is sensitive information
The Privacy Act treats health information as a category of sensitive information, which carries a higher level of protection than ordinary personal details. In practice that means health information generally cannot be collected without the individual’s consent, and it must be handled with extra care throughout its life.
For AI, this raises a direct question: what patient information does the tool collect, and is it only what is genuinely needed to do the job?
What to check before adopting AI in your pharmacy
Before signing up to any AI tool, four questions cover most of the privacy risk.
Where is the data stored and processed?
Australian law does not outright ban sending data overseas, but under the cross-border principle you generally remain accountable for how an overseas provider handles it. Data stored and processed in Australia removes that layer of risk, which is why local hosting is worth asking about.
How are consent and transparency handled?
You should be able to tell patients, plainly, what information is collected and why. A good AI tool supports that transparency rather than obscuring it.
What happens in a breach?
Ask the provider how a security incident is detected, contained, and reported, so you can meet your own obligations if something goes wrong.
Is only necessary data collected?
The less sensitive information a tool collects and keeps, the smaller your risk. Prefer tools that collect only what they need.
The data breach obligation
Since 2018, the Notifiable Data Breaches scheme has required organisations covered by the Privacy Act, including pharmacies, to notify the OAIC and affected individuals of an eligible data breach that is likely to cause serious harm. Choosing a provider with strong security and clear breach processes is part of meeting that duty.
How Krepko approaches this
Krepko built Emily with these obligations in mind. It runs on a private, Australia-based server, so patient information is stored and processed locally. It is scoped to handle routine calls and escalates clinical or complex calls to your team, which keeps the sensitive decisions with a pharmacist.
Privacy compliance is ultimately your responsibility as the pharmacy, but the tools you choose make it easier or harder. An AI built for Australian pharmacies, hosted in Australia, and designed to collect only what it needs is a sensible starting point. For where the wider rules are heading, see our guide to AI regulation in pharmacy.
Frequently asked questions
- Does the Privacy Act apply to pharmacies?
- Yes. Pharmacies are health service providers, and the small-business turnover exemption does not apply to them, so a pharmacy must follow the Privacy Act and all 13 Australian Privacy Principles regardless of its size.
- Is patient health information sensitive information?
- Yes. Under the Privacy Act, health information is a type of sensitive information, which gets a higher level of protection and generally cannot be collected without the individual's consent.
- What should a pharmacy check before using AI with patient data?
- Check where the data is stored and processed, whether the provider is accountable for any overseas handling, how consent and transparency are managed, what happens in a breach, and that only necessary data is collected.
- Do pharmacies have to report data breaches?
- Yes. Under the Notifiable Data Breaches scheme, a pharmacy must notify the OAIC and affected individuals of an eligible data breach that is likely to result in serious harm.
Sources
- Australian Privacy Principles · Office of the Australian Information Commissioner
- Small business and the Privacy Act · Office of the Australian Information Commissioner
- Notifiable Data Breaches scheme · Office of the Australian Information Commissioner


