Introduction
If your practice uses an AI receptionist, automated reminder calls, online booking or any software that sorts, scores or prioritises patients, there's a date to put in your calendar: 10 December 2026.
From that date, changes made by the Privacy and Other Legislation Amendment Act 2024 require organisations covered by the Australian Privacy Principles (APPs) to explain automated decision-making in their privacy policy. Dental practices are health service providers, so they're covered by the Privacy Act whatever their annual turnover. The small business exemption doesn't apply.
The good news is that this is a transparency obligation, not a ban. You can keep using automation. You just need to be able to say clearly what it does.
This article is general information, not legal advice. Talk to your privacy adviser or lawyer about your practice's specific situation.
What actually changes
The amended APP 1 adds new content your privacy policy must include when both of these are true:
- You've arranged for a computer program to make a decision, or to do something substantially and directly related to making a decision, using personal information; and
- That decision could reasonably be expected to significantly affect the rights or interests of an individual.
When that's the case, your privacy policy must describe:
- the kinds of personal information used by those programs;
- the kinds of decisions made solely by a computer program; and
- the kinds of decisions where a program does something substantially and directly related to the decision.
You don't have to disclose commercially sensitive details about how a system works. The test is whether a patient reading your policy can understand where automation is shaping outcomes that matter to them.
Does your AI receptionist count?
It depends on what it decides, not on whether it uses AI. Here's a practical way to think about common front-desk automation:
Probably low risk, but document it anyway:
- Answering FAQs (opening hours, parking, what to bring)
- Offering available appointment times from your calendar
- Sending reminder calls or SMS for appointments a human already booked
- Taking a message and passing it to staff
Worth a closer look, because these may "significantly affect" a patient:
- Urgency or triage decisions. Software that decides whether a caller with pain is offered a same-day emergency slot or a routine appointment next fortnight.
- Declining or restricting bookings. Rules that automatically block patients with past no-shows, outstanding balances or certain health-fund status.
- Fees and payment terms. Automatically applying cancellation fees, deposits or payment-plan eligibility.
- Recall prioritisation. Software that decides which patients get recalled first, or at all.
If a human makes the final call but relies heavily on what the software recommends, that can still be "substantially and directly related" to the decision. Having a human somewhere in the loop isn't automatically an exemption.
Why this matters now
- Enforcement has teeth. The Office of the Australian Information Commissioner (OAIC) can now issue infringement notices for privacy policy failures. Reported maximums are 200 penalty units per contravention (around $66,000 at the time of writing).
- Regulators are looking at privacy policies. In early 2026 the OAIC began a compliance sweep assessing whether organisations' privacy policies are clear and up to date.
- Patients are asking. More patients now ask "Am I talking to a real person?" A clear, honest explanation builds trust. An evasive one costs it.
A practical checklist for practice owners
Use the next eight weeks to work through this:
- List every automated tool that touches patient data. Include the AI receptionist, website chat, reminder system, online booking, recall software, payment and PMS automations.
- For each, write one sentence about what it decides. "Offers available times" is different from "decides who gets an emergency slot."
- Flag anything that could significantly affect a patient. Access to care, timing of care, cost and booking restrictions are the usual suspects.
- Record the personal information each tool uses. Name, phone number, appointment history, symptoms described on a call, call recordings, payment status.
- Ask your vendors the right questions. Where is data processed and stored? Are calls recorded or transcribed? Is any data used to train models? What rules does the system follow when it books, declines or escalates?
- Keep a human path open. Make sure callers can always reach a staff member, and that urgent clinical concerns are escalated to a person.
- Update your privacy policy with plain-English descriptions of the kinds of decisions and kinds of information involved. Avoid vague catch-alls.
- Brief your team. Front-desk staff should be able to explain, in one or two sentences, how automation is used and how a patient can speak to someone.
Sample wording to adapt
We use automated systems, including an AI phone assistant, to answer calls, offer available appointment times, and send appointment reminders. These systems use your name, contact details, appointment history and the information you provide during a call. Decisions about urgent or emergency care are made or confirmed by our clinical team. You can ask to speak with a staff member at any time.
Change this so it accurately describes your systems. If automation does make decisions that significantly affect patients, say so and describe the kinds of decisions.
How IntelliDent approaches this
We build IntelliDent's agents for Australian practices, so transparency is part of the design: practices control what the agent can book, when it must hand over to staff, and how urgent calls are escalated. If you're reviewing your privacy policy ahead of December, we're happy to walk you through exactly what our agents do with patient information, so you can describe it accurately.
Book a live demo to see how it works, or contact our team for a copy of our privacy and data-handling overview.
Sources
- HWL Ebsworth — "Can I speak with a human please?" Preparing for the new automated decision-making disclosure requirements
- Lander & Rogers — Australian privacy law update: what APP entities need to know in 2026
- Maddocks — Automated decision-making privacy obligations
- Privacy Act 1988 (Cth), s 6D(4)(b): health service providers are not small business operators