HPI-I and Victorian Student Number processing: privacy, legal, records and security controls
Research date / evidence cut-off: 3 October 2026 (Australia/Sydney)
Status: research and specification only. No runtime behaviour is changed by this document.
Implementation status: written in parallel with the experimental HPI-I and VSN detectors, which have since shipped disabled by default with structural-only validation, no egress and no logging of values (see the micro-slice record). Their hand-chosen, structurally valid fixtures predate the fixture registry in GK-HV-19 and remain subject to OD-029.
Scope: Groundskeeper evaluating LLM inputs and outputs that may contain a Healthcare Provider Identifier – Individual (au.health.hpi_i) or a Victorian Student Number (au.education.vic_vsn).
Related: identifier inventory, ADR 0007, threat model, persistence, open decisions
This is not legal advice. It summarises primary sources and regulator guidance so engineering can design conservative defaults. Every item marked [I] or [D] needs review by a qualified legal, privacy, or records owner before it is relied on.
1. Bottom line
- Both identifiers are statutorily restricted, not merely "PII". The Healthcare Identifiers Act 2010 (Cth) s 26(1)(d) prohibits any person from using or disclosing an individual healthcare provider's healthcare identifier unless an exception applies. Penalties include a criminal offence and a civil penalty. Part 5.3A of the Education and Training Reform Act 2006 (Vic) limits VSN access, use and disclosure to persons the Secretary authorises, for listed purposes. VCAA says that authorised users include third-party IT contractors.
- Groundskeeper is likely to "use" these identifiers when it detects or redacts them [I]. Whether an operator has authority for that depends on the deployment. For example, it may be a contracted service provider of a healthcare provider, a State contractor for a school, or an unrelated deployer that receives an identifier incidentally. That question cannot be resolved by engineering. It is decisions OD-023 and OD-024.
- The safe engineering default is minimise → redact → forget. Detect with local structural checks only, replace with an irreversible category placeholder before any onward disclosure, and keep identifier values out of logs, telemetry, audit records, fingerprints, caches, fixtures and external judges.
- Hashes of these identifiers are not de-identification. Each identifier has an effective space of about 10⁹ values: nine free digits for HPI-I and nine digits for VSN. Single-threaded Python computed 1.34 million SHA-256 hashes per second in this orb, so it could enumerate the whole space in about 12 minutes. A keyed HMAC protects values only while its key stays secret. ADR 0007's "keyed privacy-safe fingerprints" should therefore be prohibited by default for these two categories (OD-026).
- Synthetic fixtures can collide with real identifiers. Any 16-digit value that
starts
800361and passes Luhn may be an issued HPI-I. The VSN has no published checksum. A Victorian VET collection specification gives its value range as000000001–999999999, so almost every nine-digit number may be a real VSN. Synthetic identifier values are therefore treated as potentially real. Section 6 defines generation rules. - Never "validate" against the HI Service, the Healthcare Provider Directory or the
Victorian Student Register. Those lookups are restricted to authorised parties.
They would also create a new collection or disclosure and records. Validation stays
structuralonly. - Victorian deployments add obligations beyond the Commonwealth APPs. Under IPP 9, sending information outside Victoria is a transborder transfer, including interstate cloud hosting. IPP 7 restricts the use of another organisation's unique identifiers. VPDSS applies to contracted service providers. Decision records may be public records whose disposal requires an authority under the Public Records Act 1973 (Vic).
- Breach handling has several regimes: the Privacy Act NDB scheme for APP entities, the HI Act rule that a contravention is an interference with privacy, the OVIC incident scheme for Victorian public sector information, contractual notification to the Department or VCAA, and ransomware-payment reporting. One runbook must cover all of them (OD-028).
- Production trials are production processing. Observe or shadow mode still receives real identifiers. A trial needs the same authority, PIA, contract, residency and incident controls before the first real request (OD-030).
2. Method and labels
Primary sources were preferred: Commonwealth and Victorian legislation (current compilations), regulators (OAIC, OVIC, PROV), issuers and operators (VCAA, Australian Digital Health Agency, Services Australia via ADHA), the Victorian Department of Education Policy and Advisory Library, and ASD. Secondary commentary was used only to locate primary material. Section 11 lists URLs.
| Label | Meaning |
|---|---|
| [B] | Binding requirement: statute, regulation, legislative instrument, or a standard that is mandatory for the named class of entity, such as VPDSS for Victorian public sector bodies and their contracted service providers. Applicability still depends on the entity and deployment. |
| [G] | Regulator, issuer or departmental guidance: authoritative and often contractually imposed, but not itself statute. |
| [I] | Uncertain interpretation: an engineering reading of the sources that a qualified owner must confirm. |
| [D] | Decision needed: cannot be settled without a qualified legal, privacy, records or governance owner. It is mapped to the open-decisions register. |
Processing model assumed
Groundskeeper is a stateless decision service (architecture). A gateway sends prompt or response content. Groundskeeper evaluates it in memory and returns a verdict, findings (category, offsets, coverage), and optional transformations. By default, it does not retain raw payloads (ADR 0007).
┌──────────────┐ prompt/response ┌────────────────┐ verdict + redacted ┌──────────────┐
│ User / app │──────────────────▶│ Gateway (PEP) │◀────────────────────▶│ Groundskeeper│
└──────────────┘ └───────┬────────┘ └──────┬───────┘
│ only if allowed │ metadata only
▼ ▼
┌────────────────┐ ┌───────────────┐
│ Model provider │ │ Audit / OTel │
└────────────────┘ └───────────────┘Each arrow can be a collection, use, or disclosure. Each box can be in a different jurisdiction.
Deployment roles that change the analysis
| Role | Example | Why it matters |
|---|---|---|
| R1 Health CSP | Healthcare provider or health administration entity deploys an assistant. The Groundskeeper operator provides IT services to it. | The HI Act s 36 authority can extend to a contracted or subcontracted service provider whose duties involve implementing the authorised purpose [B]. Whether guardrail inspection implements that purpose is [I/D]. |
| R2 Victorian public sector | A Victorian government school, the Department, or VCAA uses Groundskeeper. | PDP Act IPPs and Part 4 VPDSS, the Public Records Act, Department policy, and possibly VSN authorisation apply. |
| R3 Other education APP entity | Catholic or independent school, RTO, TAFE vendor, or edtech provider. | Privacy Act APPs, including APP 9 government-related identifiers; ETR Act authorisation; and possibly the Children's Online Privacy Code. |
| R4 Incidental receipt | Unrelated deployer, such as a bank or retailer, where a user pastes an HPI-I or VSN. | The deployer probably has no HI Act or ETR Act authority [I]. The only defensible behaviour is to minimise, redact, and not forward. |
| R5 Groundskeeper engineering | Development, CI, benchmarks, fixtures. | Must not contain real identifiers. ISM-1420 applies to production-derived data. |
3. Identifier facts that drive controls
| Property | HPI-I | VSN |
|---|---|---|
| Format | 16 digits, prefix 800361, Luhn check digit (HL7 AU Base profile) | Randomly generated 9-digit number (VCAA). VET collection spec range: 000000001–999999999 |
| Free space | 9 free digits → about 10⁹ structurally valid values | About 10⁹ values. No checksum is published |
| Holders | Individual healthcare providers (adults). Ahpra-registered practitioners and others can be assigned one | Every student under 25 at a Victorian school, home-schooling registration, or in-scope VET provider. Most holders are children |
| Statute | HI Act and HI Regulations 2020; s 26 use and disclosure offence; s 27 protection; s 29 interference with privacy | ETR Act Part 5.3A; s 5.3A.9 authorisation; s 5.3A.10 offence (authorised users); s 5.3A.10B guidelines |
| Privacy-law status | Government related identifier for the Privacy Act (HI Act s 9(6)) [B] | Assigned by the Secretary of a State department, so it is likely a government related identifier for APP 9 [I]. It is likely a "unique identifier" under PDP Act IPP 7 [I] |
| Public? | May appear in healthcare directories with the provider's consent (HI Regs s 10E). That does not lift s 26 restrictions on other uses [B] | Not public. VCAA says the Act does not permit VSNs in shared communications such as class lists [G] |
| Authoritative validation | HI Service. Access is limited to registered or authorised participants [B] | Victorian Student Register. Access requires authorisation [B] |
| Groundskeeper detector class | Validated structural: prefix + Luhn (ADR 0010) | Context-bound: requires a VSN or full-label context |
4. Findings by regime
4.1 Healthcare Identifiers Act 2010 and Regulations 2020
Current compilation: Act C2026C00415 (19 September 2026). Regulations F2026C00393 (5 May 2026).
- [B] s 26(1)(d), (3), (5), (6). A person must not use or disclose an individual healthcare provider's healthcare identifier unless the use or disclosure is required or authorised under the HI Act, another Commonwealth law, or a court order; is by the provider for personal, family or household affairs; or falls within listed permitted general situations. The offence penalty is 2 years' imprisonment or 120 penalty units, or both. The civil penalty is 600 penalty units for knowing or reckless use or disclosure. Section 26(2) also prohibits use or disclosure of information disclosed in contravention.
- [B] Authorised purposes for provider identifiers. These include communicating or managing health information as part of providing healthcare or health administration (s 23); the My Health Record system (s 24); authentication in electronic communications (s 25); disclosure of an HPI-I to the provider (s 25C); and regulation-prescribed purposes (s 25D). Examples of prescribed purposes are health facilitation programs (HI Regs s 10A) and healthcare directory services (HI Regs s 10E, provider consent required).
- [B] s 36 / s 36A. An authorisation extends to employees, contracted service providers and subcontracted service providers where their duties involve, or are reasonably connected with, implementing that purpose. Section 5 defines a contracted service provider to include "information technology services relating to the communication of health information".
- [B] s 27. An entity holding healthcare identifiers must take reasonable steps to protect them from misuse, loss, and unauthorised access, modification or disclosure. It must also meet any prescribed requirements.
- [B] s 29. A contravention in connection with an HPI-I is an interference with privacy under the Privacy Act. For Part V investigations, a State or Territory authority is treated as an organisation. OAIC therefore has jurisdiction even over Victorian public bodies for this conduct.
- [B] HI Regs s 12. Retrievable records of individuals who access identifiers from the service operator must be kept, including for 7 years after authority ends. This applies only if Groundskeeper ever queries the HI Service. The control GK-HV-04 forbids such queries.
- [G] OAIC. Healthcare identifiers are personal information. Use outside the HI Act attracts penalties and is an interference with privacy. OAIC recommends audit trails of individual staff access.
- [G] ADHA HI conformance profile v5.0. For connected software, an audit trail of identifiers disclosed by the HI Service is required (008028). The ADHA security conformance profile for My Health Record connecting systems requires segregation of production from test and development environments (SEC-0520, tracing ISM-0400). This applies to Groundskeeper only by analogy unless it becomes HI-connected software.
- [I] Detecting, redacting or forwarding an HPI-I is probably a "use", and forwarding it to a model provider is probably a "disclosure". The HI Act does not expressly address transient machine inspection.
- [I] No data-location restriction specific to healthcare identifiers was found in the provisions reviewed. Do not confuse this with My Health Records Act 2012 obligations, which apply only if Groundskeeper touches My Health Record data.
- [D] OD-023. For each role (R1–R4), is Groundskeeper's inspection or redaction authorised? Is allow-through of an HPI-I to a model provider ever permitted?
4.2 Privacy Act 1988 (Cth) and the APPs
- [B] APP 3 / APP 5. Collection must be reasonably necessary for the entity's functions. Notice must be given. Content generated or inferred by AI that contains personal information is a collection [G OAIC AI guidance].
- [B] APP 6. Use and disclosure are limited to the primary purpose unless an exception applies. Entering personal information into a third-party AI product can be a disclosure [G OAIC]. As best practice, OAIC recommends not entering personal information, especially sensitive information, into publicly available generative AI tools [G].
- [B] APP 8 / s 16C. Overseas disclosure requires reasonable steps. The disclosing entity remains accountable for an overseas recipient's acts.
- [B] APP 9. An organisation must not adopt a government related identifier as its own identifier. It must not use or disclose one unless an exception applies, such as when required or authorised by law (HI Act s 28 makes HI Act authorisations count). The HPI-I is a government related identifier (HI Act s 9(6)). The VSN probably is one [I]. Using either identifier as a Groundskeeper key, fingerprint key, tenant user ID or join key risks "adoption" [I].
- [B] APP 11, including APP 11.3. From 2024, APP 11.3 states that reasonable steps include technical and organisational measures. APP 11.2 requires destruction or de-identification when information is no longer needed.
- [B] Part IIIC NDB. APP entities must assess a suspected eligible data breach within 30 days. They must notify OAIC and affected individuals where serious harm is likely. Health service providers are APP entities regardless of turnover. State authorities are generally not APP entities, although HI Act s 29 still brings HPI-I contraventions to OAIC [B/I].
- [B, commences 10 Dec 2026] APP 1.7–1.8 automated decisions. A privacy policy must describe computer programs that make, or substantially and directly relate to, decisions that could reasonably be expected to significantly affect an individual's rights or interests using personal information. Whether a guardrail block or redaction meets that test is [I/D] (OD-031).
- [B pending] Children's Online Privacy Code. OAIC must register it by 10 December 2026. The exposure draft applies to APP entities providing social media, relevant electronic or designated internet services that are likely to be accessed by children or primarily concerned with children's activities. Services provided by health service providers are excluded. It may bind R3 deployers in education. Applicability depends on the final text [D OD-031].
- [G] OAIC de-identification guidance. Hashing identifiers obscures them but is primarily a linkage technique. De-identified data can become personal information again in another environment.
4.3 Education and Training Reform Act 2006 (Vic) Part 5.3A and VCAA guidance
- [B] s 5.3A.9. The Secretary may authorise, in writing, a person, body or class to access, use or disclose VSNs or related information for listed purposes: enrolment and attendance; resources; statistical or research purposes relating to education or training; accurate educational records; as required or authorised by law; prescribed purposes; or purposes in a Ministerial Order. Authorisations may be conditional and revocable.
- [B] s 5.3A.10. An authorised user must not access, use or disclose a VSN or related information except in accordance with Division 3 (30 penalty units). This does not apply to statutory authorities.
- [B] s 5.3A.10A–10C. The Secretary must issue guidelines on the manner of access, use and disclosure and on storage and destruction. Guidelines may cover reporting requirements. Authorised users must comply with them. If an authorised user is not otherwise covered by the PDP Act or the Privacy Act, the PDP Act applies to it as if it were an organisation.
- [B] s 5.3A.13. A student may use or disclose their own VSN for any lawful purpose. A student's own VSN may therefore legitimately appear in input. That does not authorise the recipient's later handling [I].
- [G] VCAA. Requests for identifiable data or VSN data matching require authorisation. Example applicants include third-party contractors, such as IT contractors, doing work for an authorised user that requires VSN access. VCAA considers suitability, purpose, access, use, disclosure and destruction, and privacy and human-rights implications. VSN information must not appear in shared communications such as class lists.
- [G] Department of Education (schools). VSN use is regulated and limited to what legislation stipulates. Department guidance tells schools not to enter personal information into generative AI tools under any circumstances. Department policy applies to staff, contractors and service providers.
- [G] VET (DJSIR-administered collection). The Victorian VET Student Statistical
Collection Guidelines (2022 v1.0, issued by DET before VET functions moved to DJSIR)
specify VSN as numeric, length 9, values
000000001–999999999. Confirm against the current DJSIR edition. - [I] In the provisions reviewed (ss 5.3A.9–5.3A.15), no general offence was found for a person who is not an authorised user. Privacy law (IPP 7, APP 9), contracts and Department policy still constrain those persons. Do not read the absence of an offence as permission.
- Evidence gap. The current Secretary's Guidelines on the Victorian Student Number could not be retrieved. VCAA's link returned an HTML page instead of the document on 3 October 2026. Storage, destruction, reporting and contractor conditions must be taken from that document before any Victorian education deployment.
- [D] OD-024. Does the operator, or each sub-processor, need VCAA authorisation? Under which permitted purpose is guardrail inspection of VSNs justified?
4.4 Victorian privacy, security and health records
- [B] PDP Act IPP 4. Personal information must be protected, and destroyed or permanently de-identified when no longer needed. IPP 7 restricts adopting, using or disclosing another organisation's unique identifier. A contracted service provider cannot adopt a client's unique identifier as its own (OVIC guideline 7.2(c)) [G]. IPP 9 applies to any transfer outside Victoria, including interstate cloud processing. Permitted grounds include substantially similar law, contract or binding scheme, consent, and reasonable steps [G OVIC IPP 9 guidance].
- [B] PDP Act s 17 / State contracts. Contracted service providers can be bound to the IPPs. Part 4 / VPDSS V2.0 (still current; implementation guidance v2.4, January 2026) requires contracted service providers with access to public sector information to adhere to the standards. Under PDP Act s 89, the agency's security risk profile assessment and protective data security plan must cover those providers.
- [G] OVIC incident notification (VPDSS E9.010). Notify incidents affecting public sector information rated BIL 2 (limited) or above, including OFFICIAL: Sensitive, as soon as practical and within 30 days. OVIC also encourages timely notification to affected individuals.
- [I] This review found no general statutory duty in the PDP Act for Victorian public sector bodies to notify individuals of breaches. Confirm the current position.
- [B/I] Health Records Act 2001 (Vic). It may apply where an HPI-I appears with health information held in Victoria, including by private-sector bodies. Its identifier and transborder principles (HPP 7, HPP 9) parallel IPP 7 and IPP 9. Applicability to provider identifiers alone is uncertain.
4.5 Records: Public Records Act 1973 (Vic) and PROV
- [B] Public offices must make and keep full and accurate records. They may destroy them only under a retention and disposal authority (RDA) or normal administrative practice (NAP).
- [G/B for public offices] PROV AI Technologies and Recordkeeping Policy (2024). Content created by or through AI technologies is a public record. Accuracy checks and disposal must be overseen by an authorised human. Automated disposal must follow the PROV Approval Processes Policy.
- [G] PROS 22/06 (School Records RDA) governs government school records. NAP covers duplicates and backups of records held elsewhere.
- [I] For an R2 customer, Groundskeeper verdicts, transformations and audit metadata may be public records, even when processing is transient. That conflicts with "delete after N days" defaults and with APP 11.2 or IPP 4.2 minimisation unless the customer's records manager maps them to an RDA or NAP.
- [D] OD-027. Are Groundskeeper decision artefacts records? Who is the record-keeper: the customer system of record or the operator? Which RDA class applies?
4.6 Breach and incident regimes
| Regime | Trigger | Who | Timing | Label |
|---|---|---|---|---|
| Privacy Act Part IIIC (NDB) | Eligible data breach likely to cause serious harm | APP entities, including health service providers | Assess within 30 days, then notify OAIC and individuals as soon as practicable | [B] |
| HI Act s 29 | Any contravention involving an HPI-I | Any person, including State authorities, for OAIC investigation | No separate notification clock. Exposure to complaints and investigation | [B] |
| OVIC incident scheme (VPDSS E9.010) | Confidentiality, integrity or availability incident on public sector information rated BIL 2 or above | Victorian public sector bodies; contracted service providers via contract | As soon as practical and within 30 days | [G/B] |
| ETR Act guidelines / authorisation conditions | Per the Secretary's Guidelines and conditions (not retrieved) | Authorised users | Unknown until the guidelines are obtained | [B/D] |
| Department of Education privacy incident process | Privacy incident in schools | Schools, staff and contractors | Per Department policy | [G] |
| Cyber Security Act 2024 Part 3 | Ransomware or cyber-extortion payment | Businesses with turnover of at least $3 million, or SOCI responsible entities; not State bodies | 72 hours after payment | [B] |
| SOCI Act cyber incident reporting | Incident on a critical infrastructure asset | Responsible entities, such as some hospitals and higher-education assets; usually customers rather than Groundskeeper | 12 or 72 hours by severity | [B/I] |
| Contract | Any suspected incident affecting customer data | Groundskeeper operator → customer | Contractual SLA (to be decided) | [D] |
4.7 Security guidance
- ISM (ASD). ISM-0400 requires segregated development, test, staging and production environments. ISM-1420 prohibits production data in non-production environments unless they are secured to the same level. ISM-2030 requires commit scanning for secrets. ISM-2103 prohibits using organisational data processed by AI applications for training without informed, explicit consent. ISM-2123 requires deleting chat-session prompts and outputs with the session. ISM-1536 requires central logging of database queries and errors; log safely without values. All are [G] for non-government organisations and commonly contractual. Many Victorian controls trace to ISM through VPDSS.
- ASD Essential Eight and Engaging with AI (2024). Restrict admin privileges, use MFA, back up, know what data the AI system receives, and plan incident response [G].
- OAIC Guide to securing personal information gives the APP 11 reasonable-steps baseline [G].
5. Implications by engineering topic
| Topic | Implication | Basis |
|---|---|---|
| Collection / use / disclosure | Treat any request containing these identifiers as receiving restricted information. Use only for the guardrail decision. Disclose onward only when the deployment's authority covers it. Otherwise redact before the gateway forwards. Echoing the identifier to users is also disclosure. | [B] HI s 26; ETR 5.3A.9–10; APP 6/9; IPP 7. [I] inspection = use |
| Purpose limitation | Bind every deployment to a declared purpose code and authority reference. Restricted-category findings must not feed analytics, model training, benchmarking or product metrics beyond coarse aggregates. | [B] HI ss 23–25D; ETR 5.3A.9(2); APP 6. [G] ISM-2103 |
| Logging | No value, partial value, normalised value, offset-with-context snippet or hash in logs or errors. Error types and panics must not include request bodies. | [B] APP 11, HI s 27, IPP 4. [G] ADR 0007 |
| Telemetry | Metrics may record category counts only at coarse tenant and time granularity. No identifier-derived labels. Third-party APM or OTel SaaS is a disclosure and possibly an overseas or interstate transfer. | [B] APP 8 / IPP 9. [I] |
| Test data | Synthetic data only; Section 6 rules apply. No production-derived corpora. No LLM-generated identifier values, because models may reproduce memorised real ones. | [G] ISM-1420. [I] |
| Retention | Raw payloads are not retained. Audit metadata retention follows the customer RDA (R2) or an approved schedule (OD-009). Legal hold is supported. | [B] APP 11.2 / IPP 4.2 / PRA. [D] |
| Deletion | Deletion covers replicas, caches, search indices and backup expiry. Disposal of public records needs human authorisation and a disposal record. | [B] PRA. [G] PROV AI policy |
| Access controls | No standing human read path to payloads. Use least-privilege RBAC with author/approver/operator separation, MFA, privileged access logs and periodic review. | [B] HI s 27 / APP 11. [G] ISM, E8, VPDSS Std 4 |
| Audit | Use tamper-evident, metadata-only decision audit with policy digest, verdict, category counts, purpose code, authority reference, actor and time. Never store the identifier. | [G] OAIC audit-trail tip; ADHA 008028 (analogy); PROV |
| Redaction / tokenisation | Use an irreversible placeholder such as [HPI-I] or [VSN]. No partial masking: with a fixed prefix, the last four HPI-I digits leave about 10⁵ candidates. No format-preserving or deterministic tokens, because they may equal a real identifier and enable linkage. A reversible vault becomes a store of restricted identifiers. | [I]; OD-010 |
| Cross-border / cloud | Process and store all sinks in an approved Australian region. For R2, document an IPP 9 ground even for interstate regions. Maintain a sub-processor register. External judges never receive restricted identifiers. | [B] APP 8/16C, IPP 9. [G] Department and OAIC AI guidance. [D] OD-008, OD-025 |
| Incident response | One runbook maps detection → containment → regime matrix (Section 4.6) → customer notice. Treat a fixture collision with a real identifier, or a canary in a sink, as an incident. | [B/G]. [D] OD-028 |
| Production trials | Shadow or observe mode still processes real data. Before the first live request, complete authority, PIA, contract, residency, kill switch, time box, and metadata-only evaluation. Do not harvest examples from the trial. | [B] all regimes apply. [D] OD-030 |
6. Synthetic fixtures: collision risk and safe generation
6.1 Can a synthetic value map to a real identifier?
Yes, for any structurally valid value.
- HPI-I. The structurally valid space is
800361+ 9 free digits + Luhn check digit, giving (10^{9}) values. If (N) identifiers are issued uniformly at random across that space, a uniformly random fixture collides with probability (p \approx N/10^{9}). The expected number of collisions in (k) fixtures is (k \cdot N/10^{9}). Issuance is unlikely to be uniform. Sequential or blocked allocation can make small or clustered values more likely to collide. Neither (N) nor the allocation scheme is published. HL7 AU Base publishes an example HPI-I in the profile documentation, but it is not designated as non-issued. - VSN. VCAA describes VSNs as random. The VET collection range covers every
nine-digit value except
000000000. Every nine-digit fixture is therefore a candidate real VSN. With several cohorts allocated since the register began, (p) is material and cannot be made negligible by generation strategy. - Pairing raises harm. A bare number that coincides with an issued identifier is not obviously "about" that person. A fixture that pairs the number with a realistic name, date of birth, school, suburb, clinic or profession may create a plausible record about a real person [I].
- Checking a fixture against the HI Service or VSR is prohibited. It would itself be an unauthorised access, use or disclosure, and it would create access records [B].
6.2 Safe generation practices
- Prefer impossible values for negative and robustness cases. For HPI-I, use the
wrong prefix (for example
800362…, which is HPI-O space and must itself be handled), a Luhn failure, or the wrong length. For VSN, use wrong lengths,000000000, or non-digit look-alikes. These can never be a real identifier of the target class. - Use a minimal, registered set of structurally valid positives. Store them in a
single reviewed fixture registry with provenance: generator version, seed, rule,
date and reviewer. Each record carries
may_match_issued_identifier: true. Keep the set small, for example fewer than 20 per category, and reuse it everywhere. - Generate deterministically and algorithmically. Use a seeded CSPRNG to draw the nine free digits, then compute Luhn for HPI-I. Never ad hoc-generate in CI. Never ask an LLM for identifier values. Never perturb a real identifier: a one-digit change to a real number is derived from personal information and may itself be issued.
- Use only obviously fictional context. Never pair positives with realistic
person names, dates of birth, schools, clinics or suburbs. Use labelled
placeholders such as
Example Clinician AorExample School. Do not combine an HPI-I and a VSN in one fixture unless the test requires it. - Keep fixtures out of production. Production snapshots must not contain fixture allowlists or fixture-specific bypasses. Test policies and test tenants are separate. Leak canaries in production use only registered values and only through a dedicated test tenant.
- Fail CI on unregistered candidates. Add a pre-commit or CI scan that fails on any
800361-prefixed Luhn-valid 16-digit sequence, or any nine-digit sequence within about 30 code points of a VSN label, that is not in the registry. Scan built artefacts, logs and benchmark outputs too. - Rotate on collision. If anyone reports that a fixture value belongs to a real person, remove it from the registry, purge it from history where practicable, rotate it, and handle the event under the incident runbook.
- Do not use vendor test environment identifiers. HI Service or ADHA conformance test data obtained under developer registration is licensed for that purpose. Do not commit it to this repository [I].
7. Engineering control matrix
Applicability: H = HPI-I, V = VSN, All = both. Gates: P0 before any real data or trial; P1 before general production enforcement; P2 before optional features.
| ID | Control | Applies | Basis | Groundskeeper implementation | Verification | Gate |
|---|---|---|---|---|---|---|
| GK-HV-01 | Restricted-identifier classes are deny-by-default for onward flow | All | [B] HI s 26; ETR 5.3A.9–10; APP 9; IPP 7. [D] OD-023/024 | Mark au.health.hpi_i and au.education.vic_vsn as restricted. The compiler rejects any policy that forwards them unredacted unless the deployment binding carries an approved identifier_authority reference and purpose code | Compiler negative tests; binding review | P0 |
| GK-HV-02 | Redact before onward disclosure | All | [B] APP 6/8; HI s 26. [I] | Input-stage transformation replaces values with category placeholders before gateway forwarding. Output stage applies the same rule | Golden fixtures; Portkey replacement tests | P0 |
| GK-HV-03 | Block VSN in broadcast or multi-recipient outputs | V | [G] VCAA shared-communications guidance | Output-stage rule: block or redact VSNs where the request marks the destination as shared or broadcast | Conformance cases | P1 |
| GK-HV-04 | No registry lookups | All | [B] HI Act access regime; ETR authorisation. TM-11 analogue | Detectors have no network egress. Coverage state is structural. Never call the HI Service, HPD or VSR | Egress policy test; code review | P0 |
| GK-HV-05 | Value-free logs, traces, errors and metrics | All | [B] APP 11, HI s 27, IPP 4. [G] ADR 0007 | Typed log fields only; no body capture in OTel or HTTP middleware; panic recovery strips bodies; category counts only | Sink canary scan (TM-05); lint for %v of request structs | P0 |
| GK-HV-06 | No per-value fingerprints by default | All | [I] about 10⁹ space is enumerable. [D] OD-026 | Disable fingerprint emission for restricted classes. If later approved: HMAC-SHA-256, per-tenant and per-purpose non-exportable KMS key, rotation, TTL, treated as personal information | Config test; key-policy audit | P0 |
| GK-HV-07 | No value-level allowlists | All | [I] APP 9 adoption risk | Allowlisting by context rule or field only, never by identifier value or hash | Compiler rejects value allowlists for restricted classes | P1 |
| GK-HV-08 | Irreversible, non-colliding placeholders | All | [I]. OD-010 | Fixed category placeholder; no partial masking; transformations must not emit strings in the identifier's valid space | Property test: output never matches detector | P0 |
| GK-HV-09 | No reversible tokenisation or vault | All | [D] OD-010 | Feature absent. Any proposal requires a PIA, key management design, legal sign-off and authority covering storage | Architecture review | P2 |
| GK-HV-10 | External judges and models never receive restricted identifiers | All | [G] Department GenAI guidance, OAIC AI guidance. [B] APP 8 / IPP 9. [D] OD-008 | Routing layer redacts restricted spans before any remote or model-based detector, or skips that detector with unjudged coverage | Integration test with a mock remote detector | P0 |
| GK-HV-11 | Approved residency for all processing and sinks | All | [B] APP 8/16C, IPP 9. [D] OD-025 | Region-pinned deployment, logs, APM, backups and support tooling. Sub-processor register. IPP 9 ground recorded for R2 | Infrastructure-as-code policy check; vendor register review | P0 |
| GK-HV-12 | No payload persistence or memory spill | All | [B] APP 11. [G] ISM | No core dumps; encrypted or disabled swap; no request bodies in crash reporters; bounded buffers zeroed where practical | Host hardening checklist; crash drill | P0 |
| GK-HV-13 | Records-aware retention for audit metadata | All | [B] PRA; APP 11.2/IPP 4.2. [G] PROV AI policy. [D] OD-009, OD-027 | Per-tenant retention class, legal hold, human-authorised disposal job with a disposal record (no values) | Retention test; records manager sign-off | P1 |
| GK-HV-14 | Complete deletion | All | [B] APP 11.2 / IPP 4.2 | Deletion propagates to replicas, caches and indices; backups expire within a documented period; deletion evidence recorded | Deletion drill | P1 |
| GK-HV-15 | Least-privilege access, no human payload access | All | [B] HI s 27 / APP 11. [G] ISM, E8, VPDSS Std 4 | RBAC with author, approver and operator separation; MFA; privileged session logging; quarterly review; break-glass only for metadata | Access review evidence | P0 |
| GK-HV-16 | Change control for restricted-class policy | All | [G] VPDSS; TM-16/17 | Two-person approval; signed snapshots; tenant overrides cannot weaken restricted rules | Activation tests | P1 |
| GK-HV-17 | Tamper-evident metadata audit | All | [G] OAIC; ADHA 008028 (analogy); PROV | Append-only audit with policy digest, verdict, category counts, purpose and authority references, actor, time; no identifiers | Audit integrity test | P1 |
| GK-HV-18 | Purpose binding | All | [B] HI ss 23–25D; ETR 5.3A.9(2); APP 6 | Server-side deployment binding with a purpose code and authority reference that the request body cannot set | TM-01 negative tests | P0 |
| GK-HV-19 | Fixture registry and generation rules | All | [I]; Section 6; [D] OD-029 | test/fixtures/identifiers/ registry with provenance; seeded generator; context rules | CI scan (GK-HV-20) | P0 before any such fixture |
| GK-HV-20 | Repository and artefact identifier scan | All | [G] ISM-2030 analogue; ISM-1420 | CI fails on unregistered 800361 + Luhn sequences and label-adjacent nine-digit sequences in source, artefacts and benchmark outputs | CI job | P0 |
| GK-HV-21 | No production-derived data outside production | All | [G] ISM-1420; conformance doc | Corpora come from the registry or synthetic generation only; incident-derived corpus requires a separate approval | Corpus register audit | P0 |
| GK-HV-22 | Multi-regime incident runbook | All | [B/G] Section 4.6. [D] OD-028 | Runbook with a regime matrix, customer-notice SLA, evidence preservation without values, and a tabletop exercise | Tabletop record | P0 |
| GK-HV-23 | Production leak canaries | All | [I] | Registered fixture values sent through a dedicated test tenant on a schedule; all sinks scanned; alert on any hit | Scheduled job evidence | P1 |
| GK-HV-24 | No echo in user-facing messages | All | [I] disclosure | Block reasons name the category, never the value | Conformance cases | P0 |
| GK-HV-25 | Child-safe defaults for VSN contexts | V | [B pending] Children's code; [G] Department policy | Highest-privacy defaults; no age or identity inference; no profiling from findings | Policy review | P1 |
| GK-HV-26 | ADM transparency pack | All | [B from 10 Dec 2026] APP 1.7–1.8 for APP entities. [D] OD-031 | Document which decisions Groundskeeper automates (block, redact) and which inputs it uses, so deployers can assess privacy-policy disclosure | Doc review | P1 |
| GK-HV-27 | Contract flow-down | All | [B] PDP s 17, VPDSS, HI s 36. [D] OD-024/025/028 | Template clauses: IPP/APP compliance, VPDSS, HI Act contracted-service-provider duties, VSN authorisation conditions, breach SLA, sub-processors, residency, return or destruction, audit rights, no training | Legal review | P0 |
| GK-HV-28 | No training on customer data | All | [G] ISM-2103 | Contract and configuration: provider training disabled; Groundskeeper does not learn from payloads | Vendor attestation | P0 |
| GK-HV-29 | Transport and storage encryption | All | [G] ISM; VPDSS Std 11 (ICT security) | TLS 1.2+ (1.3 preferred) and mTLS gateway↔Groundskeeper; encrypted metadata stores | Configuration scan | P0 |
| GK-HV-30 | Trial guardrails | All | [B] all regimes apply. [D] OD-030 | Time-boxed, tenant-scoped, kill switch, metadata-only evaluation, documented stop criteria, no corpus harvesting | Trial readiness review | P0 |
8. Pre-production checklist
A required owner or decision is noted where one applies. Every box must be ticked, with evidence linked, before the first real request.
Authority and legal
- Deployment role (R1–R5) recorded for each tenant, with customer confirmation.
- OD-023 decided for HPI-I processing in each role, including whether allow-through is ever permitted.
- OD-024 decided. VCAA authorisation obtained or confirmed not required. Current Secretary's Guidelines obtained and their conditions mapped to controls.
- Purpose code and authority reference configured in each server-side binding (GK-HV-18).
- Contract executed with flow-down clauses (GK-HV-27), including a breach-notice SLA and sub-processor list.
Privacy and governance
- PIA completed using the template the customer requires (OAIC, OVIC, or Victorian Department of Education), covering both identifiers, children, and AI.
- APP 8 / IPP 9 basis recorded for every processing location, including interstate (OD-025).
- Children's code and APP 1.7 assessment done for APP entity deployers (OD-031).
- Indigenous Data Governance gate confirmed not triggered, or approved (IDG).
Architecture and configuration
- Restricted classes enforced by the compiler (GK-HV-01). Default transformation is redaction (GK-HV-02, GK-HV-08).
- No detector egress; validation is
structuralonly (GK-HV-04). - Remote or model detectors cannot receive restricted spans (GK-HV-10).
- Fingerprints disabled for restricted classes (GK-HV-06). No value allowlists (GK-HV-07).
- Logs, traces, metrics, error reporting and crash tooling verified value-free with canaries (GK-HV-05, GK-HV-12, GK-HV-23).
- Region pinning verified for compute, logs, APM, backups and support tooling (GK-HV-11).
- Encryption in transit and at rest verified (GK-HV-29).
Data and fixtures
- OD-029 approved. Fixture registry in place with provenance (GK-HV-19).
- CI identifier scan enabled and passing (GK-HV-20).
- No production-derived data in any non-production environment (GK-HV-21).
Access and audit
- RBAC roles, MFA and privileged access logging in place. First access review done (GK-HV-15).
- Metadata audit is append-only and tamper-evident, and contains no identifier values (GK-HV-17).
- Two-person approval for restricted-class policy changes (GK-HV-16).
Records, retention and deletion
- OD-027 decided. Retention class and RDA or NAP mapping recorded for R2 tenants. OD-009 durations set.
- Legal hold and human-authorised disposal tested (GK-HV-13). Deletion drill passed (GK-HV-14).
Incident readiness
- OD-028 decided. Runbook covers NDB, HI s 29/OAIC, OVIC, VCAA or Department, ransomware and contract (GK-HV-22).
- Tabletop exercise completed, including "fixture matches a real person" and "identifier found in a log sink".
Trial operations
- OD-030 approved: scope, duration, tenants, success and stop criteria, kill switch tested (GK-HV-30).
- Observe-mode evaluation uses metadata only. No example harvesting.
- Named privacy, security, records and customer sign-offs recorded.
9. Decisions needed
These are proposed additions to the open-decisions register. Engineering must not settle them.
| ID | Decision | Owner | Required before |
|---|---|---|---|
| OD-023 | Whether inspection, redaction and any allow-through of HPI-Is is an authorised use or disclosure under HI Act s 26 for each deployment role, and the evidence required | Health-law counsel + privacy | any health deployment or trial |
| OD-024 | Whether the operator and sub-processors need VCAA authorisation under ETR Act s 5.3A.9, which permitted purpose applies, and which Secretary's Guidelines conditions bind Groundskeeper | Legal + privacy + customer (Department, VCAA, school) | any Victorian education deployment or trial |
| OD-025 | Approved processing and storage jurisdictions and the APP 8 / IPP 9 basis, including interstate hosting and telemetry sub-processors | Privacy + legal + security | production trial |
| OD-026 | Whether any per-value fingerprint of restricted identifiers is allowed, and if so the key management, rotation and retention | Privacy + security | production telemetry |
| OD-027 | Records status of Groundskeeper decision artefacts for public-office customers, the record-keeper, and the RDA class | Records manager + legal | Victorian public sector production |
| OD-028 | Breach notification allocation and SLAs across NDB, OAIC (HI), OVIC, VCAA or Department, ransomware reporting and contracts | Privacy + legal + security | production trial |
| OD-029 | Acceptance of the residual risk that structurally valid synthetic fixtures may equal issued identifiers, and approval of the registry and generation rules | Privacy + engineering lead | adding any structurally valid HPI-I or VSN fixture |
| OD-030 | Production trial authorisation: PIA outcome, scope, duration, stop criteria, and whether HREC or research approval applies | Privacy + product + customer | production trial |
| OD-031 | Whether Groundskeeper decisions fall within APP 1.7 automated decisions and whether the Children's Online Privacy Code affects deployers, and which documentation to provide | Privacy + product | 10 December 2026 for APP entity customers |
10. Evidence gaps and caveats
- Secretary's Guidelines on the Victorian Student Number were not retrievable from the VCAA link on 3 October 2026. They are mandatory for authorised users and may impose storage, destruction and reporting conditions.
- The current DJSIR edition of the VET collection guidelines was not reviewed. The VSN range was taken from the 2022 DET edition.
- Issued-identifier counts and allocation schemes are unpublished. Collision probabilities are therefore given as formulas.
- No HPI-I-specific data-location rule was identified. A full review of the HI Act, the regulations and any applicable HI Service terms is still needed.
- The finding that the PDP Act imposes no statutory duty to notify individuals should be confirmed for Victorian public bodies.
- The penalty-unit values, the final Children's Online Privacy Code text, and OAIC ADM guidance were not final or not checked at the cut-off.
- AustLII section pages may lag the authorised compilations. Key HI Act findings were checked against legislation.gov.au compilation C2026C00415.
11. Sources (accessed 3 October 2026)
Legislation
- Healthcare Identifiers Act 2010 (Cth), compilation C2026C00415: https://www.legislation.gov.au/C2010A00072/latest/text; ss 9, 26, 29, 36 (AustLII): https://classic.austlii.edu.au/au/legis/cth/consol_act/hia2010199/
- Healthcare Identifiers Regulations 2020 (Cth), F2026C00393: https://www.legislation.gov.au/F2020L01072/latest/text
- Privacy Act 1988 (Cth), s 6FA: https://classic.austlii.edu.au/au/legis/cth/consol_act/pa1988108/s6fa.html; Privacy and Other Legislation Amendment Act 2024, Sch 1: https://classic.austlii.edu.au/au/legis/cth/num_act/paolaa2024377/sch1.html
- Education and Training Reform Act 2006 (Vic) Part 5.3A: https://www.austlii.edu.au/au/legis/vic/consol_act/eatra2006273/ (ss 5.3A.1, 5.3A.9, 5.3A.10, 5.3A.10A–10C, 5.3A.13, 5.3A.15)
- Cyber Security Act 2024 (Cth) s 27: https://classic.austlii.edu.au/au/legis/cth/num_act/csa2024181/s27.html
Regulators, issuers and departments
- OAIC, Healthcare identifiers: https://www.oaic.gov.au/privacy/privacy-legislation/related-legislation/healthcare-identifiers
- OAIC, IHI obligations for public health service providers: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/individual-healthcare-identifiers/individual-healthcare-identifiers-obligations-for-public-health-service-providers
- OAIC, Data breach preparation and response, Part 4 (NDB): https://www.oaic.gov.au/privacy/notifiable-data-breaches/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme
- OAIC, Guidance on privacy and commercially available AI products: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
- OAIC, De-identification and the Privacy Act: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/de-identification-and-the-privacy-act
- OAIC, Children's Online Privacy Code: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code; ADM transparency resources (30 Sep 2026): https://www.oaic.gov.au/news/media-centre/new-resources-on-transparency-for-use-of-ai-and-automated-decision-making
- ADHA, Healthcare Identifiers Service implementer resources: https://implementer.digitalhealth.gov.au/resources/services/healthcare-identifiers-service-hi; HI Service Conformance Profile v5.0: https://implementer.digitalhealth.gov.au/resources/download/component/10498/a9b48195-98d0-4c29-af46-73ef3358e893; HI Test and Go Live: https://implementer.digitalhealth.gov.au/resources/hi-service-test-and-go-live
- HL7 Australia AU Base, AU HPI-I profile: https://hl7.org.au/fhir/StructureDefinition-au-hpii.html
- VCAA, The Victorian Student Number: https://www.vcaa.vic.edu.au/administration/school-administration/student-numbers/victorian-student-number; VSN for providers: https://www.vcaa.vic.edu.au/administration/school-administration/student-numbers/vsn-education-and-training-providers; VSN data requests: https://www.vcaa.vic.edu.au/administration/school-administration/student-numbers/vsn-data-requests
- Department of Education (Vic), Schools' privacy policy: https://www.vic.gov.au/schools-privacy-policy; Privacy and Information Sharing (PAL): https://www2.education.vic.gov.au/pal/privacy-information-sharing/print-all; Generative AI policy: https://www2.education.vic.gov.au/pal/generative-artificial-intelligence/policy
- Victorian VET Student Statistical Collection Guidelines 2022 v1.0: https://www.education.vic.gov.au/Documents/training/providers/rto/Victorian%20VET%20Student%20Statistical%20Collection%20Guidelines%20-%202022%20v1.0.pdf
- OVIC, IPP 7 guidelines: https://ovic.vic.gov.au/book/ipp-7-unique-identifiers/; IPP 9 guidelines: https://ovic.vic.gov.au/book/ipp-9-transborder-data-flows; VPDSS V2.0: https://ovic.vic.gov.au/information-security/standards; Incident Notification Scheme v4.0 (March 2026): https://ovic.vic.gov.au/wp-content/uploads/2026/07/2026-OVIC-Information-Security-Incident-Notification-Scheme-V4.0.pdf; VPDSS implementation guidance v2.4: https://ovic.vic.gov.au/wp-content/uploads/2026/01/VPDSS-2.0-Implementation-Guidance-V2.4.pdf
- PROV, AI Technologies and Recordkeeping Policy: https://prov.vic.gov.au/sites/default/files/files/documents/ai_tech_and_recordkeeping_policy_v1_2024.pdf; Normal administrative practice: http://prov.vic.gov.au/recordkeeping-government/a-z-topics/normal-administrative-practice-nap; PROS 22/06 School Records: http://prov.vic.gov.au/recordkeeping-government/document-library/pros-2206-school-records
- ASD, ISM Guidelines for software development: https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-software-development; Engaging with AI: https://www.cyber.gov.au/sites/default/files/2024-01/Engaging%20with%20Artificial%20Intelligence%20%28AI%29.pdf
- Home Affairs, Ransomware payment reporting factsheet: https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf