[nonimo]
EN
Download

What to take out of an NDIS case note before you use AI

· Updated · Written and maintained by Joaquín Trapero, Nonimo

In February 2026 the NDIS Commission published a position statement that used a word most Australian providers had never had to define before. If you use AI, it said, all information must be appropriately de-identified. It named ChatGPT a page earlier, and it left open the question that actually decides your week: de-identified how, and by what test.

Underneath the instruction sit three words that sound interchangeable and are not. Only one of them takes a document out of the Privacy Act, and it is the one almost nobody reaches. The other two leave the note exactly where it was, which is in your hands and your file.

That matters at one specific moment: when a support worker has a progress note open, a deadline, and a chatbot in the next tab. What decides it is whether anyone at the other end could put it back, rather than how much came out.

What the NDIS Commission actually asked for

The document is short, it is dated February 2026, and it is worth reading before anyone in your service writes an AI policy. Its subject is narrow, the development and review of behaviour support plans, but the reasoning it applies is not narrow at all, and the risks it lists are the risks of every case note in the building.

It begins by refusing to bless anything. The Commission “does not endorse or approve the use of AI tools in the development and review of behaviour support plans”, and immediately adds that this “does not prevent NDIS providers using AI, so long as such use complies with providers’ legal obligations”.

Then it sets the bar. The Commission “expects that, if a provider decides to use AI, all information is appropriately de-identified and that no personal information of participants is disclosed to AI systems”.

Read those two sentences together and what you have is a condition rather than a ban, and the condition is a legal term.

The five risks it named

The statement lists what it is worried about, and the list is useful because it separates the privacy problem from the clinical one. Three of the five are about where the text goes. Two are about what comes back.

what the Commission listedwhere it bites
Disclosure of personal participant information to third partiesthe paste itself
Processing or storage of personal information overseasthe vendor’s region
No transparency about how data is stored, secured or used once enteredthe terms nobody read
Inaccurate or misleading content, including content not developed with the participantthe draft that comes back
Automated decision-making without human oversight or clinical judgementwho actually decided

The first three are the subject of this page, and the second of them, where the text is processed, is the one that pulls in the Australian rules on sending material offshore. The last two belong to practice governance, and no amount of careful redaction touches them.

Why “expects” is stronger than it looks

A position statement is not a rule, and it is easy to file it as advice. The sentence underneath it is the one that changes the temperature. The Commission says that disclosing sensitive personal information “to a third-party AI platform, such as ChatGPT, without appropriate safeguards may breach section 6 (b) of the NDIS Code of Conduct, which requires providers to respect the privacy of people with disabilities”.

Section 6(1)(b) of the Code of Conduct Rules says exactly that, in seven words: respect the privacy of people with disability. And the Rules carry a note that the advisory tone hides. Compliance with the Code is a civil penalty provision under section 73V of the NDIS Act, enforceable by an order to pay a pecuniary penalty. The instruction to de-identify is soft. The obligation sitting behind it is not.

Whether the same paste is also a notifiable data breach is a separate question with its own clock, and we work through it in our guide on pasting client data into a chatbot.

De-identified is a defined term here, and that is unusual

This is where Australia parts company with most other countries where English is spoken, and it is the single most useful thing to know before you argue with anyone about a case note.

The Privacy Act defines the word. Section 6(1) says that personal information “is de-identified if the information is no longer about an identifiable individual or an individual who is reasonably identifiable”. That is the whole definition. It is a status, not a technique, and nothing in it mentions names, numbers or black boxes.

Compare that with the picture outside Australia, which our guide to the vocabulary sets out in full: neither UK nor EU data protection law defines the term at all, and the regulators there prefer to avoid it. Here it is in the Act, which means an auditor can hold you to it.

The test is “reasonably identifiable”, and it moves

The OAIC’s guidance on de-identification is blunt about what follows. De-identification is not a property a document acquires and keeps. “The same information may be personal information in one situation, but de-identified information in another.” A licence number tells a motor registry everything and a stranger nothing.

The threshold is stated as risk, not certainty. Information is de-identified where the risk of re-identification “is very low in the relevant release context”, and the regulator calls the whole exercise “a risk management exercise, not an exact science”.

What that buys you when you get there

The payoff is real and it is worth naming, because it is the reason to do the work properly rather than quickly. Information “that has undergone an appropriate and robust de-identification process is not personal information, and is therefore not subject to the Privacy Act 1988 (Cth)”.

Out of the Act means out of the Australian Privacy Principles, out of APP 8, and out of the notifiable data breach scheme for that material. There is no equivalent prize for having tried. Swapping names for labels is one way of trying, and whether a pseudonymised file ever gets there turns on who holds the key.

Turnover does not get you out of this

Plenty of Australian businesses read the Privacy Act, find the threshold of three million dollars, and stop. For an NDIS provider that is usually the wrong stop, and the reason is a single paragraph.

Section 6D(4)(b) says an operator is not a small business operator if it “provides a health service to another individual and holds any health information except in an employee record”. There is no turnover qualifier in that paragraph. It applies to a sole trader with one participant.

Where disability sits inside the definition

The hinge is the definition of health information, and it names disability directly. Health information is “information or an opinion about the health, including an illness, disability or injury, (at any time) of an individual” that is also personal information. Disability is not the only sensitive category a provider holds: its staff files carry others, from union fees to a police check, and the full list of sensitive categories shows where each turns up.

A health service, under section 6FB, is an activity intended or claimed to assess, maintain or improve an individual’s health, or to manage it where it cannot be improved. Large parts of what NDIS providers do land inside that description without anyone intending them to.

whocovered by the Privacy Act
Allied health practice, any sizeyes, health service and health information
Support coordination holding assessments and diagnosesyes, on the same two limbs
Behaviour support practitioner, sole traderyes
Plan manager handling only invoices and budgetsdepends on whether health information is held
Provider over three million dollars in turnoveryes, on turnover alone

The OAIC says it in plain words

You do not have to reason your way there. The regulator’s own list of health service providers includes “a disability service provider (where they handle health information)”, and the page states that an organisation providing a health service and holding health information is covered “even if they’re a small business or providing a health service is not their primary activity”.

If you want the full map of who the Act reaches and which uses it permits, that is the subject of our guide to AI tools under the Privacy Act, and the councils question, which runs on state law instead, is covered in the guide for Australian local government.

What is in a case note before you touch it

Open a real progress note and count what is on it. Most services are surprised, because the identifiers arrive from several different agencies and nobody ever assembled the list in one place.

Here is the Australian set, in the order a tagger meets them. Every one of these has a shape, which makes them the easiest to catch.

what it iswhy it is on the page
NDIS participant numberthe key to every record you hold
Medicare numbercopied across from intake
Individual healthcare identifierarrives with allied health correspondence
Centrelink customer reference numberplan and payment paperwork
Tax file numberstaff records, and occasionally participant paperwork in error
Ahpra registration numberidentifies the practitioner, not the participant
Date of birth, address, phone, emailthe ordinary four

Two of those deserve separate treatment before anything else happens to the document.

The one with a criminal offence attached

A healthcare identifier is not governed by the Privacy Act alone. Section 26 of the Healthcare Identifiers Act 2010 makes unauthorised use or disclosure an offence in its own right, and the penalty is set out in the Act itself.

2 years
Maximum imprisonment for unauthorised use or disclosure of a healthcare identifier. Healthcare Identifiers Act 2010, section 26

The provision reads: “A person commits an offence if the person contravenes subsection (1) or (2). Penalty: Imprisonment for 2 years or 120 penalty units, or both.” That is a separate regime with separate consequences, and it does not care whether your privacy policy is tidy.

The tax file number is the other one that behaves differently, and the rules that surround it are set out in our Privacy Act guide rather than repeated here.

What to take out, in order

Six of the seven steps below are mechanical. A person can do them with a highlighter, and software can do them faster and more consistently. The seventh is the one that decides whether the first six mattered.

This is a list about what leaves the page. Which categories should not go into a chatbot at all, whatever you do to them first, is a different list, and it is set out in the Privacy Act guide.

  1. Structured identifiers first. The NDIS number, Medicare, the healthcare identifier, the CRN, the tax file number. These have fixed shapes, they are unambiguous, and there is never an argument about whether they identify someone.
  2. Names, all of them. Not only the participant. The mother who rang, the support worker on shift, the GP, the behaviour support practitioner, the plan manager’s contact. A note with four other names in it is a note about five people.
  3. Contact details. Address, phone, email. A street address in a country town is a stronger identifier than a name.
  4. Organisations that are effectively addresses. The school, the day program, the clinic, the group home. Naming the site narrows the population to a handful.
  5. Exact dates, where the date is not the point. An incident date plus a service is a lookup key. If the clinical question is the sequence, keep the interval and drop the calendar date.
  6. Reference numbers you did not think of as identifiers. Plan numbers, incident report numbers, support item codes tied to one participant, internal file references.
  7. The sentence that identifies without any of the above. This is the step no pattern matching performs, and it is where the work actually is.

Step seven, and why it is a person’s job

A machine matches shapes. Step seven is the realisation that “the third incident since the autism assessment in May, on the run back from school” describes exactly one child in a town of four hundred people, and that every label in the rest of the document changes nothing about that.

The OAIC’s key concepts guidance frames the same point as a question about who is holding the information and what else they can reach: whether someone is reasonably identifiable turns on the nature and amount of information available, who has access to it, and the practicability of identification, including the time and cost involved.

In a metropolitan service with two thousand participants, a diagnosis and a month is noise. In a regional service with forty, it is a name.

What still identifies when the name is gone

The uncomfortable part of the Australian test is that it points at your reader, not at your document. The release context does the work, and a chatbot is a release context with unknown members.

This is also where the sector’s own numbers stop being abstract. In the most recent statistics the OAIC has published, health is the sector that notified most, which is the backdrop against which any new disclosure route gets judged.

Health18
Finance14
Australian Government13
Share of notifications by sector, per cent, January to June 2025. OAIC, 4 November 2025

In that period the OAIC received 532 notifications. Health led with 18 per cent, finance followed with 14 and Australian Government agencies with 13. Human error accounted for 37 per cent, which the OAIC reports as 193 notifications, and a paste into the wrong window is the purest form of human error there is. Whether a particular one of those crosses into notifiable territory is a judgement with a deadline attached.

The context you cannot see from inside the note

A useful habit is to read the cleaned note as though you were the one person most likely to recognise the participant: a former support worker, a sibling, a neighbour who works at the pharmacy. That reader has context your tagger never had.

If the note survives that reading with nobody identifiable, you are close. If it does not, no further substitution will fix it, because the identifying material is the narrative itself.

Where the Australian framework points next

If you want a structured way through this rather than a habit, the OAIC and CSIRO’s Data61 published a De-Identification Decision-Making Framework in September 2017, and it is still the reference the regulator points to. The OAIC now notes on its own page that the guide may be out of date, which is itself worth knowing before you cite it at an audit.

A progress note before and after

The difference between a mechanical pass and a finished one is easiest to see in a document rather than in a principle. The note below is invented, including the town and the school. Only the shapes are Australian.

BEFORE  Participant: Aroha Webster, NDIS 430918227, DOB 14/03/2011.
        12 Kurrajong Pl, Wirrabilla NSW. Plan manager: Riverbend.
        Picked up from Wirrabilla Central at 3.10pm with Dan.
        Distressed when the route changed. Third incident since the
        autism assessment in May. Mum rang Dr Halliwell at Nyngara.

AFTER   Participant: [PERSON_1], [PERSON_2], DOB [BIRTH_DATE_1].
        [ADDRESS_1], Wirrabilla NSW. Plan manager: Riverbend.
        Picked up from Wirrabilla Central at 3.10pm with Dan.
        Distressed when the route changed. Third incident since the
        autism assessment in May. Mum rang Dr [PERSON_3] at Nyngara.

STILL   one child, one school run, one diagnosis, one month, one
THERE   regional town implied by the service that holds the file.

The AFTER is what Nonimo’s engine returned for this note on 22 September 2026, unedited. It covered the participant’s name, the date of birth, the street and the GP’s surname. It got one thing wrong you should know about: the NDIS number, sitting in a list after “Participant:”, was read as part of a name and came out as [PERSON_2]. Covered, but under the wrong label.

It left the plan manager, the school, the support worker and the clinic exactly as they were, because none of them has a shape or a label in front that software can go on. On this note, steps two and four are still yours. The last two lines are step seven, and no tagger produces them.

The version most people actually send

The common failure is doing step one and feeling finished, because something visibly changed on the screen.

ONLY THE   Aroha Webster, NDIS [REFERENCE_1], DOB 14/03/2011.
NUMBERS    12 Kurrajong Pl, Wirrabilla NSW. Third incident
           since the autism assessment in May.

FULL PASS  [PERSON_1], NDIS [REFERENCE_1], DOB [DATE_1].
           [ADDRESS_1]. Third incident since the autism
           assessment in May.

The first version still carries a name, a street, a town and a date of birth. It is the one that feels safe, and it is the one that gives away everything the participant number never did on its own. The same failure on an ordinary employment file, with the overseas definitions alongside it, is worked through in our vocabulary guide.

De-identified, masked or pseudonymised: which one you did

Three words, three different claims, and only one of them is the claim the NDIS Commission asked for. Using the wrong one in a policy document is the kind of error that reads as carelessness to a regulator and as a misrepresentation to a lawyer.

what you didwhat it meanswhere the note ends up
Maskedcharacters hidden inside a value you keepstill personal information
Pseudonymisedlabels swapped in, correspondence kept somewherestill personal information
De-identifiedno longer about a reasonably identifiable individualoutside the Privacy Act

The distinction is not academic. If the link back exists anywhere, including in your own encrypted key file, the material is still personal information and the Act still applies to it. The full treatment of the three terms, with the overseas definitions alongside, is in our vocabulary guide.

The claim to avoid making about your own service

There is a sentence that shows up in AI policies across the sector and it is the one to strike: that because names and numbers are removed, the service is compliant. The OAIC’s AI guidance says the opposite in passing, noting that personal information “may be at risk of re-identification even when de-identified or anonymised”.

Say what you did. Do not say what it achieved.

Where taking things out stops being the answer

Cleaning the document answers one question. It does not answer the other two, and conflating them is how services end up confident and exposed at the same time.

The first unanswered question is whether the disclosure was permitted at all. A paste is a use or a disclosure, and APP 6.1 requires that information collected for a primary purpose not be used or disclosed for another purpose without consent or an exception. That analysis, and APP 8 on sending material offshore, is set out in the Privacy Act guide and there is no point repeating it here.

The second is whether the tool holds what you send it. That varies by product and by account type, and the answers are worth checking before the policy is written: what OpenAI keeps and deletes, what Anthropic does by plan, what Google reviews and retains, and which Copilot account you are actually signed into.

Best practice, according to the regulator

The OAIC’s guidance on commercially available AI products puts its recommendation at the level of the input rather than the vendor. As a matter of best practice it “recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools”.

For an NDIS provider that recommendation and the Commission’s expectation point the same way, from two different regulators, sixteen months apart. Registered clinicians on the team will find much the same line drawn in the Ahpra AI guidelines on patient data.

Writing it down so it survives an audit

None of the above helps on the day someone asks unless it exists on paper. The record is the artefact, and it takes an afternoon.

Name the tools people may use, and the account type

A policy that says "AI tools" governs nothing, because the answer changes between a personal login and a business tenant.

Write the de-identification step as a procedure, not a principle

The seven steps above, in your own words, with your own document types named.

Say who does step seven

If nobody is named, nobody does it.

Record the decision, not just the rule

Which tool, which date, who approved it, what was considered. That is what an auditor asks for.

Keep the participant in the loop where the Code requires it

Behaviour support plans must be developed in consultation with the participant, their family and carers, and that obligation does not move because a machine helped with a draft.

The written record for an NDIS provider's AI use, in the order an auditor reads it

A starting structure, written for a general audience rather than for the NDIS specifically, is in our AI policy template, and the insurance question that follows from all of this is covered in the Australian cyber cover guide.

What our software does here, and what it does not

Nonimo runs on the machine. It replaces identifiers in text before that text goes anywhere, it shows what it changed and why, and the change can be undone. Among the Australian identifiers it recognises as such are the tax file number, the Medicare number, the individual healthcare identifier and the Centrelink reference. The NDIS number is found only by the label in front of it, as an invented provider referral before and after the key shows.

It pseudonymises. The correspondence can be reversed and is kept encrypted on the user’s own computer, which means the output is still personal information in the sense the Act uses. That is a smaller claim than de-identification, and by now it should be clear why the difference matters more here than almost anywhere else.

What it keeps on the computer is set out on Nonimo’s security page, and the licence terms on the licence page.

The judgement stays with the person who knows the participant, and the guides on using AI with client data are there for judging any tool in this category, including ours.

The question to ask before you send it

Not “did I take enough out”. The Australian test is the other one: in the hands of whoever ends up reading this, is the person still reasonably identifiable?

If the answer is yes, or if you are not sure, the note has not been de-identified, whatever the labels on the screen say. It is still a participant’s health information, it is still yours to answer for, and the Code of Conduct still applies to what happens to it next. The next question after that one, which tool and which account, is the subject of the Privacy Act guide.

Sources

Every page below was open in front of us on 21 September 2026.

The progress note in this guide is invented. The names, numbers, street and town in it belong to nobody. One publisher here blocks automated requests: the NDIS Commission’s position statement returns no response to a plain fetch from the command line and downloads normally with browser headers, which is how it was read.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Can NDIS providers use ChatGPT for case notes?

Nothing prohibits it. In February 2026 the NDIS Commission said it does not endorse or approve AI tools for behaviour support plans, but that providers may use AI so long as the use is lawful, and that no personal information of participants should be disclosed to AI systems.

What does de-identified mean under the Privacy Act?

Section 6(1) says personal information is de-identified if it is no longer about an identifiable individual or an individual who is reasonably identifiable. It is a defined term in Australia, which is unusual: the UK and Irish regimes do not define it at all.

Is removing the participant's name enough to de-identify a case note?

Usually not. The OAIC treats de-identification as contextual, and says the same information can be personal information in one situation and de-identified in another. A diagnosis, a town, a plan date and a support category can single out one person with no name attached.

Does the small business exemption cover an NDIS provider?

Rarely. Section 6D(4)(b) removes the exemption from anyone who provides a health service and holds health information, whatever the turnover. The OAIC's own list of health service providers names a disability service provider where they handle health information.

Is an NDIS progress note sensitive information?

Generally yes. Health information is a subset of sensitive information, and the Privacy Act's definition of health information expressly covers information or an opinion about the health, including an illness, disability or injury, of an individual.

What happens if a participant's healthcare identifier goes into a chatbot?

It may be an offence. Section 26 of the Healthcare Identifiers Act 2010 makes unauthorised use or disclosure of a healthcare identifier punishable by imprisonment for 2 years or 120 penalty units, or both. That sits outside the Privacy Act and outside the NDIS rules.

Does masking a number make a note anonymous?

No. Masking hides characters in a value you keep, so the record and the link survive. If you or anyone else can restore the link, the result is pseudonymous, which stays personal information and stays your responsibility under the Act.

Do I need consent to put a de-identified note into an AI tool?

If the material is genuinely de-identified it is not personal information, so the Australian Privacy Principles do not apply to it. The difficulty is proving you got there, which the OAIC describes as a risk management exercise rather than an exact science.

Is breaching the NDIS Code of Conduct actually enforceable?

Yes. The Code of Conduct Rules note that compliance is a civil penalty provision under section 73V of the NDIS Act, enforceable by an order to pay a pecuniary penalty. Section 6(1)(b) requires providers to respect the privacy of people with disability.