What to take out of an NDIS case note before you use AI
· Updated · Written and maintained by Joaquín Trapero, Nonimo
In February 2026 the NDIS Commission published a position statement that used a word most Australian providers had never had to define before. If you use AI, it said, all information must be appropriately de-identified. It named ChatGPT a page earlier, and it left open the question that actually decides your week: de-identified how, and by what test.
Underneath the instruction sit three words that sound interchangeable and are not. Only one of them takes a document out of the Privacy Act, and it is the one almost nobody reaches. The other two leave the note exactly where it was, which is in your hands and your file.
That matters at one specific moment: when a support worker has a progress note open, a deadline, and a chatbot in the next tab. What decides it is whether anyone at the other end could put it back, rather than how much came out.
What the NDIS Commission actually asked for
The document is short, it is dated February 2026, and it is worth reading before anyone in your service writes an AI policy. Its subject is narrow, the development and review of behaviour support plans, but the reasoning it applies is not narrow at all, and the risks it lists are the risks of every case note in the building.
It begins by refusing to bless anything. The Commission “does not endorse or approve the use of AI tools in the development and review of behaviour support plans”, and immediately adds that this “does not prevent NDIS providers using AI, so long as such use complies with providers’ legal obligations”.
Then it sets the bar. The Commission “expects that, if a provider decides to use AI, all information is appropriately de-identified and that no personal information of participants is disclosed to AI systems”.
Read those two sentences together and what you have is a condition rather than a ban, and the condition is a legal term.
The five risks it named
The statement lists what it is worried about, and the list is useful because it separates the privacy problem from the clinical one. Three of the five are about where the text goes. Two are about what comes back.
| what the Commission listed | where it bites |
|---|---|
| Disclosure of personal participant information to third parties | the paste itself |
| Processing or storage of personal information overseas | the vendor’s region |
| No transparency about how data is stored, secured or used once entered | the terms nobody read |
| Inaccurate or misleading content, including content not developed with the participant | the draft that comes back |
| Automated decision-making without human oversight or clinical judgement | who actually decided |
The first three are the subject of this page, and the second of them, where the text is processed, is the one that pulls in the Australian rules on sending material offshore. The last two belong to practice governance, and no amount of careful redaction touches them.
Why “expects” is stronger than it looks
A position statement is not a rule, and it is easy to file it as advice. The sentence underneath it is the one that changes the temperature. The Commission says that disclosing sensitive personal information “to a third-party AI platform, such as ChatGPT, without appropriate safeguards may breach section 6 (b) of the NDIS Code of Conduct, which requires providers to respect the privacy of people with disabilities”.
Section 6(1)(b) of the Code of Conduct Rules says exactly that, in seven words: respect the privacy of people with disability. And the Rules carry a note that the advisory tone hides. Compliance with the Code is a civil penalty provision under section 73V of the NDIS Act, enforceable by an order to pay a pecuniary penalty. The instruction to de-identify is soft. The obligation sitting behind it is not.
Whether the same paste is also a notifiable data breach is a separate question with its own clock, and we work through it in our guide on pasting client data into a chatbot.
De-identified is a defined term here, and that is unusual
This is where Australia parts company with most other countries where English is spoken, and it is the single most useful thing to know before you argue with anyone about a case note.
The Privacy Act defines the word. Section 6(1) says that personal information “is de-identified if the information is no longer about an identifiable individual or an individual who is reasonably identifiable”. That is the whole definition. It is a status, not a technique, and nothing in it mentions names, numbers or black boxes.
Compare that with the picture outside Australia, which our guide to the vocabulary sets out in full: neither UK nor EU data protection law defines the term at all, and the regulators there prefer to avoid it. Here it is in the Act, which means an auditor can hold you to it.
The test is “reasonably identifiable”, and it moves
The OAIC’s guidance on de-identification is blunt about what follows. De-identification is not a property a document acquires and keeps. “The same information may be personal information in one situation, but de-identified information in another.” A licence number tells a motor registry everything and a stranger nothing.
The threshold is stated as risk, not certainty. Information is de-identified where the risk of re-identification “is very low in the relevant release context”, and the regulator calls the whole exercise “a risk management exercise, not an exact science”.
What that buys you when you get there
The payoff is real and it is worth naming, because it is the reason to do the work properly rather than quickly. Information “that has undergone an appropriate and robust de-identification process is not personal information, and is therefore not subject to the Privacy Act 1988 (Cth)”.
Out of the Act means out of the Australian Privacy Principles, out of APP 8, and out of the notifiable data breach scheme for that material. There is no equivalent prize for having tried. Swapping names for labels is one way of trying, and whether a pseudonymised file ever gets there turns on who holds the key.
Turnover does not get you out of this
Plenty of Australian businesses read the Privacy Act, find the threshold of three million dollars, and stop. For an NDIS provider that is usually the wrong stop, and the reason is a single paragraph.
Section 6D(4)(b) says an operator is not a small business operator if it “provides a health service to another individual and holds any health information except in an employee record”. There is no turnover qualifier in that paragraph. It applies to a sole trader with one participant.
Where disability sits inside the definition
The hinge is the definition of health information, and it names disability directly. Health information is “information or an opinion about the health, including an illness, disability or injury, (at any time) of an individual” that is also personal information. Disability is not the only sensitive category a provider holds: its staff files carry others, from union fees to a police check, and the full list of sensitive categories shows where each turns up.
A health service, under section 6FB, is an activity intended or claimed to assess, maintain or improve an individual’s health, or to manage it where it cannot be improved. Large parts of what NDIS providers do land inside that description without anyone intending them to.
| who | covered by the Privacy Act |
|---|---|
| Allied health practice, any size | yes, health service and health information |
| Support coordination holding assessments and diagnoses | yes, on the same two limbs |
| Behaviour support practitioner, sole trader | yes |
| Plan manager handling only invoices and budgets | depends on whether health information is held |
| Provider over three million dollars in turnover | yes, on turnover alone |
The OAIC says it in plain words
You do not have to reason your way there. The regulator’s own list of health service providers includes “a disability service provider (where they handle health information)”, and the page states that an organisation providing a health service and holding health information is covered “even if they’re a small business or providing a health service is not their primary activity”.
If you want the full map of who the Act reaches and which uses it permits, that is the subject of our guide to AI tools under the Privacy Act, and the councils question, which runs on state law instead, is covered in the guide for Australian local government.
What is in a case note before you touch it
Open a real progress note and count what is on it. Most services are surprised, because the identifiers arrive from several different agencies and nobody ever assembled the list in one place.
Here is the Australian set, in the order a tagger meets them. Every one of these has a shape, which makes them the easiest to catch.
| what it is | why it is on the page |
|---|---|
| NDIS participant number | the key to every record you hold |
| Medicare number | copied across from intake |
| Individual healthcare identifier | arrives with allied health correspondence |
| Centrelink customer reference number | plan and payment paperwork |
| Tax file number | staff records, and occasionally participant paperwork in error |
| Ahpra registration number | identifies the practitioner, not the participant |
| Date of birth, address, phone, email | the ordinary four |
Two of those deserve separate treatment before anything else happens to the document.
The one with a criminal offence attached
A healthcare identifier is not governed by the Privacy Act alone. Section 26 of the Healthcare Identifiers Act 2010 makes unauthorised use or disclosure an offence in its own right, and the penalty is set out in the Act itself.
The provision reads: “A person commits an offence if the person contravenes subsection (1) or (2). Penalty: Imprisonment for 2 years or 120 penalty units, or both.” That is a separate regime with separate consequences, and it does not care whether your privacy policy is tidy.
The tax file number is the other one that behaves differently, and the rules that surround it are set out in our Privacy Act guide rather than repeated here.
What to take out, in order
Six of the seven steps below are mechanical. A person can do them with a highlighter, and software can do them faster and more consistently. The seventh is the one that decides whether the first six mattered.
This is a list about what leaves the page. Which categories should not go into a chatbot at all, whatever you do to them first, is a different list, and it is set out in the Privacy Act guide.
- Structured identifiers first. The NDIS number, Medicare, the healthcare identifier, the CRN, the tax file number. These have fixed shapes, they are unambiguous, and there is never an argument about whether they identify someone.
- Names, all of them. Not only the participant. The mother who rang, the support worker on shift, the GP, the behaviour support practitioner, the plan manager’s contact. A note with four other names in it is a note about five people.
- Contact details. Address, phone, email. A street address in a country town is a stronger identifier than a name.
- Organisations that are effectively addresses. The school, the day program, the clinic, the group home. Naming the site narrows the population to a handful.
- Exact dates, where the date is not the point. An incident date plus a service is a lookup key. If the clinical question is the sequence, keep the interval and drop the calendar date.
- Reference numbers you did not think of as identifiers. Plan numbers, incident report numbers, support item codes tied to one participant, internal file references.
- The sentence that identifies without any of the above. This is the step no pattern matching performs, and it is where the work actually is.
Step seven, and why it is a person’s job
A machine matches shapes. Step seven is the realisation that “the third incident since the autism assessment in May, on the run back from school” describes exactly one child in a town of four hundred people, and that every label in the rest of the document changes nothing about that.
The OAIC’s key concepts guidance frames the same point as a question about who is holding the information and what else they can reach: whether someone is reasonably identifiable turns on the nature and amount of information available, who has access to it, and the practicability of identification, including the time and cost involved.
In a metropolitan service with two thousand participants, a diagnosis and a month is noise. In a regional service with forty, it is a name.
What still identifies when the name is gone
The uncomfortable part of the Australian test is that it points at your reader, not at your document. The release context does the work, and a chatbot is a release context with unknown members.
This is also where the sector’s own numbers stop being abstract. In the most recent statistics the OAIC has published, health is the sector that notified most, which is the backdrop against which any new disclosure route gets judged.
In that period the OAIC received 532 notifications. Health led with 18 per cent, finance followed with 14 and Australian Government agencies with 13. Human error accounted for 37 per cent, which the OAIC reports as 193 notifications, and a paste into the wrong window is the purest form of human error there is. Whether a particular one of those crosses into notifiable territory is a judgement with a deadline attached.
The context you cannot see from inside the note
A useful habit is to read the cleaned note as though you were the one person most likely to recognise the participant: a former support worker, a sibling, a neighbour who works at the pharmacy. That reader has context your tagger never had.
If the note survives that reading with nobody identifiable, you are close. If it does not, no further substitution will fix it, because the identifying material is the narrative itself.
Where the Australian framework points next
If you want a structured way through this rather than a habit, the OAIC and CSIRO’s Data61 published a De-Identification Decision-Making Framework in September 2017, and it is still the reference the regulator points to. The OAIC now notes on its own page that the guide may be out of date, which is itself worth knowing before you cite it at an audit.
A progress note before and after
The difference between a mechanical pass and a finished one is easiest to see in a document rather than in a principle. The note below is invented, including the town and the school. Only the shapes are Australian.
BEFORE Participant: Aroha Webster, NDIS 430918227, DOB 14/03/2011.
12 Kurrajong Pl, Wirrabilla NSW. Plan manager: Riverbend.
Picked up from Wirrabilla Central at 3.10pm with Dan.
Distressed when the route changed. Third incident since the
autism assessment in May. Mum rang Dr Halliwell at Nyngara.
AFTER Participant: [PERSON_1], [PERSON_2], DOB [BIRTH_DATE_1].
[ADDRESS_1], Wirrabilla NSW. Plan manager: Riverbend.
Picked up from Wirrabilla Central at 3.10pm with Dan.
Distressed when the route changed. Third incident since the
autism assessment in May. Mum rang Dr [PERSON_3] at Nyngara.
STILL one child, one school run, one diagnosis, one month, one
THERE regional town implied by the service that holds the file.
The AFTER is what Nonimo’s engine returned for this note on 22 September 2026, unedited. It covered the participant’s name, the date of birth, the street and the GP’s surname. It got one thing wrong you should know about: the NDIS number, sitting in a list after “Participant:”, was read as part of a name and came out as [PERSON_2]. Covered, but under the wrong label.
It left the plan manager, the school, the support worker and the clinic exactly as they were, because none of them has a shape or a label in front that software can go on. On this note, steps two and four are still yours. The last two lines are step seven, and no tagger produces them.
The version most people actually send
The common failure is doing step one and feeling finished, because something visibly changed on the screen.
ONLY THE Aroha Webster, NDIS [REFERENCE_1], DOB 14/03/2011.
NUMBERS 12 Kurrajong Pl, Wirrabilla NSW. Third incident
since the autism assessment in May.
FULL PASS [PERSON_1], NDIS [REFERENCE_1], DOB [DATE_1].
[ADDRESS_1]. Third incident since the autism
assessment in May.
The first version still carries a name, a street, a town and a date of birth. It is the one that feels safe, and it is the one that gives away everything the participant number never did on its own. The same failure on an ordinary employment file, with the overseas definitions alongside it, is worked through in our vocabulary guide.
De-identified, masked or pseudonymised: which one you did
Three words, three different claims, and only one of them is the claim the NDIS Commission asked for. Using the wrong one in a policy document is the kind of error that reads as carelessness to a regulator and as a misrepresentation to a lawyer.
| what you did | what it means | where the note ends up |
|---|---|---|
| Masked | characters hidden inside a value you keep | still personal information |
| Pseudonymised | labels swapped in, correspondence kept somewhere | still personal information |
| De-identified | no longer about a reasonably identifiable individual | outside the Privacy Act |
The distinction is not academic. If the link back exists anywhere, including in your own encrypted key file, the material is still personal information and the Act still applies to it. The full treatment of the three terms, with the overseas definitions alongside, is in our vocabulary guide.
The claim to avoid making about your own service
There is a sentence that shows up in AI policies across the sector and it is the one to strike: that because names and numbers are removed, the service is compliant. The OAIC’s AI guidance says the opposite in passing, noting that personal information “may be at risk of re-identification even when de-identified or anonymised”.
Say what you did. Do not say what it achieved.
Where taking things out stops being the answer
Cleaning the document answers one question. It does not answer the other two, and conflating them is how services end up confident and exposed at the same time.
The first unanswered question is whether the disclosure was permitted at all. A paste is a use or a disclosure, and APP 6.1 requires that information collected for a primary purpose not be used or disclosed for another purpose without consent or an exception. That analysis, and APP 8 on sending material offshore, is set out in the Privacy Act guide and there is no point repeating it here.
The second is whether the tool holds what you send it. That varies by product and by account type, and the answers are worth checking before the policy is written: what OpenAI keeps and deletes, what Anthropic does by plan, what Google reviews and retains, and which Copilot account you are actually signed into.
Best practice, according to the regulator
The OAIC’s guidance on commercially available AI products puts its recommendation at the level of the input rather than the vendor. As a matter of best practice it “recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools”.
For an NDIS provider that recommendation and the Commission’s expectation point the same way, from two different regulators, sixteen months apart. Registered clinicians on the team will find much the same line drawn in the Ahpra AI guidelines on patient data.
Writing it down so it survives an audit
None of the above helps on the day someone asks unless it exists on paper. The record is the artefact, and it takes an afternoon.
A policy that says "AI tools" governs nothing, because the answer changes between a personal login and a business tenant.
The seven steps above, in your own words, with your own document types named.
If nobody is named, nobody does it.
Which tool, which date, who approved it, what was considered. That is what an auditor asks for.
Behaviour support plans must be developed in consultation with the participant, their family and carers, and that obligation does not move because a machine helped with a draft.
A starting structure, written for a general audience rather than for the NDIS specifically, is in our AI policy template, and the insurance question that follows from all of this is covered in the Australian cyber cover guide.
What our software does here, and what it does not
Nonimo runs on the machine. It replaces identifiers in text before that text goes anywhere, it shows what it changed and why, and the change can be undone. Among the Australian identifiers it recognises as such are the tax file number, the Medicare number, the individual healthcare identifier and the Centrelink reference. The NDIS number is found only by the label in front of it, as an invented provider referral before and after the key shows.
It pseudonymises. The correspondence can be reversed and is kept encrypted on the user’s own computer, which means the output is still personal information in the sense the Act uses. That is a smaller claim than de-identification, and by now it should be clear why the difference matters more here than almost anywhere else.
What it keeps on the computer is set out on Nonimo’s security page, and the licence terms on the licence page.
The judgement stays with the person who knows the participant, and the guides on using AI with client data are there for judging any tool in this category, including ours.
The question to ask before you send it
Not “did I take enough out”. The Australian test is the other one: in the hands of whoever ends up reading this, is the person still reasonably identifiable?
If the answer is yes, or if you are not sure, the note has not been de-identified, whatever the labels on the screen say. It is still a participant’s health information, it is still yours to answer for, and the Code of Conduct still applies to what happens to it next. The next question after that one, which tool and which account, is the subject of the Privacy Act guide.
Sources
Every page below was open in front of us on 21 September 2026.
- NDIS Quality and Safeguards Commission, Position statement: Use of artificial intelligence in the development of behaviour support plans, February 2026. The refusal to endorse or approve, the expectation that all information is appropriately de-identified and that no personal information of participants is disclosed to AI systems, the five listed risks, the passage naming ChatGPT and section 6(b) of the Code of Conduct, and the requirement that behaviour support plans be developed in consultation with the participant, their family, carers, guardian, NDIS providers and support workers.
- National Disability Insurance Scheme (Code of Conduct) Rules 2018, compilation F2024C00048. Section 6(1)(b), respect the privacy of people with disability, and the note at section 5(3) that compliance with the Code is a civil penalty provision under section 73V of the NDIS Act.
- Privacy Act 1988 (Cth), Federal Register of Legislation. The section 6(1) definition of de-identified quoted in full, the definition of health information and its reference to disability, section 6FB on the meaning of health service, section 6D(4)(b) on health service providers and the small business exemption, and Australian Privacy Principles 6.1 and 11.1.
- OAIC, De-identification and the Privacy Act, published 21 March 2018 and flagged by the OAIC as being updated for the Privacy and Other Legislation Amendment Act 2024. That the same information may be personal information in one situation and de-identified in another, the very low risk in the relevant release context formulation, the description of the exercise as risk management rather than an exact science, and the statement that properly de-identified information is not subject to the Act.
- OAIC, What is a health service provider?. The list of examples including a disability service provider where they handle health information, and the statement that coverage applies even if the organisation is a small business or a health service is not its primary activity.
- OAIC, Guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025. The best practice recommendation not to enter personal information, and particularly sensitive information, into publicly available generative AI tools, and the note on re-identification risk.
- OAIC, APP Guidelines chapter B, key concepts. The factors that decide whether an individual is reasonably identifiable, including the nature and amount of information, who has access to it, and the practicability of identification.
- Healthcare Identifiers Act 2010, Compilation No. 21, compilation date 5 December 2025. Section 26 and its penalty of imprisonment for 2 years or 120 penalty units, or both.
- OAIC, latest Notifiable Data Breach statistics for January to June 2025, 4 November 2025. The 532 notifications, health as the leading sector on 18 per cent ahead of finance on 14 and Australian Government agencies on 13, and the human error share given as “37% of all data breaches (193 notifications)”, which is how the OAIC pairs the two figures.
- OAIC and CSIRO Data61, De-Identification Decision-Making Framework, September 2017, with the OAIC’s own note that the guide may now be out of date.
The progress note in this guide is invented. The names, numbers, street and town in it belong to nobody. One publisher here blocks automated requests: the NDIS Commission’s position statement returns no response to a plain fetch from the command line and downloads normally with browser headers, which is how it was read.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Can NDIS providers use ChatGPT for case notes?
Nothing prohibits it. In February 2026 the NDIS Commission said it does not endorse or approve AI tools for behaviour support plans, but that providers may use AI so long as the use is lawful, and that no personal information of participants should be disclosed to AI systems.
What does de-identified mean under the Privacy Act?
Section 6(1) says personal information is de-identified if it is no longer about an identifiable individual or an individual who is reasonably identifiable. It is a defined term in Australia, which is unusual: the UK and Irish regimes do not define it at all.
Is removing the participant's name enough to de-identify a case note?
Usually not. The OAIC treats de-identification as contextual, and says the same information can be personal information in one situation and de-identified in another. A diagnosis, a town, a plan date and a support category can single out one person with no name attached.
Does the small business exemption cover an NDIS provider?
Rarely. Section 6D(4)(b) removes the exemption from anyone who provides a health service and holds health information, whatever the turnover. The OAIC's own list of health service providers names a disability service provider where they handle health information.
Is an NDIS progress note sensitive information?
Generally yes. Health information is a subset of sensitive information, and the Privacy Act's definition of health information expressly covers information or an opinion about the health, including an illness, disability or injury, of an individual.
What happens if a participant's healthcare identifier goes into a chatbot?
It may be an offence. Section 26 of the Healthcare Identifiers Act 2010 makes unauthorised use or disclosure of a healthcare identifier punishable by imprisonment for 2 years or 120 penalty units, or both. That sits outside the Privacy Act and outside the NDIS rules.
Does masking a number make a note anonymous?
No. Masking hides characters in a value you keep, so the record and the link survive. If you or anyone else can restore the link, the result is pseudonymous, which stays personal information and stays your responsibility under the Act.
Do I need consent to put a de-identified note into an AI tool?
If the material is genuinely de-identified it is not personal information, so the Australian Privacy Principles do not apply to it. The difficulty is proving you got there, which the OAIC describes as a risk management exercise rather than an exact science.
Is breaching the NDIS Code of Conduct actually enforceable?
Yes. The Code of Conduct Rules note that compliance is a civil penalty provision under section 73V of the NDIS Act, enforceable by an order to pay a pecuniary penalty. Section 6(1)(b) requires providers to respect the privacy of people with disability.