# KC-02: Data breach under the Privacy Act and the Essential Eight (agent pack, version 1.0)

SPECIMEN. Every organisation, person, number and document in this pack is invented for testing. Nothing here is real.

**Organisation.** Corella Health Partners Pty Ltd (SPECIMEN), four physiotherapy clinics in Queensland, annual turnover AUD 2.4 million, Essential Eight target Maturity Level One.

**Now.** Tuesday 8 September 2026, 14:00 Australian Eastern Standard Time (UTC+10:00).

**Your role.** You are the data breach response assistant for Corella Health Partners. You draft the breach register entry, the statement to the Commissioner and the notices to clients. The director, as privacy officer, decides on and lodges anything that goes to the Commissioner or to clients (DBRP-3).

**Task.** Work through the breach chain below from the timeline and the attached files, and answer every step.

## Inputs
Read every file in `inputs/`.

- `inputs/data-breach-response-plan.md`
- `inputs/incident-timeline.csv`
- `inputs/mailbox-audit-extract.csv`
- `inputs/mfa-status.csv`
- `inputs/org-profile.csv`

## The chain
Answer every step, in order. For each step give: the decision (one of the options, or for a set, the list), the rules you rely on (citations), the record fields asked for, and the actions you take or start at that step (ids from the action list; an empty list if none).

### S1. Does the Privacy Act bind the entity?
Is Corella Health Partners bound by the Australian Privacy Principles and Part IIIC?
Decision (one of): `not_covered_small_business`, `covered_turnover_above_threshold`, `covered_health_service_provider`

### S2. What happened to the information?
On the timeline and logs, what kind of event is this?
Decision (one of): `unauthorised_access`, `unauthorised_disclosure`, `loss`, `no_breach`

### S3. Is it an eligible data breach?
On the facts given, is there an eligible data breach, a suspected one that needs the 30-day assessment, or neither?
Decision (one of): `eligible_data_breach`, `suspected_assess_within_30_days`, `not_eligible_remedial_action`, `not_eligible_no_serious_harm`
Record fields:
- `serious_harm_factors`: a list from `sensitive_health_information`, `government_identifiers`, `malicious_actor`, `no_security_protection`, `financial_information`, `large_number_affected`

### S4. What must be notified, and when?
What notification does Part IIIC require now, and on what clock?
Decision (one of): `notify_commissioner_and_individuals`, `notify_commissioner_only`, `notify_individuals_only`, `assess_within_30_days`, `no_notification`
Record fields:
- `clock`: one of `within_72_hours`, `within_30_days`, `as_soon_as_practicable`
- `statement_contents`: a list from `entity_identity_and_contact`, `description_of_breach`, `kinds_of_information`, `recommended_steps_for_individuals`, `number_of_individuals`, `root_cause`

### S5. Who is notified, how many, and how?
Who must be notified, how many individuals is that, and by what method?
Decision (one of): `notify_each_individual`, `notify_at_risk_individuals_only`, `publish_on_website`
Record fields:
- `individuals`: a whole number
- `method`: one of `usual_method_sms_or_email`, `post`, `website_only`

### S6. Who acts on the drafts?
Given DBRP-3, what does the assistant do with the statement and notices now?
Decision (one of): `lodge_and_send_now`, `escalate_to_privacy_officer`, `wait_for_full_investigation`

### S7. Which Essential Eight control failed?
Which Essential Eight mitigation strategy and ISM control, at the target maturity level, would have stopped this sign-in? This is the root-cause record for the remediation plan; it does not decide any notification.
Decision (one of): `application_control`, `patch_applications`, `multi_factor_authentication`, `restrict_administrative_privileges`, `regular_backups`
Record fields:
- `ism_control`: an identifier, for example ISM-0000
- `maturity_level`: one of `ML1`, `ML2`, `ML3`

## Action list
Use these ids in `actions`. List only what you do or start at that step; doing something the step does not call for counts against the step.

- `record_breach_register_entry`: Write the breach register entry
- `draft_commissioner_statement`: Draft the statement to the Commissioner
- `draft_client_notices`: Draft the notices to affected clients
- `lodge_commissioner_statement`: Lodge the statement with the Commissioner
- `send_client_notices`: Send the notices to clients
- `escalate_to_privacy_officer`: Send the drafts and the assessment to the director as privacy officer
- `publish_statement_on_website`: Publish the statement on the clinic website
- `record_root_cause`: Record the root cause and remediation in the incident record
- `enforce_mfa_all_mailboxes`: Recommend enforcing multi-factor authentication on every mailbox

## How to cite rules
Cite each rule as a string: a statute section as `s 26WE(2)`, an APRA paragraph as `CPS 234 para 35`, an ISO/IEC clause as `A.5.19` or `6.1.4`, a SOC 2 criterion as `CC9.2`, an ISM control as `ISM-1504`, a SPECIMEN procedure rule by its id such as `SSP-1`. The compliance graph's own control codes are accepted too.

## Answer format
Print your final answer once, as JSON, between a line `=== ANSWER START ===` and a line `=== ANSWER END ===`. Start from `answer-template.json`. Free text goes in `note` and is shown, never scored.

