Skip to main content
Rules Mate

Do private health insurers need to comply with APRA CPS 234 (Information Security)?

A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.

Short answer: Yes

Yes. This obligation applies to private health insurers whatever their structure or size. The deciding fact: Private health insurer — APRA-regulated.

The obligation in brief

Comply with APRA CPS 234 (Information Security). CPS 234 requires APRA-regulated entities (ADIs, insurers, RSE licensees) to clearly define information security-related roles, maintain capability, implement controls commensurate with vulnerabilities and threats, and notify APRA within 72 hours of a material information security incident.

Trigger: Being APRA-regulated.

Why private health insurers get a different answer

Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 32 of those industries the answer for "Comply with APRA CPS 234 (Information Security)" is no. Private health insurers is one of the 3 where the answer is different: yes.

The deciding fact for private health insurers: Private health insurer — APRA-regulated.

About the industry: Insurers regulated by APRA under the Private Health Insurance Act.

Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires APRA regulation).

Answer by business structure and size

Each cell is the engine's outcome for a business in private health insurers with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.

"Comply with APRA CPS 234 (Information Security)": outcome for private health insurers by structure and size
StructureNo employees1–5 employees6–19 employees20–99 employees100–499 employees500+ employees
Sole traderYesYesYesYesYesYes
PartnershipYesYesYesYesYesYes
TrustYesYesYesYesYesYes
Pty Ltd companyYesYesYesYesYesYes
Public companyYesYesYesYesYesYes
Not-for-profit (unregistered)YesYesYesYesYesYes
Registered charityYesYesYesYesYesYes
Super fundYesYesYesYesYesYes
Foreign companyYesYesYesYesYesYes

What the obligation requires

When due
Continuous; APRA notification within 72 hours of a material incident.
Evidence to keep
Information security policy, control testing, internal audit reports, incident notifications.
Maximum penalty
APRA enforcement actions including additional capital, licence conditions, directions
Regulator
APRA
Jurisdiction
Commonwealth (national)

Other obligations where private health insurers differ from the norm

Other industries with a non-default answer

Questions

Do private health insurers need to comply with APRA CPS 234 (Information Security)?
Yes. This obligation applies to private health insurers whatever their structure or size. The deciding fact: Private health insurer — APRA-regulated.
Is the answer the same for every industry?
No. For 32 of the 35 industries Rules Mate maps, the answer is no. Private health insurers is one of 3 industries with a different answer.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.