Getting your claim processed by a health fund sounds like a straightforward transaction – you see a provider, they bill correctly, the fund pays out. But a growing number of hospitals and clinicians say the reality is far messier, with some health insurers reportedly demanding far more than a simple item-number check when they come knocking for an audit.
The Australian Private Hospitals Association has described some of this conduct as “aggressive,” and its chief executive Brett Heffernan says complaints from members are becoming more frequent. The core issue isn’t that audits happen – everyone accepts insurers need some way to confirm claims are legitimate. It’s the scope of what’s being requested that has raised alarm: not a patient’s notes from a single episode of care, but their entire clinical history.
Why Health Insurers Say Audits Are Necessary
Health insurers argue payment audits are simply part of responsible stewardship of members’ premiums. Industry figures suggest health funds manage tens of billions of dollars in healthcare payments each year, and with that scale come an obligation to ensure money is going toward genuine, correctly billed care. Bupa health insurance is among the providers facing scrutiny over how far its checks reach. Officials from the sector say the vast majority of claims are legitimate, but audits occasionally uncover fraud, billing errors or inappropriate claiming, sometimes involving significant sums.
Under standard agreements, health insurers are entitled to request a patient’s notes relating to a specific treatment episode, purely to confirm the right procedure was billed at the right rate. That narrower kind of audit rarely draws complaint. The trouble, according to hospitals and allied health providers, starts when insurers push past that boundary and ask for everything.
A Physiotherapist’s Experience with Bupa
One physiotherapist described being audited twice by his health fund, and said the insurer asked for the complete clinical history of every customer holding a Bupa health insurance policy he treated – not just the sessions relevant to a specific claim. When he wrote to patients seeking permission to release their files, roughly two-thirds declined. He says he was told the insurer wanted the material anyway, regardless of consent, and that providing it was a condition of remaining a preferred provider under his existing agreement.
Caught between his professional regulator, which warned he couldn’t release records without patient consent, and the insurer’s threat to claw back hundreds of thousands of dollars in benefits, he eventually took the matter to the Commonwealth Ombudsman before it was resolved. A Bupa spokesperson said its checks are conducted fairly and proportionately, and that the company remains committed to protecting customer privacy while working constructively with providers.
Dentists, like allied health providers before them, have reported similar pressure. The Independent Dentist Network’s managing director recounted a case involving a WA dentist accused of submitting a million dollars in questionable claims, later negotiated down to $500,000 after auditors – described as practice managers rather than qualified dentists – were sent to review complex patient histories. Separately, the same health fund fought and lost a Federal Court case against a Sydney ophthalmologist after a court found no genuine specialist expertise had informed the audit findings against him.
The Legal Grey Area around Medical Records
A University of Sydney Law School researcher who has studied the industry argues that releasing medical records without a patient’s explicit consent is unlawful, regardless of what’s written into an insurance contract. Patient confidentiality, she notes, is a serious obligation placed on every healthcare provider, and a contract clause can’t simply override that legal protection.
Heffernan, from The Australian Private Hospitals Association, agrees the practice sits on shaky legal ground. Hospitals, he says, are increasingly being asked for entire clinical histories rather than material tied to a specific claim, something he insists isn’t appropriate. Insurers are only permitted to view hospital records with a staff chaperone present, and hospitals argue the process itself now adds real cost and administrative burden, simply to facilitate access they believe shouldn’t be granted so broadly in the first place.
Private Healthcare Australia’s chief executive maintains the intent behind these checks isn’t to dodge legitimate claims but to protect the broader system – pointing out that inappropriate claiming ultimately pushes premiums higher for everyone. Health insurers estimate a small but costly percentage of claims are over-billed annually, running into hundreds of millions of dollars. Officials say privacy safeguards, including secure transmission and strict document destruction protocols, remain central to how audits are meant to be conducted, and that random or targeted audits regularly confirm most billing is correct.
