Most practice owners know there is a number attached to an AHPRA advertising breach. Very few have checked what it is, and almost nobody has checked how it is counted.
That second part is where the real cost sits. The maximum penalty for unlawful advertising of a regulated health service is $60,000 for an individual and $120,000 for a body corporate, and both are per offence. Not per website. Not per investigation. Per offence.
We watched this land in real time while recording an episode of AI Your Practice with Anthony Middlemiss, our co founder at Trilbii AI. He assumed the penalty attached to the website. It does not, and the difference between those two assumptions is the difference between a manageable risk and an existential one.
The number is not the problem. The arithmetic is
A practice owner imagining a single fine is doing the sums on one event. One website, one penalty, one bad week.
That is not how a breach investigation works. When AHPRA looks at a practice, it does not look at the page that prompted the complaint. It looks at the marketing. All of it. The report that comes back is not a finding, it is a list, and we have seen them run page after page after page.
Every item on that list is an offence. The maximum is applied per offence, so a practice with a testimonial problem does not have one testimonial problem. It has one for every page carrying one, every social post, every review widget pulling in patient comments, every piece of print material still in circulation.
Two things follow from that. The first is that the risk scales with how long you have been marketing rather than with how badly you got it wrong once. The second is that the most exposed practices are usually the ones doing the most marketing, which is to say the ones growing fastest.
We should be careful here, because a headline number invites a headline reaction. These are maximums, decided by a court, and most matters never get near one. Many are resolved with a direction to fix the advertising. But the exposure is real, and the way practices currently price it is wrong by an order of magnitude.
Compliance is a build decision, not a checking decision
Anthony spent twenty years running allied health practices before he went back to IT. In between, he built websites for dentists, which meant he spent a lot of time going through other people’s AHPRA breaches and repairing them by hand.
That experience produced the argument we think is the most useful thing in the episode, and it applies well beyond software.
When your code base gets large, it gets harder to get rid of tech debt or retrofit things. So the safest bet, especially in this day and age, is to start with compliance first.
He is describing software, but the same shape holds for a practice. Compliance built into how content gets made is cheap. Compliance applied afterwards, to a website with two hundred pages and six years of social history, is expensive, slow and never quite finished. The window for doing it the cheap way closes as you grow, and it does not reopen.
Most practices are in the second position without having chosen it. Nobody decided to retrofit. The website was built by a general web agency, the social was handed to somebody local, the reviews plugin was installed because it looked good, and none of those people had read the advertising guidelines. The breach was not a decision, it accumulated.
AI has made this faster in both directions
There is a version of this article that would tell you AI is coming for your advertising compliance and you should be worried. We do not want to write that version, because the honest position is more limited.
What we can tell you is what we saw this week: a report from an organisation we trust, saying AHPRA has AI checks running on the clinical side, specifically around cosmetic dentistry. We do not know whether that extends to advertising. Anthony expects it will. That is his expectation, not a statement from the regulator, and we are not going to dress it up as one.
What we are confident about is the other direction. The volume of marketing a practice produces has gone up sharply, because AI made it cheap to produce. More blog posts, more social, more landing pages, more email. Every one of those is a surface, and every surface is countable.
You do not need AHPRA to gain new capabilities for your exposure to have increased. You only need to have published more, which almost everyone has.
The risk in using a general purpose AI writing tool for practice marketing is not that it writes badly. It writes fluently, and fluent breaches are harder to spot than clumsy ones. It has no way of knowing what your profession cannot say, and it will produce a confident, well written testimonial reference without hesitating.
Anthony put the engineering version of this plainly: “We can’t afford hallucinations, where it just makes stuff up because it thinks it’s compliant.” The reason that matters is not the software. It is what he said next. “It’s people’s livelihoods.”
What an investigation actually looks at
If you want to understand your own exposure, stop thinking about your website and start counting surfaces. These are the ones that come up.
- The website, including service pages, the about page, and any page a previous agency built and nobody has opened since.
- Google Business Profile, including the posts feature, which most practices forget is public marketing.
- Every social account, including ones that are dormant. A dormant account is still published.
- Review widgets and embedded testimonials. Patient reviews about clinical care are the most common breach and they are frequently syndicated onto a site automatically.
- Image alt text and file names. Banned terms hide in the back end of a site, and they are trivially searchable.
- Email templates, including automated recalls and reactivation sequences that nobody has read in two years.
- Printed material still in circulation, which does not stop being advertising because it is on paper.
Most practices, working through that list properly, find something. That is not a failure. It is what happens when marketing is produced over years by people who were never told the rules.
What to do this week
Pick one hour and write the list. Not fix anything, just list every surface where your practice appears in public, and put a name next to each one for who wrote what is on it.
Almost every practice we have done this with finds two things. There is at least one surface nobody has looked at in over a year, and there is nobody whose actual job it is to own advertising compliance. Both are fixable, and neither gets fixed while they are invisible.
Then decide who owns it. Not as a task on a list, as a named person. In most practices that is the practice manager, and in most practices nobody has ever said so out loud.
The two questions worth asking any AI tool
If you are using AI to produce marketing, or you are about to buy something that does, ask two questions rather than one.
Where do your compliance rules come from, and when are they applied? There is a difference between a tool that looks up the guidelines and a tool that has them inside it. Only the second one can refuse to produce something.
Does our data train your models, and can another practice see it? These are two different protections. Isolating each practice in its own tenancy stops data leaking sideways. Not sending practice data to the model at all is what keeps it out of a training set. Vendors routinely answer one and let you assume the other.
For what it is worth, the way we built Trilbii AI is that content is checked three times against AHPRA before it is released, which is why generation can take thirty seconds to a minute rather than being instant. We mention it as an example of what a specific answer sounds like, not as a claim about anyone else’s product. Ask any vendor the same questions and see whether the answer has that shape.
Anthony Middlemiss is co founder and Head of Customer Success at Trilbii AI. He ran allied health practices for around twenty years before returning to IT and completing post graduate study in AI and machine learning. The full conversation is on the AI Your Practice podcast.
Sources: AHPRA, Advertising and the law and the Guidelines for advertising a regulated health service.
Frequently asked questions
Up to $60,000 per offence for an individual and up to $120,000 per offence for a body corporate. These are maximums decided by a court.
Per offence. A single investigation can identify many breaches across a website, social accounts and printed material, and each one is counted.
No. It depends entirely on whether the compliance rules are built into the system or looked up afterwards, and on whether the output is checked before it is released.
Because the output is being checked and regenerated until it passes. Instant generation means nothing was rejected.
It depends on the vendor’s architecture. Ask specifically whether practice data is sent to the model at all, rather than whether it is stored securely.
For anything touching patient data in Australia, it should be stored in Australia.
Yes. The advertising provisions of the National Law apply to all regulated health services.
Watch it again
The full conversation is on YouTube: watch it here.
Related reading: how to tell whether an AI writing tool is safe for your practice.

It’s people’s livelihoods.
Anthony Middlemiss, Trilbii AI
From the AI Your Practice podcast with Carolyn S Dean.




