Partnered Health, one of Australia’s largest healthcare groups, has confirmed a data breach affecting patient medical records across 21 clinics in NSW, Victoria, Queensland, Canberra, and Western Australia.
The company said it became aware of a malicious actor accessing its data on June 23, and investigations confirmed that personal and health information was taken from clinics in its network. Affected data includes names, dates of birth, Medicare numbers, consultation notes, referral letters, and pathology or diagnostic results.
Partnered Health has reported the incident to law enforcement, the Office of the Australian Information Commissioner, and the Australian Cyber Security Centre. It has also obtained an interim injunction from the Supreme Court of New South Wales to block the use or publication of the stolen data.
However, cybersecurity experts questioned the effectiveness of the injunction, noting that threat actors operating offshore are unlikely to be deterred by Australian court orders. “An injunction is absolutely not going to stop these criminals sharing or weaponising this data,” said Jamieson O’Reilly, founder of Dvuln.
The company is communicating with affected patients and has arranged additional monitoring on impacted Medicare cards through Services Australia. No ransom demands have been confirmed, and no stolen data has been located on the dark web at this time.
