Patients at a private hospital in South Australia are learning that an intruder made off with files taken from its servers, making the facility the newest healthcare provider to disclose a breach after shutting its systems down as a safeguard.
A subset of data from the hospital’s servers had been downloaded, according to Nathan Crettenden, the chief information officer at St Andrew’s Hospital, who said the finding came out of an internal investigation. The environment was isolated, controls were tightened, and forensic specialists were brought in.
Angela McCabe, the chief executive, said the review had moved far enough along that the hospital could reach out to the people affected, something regulators expect, and that guidance on safeguarding their information had been given to them. Two bodies were alerted to the incident: the Australian Cyber Security Centre and the Office of the Australian Information Commissioner.
Private hospitals keep detailed clinical, billing and identity records, and a single theft of that material can leave patients facing fraud risk well after their care has ended. A briefing is expected by the state government, which wants to know among other things whether a criminal element was present, and law enforcement agencies would have to assess the situation, South Australian Premier Peter Malinauskas said.