Primary care provider Partnered Health took 22 days to let its patients and authorities know that personal details and medical information of thousands of patients had been stolen.
The company – which operates more than 60 primary care clinics and skin cancer clinics around the country – said it became aware of the attack on 23 June, but it released a statement and advice to patients just yesterday.
Deakin University lecturer in cybersecurity, Dr Fariha Tasmin Jaigirdar, said the 22-day delay in telling patients about the cyber attack was “not acceptable” and said patients had a right to know when their health data was compromised.
Dr Jaigirdar said as individuals often built passwords and usernames from names, birth dates and addresses, it was possible they had the same usernames and passwords for other systems.
“Every day of silence, therefore, is a token of help to attackers working through exactly those combinations,” she said.
“Patients needed to know immediately so they could take extra caution with their data.
“From a company that claims to be Australia’s most trusted provider of primary healthcare, that delay undermines the very trust it trades on.”
The attack was on 21 Partnered Health clinics in NSW, Victoria, Queensland, Western Australian and the ACT, with experts warning that the breach could have long-term consequences for patients.
Partnered Health said it was continuing to work with authorities and had reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement.
In a statement, the company apologised to patients and said it had obtained an interim injunction from the NSW Supreme Court to prevent the accessed data being used or published.
In a statement to patients, Partnered Health said the company took immediate steps to contain the incident and engaged specialist cyber experts for advice.
“This investigation remains ongoing. Our investigations to date have confirmed that personal information (including health information) was taken from some of the clinics in our network.
“We are continuing to investigate and we are communicating with patients from impacted clinics.”
Partnered Health said the incident “may have affected personal information patients have provided to us, or which was collected while providing patients with healthcare services”.
That includes personal patient information such as names, dates of birth, addresses, contact details, Medicare number, private health insurance details, veteran card numbers and concession card numbers, the company said.
Medical information and treatment details were also included in the data breach, such as consultation notes, referral letters, and pathology or diagnostic results recorded by GPs or other clinicians at the clinics.
Patients were texted yesterday about “a recent cyber incident”, with a link to the website for more information.

Source: provided
A spokesperson for the Office of the Australian Information Commissioner (OAIC) confirmed it had been contacted by Partnered Health about the incident.
“Generally, organisations covered by the Privacy Act have 30 days to assess whether a data breach is likely to result in serious harm and to notify the OAIC under the Notifiable Data Breaches scheme,” the spokesman told The Medical Republic.
“Health data is one of the most sensitive types of data under the Privacy Act.
“Cyber hacking remains the primary cause of data breaches reported to the OAIC.”
The spokesperson said 1205 data breaches were notified last year, and most (716) were attributable to malicious or criminal activity. Health service providers were the most commonly affected, accounting for 19% of notifications.
Last month, private health insurer Bupa Australia announced that it had agreed to acquire the Partnered Health Group. The acquisition remains subject to regulatory approval, with settlement expected later this year.
Bupa Australia said that it was recently advised by Partnered Health of a cyber security incident impacting some of Partnered Health’s internal systems.
“Partnered Health is not yet owned nor managed by Bupa Australia, and there has been no integration of our systems given the transaction has not been finalised,” Bupa said.
“No customer or employee data held by Bupa Australia is impacted nor at risk as a result of this incident and there is no action Bupa Australia customers need to take at this time.
“If a Bupa Australia customer is also a patient of Partnered Health and has been impacted, they will be contacted directly by Partnered Health.
“Protecting our customers’ privacy remains our priority through this acquisition and Partnered Health is continuing to provide Bupa with regular updates about this incident.”
The breach is a wake-up call for healthcare organisations who need to give cybersecurity the same attention as patient safety and clinical quality, experts say.
Field chief information security officer at cybersecurity firm TrendAI ANZ, Andrew Philp, said patient data was a lucrative target for cybercriminals.
“Unlike a credit card, a patient’s diagnoses, treatment history or biometric data cannot simply be cancelled and reissued, which makes healthcare organisations uniquely attractive to ransomware groups and data brokers,” he said.
“A single breach can create long-term consequences for individuals, healthcare providers and the wider health ecosystem.
“It’s also prime currency within the broader underground economy, fuelling criminal activity and creating a ripple-effect across industry and government.
“As a result, we’re seeing a growing ‘industrialisation’ of cybercrime targeting healthcare, with underground marketplaces offering everything from hospital network login details to insurance data and even fake medical documentation.
“Initial access brokers, ransomware affiliates, credential sellers and fraud specialists all work together as part of an interconnected supply chain designed to monetise patient data repeatedly and at scale.”
Professor of computer science at Murdoch University and a fellow at the Australasian Institute of Digital Health, Professor David Parry, said the fact that the attack has been discovered “probably means this is at the lower end of the sophistication scale”.
“Given that the reports say that it appears to be multiple systems at different times, this looks like an attack where the attackers discovered a known vulnerability or ‘got lucky’ with some sort of phishing or other social engineering attack, rather than a targeted attack,” Professor Parry said.
“The data is not being withheld from the owners and denied to the health provider. This has happened in health systems before (ransom attacks), which is even more disruptive and dangerous. Alteration of data is relatively difficult to do, and this doesn’t seem to have happened.”
Professor Parry said smaller healthcare providers did not have large security teams.
“It would be very helpful if the government, health organisations and professional bodies got together to not only produce guidelines for safe working but establish practical methods for audit and securing of health systems – this is a patient safety issue.”
RMIT University centre for cyber security research and innovation director Professor Matthew Warren said smaller healthcare operators were at risk of cyber incidents due to the sensitive personal information they held, but may not have the capabilities to protect against cyber attacks.
“Attackers are keen to obtain personally identifiable information such as people’s personal details or Medicare care details that they can use in subsequent scams.
“The key concern is that patients’ medical information and treatment details could have been taken in the hack, which is a real concern, especially if all the hacked information ends up on the darknet.”
Senior lecturer in cyber security at UNSW, Dr Rahat Masood said there had been similar attacks on healthcare providers in Australia and overseas over recent years.
“Cybersecurity must be treated as a patient safety issue, not just an IT issue,” she said.
“My biggest concern is the long-term impact on affected patients. Unlike passwords, medical records cannot simply be changed.
“Stolen health information can be used for identity fraud, highly targeted phishing scams, and other forms of exploitation for years to come.”
Associate Professor Mihai Lazarescu from the school of electrical engineering, computing and mathematical sciences at Curtin University said incidents like this would become more common if “the same approach to cyber defence is used as in the past”.
“AI and the cloud model will not solve the problem – on the contrary, it will turn it into something that people cannot grasp yet,” he said.
“There is not enough expertise available to effectively defend online organisations, and this will be more clearly seen as time goes by.”
Deputy director of Sydney Health Law at the University of Sydney, Dr Christopher Rudge, said the Office of the Australian Information Commissioner received a record number of data breach notifications last year, with health providers the largest single source.
Dr Rudge said the injunction that Partnered Health sought to prevent use or publication of the data “restrains only further disclosure”.
“It does not undo the theft, nor compensate the patients whose records have been taken,” he said.
“Redress is therefore difficult. The new statutory tort is directed to a serious invasion of the privacy of one individual. It is not for a breach that affects thousands at once.
“A patient whose data is circulated has, in practice, two avenues: a complaint to the privacy regulator, or an action for breach of confidence. Neither is designed to compensate harm on this scale.”
The OAIC said has published a quick reference guide for responding to data breaches to help organisations meet their obligations under the Notifiable Data Breaches scheme. The first two steps involve containing the breach and assessing the risk.
The post Delay in cyber attack notification ‘not acceptable’, says expert appeared first on Medical Republic.







Add Comment