• 07 3184 7575
  • July 21, 2026
  • 0 Comments

Cyber Security Alert 

One of Australia’s largest healthcare clinic networks, Partnered Health, has disclosed a significant cybersecurity incident affecting multiple medical centres across Australia. 

The organisation reported that a malicious actor gained access to data held by clinics within its network and confirmed that personal and health information was taken from some affected systems (ref: https://partneredhealth.com.au/partnered-health-recent-cyber-incident).  

Partnered Health operates more than 60 medical centres, skin cancer clinics, allied health and mental health practices nationwide. The organisation became aware of the incident on 23 June 2026 and publicly disclosed the breach on 15 July 2026.  

What Information May Have Been Compromised? 

According to Partnered Health’s public notification, the information potentially accessed includes: 

  • Patient names 
  • Dates of birth 
  • Residential addresses 
  • Phone numbers and contact details 
  • Medicare card numbers 
  • Private health insurance information 
  • Veterans’ Affairs (DVA) card details 
  • Concession card information 
  • Consultation notes 
  • Referral letters 
  • Pathology and diagnostic results 
  • Other treatment-related medical records 

This type of information is considered highly sensitive and can be particularly valuable to cybercriminals for identity theft, financial fraud, social engineering and extortion activities.  

Geographic Impact 

Partnered Health has indicated that clinics in New South Wales, Victoria, Queensland, Western Australia and the ACT were affected or remain under investigation. Publicly reported impacted clinics include facilities in Sydney, Melbourne, Canberra, the Gold Coast, Sunshine Coast and other regional locations.  

How Has the Organisation Responded? 

Partnered Health has advised that it: 

  • Engaged specialist cyber incident response experts. 
  • Reported the matter to the Australian Cyber Security Centre (ACSC). 
  • Reported the incident to the Office of the Australian Information Commissioner (OAIC). 
  • Notified law enforcement authorities. 
  • Begun communicating with affected patients. 
  • Obtained an interim injunction from the Supreme Court of New South Wales seeking to prevent the publication or misuse of stolen information. 

Why This Incident Matters 

This breach serves as another reminder that Australian organisations holding sensitive personal information remain attractive targets for cybercriminals. 

Healthcare providers are particularly vulnerable because they store: 

  • Personally identifiable information (PII) 
  • Medicare and insurance information 
  • Clinical and treatment data 
  • Historical records that cannot easily be changed if compromised 

Unlike passwords or payment cards, medical information may retain value for many years and can be used in sophisticated fraud and impersonation schemes.  

Key Takeaways for Businesses 

While this incident occurred within the healthcare sector, the lessons apply to organisations across all industries: 

1. Assume You Are a Target 

Cybercriminals are increasingly targeting organisations of all sizes, not just large enterprises. 

2. Protect Identity Systems 

Implement: 

  • Multi-Factor Authentication (MFA) 
  • Phishing-resistant authentication where possible 
  • Privileged access controls 
  • Regular access reviews 

3. Strengthen Detection Capability 

Ensure you have: 

  • Endpoint Detection and Response (EDR) 
  • Security monitoring and alerting 
  • Centralised log collection 
  • Incident response procedures 

4. Prepare for Data Breach Obligations 

Australian organisations should understand their obligations under: 

  • Cyber Security Act 2024 
  • Privacy Act 1988 
  • Notifiable Data Breaches (NDB) Scheme 
  • Industry-specific compliance requirements 

5. Train Staff Continuously 

Employees remain a primary target for phishing and social engineering attacks. Regular awareness training can significantly reduce risk. 

What Should Organisations Do Now? 

Cyber Safe Business recommends the following immediate actions: 

  • Review MFA coverage across all staff accounts 
  • Verify backups are functioning and recoverable 
  • Ensure all systems are receiving security updates 
  • Confirm EDR or managed detection services are operational 
  • Review incident response plans and contact lists 
  • Conduct phishing awareness training for staff 
  • Evaluate whether sensitive data holdings are appropriately protected 

About Cyber Safe Business 

Cyber Safe Business helps Barristers, Australian law firms, accounting practices, medical clinics and professional services organisations reduce cyber risk through managed security, compliance support, security awareness training and strategic cybersecurity advisory services. 

Is Your Cybersecurity Adequate?

The recent Partnered Health breach demonstrates that organisations of all sizes are potential targets for cybercriminals. A successful attack can lead to the loss of sensitive information, operational disruption, regulatory scrutiny and reputational damage. Understanding whether your current security controls are adequate to protect your business is no longer optional. 

Need a Cybersecurity Adequacy Check?

Cyber Safe Business can help determine whether your organisation’s cybersecurity controls, policies, monitoring capabilities and incident response preparedness are adequate for: 

  • Your business risks 
  • Industry obligations and compliance requirements 
  • Client and stakeholder expectations 
  • Today’s evolving cyber threat landscape 

Our Cybersecurity Adequacy Check provides an independent assessment of your current security posture and identifies practical, prioritised improvements to strengthen your resilience against cyber threats. 

Contact Cyber Safe Business to arrange a Cybersecurity Adequacy Check and gain confidence that your organisation is appropriately protected. 

Ph. 07 3184 7575 | Web: https://cybersafebusiness.au/contact-us/ 

Previous Post
AI Voice Cloning Is Fueling a New Wave of Scam Calls in Australia