A major cyber attack has struck one of Australia’s biggest clinic networks, with stolen patient files now raising fears sensitive medical details could be exposed or exploited.
Partnered Health, which operates 57 GP practices and skin cancer clinics nationwide, said hackers accessed and took personal information, including health records, from some clinics in its network after the company became aware of the breach on June 23.
The provider said it had been working with police, the Australian Cyber Security Centre and specialist cyber experts as it tried to determine the full scale of the attack. Some affected patients were contacted late on Tuesday afternoon.
In an incident notice published online, Partnered Health said its investigations had already confirmed data had been taken.
“Our investigations to date have confirmed that personal information, including health information, was taken from some of the clinics in our network,” the company said.
“We are continuing to investigate and we are communicating with patients from impacted clinics.”
The company listed 16 clinics across Melbourne, Sydney, Canberra, the Gold Coast, Sunshine Coast and Coffs Harbour where patient information may have been stolen.
Another five clinics, including some in Western Australia, remained under investigation.
A list of affected clinics can be found here.
The potentially compromised information included names, contact details, addresses, Medicare information, private health insurance details and highly sensitive medical documents such as consultation notes, referral letters and pathology results.
Partnered Health said it had moved to limit the fallout, revealing it had secured urgent court orders in an effort to stop any stolen information from being shared.
“To help protect our patients and people we have obtained an interim injunction from the Supreme Court of New South Wales ordering that the accessed data is not used or published,” it said.
Patients were also warned to be alert to scam emails, texts or phone calls that could reference private medical details to appear legitimate.
The company said it had contacted Services Australia to help enable extra monitoring for anyone whose Medicare information may have been caught up in the breach.