Experts believe the Australian healthcare provider targeted in a major cyberattack should have been better prepared.
Partnered Health revealed on Wednesday night that 21 clinics across five states and territories had been affected by the breach on June 23, blaming a “malicious actor”.

Partnered Health revealed on Wednesday night revealed 21 clinics across five states and territories had been affected by the breach on June 23. 9News
The company said the stolen information could include name, date of birth, address and contact details, Medicare and other healthcare card numbers and personal medical information and treatment details.
The third category could include consultation notes, referral letters, and pathology or diagnostic results.
Andrew Philp, field chief information security officer, A/NZ of security firm TrendAI, said organisations needed to proactively prepare for these scenarios.
“I think it can be a real challenge,” Philp said.
“I think one of the things organisations need to do is practise this as if we know it’s going to happen, so that when something does happen, we know exactly what we need to do, we know who we need to notify, it becomes like a fire drill.
“We really need organisations, particularly if they are holding data like this, to take it seriously and be ready for something like to happen to mitigate those consequences.”
Nine tech expert Trevor Long said patients could potentially fall victims to scammers in these scenarios.
“Far more than just names and addresses, even medicare numbers, the actual treatments you received may be in the hands of hackers,” he said.
“They will begin selling data and that means in the hands of scammers.”
RMIT University Centre for Cybersecurity Research and Innovation Professor Matthew Warren said smaller health care operators were often at risk due to the sensitive personal information they hold.
“But they may not have the cyber capabilities to protect against cyberattacks,” Warren said.

The company said the stolen information could include personal details and medical information. 9News
“Attackers are keen to obtain personally identifiable information such as people’s personal details or Medicare care details that they can use in subsequent scams.
“The key concern is that patients’ medical information and treatment details could have been taken in the hack, which is a real concern, especially if all the hacked information ends up on the dark net.”
Partnered Health apologised to patients in a statement on its website on Wednesday night.
“As a health services provider, we know our patients and our people trust us with personal and medical information and we sincerely apologise for any concern and inconvenience this may cause them,” the statement said.
“Partnered Health has reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement, and we are continuing to work with the authorities.”
The potentially affected practices are:
Blackburn Road Medical CentreBroadway General PracticeBundall Medical CentreCardiff Medical Centre & Skin Cancer ClinicCastle Hill Family DoctorsChampion Drive Medical CentreChancellor Park Family Medical PracticeDromana Family DoctorsDural Medical CentreJoondalup City Medical GroupKealba Family PracticeMornington Family DoctorsNoosaville Seven Day Medical CentreNorth Canberra Family PracticePark Beach Family PracticePark Orchards Family PracticeRockingham City Family PracticeSans Souci Medical PracticeTemplestowe District Medical CentreWentworth Avenue Family PracticeWyong Family Practice