Patient records exposed as GP network breach reaches dark web

Healthcare sector already leads Australia’s breach notifications – now brokers have a live example

Patient records exposed as GP network breach reaches dark web

Cyber

By Roxanne Libatique

On June 23, 2026, Partnered Health, an Australian primary healthcare provider operating a national network of general practice and skin cancer clinics, disclosed that a malicious actor had accessed data from its systems. By July 31, 2026, the organisation confirmed the attacker had published 11 files on a part of the internet inaccessible through standard browsers.

Personal information potentially accessed includes names, dates of birth, addresses, Medicare numbers, private health insurance membership numbers, Department of Veterans’ Affairs (DVA) card numbers, and detailed medical records – consultation notes, referral letters, and pathology results among them. “Available evidence indicates this publication by the malicious actor relates to the recent incident that impacted some parts of our network,” the company stated, adding that it is “urgently reviewing the material to assess its authenticity” and that “statements made by malicious actors following a cyber incident should not be assumed to be accurate.”

Partnered Health has notified the Australian Cyber Security Centre (ACSC), the Office of the Australian Information Commissioner (OAIC), and law enforcement and obtained an interim injunction from the Supreme Court of New South Wales ordering that the data are not used or published.

The sector context

The Partnered Health incident is consistent with a documented national pattern. Health service providers were the most commonly affected sector under the Notifiable Data Breaches (NDB) scheme in 2025, accounting for 19% of 1,205 total notifications – the highest annual figure since the scheme commenced in 2018. Australian Privacy Commissioner Carly Kind described the trend as a risk that is “substantial and rising year on year.”

The financial cost of incidents is rising sharply. The Australian Signals Directorate’s (ASD) Annual Cyber Threat Report 2024-25 found that the average self-reported cost of a cybercrime incident for medium-sized businesses rose 55% year on year to $97,200, while small businesses reported a 14% increase to an average of $56,600. These figures reflect self-reported costs to businesses and exclude downstream regulatory and legal exposure.

The Partnered Health structure illustrates a compounding risk specific to networked healthcare groups: a single compromise across a multi-site operation multiplies notification obligations and regulatory exposure simultaneously, in a way that a standalone clinic does not.

A changed regulatory environment

Three regulatory developments since late 2024 have materially altered the liability exposure of healthcare entities. First, the Privacy and Other Legislation Amendment Act 2024 received Royal Assent on December 10, 2024, introducing tiered civil penalties. A non-serious interference with privacy now carries a penalty of up to $3.3 million for companies, which the OAIC can pursue directly through the Federal Court – removing the previous requirement to demonstrate that a breach was serious or repeated.

Second, a Statutory Tort of Privacy commenced in June 2025, giving individuals a direct cause of action where a privacy breach involves deliberate or reckless conduct. Available remedies include compensatory damages including for emotional harm, injunctions, and orders for data destruction. Gallagher has noted that cyber policy treatment of emotional distress and non-financial loss varies materially between insurers, making policy wording review essential for clients with significant health data exposure.

Third, the Medibank proceedings – arising from its 2022 breach affecting 9.7 million customers – continue to advance. In March 2026, Medibank was refused leave to appeal a ruling requiring production of post-incident Deloitte reports to class action applicants. A joint initial trial of the consumer class action and the OAIC’s civil penalty case has been flagged by the Federal Court. When findings emerge, they are expected to set precedent for how Australian courts assess negligence in large-scale health data breaches.

The protection gap

Lower premiums have not produced greater uptake. EBM Insurance & Risk’s May 2026 Insurance Market Trends and Outlook report identified a widening gap between favourable insurance conditions and the actual cost of cyber incidents. Cyber gross written premium in Australia stood at $32 million in the March 2026 quarter – less than 0.2% of total industry premium, with just 6,000 risks written.

Healthcare is not sharing in the broader market softness. Gallagher’s 2026 Cyber Insurance Market Outlook identified healthcare as a sector facing single-digit rate increases, describing cyber insurance competition there as “less fierce” given the claims environment. For brokers, the arithmetic is straightforward: healthcare clients face above-market premiums, rising incident costs, and an expanded regulatory liability profile – yet the majority of the potential client base carries no cyber cover at all.

Three policy lines, three observations

For brokers reviewing healthcare client coverage, the Partnered Health incident maps directly onto gaps across three lines.

On cyber, the core questions are whether limits are adequate to cover OAIC notification costs, forensic investigation, regulatory response, and third-party liability now activated by the Privacy Act statutory tort – and whether sub-limits on non-financial loss are fit for purpose given the wording variation Gallagher has flagged across the market.

On professional indemnity (PI), the coverage boundary between PI and cyber for clinically sensitive data remains unsettled in Australian policy wording. Standard professional indemnity policies typically exclude cyber-related losses – either explicitly or because their coverage triggers – such as physical damage, bodily injury, or professional error – do not apply to most cyber incidents. A broker placing PI for a healthcare client without a concurrent standalone cyber policy is leaving a gap that the client is unlikely to identify themselves.

On management liability, directors of healthcare entities now operate under an OAIC with expanded enforcement powers and an active civil penalty agenda. Whether existing D&O or management liability policies adequately cover regulatory investigation costs – and at what sub-limit – warrants explicit review at placement rather than at the point of a claim.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!