Patients of medical clinics run by Partnered Health Group across Australia are being warned that sensitive personal information may have been accessed in a June 23 cyberattack.
The breach potentially affects more than 20 medical centres including North Canberra Family Practice in the ACT and Joondalup City Medical Group in Western Australia.
Partnered Health says a “malicious actor” infiltrated its systems and the group is still working out exactly what data was exposed.
The company confirms the attack occurred three weeks before it publicly disclosed the incident.
Partnered Health, controlled by private equity group Quadrant since 2000, is currently the subject of a $450 million acquisition by UK-based healthcare giant Bupa.
Regulators and investors are scrutinising data security standards in healthcare, a sector that holds highly sensitive records.
Partnered Health has told patients the stolen information could stretch beyond basic identifiers.
It potentially covers home addresses, phone numbers, Medicare and private health insurance details, consultation notes and referral letters.
Pathology and diagnostic test results may also be among the compromised files, raising particular concern for patients.
Cybersecurity specialists say medical records are especially valuable on the black market because they can be used for identity theft and insurance fraud.
Healthcare operators like Partnered Health typically hold linked datasets, combining contact details with Medicare numbers and detailed clinical histories.
That combination makes any breach more serious than a standard customer database hack.
The incident now forces Partnered Health to work with forensic experts and authorities to trace how the “malicious actor” gained access and whether data has already been exfiltrated or traded.
Bupa’s pending takeover of Partnered Health now faces heightened questions from regulators about how patient data is governed and protected.
Pressure is intensifying on private equity-owned healthcare groups to lift cybersecurity investment, particularly when selling assets to larger hospital and insurance operators.
Patients affected by the breach are weighing up the risks of their information circulating beyond the health system.

