Overview
- Partnered Health detected unauthorised access on June 23, 2026 and publicly disclosed the incident on July 15 after identifying 16 clinics where data was likely taken and flagging five more for investigation.
- The company says stolen material includes names, dates of birth, addresses, Medicare and private insurance details, consultation notes, referral letters and pathology or diagnostic results.
- Partnered Health has reported the breach to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and police and has engaged specialist cyber firms to conduct forensic work.
- The firm obtained an interim injunction from the NSW Supreme Court to bar publication or use of the accessed files, but cyber experts and patients have criticised the more-than-three-week delay between detection and public notification as increasing risk of fraud and misuse.
- Investigations are ongoing, no threat actor has claimed responsibility, and the breach has renewed calls for tougher, faster breach-reporting rules for health providers and for patients to monitor for scams and identity theft.