A cyber-attack on Australian healthcare provider Partnered Health has resulted in the theft of thousands of medical records and patient information. The breach, which occurred on June 23, affected 21 clinics across several cities, including Sydney, Melbourne, and Canberra. According to Partnered Health, a malicious actor accessed the data, prompting the company to report the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and law enforcement.
The healthcare provider apologized for the concern and inconvenience caused to its patients, stating that it takes the trust placed in it to protect personal and medical information seriously. The stolen personal information includes names, dates of birth, addresses, and contact details, as well as Medicare, private health insurance, and concession card details. Medical information and treatment details, including consultation notes, referral letters, and pathology or diagnostic results recorded by a GP, were also breached.
Partnered Health has sought an interim injunction from the supreme court of NSW ordering that the accessed data not be used or published. The incident is the latest in a series of high-profile cyber-attacks on Australian businesses. Bupa announced in June that it was acquiring Partnered Health, which has more than 60 medical centres nationwide and services reaching over 5 million people.
Data breach notifications to the Office of the Australian Information Commissioner reached a record high in 2025, with major incidents including a cyber-attack on Qantas that compromised the details of 5.7 million customers. The Office of the Australian Information Commissioner reported receiving 1,205 data breach notifications in the 2025 calendar year, representing an 8% increase from 2024.



