Practice owners: The Partnered Health cyber breach is a warning to test your privacy response now

Healthcare practices hold some of the most sensitive information about Australians. When that information is accessed in a cyber incident, the consequences for patients can extend well beyond simply replacing a password or cancelling a bank card.

On 15 July 2026, Partnered Health announced that personal information, including health information, had been taken from clinics within its national network. Partnered Health first became aware on 23 June 2026 that a malicious actor had accessed some of its data.

The information potentially accessed includes patient names, dates of birth, addresses and contact details, as well as Medicare, private health insurance, Veteran Card and concession card information. For some clinics, medical information and treatment details including consultation notes, referral letters, pathology results, diagnostic results and other treatment information may also have been affected.

Partnered Health has reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner (‘OAIC’) and the police. It has also obtained an interim injunction from the Supreme Court of New South Wales ordering that the accessed data not be used or published.

The investigation is ongoing, and the circumstances surrounding the incident, including Partnered Health’s compliance with its legal obligations, are yet to be determined.

In the meantime, the breach provides an important and timely reminder for practice owners to consider whether their own privacy, cybersecurity and data-breach response systems are equipped to operate effectively in the event of a real incident.

1. What happened in the Partnered Health cyber incident?

Partnered Health has confirmed that personal information was taken from some clinics within its network.

As of 31 July 2026, Partnered Health had identified at least 22 clinics connected with the incident. At five clinics, the organisation is continuing to investigate whether specific personal information was affected. At a further 16 clinics, the incident may also have affected information contained in patients’ healthcare records.

Partnered Health has written to patients from the relevant clinics and established a dedicated support page and contact centre. It has also advised patients to remain alert to suspicious emails, text messages and telephone calls, particularly communications that refer to medical information to appear legitimate.

The incident demonstrates the complexity of responding to a healthcare data breach. A practice may need to secure its systems, engage forensic specialists, establish what information was accessed, determine which patients are affected, assess the risk of serious harm and prepare accurate patient communications, all at the same time.

This is difficult to manage effectively if responsibilities and processes are only being decided after an incident has occurred.

2. Why health information creates a different level of risk

Health information is not ordinary business data.

A password can be changed. A compromised credit card can be cancelled. A person cannot replace their medical history, diagnosis, treatment record or consultation notes.

Health information can reveal highly sensitive details about a patient’s physical and mental health, medications, reproductive health, disability, personal relationships and treatment history. When this information is disclosed alongside identifying details such as a patient’s name, address, date of birth or Medicare number, the potential consequences of a data breach can be significant, including identity misuse, targeted fraud, reputational harm and other forms of personal, financial and serious harm.

The Australian Signals Directorate has warned that healthcare data is valuable to cybercriminals because it can facilitate fraud and identity theft. Its 2024-25 Annual Cyber Threat Report also recorded an increase in malicious cyber activity affecting the healthcare sector.

For practice owners, managing this risk extends beyond the security of IT systems. It required effective governance over how patient information is handled across the practice, including;

  • what information the clinic collects;
  • where that information is stored;
  • who has access to it;
  • which external platforms receive it;
  • how long the information it is retained; and
  • how the practice identifies, responds to and manages suspected unauthorised access or data breaches.

3. What does privacy law require from healthcare practices?

An organisation that provides a health service and holds health information is covered by the Privacy Act 1988 (Cth), even if they are a small business. This means medical and allied health practices must comply with the Australian Privacy Principles (‘APPs’) regardless of whether their annual turnover exceeds $3 million.

Under APP 11, a practice must take reasonable steps to protect the personal information it holds against misuse, interference, loss and unauthorised access, modification or disclosure.

Those reasonable steps include both technical and organisational measures. Depending on the practice, they may include access controls, staff training, internal policies, secure technology, management of third-party providers, physical security and a documented process for responding to data breaches.

The Notifiable Data Breaches (‘NDB’) Scheme also requires regulated entities to notify affected individuals and the OAIC where an eligible data breach is likely to cause serious harm to an individual whose personal information is involved and that risk has not been prevented through remedial action. Relevant harm may be financial, psychological, emotional, physical or reputational.

Where a practice suspects that an eligible data breach may have occurred, it must undertake a reasonable and expeditious assessment. All reasonable steps must be taken to complete that assessment within 30 calendar days, with the OAIC making clear that this period is intended as a maximum timeframe rather than a standard response period.

A practice should have an established assessment process in place before an incident occurs, rather than developing one while systems are disrupted, patient enquiries are being managed and forensic investigations are underway.

Want to talk it through with a lawyer?

Daniela Cecere-Palazzo, Senior Lawyer at You Legal, works with practice owners on privacy, data breach response and risk. Book a time that suits you.

Contact us

4. What practice owners should review now

The purpose of reviewing your systems is not to suggest that every practice will experience a major cyberattack, but to ensure that any suspected breach can be identified, contained and assessed promptly, consistently and without avoidable confusion.

Step 1: Check your Privacy Policy

Your Privacy Policy should describe how your clinic actually collects, stores, uses and discloses personal information.

Many practices are still relying on policies drafted before they introduced cloud-based patient management systems, online bookings, digital intake forms, automated reminders, telehealth platforms, virtual assistants or AI tools.

Warning signs that your Privacy Policy may need updating include:

  • third-party platforms are not identified or addressed;
  • the policy does not reflect current collection methods;
  • staff cannot explain how patients access or correct information;
  • the clinic’s actual safeguards differ from those described; or
  • the policy has not been reviewed after a system or service change.

A generic policy may describe broad privacy principles, but it will not necessarily explain the information flows and safeguards within your clinic.

Step 2: Confirm who leads the breach response

Your response plan should allocate responsibility before an incident occurs.

Practice owners should know:

  • who receives an initial breach report;
  • who has authority to contain the incident;
  • who contacts IT, legal advisers and insurers;
  • who assesses whether the NDB Scheme applies;
  • who communicates with practitioners and staff; and
  • who approves communications to patients and regulators.

The plan should also address what happens if the usual decision-maker is unavailable.

Step 3: Map where patient information is held

Patient information may exist outside the primary clinical record system.

It may also be held in email accounts, online booking systems, pathology portals, payment systems, shared drives, scanned documents, staff devices, messaging platforms, cloud backups and third-party applications.

Without an accurate information map, a practice may struggle to establish the scope of a breach or identify affected patients.

Step 4: Review third-party access

Using an external platform does not remove the practice’s privacy responsibilities.

APP 11 can apply where information is stored by an external provider but remains within the practice’s possession or control. Practice owners should understand what information each provider receives, where it is stored, how access is controlled and what incident notification obligations apply under the provider’s contract.

Step 5: Test the plan with staff

A response plan that has never been tested may fail when it is needed.

A short scenario exercise can reveal whether staff know how to recognise and escalate suspicious activity, preserve evidence, avoid inappropriate communications and continue essential patient services.

The OAIC recommends that health service providers investigate the cause of a breach, develop and test prevention and response processes, strengthen security practices and revise staff training following an incident.

5. A Privacy Policy and breach response plan perform different roles

One of the most common misunderstandings we see is that having a Privacy Policy means the clinic is prepared for a data breach.

The documents serve different purposes.

A Privacy Policy explains to patients how the practice manages personal and sensitive information. It should address what is collected, why it is collected, how it is used or disclosed, how it is protected and how patients can exercise their privacy rights.

A data breach response framework is an internal operational tool. It guides the practice through detection, containment, assessment, escalation, notification, documentation and post-incident review.

A clinic needs both. A Privacy Policy without an operational response plan may provide transparency but little practical direction during an incident. A response plan without an accurate Privacy Policy may be based on an incomplete understanding of how patient information moves through the practice.

Why periodic agreement reviews matter

Privacy documents and breach response processes should be reviewed as the practice changes.

New software, additional clinic locations, changing staff responsibilities, outsourced administration, telehealth services and AI-enabled systems can all alter how patient information is collected, accessed and disclosed.

Periodic reviews help practice owners confirm that their documents reflect operational reality, that responsibilities are clearly allocated and that staff understand what to do when a concern is raised. They also provide an opportunity to identify unnecessary data holdings, outdated access permissions and gaps between supplier contracts and the practice’s own procedures.

The Partnered Health incident is still developing. However, it serves as a timely reminder that practices should establish clear systems for protecting patient information and responding to suspected data breaches before an incident arises, rather than developing those processes in response to a suspicious login, patient complaint or cyberattack.

To strengthen or implement both aspects of your privacy framework in place, learn more about You Legal’s Notifiable Data Breach Package + Privacy Policy Bundle, which combines a tailored Privacy Policy with practical assessment processes, manuals, templates, checklists and notification tools to help your medical or allied health practice prepare for and respond to an actual or suspected data breach. Feel free to contact our team here if you have any questions.

This article is general information only and is not legal advice. Every practice is different and the law can differ across Australian jurisdictions. Please seek advice tailored to your circumstances before acting.

Sarah Bartholomeusz