Partnered Health
Incident posture
Linked entities
- Victim
- Partnered Health
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Partnered Health disclosed a data breach affecting 21 of its clinics across Australia, with unauthorized access to personal and medical information. The compromised data included patients’ names, addresses, contact details, Medicare and private health insurance numbers, Veteran Card information, consultation notes, referral letters, and pathology or diagnostic results. The provider reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and police, and obtained an interim injunction preventing the use or publication of the stolen data. Patients were advised to watch for scams that might misuse the exposed information.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 23, 2026, Partnered Health became aware that a malicious actor had accessed its data across its network of general practitioner clinics. The company disclosed the breach on July 16, 2026, informing patients and relevant authorities that 21 practices were affected. The impacted clinics include Blackburn Road Medical Centre, Broadway General Practice, Bundall Medical Centre, Cardiff Medical Centre & Skin Cancer Clinic, Castle Hill Family Doctors, Champion Drive Medical Centre, Chancellor Park Family Medical Practice, Dromana Family Doctors, Dural Medical Centre, Joondalup City Medical Group, Kealba Family Practice, Mornington Family Doctors, Noosaville Seven Day Medical Centre, North Canberra Family Practice, Park Beach Family Practice, Park Orchards Family Practice, Rockingham City Family Practice, Sans Souci Medical Practice, Templestowe District Medical Centre, Wentworth Avenue Family Practice, and Wyong Family Practice. Partnered Health stated that the breach was discovered after detecting unauthorized access to its systems.
The data that may have been taken includes patients' names, addresses, contact details, Medicare numbers, private health insurance information, Veteran Card numbers, consultation notes, referral letters, pathology or diagnostic results, and other treatment information. Partnered Health warned patients to be alert for scams that could misuse the stolen personal data to appear more convincing. In response, the organization reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and state police. Additionally, Partnered Health obtained an interim injunction from the Supreme Court of New South Wales ordering that the accessed data not be used or published.
The company said its investigations are ongoing to determine the full extent of the information impacted and that it is communicating directly with patients from the affected clinics. Partnered Health expressed regret for any concern or inconvenience caused and apologized to patients and staff. At the time of the breach, health insurer Bupa had announced a pending acquisition of Partnered Health for $450 million, subject to approval from the Australian Competition and Consumer Commission and the Foreign Investment Review Board. No further technical details about the attack vector or the volume of data exfiltrated were provided in the statements.
Sources
Sources available to members: 2 sources.