Menu
Browse

Cyber Incident Victim: Ochre Health Wollongong

Date:

Jul 2018

Location:

Australia

Summary

A cyber incident at Ochre Health Wollongong disrupted access to patient medical records for general practitioners over a two-week period, leaving the issue unresolved at the time of reporting. Patients expressed concerns that their sensitive health information might have been compromised, lost, or illegally accessed due to the hacking incident, despite the organization's spokesperson attempting to alleviate fears about potential breaches. The prolonged system inaccessibility caused significant unease among affected individuals regarding the security and integrity of their personal data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 3 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

A cyber incident at Ochre Health Wollongong medical center disrupted operations for at least two weeks beginning on or around July 6, 2018. The attack prevented general practitioners from accessing patient medical records, severely impacting clinical workflows and service delivery. Patients expressed concerns that their sensitive health information might have been permanently lost or illegally accessed by unauthorized parties due to the breach. The medical center acknowledged the incident publicly but provided limited technical details about the nature of the compromise or the specific systems affected. A spokesperson for Ochre Health attempted to reassure patients about their data security, though these assurances failed to fully alleviate patient anxieties regarding potential privacy violations.

Cyber Incident Image

As of July 20, 2018 – fourteen days after the initial disruption – the incident remained unresolved, with medical staff still unable to retrieve patient records through normal systems. The prolonged outage suggested significant infrastructure compromise or data integrity issues requiring extensive recovery efforts. No evidence emerged publicly confirming whether patient data was exfiltrated or merely rendered inaccessible through encryption or system corruption. The incident generated substantial patient distress, with individuals reporting feeling "rattled" by both the potential privacy implications and the operational impacts on their healthcare services. Ochre Health maintained public communications through spokesperson statements but did not disclose remediation timelines, forensic findings, or specific containment measures undertaken during the two-week outage period.

Sources
Sources available to members
1 source