Partnered Health Breach: Why Stolen Health Data Isn't Like Stolen Card Details

17.07.26 13:05 - By Shaun Barnett

If you're a patient at one of 21 Partnered Health clinics across Australia, your medical history may now be in the hands of criminals. Not just your name and address — your consultation notes, your referral letters, your pathology results.

That distinction matters more than most breach coverage will tell you.

What happened


Partnered Health became aware on 23 June 2026 that a malicious actor had accessed its data. The company disclosed the incident publicly on 15 July — 22 days later. Patients began receiving SMS notifications the same week.

Partnered Health operates more than 60 medical centres nationally, including skin cancer, allied health and mental health clinics, with services reaching over five million people. The company is owned by private equity firm Quadrant, and health insurer Bupa announced its intention to acquire the business in June — five days before the breach was detected.

Twenty-one clinics are confirmed affected across New South Wales, Victoria, Queensland, Western Australia and the ACT. The extent of the breach is still being determined at a further five clinics.

Partnered Health has reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement. It has also obtained an interim injunction from the Supreme Court of New South Wales ordering that the accessed data not be used or published.

What was taken

According to Partnered Health's own disclosure, the affected information may include:

  • Name, date of birth, address and contact details
  • Medicare number, and where applicable private health insurance, Veteran Card (DVA) or concession card numbers
  • Medical information and treatment details — including consultation notes, referral letters, and pathology or diagnostic results

That third category is the one to sit with.

Why health data is different

When your credit card is stolen, you cancel it. The bank issues a new number. The harm has an expiry date.

Your medical history has no expiry date. You cannot reissue a diagnosis. You cannot cancel the fact that you attended a mental health appointment in 2023, or that a pathology result came back a particular way, or that your GP wrote a referral to a specialist you'd rather your employer didn't know about.

This creates three distinct risks that ordinary identity theft doesn't.

1. Scams that know things about you

Most phishing works on volume — a generic message hoping to catch someone. Health data enables the opposite: a message that names your clinic, references your last visit, and mentions a condition you actually have.

That's not a scam you spot because the grammar is off. That's a scam that sounds like your doctor's office, because the person writing it has read your file.

Expect calls and texts referencing test results, follow-up appointments, Medicare rebates, or specialist referrals. Expect them to be convincing.

2. Extortion, not just fraud

Financial data gets sold. Health data gets used as leverage. A criminal holding your mental health notes, your sexual health results, or a diagnosis you haven't told your family about has something that money can't easily replace: the ability to threaten you with disclosure.

The Supreme Court injunction Partnered Health obtained is designed to prevent publication. An injunction binds parties who can be identified and reached by an Australian court. It offers no practical constraint on an anonymous actor operating offshore. It's a meaningful legal step, but it is not a technical guarantee that your data stays private.

3. Medicare and identity stacking

Medicare, DVA and private health insurance numbers combined with a real medical history is a full identity kit. It supports fraudulent claims, account takeover at other health providers, and identity applications where health records serve as supporting documentation.

Criminals blend real details with fabricated ones to appear credible. The real details are what get past your guard.

What to do now


  • If you received an SMS or email from Partnered Health, your data was likely involved. Read the notification. Don't click links inside it — go to partneredhealth.com.au directly and find their support page yourself.
  • If you attended an affected clinic but haven't been contacted, stay alert anyway. Five clinics are still under investigation and the list could grow.
  • Verify every health-related contact independently. If someone calls or texts about your health — results, appointments, rebates, referrals — end the contact. Do not continue the conversation. Then call your clinic on a number you already have, not one from the message.
  • Assume the caller knows things. Under normal circumstances, someone knowing your details is a signal they're legitimate. Right now, for these clinics, it is not. That's the specific inversion this breach creates, and it's what makes it dangerous.
  • Watch your Medicare and health fund statements for claims you didn't make. Report anything unexpected to Services Australia and your insurer.
  • Enable multi-factor authentication on your MyGov, health fund, and email accounts. Email is the recovery path for everything else.
  • Consider whether you're being targeted personally. If contact escalates from generic to specific — someone referencing a particular condition, or threatening disclosure — that's extortion, not fraud, and it's a different response pathway.


The affected clinics

Partnered Health has confirmed the following practices as impacted:

Blackburn Road Medical Centre · Broadway General Practice · Bundall Medical Centre · Cardiff Medical Centre & Skin Cancer Clinic · Castle Hill Family Doctors · Champion Drive Medical Centre · Chancellor Park Family Medical Practice · Dromana Family Doctors · Dural Medical Centre · Joondalup City Medical Group · Kealba Family Practice · Mornington Family Doctors · Noosaville Seven Day Medical Centre · North Canberra Family Practice · Park Beach Family Practice · Park Orchards Family Practice · Rockingham City Family Practice · Sans Souci Medical Practice · Templestowe District Medical Centre · Wentworth Avenue Family Practice · Wyong Family Practice

The bigger pattern


Australia's health sector has become a priority target. The OAIC recorded 1,205 notifiable data breaches in 2025 — the highest since the scheme began. Health providers hold the richest possible data on the most people, often on systems built for clinical care rather than adversarial defence.

Partnered Health did several things right: it engaged specialists, contained the incident, notified regulators, and sought an injunction. What it also did was take 22 days to tell patients — 22 days in which affected people had no reason to treat an unexpected call from "their clinic" with suspicion.

That gap between a breach happening and an ordinary person knowing what to do about it is the entire problem SelfCybr exists to close.

---

If you've been caught up in this breach and you're not sure what to do next, SelfCybr helps individuals and families work through exactly this — in plain language, with Australian data residency and real human support. [Find out more]

*If you're receiving threats about disclosure of your health information, IDCARE (1800 595 160) provides free identity and cyber support to Australians.*


Shaun Barnett

Shaun Barnett