
A massive breach has exposed thousands of medical records and sensitive patient information from a leading healthcare provider, igniting concerns over data protection.
Partnered Health, which operates under the ownership of the private equity powerhouse Quadrant, revealed that a cyberattack compromised 21 clinics across Australia. The affected locations include major cities such as Sydney, Melbourne, and Canberra, with the breach occurring on June 23.
In a statement released Wednesday, the healthcare provider confirmed, “Our investigations have established that personal information, including health data, was exfiltrated from several clinics within our network.”
The statement further added, “As a provider of critical health services, we recognize the enormous trust our patients and employees place in us to safeguard their personal and medical information. We deeply regret any distress and disruption this event may cause them.”
The healthcare organization has identified “a malicious actor” as responsible for the data breach. Consequently, it has reported the incident to several authoritative bodies, including the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and law enforcement agencies.
Personal information stolen included names, dates of birth, addresses and contact details as well as Medicare, private health insurance and concession card details.
Medical information and treatment details, including consultation notes, referral letters, and pathology or diagnostic results recorded by a GP were also breached.
The medical group has sought an interim injunction from the Supreme Court of NSW ordering that the accessed data is not used or published.
Established in 2013, Partnered Health has more than 60 medical centres nationwide as well as skin cancer, allied health and mental health clinics, with its services reaching more than five million people.
Health insurer Bupa announced in June it was acquiring Partnered Health, the latest major business to be struck by hackers.
Data breach notifications to the Office of the Australian Information Commissioner reached a record high in 2025, with major incidents including a cyberattack on Qantas that compromised the details of 5.7 million customers and reportedly leaked on the dark web.
The office said it received 1205 data breach notifications in the 2025 calendar year, representing an eight per cent increase from 2024.