Visualização de leitura

Partnered Health Cyberattack Exposes Patient Data Across Australia

Partnered Health cyberattack

The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. The Partnered Health data breach, involving clinics owned by healthcare provider Partnered Health, a company backed by Quadrant, affected facilities in New South Wales, Victoria, Queensland, Western Australia, and the ACT. The incident has also renewed scrutiny of the growing number of cyberattacks targeting Australia's healthcare sector.

Partnered Health Data Breach Impacted Medical and Personal Information 

Partnered Health confirmed that a malicious actor accessed its systems on 23 June, compromising data from 21 clinics across cities, including Sydney, Melbourne, and Canberra. The healthcare provider disclosed the breach more than three weeks later, informing patients that investigations had confirmed personal and health information had been taken from some clinics within its network. "Our investigations to date have confirmed that personal information (including health information) was taken from some of the clinics in our network," the company said. It added, "As a health services provider, we know our patients and our people trust us with personal and medical information, and we sincerely apologise for any concern and inconvenience this may cause them." The stolen information includes names, dates of birth, addresses, contact details, Medicare information, private health insurance details, concession card information, consultation notes, referral letters, pathology reports, diagnostic results, and other treatment records maintained by general practitioners.

Investigation into the Partnered Health Cyberattack Continues 

Partnered Health said the cyberattack has been reported to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and law enforcement authorities. The company has also secured an interim injunction from the NSW Supreme Court preventing the stolen information from being used or published. While investigations remain ongoing, the provider said the extent of the breach is still being determined at five clinics, including three in Western Australia and two in Victoria. "While there is no direct evidence that patient records have been viewed, as a precaution we have written to patients from these clinics to make them aware of this and provide details of steps that can be taken to protect their information," a Partnered Health spokesperson said. The spokesperson added, "We understand that this sort of news can cause concern. We sincerely apologize for any distress this may have caused our patients."

Quadrant-backed Healthcare Provider Faces Growing Scrutiny 

Established in 2013, Partnered Health operates more than 60 medical centres, along with skin cancer, allied health, and mental health clinics, providing services to more than 5 million people nationwide. The company is owned by Quadrant, while Bupa announced in June that it would acquire the healthcare provider. The Partnered Health data breach comes amid a record year for cybersecurity incidents in Australia. According to the Office of the Australian Information Commissioner, 1,205 data breach notifications were recorded in 2025, marking an 8% increase compared with 2024. Among the year's largest incidents was the cyberattack on Qantas, which compromised the information of 5.7 million customers and was reportedly leaked on the dark web. A spokesperson for the Department of Home Affairs said the federal government is aware of the Partnered Health cyberattack and confirmed that relevant agencies are engaged as investigations continue. Authorities have not yet disclosed how many patients were affected or the full scope of the stolen data.

Ransomware Attack on Dutch Software Vendor Disrupts Hospital Systems

ChipSoft ransomware incident

The ChipSoft ransomware incident has disrupted healthcare operations across multiple institutions after the Dutch software vendor was hit by a cyberattack on April 7. The attack forced hospitals to disconnect critical systems and triggered widespread precautionary actions, highlighting the ongoing risks ransomware poses to the healthcare sector. Z-CERT confirmed it has been working closely with ChipSoft, healthcare institutions, and other stakeholders since the incident was first detected. The organization is actively monitoring the situation while providing support and threat intelligence to affected entities.

ChipSoft Ransomware Incident Forces System Shutdowns

In response to the ransomware incident, the company disabled connections to key platforms, including Zorgportaal, HiX Mobile, and the Zorgplatform, as a precaution. These systems remain temporarily unavailable as ChipSoft works to restore services in phases. Users are being issued new login credentials as part of the recovery process. ChipSoft has maintained direct communication with its customers, outlining steps to manage disruptions while systems are gradually brought back online. According to reports, 11 hospitals disconnected ChipSoft software from their networks following the attack. A confidential advisory also urged customers to cut secure VPN connections after the compromise was identified.

Hospitals Face Operational Challenges, Not Critical Disruptions

The ChipSoft ransomware incident has led to logistical challenges across healthcare institutions rather than critical failures in patient care. Hospitals have increased staffing at service desks, expanded telephony support, and relied more heavily on direct communication channels. Systems were reported unavailable at several hospitals, including Sint Jans Gasthuis, Laurentius Hospital, VieCuri Medical Center, and Flevo Hospital. Despite these disruptions, Z-CERT noted that no critical care processes have come to a standstill so far, suggesting that contingency plans and manual workflows are helping maintain essential medical services.

Investigation Ongoing, Attackers Yet to Be Identified

At this stage, the source of the ChipSoft ransomware incident remains unknown, and no ransomware group has claimed responsibility. ChipSoft’s website was also reported unreachable at the time of writing, indicating ongoing technical or security challenges. The attack appears to have originated from a compromise within ChipSoft’s environment, prompting widespread defensive actions by its customers to limit further risk.

Ripple Effects Extend Beyond Immediate Disruptions

The impact of the ransomware incident has extended beyond system outages. Leiden University Medical Center (LUMC) announced it has postponed the rollout of a new electronic patient record system supplied by ChipSoft following the breach. The hospital clarified that there are no indications that patient data has been leaked, reinforcing the current assessment that the incident has not resulted in data exposure.

Healthcare Sector Remains a Prime Target

The ChipSoft ransomware incident highlights the persistent threat facing healthcare organizations. Cybercriminals frequently target hospitals and medical software providers due to the critical nature of their services, where downtime can create pressure to restore systems quickly. A recent example includes the cyberattack on University of Hawaiʻi Cancer Center, where a ransomware incident impacted research systems and exposed sensitive personal data collected over decades. While clinical operations were not affected, the breach highlighted the long-term risks associated with storing large volumes of historical data.

Z-CERT Continues Support and Monitoring

Z-CERT continues to play a central role in managing the fallout from the ransomware incident. The organization is assisting healthcare institutions with prevention, detection, response, and recovery efforts, while also sharing updated threat intelligence. As restoration efforts progress, authorities and healthcare providers remain focused on minimizing disruption and ensuring patient care remains uninterrupted. The ransomware incident serves as another reminder of how cyberattacks on third-party vendors can cascade across critical sectors, reinforcing the need for stronger resilience in healthcare cybersecurity systems.

In 2026, Businesses Should Be Breach Ready and Never Shut Down Their Core Business

“We do not know how long this situation may last. As a precaution, all of our IT systems have been taken down, and a risk assessment will be conducted before we bring things back up.” Vice Chancellor LouAnn Woodward of the University of Mississippi Medical Center uttered these words standing before cameras on Thursday, February […]

The post In 2026, Businesses Should Be Breach Ready and Never Shut Down Their Core Business appeared first on ColorTokens.

The post In 2026, Businesses Should Be Breach Ready and Never Shut Down Their Core Business appeared first on Security Boulevard.

❌