🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇦🇺 AU › Healthcare
Healthcare sector · leaderboard
Own the Healthcare leaderboard
The top banner across the Healthcare overview and every Healthcare record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Partnered Health

🇦🇺 Multiple states (NSW, VIC, QLD, WA, ACT) · Partnered Health (Quadrant subsidiary) · Record AU-2026-0002
● Confirmed
People affected
Not disclosed
Breach date
2026-06-23
Regulator
OAIC
Trust tier
A · Confirmed

Data exposed

Medical records and consultation notes Company-confirmed
Pathology and diagnostic results Company-confirmed
Referral letters and treatment details Company-confirmed
Patient names, dates of birth, addresses Company-confirmed
Medicare card numbers Company-confirmed
Private health insurance details Company-confirmed

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

Partnered Health, a large Australian healthcare provider operating 21 general practice clinics across New South Wales, Victoria, Queensland, Western Australia, and the Australian Capital Territory, suffered a cyber attack. Unauthorised access to Partnered Health’s systems occurred on June 23, 2026, and was detected by the organisation. [partnered-health-statement] The company publicly disclosed the breach on July 15, 2026, approximately three weeks after discovery. [partnered-health-statement] Partnered Health (owned by Quadrant) has engaged external cybersecurity experts, notified the Australian Federal Police, the Australian Cyber Security Centre (ACSC), the Office of the Australian Information Commissioner (OAIC), and obtained a court injunction to prevent publication of stolen data. [partnered-health-statement]

Data exposed

The breach exposed sensitive patient and medical information across the 21-clinic network, including: [partnered-health-statement]

  • Medical records, consultation notes, and treatment details
  • Pathology and diagnostic results
  • Referral letters
  • Patient names, dates of birth, and addresses
  • Medicare card numbers
  • Private health insurance details

The total number of affected individuals has not been formally disclosed as of September 10, 2026. Investigation into the full scope remains ongoing. The INC ransomware group has claimed responsibility and alleged ~500GB of data was stolen; Partnered Health’s own investigation is ongoing and has not confirmed the threat actor’s data volume claims. [inc-ransom-claim]

Timeline

  • 2026-06-23 — Unauthorised access to Partnered Health systems detected; investigation initiated.
  • 2026-07-15 — Partnered Health publicly discloses the cyber incident; notifies patients, law enforcement (AFP), ACSC, OAIC; engages external cyber forensic specialists.
  • 2026-07-? — Court injunction sought to prevent publication or misuse of stolen data.
  • 2026-07-? — INC ransomware group claims responsibility on leak site, alleging ~500GB exfiltrated.
  • 2026-09-10 — Investigation ongoing; OAIC engagement confirmed; no formal determination or enforcement action announced.

Regulatory outcome

OAIC and ACSC actively engaged. Partnered Health notified regulators and law enforcement as required. As of September 10, 2026, the OAIC has not announced formal civil penalty proceedings or an investigation. Court injunction is in place to prevent data publication, though threat actor’s leak site claim remains active.

Why it matters

Partnered Health’s breach affects a large, multi-state healthcare provider serving patients across five Australian states. The exposure of complete medical records, treatment histories, and personal identifiers creates significant privacy and identity theft risks for affected patients. The incident demonstrates ongoing cybersecurity challenges in the general practice sector and will inform regulatory expectations for healthcare providers’ data protection obligations under the Privacy Act. The case may prompt OAIC enforcement if investigation confirms systemic security failures.


Status note: Investigation is active and ongoing. Patient count and full data scope remain unconfirmed pending Partnered Health’s forensic analysis. This record will be updated as the company and OAIC release verified findings.

GGOVERN Tabletop Exercises · Govern house When ransomware hits the ward, will your team know the call? Book a Discovery Call →