🔒
breach
.co.nz
· the NZ & Australia breach register
Register
By sector
Learn
Quiz
Graph
Methodology
Alerts
About
🛡️ A Govern service
☰
By sector
› Healthcare
🏥 Healthcare — data breaches
21 records in the healthcare sector across New Zealand and Australia.
Healthcare sector · leaderboard
Own the Healthcare leaderboard
The top banner across the Healthcare overview and every Healthcare record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz
Zenith Technology Corporation Limited — ZenTech
🇳🇿 Dunedin, Otago
· breach 2026-08-18
● Under investigation
People affected
Not disclosed
Data taken
Clinical trial files and documentation, Sensitive health information (participant-level details)
Regulator
NZ-Police
Trust tier
Confirmed
Source: Health New Zealand Te Whatu Ora ·
View record →
Partnered Health
🇦🇺 Multiple states (NSW, VIC, QLD, WA, ACT)
· breach 2026-06-23
● Under investigation
People affected
Not disclosed
Data taken
Medical records and consultation notes, Pathology and diagnostic results, Referral letters and treatment details
Regulator
OAIC
Trust tier
Confirmed
Source: Partnered Health ·
View record →
Sponsored placement
Reach decision-makers, in-feed
Native placement alongside the breaches your buyers are already reading.
Enquire → breach@govern.co.nz
Partnered Health — national GP clinic network
🇦🇺 Multiple states (national clinic network)
· breach 2026-06
● Disclosed
People affected
Not disclosed
Data taken
Names, dates of birth, addresses, contact details, Medicare numbers, Private health insurance / DVA / concession card numbers
Regulator
OAIC
Trust tier
Reported
Source: Partnered Health ·
View record →
Ochre Health (Tuggeranong)
🇦🇺 Canberra, ACT
· breach 2026-06
● Under investigation
People affected
Not disclosed
Data taken
Unauthorised access via two compromised accounts on the HotDoc third-party booking platform (Tuggeranong clinic), Reported to include names, dates of birth, addresses, emails, phone numbers, Medicare numbers, DVA numbers, appointment details and billing information
Regulator
OAIC and ACSC (notified)
Trust tier
Reported
Source: Ochre Health ·
View record →
Manage My Health Limited
🇳🇿 New Zealand (multi-region)
· breach 2026-01-01
● Under investigation
People affected
126,000 (approx)
Data taken
Medical records and documents, Patient personal and health information
Regulator
NZ-Privacy-Commissioner
Trust tier
Confirmed
Source: Office of the Privacy Commissioner (New Zealand) ·
View record →
Manage My Health
🇳🇿 New Zealand
· breach 2026
● Under investigation
People affected
126,000 (approx)
Data taken
Patient health records and personal information
Regulator
NZ Privacy Commissioner
Trust tier
Confirmed
Source: Office of the Privacy Commissioner ·
View record →
Genea Fertility
🇦🇺 Sydney, NSW
· breach 2025-02
● Under investigation
People affected
Not disclosed
Data taken
Sensitive patient and fertility/medical records (published on the dark web)
Regulator
OAIC (notified)
Trust tier
Reported
Source: TechCrunch ·
View record →
Health New Zealand — Te Whatu Ora (staff data)
🇳🇿 Central region (Capital, Coast & Hutt Valley; Wairarapa)
· breach 2024-10
● Disclosed
People affected
Not disclosed
Data taken
Staff occupational health and safety information, including medical assessments and health-related correspondence (2020–2024)
Regulator
OPC notified; NZ Police Cybercrime Unit investigating
Trust tier
Reported
Source: RNZ ·
View record →
I-MED Radiology Network
🇦🇺 Australia
· breach 2024-09
● Under investigation
People affected
Not disclosed
Data taken
Patient records and imaging referral information (tens of thousands of files)
Regulator
OAIC
Trust tier
Confirmed
Source: OAIC ·
View record →
MediSecure
🇦🇺 Melbourne, VIC
· breach 2024-04
● Disclosed
People affected
12,900,000 (approx)
Data taken
Prescription and personal health information
Regulator
OAIC
Trust tier
Confirmed
Source: OAIC ·
View record →
Health New Zealand (Te Whatu Ora)
🇳🇿 New Zealand
· breach 2024-02
● Resolved
People affected
12,000 (approx)
Data taken
Personal information relating to COVID-19 vaccination records
Regulator
NZ Privacy Commissioner
Trust tier
Confirmed
Source: Health New Zealand — Te Whatu Ora ·
View record →
St Vincent's Health Australia
🇦🇺 Australia (national)
· breach 2023-12
● Under investigation
People affected
Not disclosed
Data taken
Data removed from the network
Regulator
Australian Cyber Security Centre; National Office of Cyber Security
Trust tier
Reported
Source: St Vincent's Health Australia ·
View record →
TissuPath
🇦🇺 Melbourne, VIC
· breach 2023-08
● Disclosed
People affected
Not disclosed
Data taken
Names, dates of birth, gender, phone, address, Medicare numbers, health-insurance details, referring-doctor information and scanned pathology referrals
Regulator
OAIC and ACSC notified
Trust tier
Reported
Source: Cyber Daily ·
View record →
Pinnacle Midlands Health Network
🇳🇿 Hamilton, Waikato
· breach 2022-09
● Under investigation
People affected
450,000 (approx)
Data taken
Patient addresses and National Health Index (NHI) numbers, Immunisation and screening status, and data about services provided
Regulator
Office of the Privacy Commissioner (NZ)
Trust tier
Reported
Source: RNZ ·
View record →
CTARS (NDIS client-management provider)
🇦🇺 Australia
· breach 2022-05
● Disclosed
People affected
Not disclosed
Data taken
Names, dates of birth, addresses, phone numbers, emails, usernames/passwords and genders, Sensitive health and disability data
Regulator
OAIC and ACSC (notified)
Trust tier
Reported
Source: Information Age (ACS) ·
View record →
Australian Clinical Labs — Medlab Pathology
🇦🇺 Sydney, NSW
· breach 2022-02
● Penalty issued
People affected
223,000+
Data taken
Names, addresses, contact details, Medicare card numbers, Medical & pathology results
Regulator
OAIC
Penalty
AUD 5.8M
Source: OAIC ·
View record →
Waikato DHB (Te Whatu Ora Waikato)
🇳🇿 Hamilton, Waikato
· breach 2021-05
● Resolved
People affected
Not disclosed
Data taken
Patient and staff personal and health information (leaked to media / dark web)
Regulator
NZ Privacy Commissioner
Trust tier
Confirmed
Source: Te Whatu Ora ·
View record →
NSW Health
🇦🇺 New South Wales
· breach 2021-01
● Disclosed
People affected
Not disclosed
Data taken
Identity information and, in some cases, health-related personal information contained in files accessed; NSW Health said medical-records systems were not affected
Regulator
NSW Police (Strike Force Martine); Cyber Security NSW
Trust tier
Reported
Source: NSW Health ·
View record →
Ambulance Tasmania
🇦🇺 Tasmania
· breach 2020-11
● Disclosed
People affected
Not disclosed
Data taken
Patient names, incident locations, age, gender and the medical condition or nature of the callout
Regulator
Referred to Tasmania Police; Tasmanian Department of Health investigation
Trust tier
Reported
Source: The Examiner ·
View record →
Regis Healthcare
🇦🇺 Australia
· breach 2020-07
● Disclosed
People affected
Not disclosed
Data taken
Personal data copied and, in part, published by the Maze double-extortion group; reporting referenced resident/client and employee information
Regulator
OAIC and ACSC notified
Trust tier
Reported
Source: iTnews ·
View record →
Tū Ora Compass Health
🇳🇿 Wellington region
· breach 2019-08
● Resolved
People affected
1,000,000 (approx)
Data taken
Enrolled patient information (names, dates of birth, contact and health-related data)
Regulator
NZ Privacy Commissioner
Trust tier
Reported
Source: Cyber Security Hub ·
View record →
G
GOVERN
Tabletop Exercises · Govern house
When ransomware hits the ward, will your team know the call?
Book a Discovery Call →