Why health professionals lead Australia’s data breach statistics

Australia’s doctors, dentists, allied health providers and private health businesses have held the top spot for data breaches since the Notifiable Data Breaches (NDB) scheme began in February 2018. That position has not changed. The Office of the Australian Information Commissioner (OAIC) consistently records the health sector as Australia’s most breach-prone industry, and the numbers are getting worse, not better.
In 2024, the OAIC received 1,113 data breach notifications across all sectors, a record high and a 25% jump from 2023. The health sector accounted for 20% of those. In the first half of 2025 alone, health providers lodged 104 notifications, again more than any other industry. For context, the next highest sector (finance) reported 63 in the same period.
Why health data is a prime target
Patient records are among the most valuable data sets on the black market. A clinical file typically holds a patient’s full name, date of birth, Medicare number, address, health insurance details, medication history and diagnoses. That combination gives a criminal everything needed for identity fraud, blackmail or targeted phishing, far more than a stolen credit card number provides.
High-profile incidents show what is at stake. In 2024, prescription delivery service MediSecure suffered a ransomware attack that exposed personal and health information linked to 12.9 million Australians. In 2022, Medibank Private’s breach affected 9.7 million customers. Both attacks started with access to a third-party system, not a direct breach of the organisation’s own defences.
Stolen health records can also be used to extort patients directly. Ransomware groups have threatened to release sensitive details, medication histories suggesting mental illness, fertility treatment or gender transition, unless ransoms are paid. The risk is personal, not just financial.
Where breaches are actually coming from
Malicious or criminal attacks drove 59% of all NDB notifications in the first half of 2025. Ransomware, phishing and compromised credentials are the main methods. But the second-biggest cause is one that surprises many practice managers: human error.
Human error accounted for 37% of all breach notifications in January, June 2025, up from 29% in the previous six months. Common causes include sending patient records to the wrong email address, misdirected faxes, and staff clicking phishing links on work devices. No technical attack is needed for these; a simple process failure is enough to trigger a reportable breach.
Third-party risk is the third major factor. The OAIC has specifically flagged outsourcing personal information to vendors as a growing risk. When a health practice shares records with a pathology lab, a specialist, a billing provider or a cloud-based practice management platform, each of those relationships is a potential breach point. The OAIC is clear: the practice is responsible for what happens to patient data even after it leaves their hands.
The structural problem for health practices
Running a secure health practice is genuinely difficult. Patient records need to be accessible across a wide network of care providers. A GP sends referrals to specialists. Radiologists access imaging results. Physiotherapists and other allied health providers need follow-up notes. Each access point is another potential weak link.
Mobile devices add further risk. Staff increasingly use laptops, tablets and phones to access clinical systems, especially in telehealth and after-hours care. A device left unlocked, a personal phone with no mobile device management (MDM) policy, or an unsecured Wi-Fi connection can each create an opening.
Legacy systems make things worse. Many practices run practice management software that hasn’t been updated in years, sitting on ageing hardware that can’t run current security tools. Patching is irregular. Multi-factor authentication (MFA) is often not enabled. These gaps are well-known to attackers.
What the law requires now
Under the Privacy Act 1988 and the NDB scheme, any health practice bound by the Privacy Act must report a breach to the OAIC, and notify affected patients, when a data breach is likely to cause serious harm. The reporting window is 30 days from when the entity becomes aware of the incident.
Penalties for failure to comply have increased significantly. Organisations that fail to adequately protect personal information can now face civil penalties of up to $50 million. The OAIC’s enforcement stance has hardened since 2022, and investigations into health providers are ongoing.
Crucially, My Health Record breaches are handled separately under the My Health Records Act 2012, but standard patient records held by private practices fall squarely under the NDB scheme.
Practical steps for health practices
No security setup eliminates all risk. But a few foundational steps reduce it substantially:
- Enable multi-factor authentication on all clinical systems and email accounts.
- Put a clear mobile device policy in place, covering both practice-owned and personal devices used for work.
- Review third-party vendor contracts to confirm data handling and breach notification obligations are documented.
- Run regular staff training on phishing recognition and safe data handling, human error is now the second-largest cause of breaches.
- Conduct an IT security audit to identify where patient data lives, who can access it and what controls are in place.
- Back up clinical data properly, ideally with an immutable off-site copy, so a ransomware attack doesn’t also destroy your ability to treat patients.
What we see at TTA working with health practices in Queensland
The practices we work with across Queensland typically come to us after one of three events: a near-miss (staff clicking a phishing link), a failed IT audit, or a cyber insurance renewal where the insurer has asked questions they can’t answer. Most have functioning clinical software; what they’re missing is the security layer around it.
We design and manage secure network environments for medical and dental practicescovering network segmentation, MFA rollout, endpoint protection, email security and clinical data backup. Our cyber insurance compliance support also helps practices document the controls their insurer expects to see.
The challenges are real but they are manageable with the right setup. The OAIC data makes clear that doing nothing is no longer a viable option.
Frequently asked questions
Does the NDB scheme apply to small medical practices?
Yes. Health service providers, including sole-practitioner GP clinics, dental practices and allied health providers, are covered by the Privacy Act regardless of their size or annual turnover. If your practice holds patient health information, you have NDB obligations.
What counts as a reportable breach under the NDB scheme?
A breach is reportable if it is likely to result in serious harm to the individuals whose data was involved. This includes unauthorised access or disclosure of patient records, ransomware encrypting clinical data, or even an email sent to the wrong person containing sensitive health details. You have 30 days to assess and notify from when you become aware.
What happens if we don’t report a breach?
Failure to notify the OAIC and affected individuals when required is a breach of the Privacy Act. Penalties can reach up to $50 million for organisations. The OAIC has actively investigated healthcare providers for late or absent notifications since tightening its enforcement approach in 2022.
Is human error really as dangerous as a cyberattack?
In volume terms, yes. Human error accounted for 37% of all data breach notifications in the first half of 2025, up from 29% the previous period. Sending a patient file to the wrong recipient, leaving a device unlocked or falling for a phishing email can each trigger a reportable breach. Staff training and clear procedures are not optional extras.
What should a health practice do first?
Start with an IT audit to understand where patient data is stored, who can access it and what protections are in place. From there, enable MFA, review your third-party vendor arrangements and put a basic incident response plan in place. These steps address the most common breach vectors identified by the OAIC across the health sector.
Where do we get started?
If you run a medical, dental or allied health practice and want to understand your current risk exposure, we’re happy to help. Get in touch with the TTA team to talk through a security assessment or an IT support arrangement that fits your practice.



