
Partnered Health, a healthcare provider operating more than 60 medical centers across Australia, confirmed this week that a cyberattack on its network resulted in the theft of patient personal and medical information from clinics in several states.
The company, owned by private equity firm Quadrant, said it first became aware of malicious activity on its network on June 23. In a disclosure issued July 15, Partnered Health said its investigation had confirmed that personal information, including health information, was taken from some clinics within its network, and that the inquiry into the scope of the impact was continuing.
Partnered Health said it engaged cybersecurity specialists to advise on the incident and took immediate steps to contain it and assess whether personal information had been accessed. The company said it is communicating with patients from affected clinics as the investigation proceeds.
The compromised data includes patient names, email addresses, dates of birth, home addresses and contact details, along with Medicare numbers, private health insurance information and concession card details. Veteran Card numbers may also have been affected. The breach further extended to medical information and treatment records, including consultation notes, referral letters, and pathology or diagnostic results recorded by general practitioners and other medical professionals at the clinics.
Twenty-one clinics, spanning cities including Sydney, Melbourne and Canberra, were affected with practices including Blackburn Road Medical Centre, Broadway General Practice, Bundall Medical Centre, Cardiff Medical Centre and Skin Cancer Clinic, Castle Hill Family Doctors, Champion Drive Medical Centre, Chancellor Park Family Medical Practice, Dromana Family Doctors, Dural Medical Centre, Joondalup City Medical Group, Kealba Family Practice, Mornington Family Doctors, Noosaville Seven Day Medical Centre, North Canberra Family Practice, Park Beach Family Practice, Park Orchards Family Practice, Rockingham City Family Practice, Sans Souci Medical Practice, Templestowe District Medical Centre, Wentworth Avenue Family Practice and Wyong Family Practice.
Partnered Health said a malicious actor accessed the data and that it has reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement. No group or individual has yet claimed responsibility for the attack.
The company has obtained an interim injunction from the Supreme Court of New South Wales ordering that the accessed data not be used or published. Clinics affected by the breach are already in the process of contacting patients.
In its statement, Partnered Health said it recognizes that patients and staff trust it with personal and medical information and apologized for any concern and inconvenience the breach may cause.
Founded in 2013, Partnered Health operates medical centers along with skin cancer, allied health and mental health clinics nationwide, with services reaching more than 5 million people. Health insurer Bupa announced in June that it was acquiring Partnered Health, making it the latest major Australian business to be targeted by hackers.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543