
Australian e-prescription provider MediSecure said the data security incident it suffered earlier this year compromised the sensitive personal information of about 12.9 million individuals.
In a data security incident notice earlier this year, MediSecure said it identified a data security incident that compromised the personal and health information of individuals. The company launched an investigation to determine the nature and scope of the incident and initiated efforts to mitigate the impact of the incident.
The e-prescription provider added that initial investigation revealed the data security incident originated from one of its third-party service providers.
In a recent press release, MediSecure said that a joint investigation with National Cyber Security Coordinator, the Australian Federal Police, the Australian Signals Directorate, and the Office of the Australian Information Commissioner revealed that at least 12.9 million individuals were impacted by the data security incident.
“MediSecure wishes to inform the public that the personal and sensitive information, including contact and health information, of approximately 12.9 million Australians who used the MediSecure prescription delivery service during the approximate period of March 2019 to November 2023 was contained within MediSecure data stolen by a malicious third-party actor,” reads the press release.
The personal data compromised during the incident included citizens’ names, dates of birth, addresses, phone numbers and email addresses, individual healthcare identifiers, Medicare card numbers, prescription medication, reason for prescription and instructions.
“MediSecure would like to reiterate that it is not a current participant in Australia’s digital health network. At the time of the Incident, MediSecure did not have any connections to the prescribing and dispensing of medications.
“Australians can continue to access medicines safely, and healthcare providers can still prescribe and dispense as usual through the national prescription delivery service, eRx,” the company added.
In a post on X, the Australian National Cyber Security Coordinator advised affected individuals to look out for scams referencing the MediSecure data breach, and not to respond to unsolicited contact that references the incident.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543