Australian healthcare is the most persistently breached sector in the country. Not the most targeted — financial services receive more attempts. But healthcare leads in successful breaches, year after year, because the fundamental security failures that enable these attacks have not been addressed. The same vulnerabilities that caused breaches in 2022 are still causing breaches in 2025: no MFA on email, unpatched clinical software, untested backups, and staff who cannot recognise a phishing email.
The Office of the Australian Information Commissioner (OAIC) publishes quarterly and annual Notifiable Data Breach (NDB) reports that provide the most comprehensive public data on Australian healthcare breaches available. This analysis draws on the 2025 OAIC annual data summary, ACSC threat reporting, and direct engagement with Australian healthcare organisations to identify the most significant findings and their implications for 2026.
OAIC 2025 Annual Data: Healthcare Breach Overview
Healthcare consistently accounts for between 18% and 22% of all NDB reports to the OAIC — the highest or second-highest proportion of any sector, depending on the reporting period. For perspective, healthcare's share of the Australian workforce is approximately 14%. Healthcare is therefore over-represented in breach data relative to its size, indicating that the sector's security posture lags behind others.
The year-on-year trend is a steady increase in healthcare breach notifications. This reflects both an actual increase in attack frequency and — encouragingly — increasing compliance with the NDB notification obligation as awareness grows. However, the OAIC notes that healthcare breaches remain significantly under-reported, particularly by smaller practices that may not be aware of their notification obligations or that may be avoiding the reputational implications of self-reporting.
Top 5 Findings from 2025 Breach Data Analysis
Ransomware Is Now the Dominant Attack Type
Ransomware overtook phishing as the leading cause of malicious healthcare breaches in 2025. This shift reflects the ransomware-as-a-service (RaaS) model — criminal groups now offer ready-made ransomware tools to affiliates who conduct the attacks, dramatically lowering the skill barrier for targeting healthcare organisations. LockBit and BlackCat/ALPHV affiliates were responsible for a significant proportion of Australian healthcare ransomware incidents in 2025.
Small Practices Are Disproportionately Affected
Breaches affecting private medical practices — including GP practices, specialist clinics, and allied health providers — were the most common breach type by volume. These practices typically operate with no dedicated IT staff, out-of-date clinical software, and no incident response plan. They are targeted precisely because they are easy — far less hardened than hospitals, which have invested in security infrastructure under government pressure.
MFA Absence Is the Single Most Common Enabling Factor
In the majority of 2025 healthcare breaches involving initial credential compromise, the breached account had no MFA enabled. This is a striking finding given that MFA is free for most healthcare providers using Microsoft 365 or Google Workspace. The absence of this single, free control was the key enabling factor in hundreds of Australian healthcare breaches last year.
Human Error Remains Significant
Approximately 35% of healthcare NDB reports in 2025 involved human error rather than malicious attack: misdirected emails, incorrect disposal of paper records, mistaken sharing of files with the wrong recipient. These breaches are not glamorous and do not make headlines, but they are consistently significant in volume and entirely preventable through staff training and process controls.
Late Notification Is an Ongoing Compliance Problem
The OAIC noted that late notification — completing the NDB assessment and filing outside the 30-day window — remains a widespread problem in healthcare. Many practices either did not know the 30-day clock had started (because they were not aware of their obligation to assess promptly) or delayed assessment in the hope that the breach scope would turn out to be smaller than initially feared. Neither is an acceptable approach.
Case Study 1: GP Practice Ransomware (Anonymised)
Background: A two-GP suburban practice in south-east Queensland, serving approximately 4,500 active patients. One full-time practice manager, two part-time nurses. Clinical software: Best Practice Software on a Windows Server 2019. No dedicated IT support — IT maintenance performed ad hoc by a local IT generalist on an hourly basis.
The attack: A phishing email impersonating Medicare arrived on a Tuesday morning, directing the practice manager to "confirm updated bank details" via a fake Services Australia portal. The practice manager's credentials were captured. Over the following 18 days, the attacker moved through the network, acquiring administrator credentials from a locally stored password file. On day 19, ransomware was deployed across all networked drives, including the Best Practice database. The clinical server, all workstations, and the external hard drive — which was permanently connected — were encrypted simultaneously.
What happened next: The practice could not see patients safely for 4 business days. Paper records were used for emergency appointments. The ransom demand was $120,000 AUD (0.5 BTC at prevailing rates). On the advice of their cybersecurity incident response provider and the ACSC, the practice did not pay. Recovery took 11 days using a 14-day-old cloud backup (the offline drive had been connected and was encrypted). An estimated 380 patient records were exfiltrated before encryption.
OAIC outcome: The practice self-reported an NDB. The OAIC assessed the breach as eligible. A compliance assessment was initiated. The practice was required to implement MFA on all systems, engage a managed security provider for ongoing monitoring, and provide documented evidence of backup testing quarterly for 12 months.
Total estimated cost: $145,000 AUD, including recovery costs, lost revenue, OAIC response legal advice, and the managed security engagement. This was not covered by the practice's professional indemnity insurance (cyber coverage was absent from the policy).
Case Study 2: Allied Health BEC (Anonymised)
Background: A psychology group practice in inner Melbourne, three clinicians, running Power Diary for practice management and standard Microsoft 365 Business Basic for email. Clinicians worked from both the office and home. All three had personal Outlook accounts linked to their work email for convenience.
The attack: One clinician's Microsoft 365 account was compromised via a phishing email after the clinician reset their password without MFA active on a home computer. The attacker accessed the account for 34 days before discovery, reading all emails including patient correspondence, referral letters, and clinical summaries sent via email between clinicians.
What was accessed: An estimated 67 patient email threads involving clinical correspondence, including information identifying patients as having mental health diagnoses, NDIS plans, and family law matters. Several patients' records included information about domestic violence and child protection involvement.
Professional conduct investigation: The OAIC investigation noted that sending clinical summaries containing sensitive mental health information via standard unencrypted email — without patient consent to this transmission method — was itself a potential APP 6 breach, separate from the account compromise. The practice was referred to the AHPRA for review of its record-handling practices.
Lessons: MFA would have prevented the initial account compromise entirely. A clear policy prohibiting email transmission of clinical correspondence without encryption or patient consent would have limited the privacy harm. The connection between security failure and professional conduct obligation was stark.
The Prevention Gap: 94% Preventable, So Why Isn't It Happening?
The ACSC estimates that 94% of cyberattacks could be prevented through consistent implementation of the Essential Eight controls. For healthcare, this figure is likely even higher — the majority of breaches involve the absence of a small number of basic controls: MFA, patching, and tested offline backups. If every Australian GP practice and allied health provider implemented just these three controls to ML1 standard, the healthcare breach rate would fall dramatically.
So why isn't it happening? Three root causes explain the persistent gap:
Root Cause 1: Budget Constraints
Healthcare practices — particularly small private practices — operate on thin margins. The principal GPs are focused on clinical care, not IT. When there is no budget line item for cybersecurity and no immediate pain, it is easy to defer. The irony is that the three most impactful controls (MFA, patching, backups) are almost free — the barrier is not money, it is awareness and prioritisation.
Root Cause 2: Lack of Awareness
Many healthcare practitioners genuinely do not know what their Privacy Act obligations require of them in security terms. They know they must protect patient information, but do not understand that "protection" means MFA, encryption, tested backups, and an incident response plan. This awareness gap is the most solvable of the three root causes.
Root Cause 3: No Mandated Standard for Private Healthcare
Public hospital networks and large health organisations face increasing regulatory pressure and government procurement requirements that drive security investment. Private GP practices and allied health providers face no equivalent pressure. The Privacy Act creates obligations, but enforcement has historically been reactive rather than proactive. The OAIC's increasing enforcement activity in 2026 is beginning to change this dynamic.
What the OAIC Is Doing in 2026
The OAIC's enforcement approach has shifted materially in 2026. Rather than waiting for breach notifications and responding reactively, the Commissioner has signalled a proactive compliance assessment program targeting healthcare providers — particularly in general practice and allied health — who hold sensitive information but have not demonstrated adequate security practices.
Key changes in 2026 enforcement posture: increased use of public investigation reports that name healthcare practices (previously, reports typically anonymised small practices — this is changing); larger and more demanding enforceable undertakings; referral of individuals to professional registration bodies (AHPRA) where professional conduct is engaged; and civil penalty applications in cases of serious or repeated breaches under the expanded penalty regime of the Privacy Act amendments.
The message from the OAIC to the healthcare sector is unambiguous: the era of low-consequence data breaches for private healthcare providers is ending. The regulatory environment is catching up to the threat landscape.
5 Things Every Healthcare Practice Should Do Immediately
Enable MFA on everything today
Microsoft 365, Google Workspace, Cliniko, Nookal, Power Diary, PRODA, banking. Fifteen minutes per account. Free. The single highest-impact action you can take right now.
Test your backup — today
Not set it up. Not check if it is running. Actually restore a set of files from your most recent backup and document it. If you cannot restore, you do not have a working backup.
Patch all software — this week
Run Windows Update. Update your clinical software. Update every browser. This closes the vulnerabilities ransomware exploits to move through your network.
Run a 20-minute phishing awareness session with all staff
Show staff what a phishing email looks like. Teach them to hover over links before clicking. Make it practical and brief. Human awareness prevents more breaches than most technical controls.
Document your incident response plan
Write down: who to call, how to isolate an infected computer, when the OAIC must be notified, and who is responsible for what. Print it and put it in a physical folder at reception. One page is sufficient.
What 2026 Looks Like for Healthcare Cyber Threats
The threat landscape for Australian healthcare in 2026 is more severe than in any prior year. Several factors are converging to increase attack frequency and impact:
AI-generated phishing emails are now indistinguishable from legitimate correspondence. The spelling errors and awkward phrasing that trained staff to recognise phishing no longer reliably appear. Technical email authentication controls (DMARC, DKIM, SPF) are now critical.
Ransomware-as-a-service platforms have lowered the barrier to entry for healthcare-targeted attacks. Criminal groups with no technical sophistication can conduct effective ransomware campaigns against Australian healthcare using commercial tools.
My Health Record integration creates new attack surfaces — clinical software connected to the My Health Record system expands the potential blast radius of a successful breach.
NDIS growth is creating new attack vectors in allied health, as fraudulent NDIS billing becomes an increasingly attractive target for cybercriminals.
The OAIC enforcement escalation is creating reputational stakes that were previously absent for small practices — the consequences of a breach are now genuinely severe, both financially and reputationally.
Don't Wait for a Breach to Act
ShieldForce provides free cybersecurity assessments for Australian healthcare providers. Identify and fix your critical vulnerabilities before attackers find them.
Book a Free Healthcare Security AssessmentRelated Articles
References
See our full author credentials
