July 15, 2026: Partnered Health—an Australian network of roughly 57 GP and skin-cancer clinics, now headed toward a Bupa acquisition—confirmed that a cyberattack discovered around June 23 resulted in thieves taking personal and health information from some clinics. Patients started getting SMS notices the afternoon national outlets broke the story.
What Partnered Health confirmed
ABC News reports the company's incident notice states: "Our investigations to date have confirmed that personal information, including health information, was taken from some of the clinics in our network." Sixteen clinics are listed as potentially impacted; five more remained under investigation at disclosure time.
Categories that may be involved include names, dates of birth, addresses, contact details, Medicare card numbers, private health / DVA / concession identifiers where held, plus consultation notes, referral letters, and pathology results.
Court order against reuse
Partnered Health said it obtained an interim injunction from the NSW Supreme Court ordering that accessed data not be used or published. That does not undo theft—it raises the legal cost of dumping or selling the files. The company also warned patients about scam contacts that drop real medical details to sound authentic.
Why this hits harder than a retail email leak
GP notes and pathology results are blackmail and impersonation fuel. Medicare numbers unlock other social-engineering paths in Australia's health system. Even without a public victim count, a multi-clinic primary-care network breach is material for patients, insurers, and the forthcoming Bupa deal.
What was not published
Partnered Health has not released a nationwide patient total. Treat social posts inventing "millions of records" as unverified unless the OAIC or the company posts a number.
Action items
- If you attended a listed clinic, read the firm's SMS/email notice carefully and verify any callback number against partneredhealth.com.au.
- Watch for Medicare, pathology, or "book follow-up" phishing—especially messages that correctly name your GP.
- Review My Health Record access logs where available and report unexpected activity.
- Do not open alleged leak archives of medical files circulating on forums or Telegram.
Canonical record: Partnered Health 2026 on BreachHistory. Also: The Guardian, EFTM.