Australian medical practices are becoming an increasingly important target for cybercriminals. In 2025, health service providers were the most commonly affected sector in Australia’s reported data breaches, accounting for 225 of the 1,205 data breach notifications received by the Office of the Australian Information Commissioner (OAIC). That represented 19% of all reported breaches for the year.
The risk is not limited to large hospitals.
GP clinics, specialist practices, allied health providers and other healthcare organisations rely on patient management systems, email, cloud platforms, online booking systems, pathology integrations and digital health services every day.
That creates multiple systems that need to be protected.
At the same time, healthcare data is particularly sensitive, and a cyber attack can affect more than business operations. It can disrupt access to patient information and potentially affect the delivery of healthcare. So why are Australian medical practices being targeted, what are the biggest risks, and how can healthcare businesses improve their cybersecurity?
Cybersecurity for Australian SMEs has quietly gone from a nice-to-have to a survival issue. Here’s why attackers have shifted their attention downward, and what’s actually changed.
Why Are Australian Medical Practices Targeted by Cyber Attacks?
Cybercriminals generally look for valuable information, vulnerable systems and opportunities to make money. Medical practices can have all three.
A typical practice may hold:
- Patient names and contact details
- Medicare information
- Health records
- Medical histories
- Prescription information
- Referral information
- Billing and payment information
- Employee records
- Insurance information
- Specialist and pathology reports
This information can be highly sensitive and difficult to replace once exposed. Healthcare also has another characteristic that makes cybersecurity particularly important: availability matters.
If a practice loses access to patient records, appointment systems or critical IT systems, staff may struggle to operate normally.
The Australian Signals Directorate (ASD) specifically identifies healthcare as an important cyber threat area. Its Annual Cyber Threat Report 2024–25 states that healthcare data is valuable to criminals because it can support activities such as fraud and identity theft. The report also found that ransomware incidents against the Australian healthcare sector doubled compared with FY2023–24.
Is Healthcare Australia’s Most Targeted Sector for Data Breaches?
According to the latest OAIC annual data, health service providers were the sector with the highest number of reported data breaches in 2025. The OAIC received 1,205 data breach notifications during the 2025 calendar year.
Health service providers accounted for:
225 notifications, or 19% of the total. Financial services followed with 157 notifications, while Australian Government agencies recorded 118.
The OAIC also reported that 716 of the 1,205 notifications were attributed to malicious or criminal activity. This does not mean every medical practice is likely to experience a breach.
It does show that healthcare organisations need to treat cybersecurity as an ongoing operational priority rather than an occasional IT task.
Why Is Patient Data So Valuable to Cybercriminals?
Patient information can contain a combination of personal and health information that can be used for identity fraud, scams and other criminal activity. Unlike a compromised password or payment card, health information cannot simply be cancelled and replaced.
A patient’s medical history, health information or identity details may remain sensitive for years. This makes protecting patient data particularly important for medical practices. Healthcare businesses therefore need to think beyond traditional antivirus software.
Cybersecurity should cover:
- Identity and access management
- Email security
- Endpoint protection
- Data backups
- Cloud security
- Network security
- Staff training
- Third-party access
- Incident response
- Patient data protection
Why Can Ransomware Be Especially Serious for Medical Practices?
Ransomware can prevent staff from accessing files, applications or systems needed to operate a practice.
For a medical centre, that can potentially affect:
- Patient records
- Appointment systems
- Clinical workflows
- Prescription processes
- Billing
- Communication
- Referral information
- Access to other connected systems
ASD’s Annual Cyber Threat Report 2024–25 reported that ransomware incidents against the healthcare sector doubled in FY2024–25 compared with the previous financial year. ASD also reported that malicious cyber actors were successful in 95% of healthcare and social assistance incidents to which the ACSC responded, compared with nearly 52% across all sectors.
These figures relate to incidents handled by ASD’s ACSC and should not be interpreted as the percentage of all Australian healthcare organisations that were attacked. However, they demonstrate why healthcare organisations need strong prevention, detection and recovery controls.
What Happened in the MediSecure Cyber Incident?
One of Australia’s major healthcare-related cyber incidents involved MediSecure, an e-prescription service. According to ASD’s Annual Cyber Threat Report 2024–25, approximately 6.5 terabytes of data were exfiltrated from the e-prescription service database in a suspected ransomware attack.
The affected data related to approximately 12.9 million Australian customers who used the e-prescription service between March 2019 and November 2023. The incident demonstrates how a cyber attack involving a healthcare technology provider can potentially affect information belonging to millions of people.
For individual medical practices, it also highlights the importance of understanding third-party technology and data access.
What Are the Biggest Cybersecurity Threats Facing Australian Medical Practices?
1. Phishing and Business Email Compromise
Phishing remains one of the easiest ways for attackers to target staff.
An attacker may send an email pretending to be:
- A practice manager
- A doctor
- A supplier
- An accountant
- A pathology provider
- A software company
- A government organisation
The goal may be to steal login credentials, install malware or convince an employee to transfer money.
Medical practices should train staff to look beyond spelling mistakes.
Warning signs can include:
- Unexpected login requests
- Urgent payment requests
- Changes to supplier bank details
- Unusual attachments
- Requests for patient information
- Unexpected password-reset messages
- Requests to bypass normal procedures
For financial or sensitive requests, independent verification should be required.
2. Ransomware
Ransomware can encrypt or otherwise disrupt access to business data and systems.
For a medical practice, the consequences can extend beyond lost productivity.
If staff cannot access critical systems, the practice may need to change how it manages appointments, records and other workflows.
Protection should include:
- Regular backups
- Tested backup restoration
- Endpoint protection
- Patch management
- MFA
- Network security
- Restricted administrator access
- Incident response planning
A backup that has never been tested should not be treated as a fully reliable recovery strategy.
3. Stolen Passwords and Compromised Accounts
A stolen password can provide an attacker with access to email, cloud applications or patient-related systems.
Medical practices should use multi-factor authentication wherever practical, especially for:
- Microsoft 365
- Practice management systems
- Cloud applications
- Administrator accounts
- Remote access
- Financial systems
Access should also be removed promptly when an employee leaves the practice.
4. Outdated Software and Unpatched Systems
Medical practices depend on many software products and devices.
These may include:
- Practice management software
- Operating systems
- Browsers
- Routers
- Firewalls
- VPN devices
- Patient portals
- Websites
- Cloud applications
- Medical devices
Unpatched systems can create opportunities for attackers.
Practices should maintain an inventory of important systems and establish a regular patching process.
5. Third-Party and Supply Chain Risks
A medical practice rarely operates entirely on its own.
It may connect with:
- Pathology providers
- Imaging providers
- Specialist services
- IT companies
- Practice management software
- Cloud providers
- Payment providers
- Appointment platforms
- Medical software vendors
Each connection can introduce another security consideration.
Practices should understand:
- What information each provider can access
- Why access is required
- Which systems are connected
- How accounts are secured
- How access is removed
- What happens after a security incident
Third-party access should be reviewed regularly.
6. Insider Threats and Human Error
Cybersecurity incidents do not always involve a malicious employee.
A staff member may accidentally:
- Send information to the wrong recipient
- Click a phishing link
- Share a password
- Upload patient information to an inappropriate service
- Leave a device unsecured
- Give excessive access to another user
Good cybersecurity therefore combines technology with clear processes and staff training.
7. Cloud and Microsoft 365 Security
Many medical practices rely heavily on cloud services.
Microsoft 365 and other cloud platforms can provide strong security controls, but these controls need to be configured and maintained correctly.
Practices should review:
- MFA
- Administrator accounts
- User permissions
- External sharing
- Email security
- Login activity
- Third-party applications
- Former employee accounts
Cloud migration does not remove cybersecurity responsibility.
It changes where security needs to be managed.
What Cybersecurity Obligations Apply to Australian Medical Practices?
Healthcare organisations can have specific privacy and digital health obligations in addition to their general cybersecurity responsibilities.
The Privacy Act and Notifiable Data Breaches (NDB) scheme may apply to eligible data breaches involving personal information.
Medical practices participating in My Health Record also have specific obligations under the My Health Records Act 2012 and My Health Records Rules 2026.
The Australian Digital Health Agency states that organisations participating in My Health Record must have a security and access policy covering areas such as staff training, authorised access and user account management.
The 2026 rules also introduce updated requirements for healthcare provider organisations participating in My Health Record.
From 1 October 2026, registered healthcare provider organisations must ensure their security and access policy complies with the My Health Records Rules 2026.
This makes it important for practices to review their current security and access policies before the updated requirements take effect.
What Happens If a Medical Practice Experiences a My Health Record Data Breach?
If a breach relates to, or may relate to, the My Health Record system, healthcare organisations have specific notification obligations.
The Australian Digital Health Agency states that participating organisations must notify the Agency of actual or potential data breaches involving My Health Record.
Importantly, notification may be required even when the breach has not yet been fully confirmed.
The response process includes:
- Containing the incident
- Assessing what happened
- Identifying affected information
- Managing required notifications
- Investigating the incident
- Taking steps to prevent similar incidents
The exact reporting obligations depend on the circumstances of the incident, including whether My Health Record information or systems are involved.
Medical practices should therefore have an incident response process in place before a breach occurs.
How Can Australian Medical Practices Improve Cybersecurity?
The strongest approach is to combine technical controls, staff awareness and clear processes.
1. Enable Multi-Factor Authentication
Use MFA for critical accounts wherever available.
Prioritise:
- Microsoft 365
- Practice management systems
- Remote access
- Administrator accounts
- Financial systems
2. Keep Software Updated
Create a documented process for updating:
- Operating systems
- Practice software
- Browsers
- Firewalls
- VPNs
- Websites
- Plugins
- Cloud applications
3. Use Secure and Tested Backups
Maintain regular backups of important business data.
Then test restoration.
The goal is not simply to have a backup.
The goal is to know that your practice can recover from a serious incident.
4. Apply Least-Privilege Access
Not every employee needs access to every system or patient record.
Access should be based on job responsibilities.
For example, reception staff, clinicians, administrators and external contractors may require different levels of access.
Review access regularly and remove unnecessary permissions.
5. Secure Microsoft 365 and Cloud Accounts
Review:
- MFA
- Administrator permissions
- External sharing
- User accounts
- Suspicious login activity
- Third-party applications
6. Train Healthcare Staff
Cybersecurity training should cover:
- Phishing
- Password security
- MFA
- Social engineering
- Patient information
- Suspicious attachments
- Fraudulent payment requests
- Secure use of cloud services
- Incident reporting
Training should be practical and repeated regularly.
7. Review Third-Party Access
Create an inventory of external providers that can access practice systems or information.
For each provider, ask:
What can they access?
Why do they need access?
Is MFA enabled?
How is access monitored?
What happens if they experience a breach?
8. Create an Incident Response Plan
Your practice should know exactly what to do if:
- A staff account is compromised
- Ransomware is detected
- Patient information is exposed
- A laptop is stolen
- A supplier suffers a cyber incident
- The practice management system becomes unavailable
- My Health Record may be affected
The plan should identify who is responsible for IT, management, communication, investigation and reporting.
Cybersecurity Checklist for Australian Medical Practices
Use this checklist to identify potential security gaps:
- MFA enabled on critical accounts
- Microsoft 365 security reviewed
- Practice management systems regularly patched
- Endpoint protection enabled
- Critical software and devices inventoried
- Patient data access reviewed
- Former employee accounts removed
- Administrator access restricted
- Regular backups maintained
- Backup restoration tested
- Email security configured
- Staff cybersecurity training provided
- Third-party access reviewed
- My Health Record security and access policy reviewed
- Incident response plan documented
- Data breach notification responsibilities understood
- Remote access secured
- Security policies regularly reviewed
Final Thoughts
Cybersecurity is now an essential part of running a modern Australian medical practice. Healthcare organisations are managing valuable patient information while depending on increasingly connected systems, cloud platforms and third-party services.
The latest Australian data shows why this deserves attention. Health service providers recorded 225 data breach notifications in 2025, the highest number among reported sectors, while ASD reported that ransomware incidents against Australian healthcare doubled in FY2024–25.
The solution is not one security product. Medical practices need a layered approach that combines:
MFA + secure email + patching + endpoint protection + access controls + tested backups + staff training + incident response.
For practices using My Health Record, reviewing security and access policies is also important, particularly with the updated My Health Records Rules 2026 taking effect from 1 October 2026.
If your medical practice needs help reviewing its IT environment, cybersecurity controls, Microsoft 365 security, backups or ongoing IT support, LucidByte can help Australian healthcare organisations build and maintain a more secure IT environment. Contact LucidByte for a practical cybersecurity and IT assessment for your medical practice.


