Aussie healthcare provider in major data breach after ransomware attack

An Australian private health organisation has been hit by a large-scale ransomware attack.

National Cyber Security Coordinator Michelle McGuinness said in a statement she had been advised of the incident against MediSecure, a private health information provider on Wednesday afternoon.

'We are in the very preliminary stages of our response and there is limited detail to share at this stage, but I will continue to provide updates as we progress while working closely with the affected commercial organisation to address the impacts caused by the incident,' Ms McGuinness said.

The private health organisation MediSecure has been hacked in a large scale ransomware attack that is being investigated (pictured stock image)

The private health organisation MediSecure has been hacked in a large scale ransomware attack that is being investigated (pictured stock image)

The Australian Signals Directorate's Cyber Security Centre and Australian Federal Police are investigating the situation, which is believed to be in its early stages.

Sky News reported that the breach has impacted 'a medium-sized health provider'.

'Now it's not the public health system or public hospitals we're taking about, but a provider within the health system,' anchor Kieran Gilbert said.

Home Affairs Minister Clare O'Neil has convened peak intelligence and security officers in response to the crisis incident.

'I have been briefed on this incident in recent days and the government convened a National Coordination Mechanism regarding this matter today,' she wrote on X.

The data breach is understood to have affected a medium sized health provider (stock image)

The data breach is understood to have affected a medium sized health provider (stock image) 

National Cyber Security Coordinator Michelle McGuinness (pictured) said there is limited detail available at this stage about the scale of the ransomware attack, as security agencies respond to the data breach

National Cyber Security Coordinator Michelle McGuinness (pictured) said there is limited detail available at this stage about the scale of the ransomware attack, as security agencies respond to the data breach

In 2022, the private data of millions of Australians, including sensitive medical information, was breached when Medibank's network was hacked.

Earlier this year, Australia slapped sanctions on Russian citizen Aleksandr Ermakov for his alleged role in that data breach. 

MediSecure is an electronic prescriptions provider that has been operating since 2009.

The company’s software allows patients to obtain scripts from their doctor digitally, increasing the chances of personal medication information leaking online.

On Thursday MediSecure posted a statement on its website:

‘While we continue to gather more information, early indicators suggest the incident originated from one of our third-party vendors.

‘MediSecure takes its legal and ethical obligations seriously and appreciate this information will be of concern.’

‘MediSecure understands the importance of transparency and will provide further updates as soon as more information becomes available. We appreciate your patience and understanding during this time.’

 

More to come.