
A cyber attack on a single company’s head office has exposed patient data from 21 GP practices at once. That number is the story. Not because of who was breached, but because of what it reveals about how a network of medical clinics has to think about security. When many practices sit behind one shared set of systems, the weakest point is no longer any single clinic. It is the centre they all depend on.
What has been confirmed
Partnered Health, which operates more than 60 healthcare clinics across Australia, disclosed on 15 July 2026 that it had detected a malicious actor on its network on 23 June. Its investigation, which it says is ongoing, has confirmed that personal information, including health information, was taken from a number of the clinics in its network. It has named 21 affected practices across five states and territories.
The data confirmed as accessed includes patient names, email addresses, dates of birth and addresses. Medicare numbers, private health insurance details, Veteran Card numbers and concession card numbers may also have been taken, along with medical information such as consultation notes, referral letters and pathology or diagnostic results. Partnered Health has reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, notified Services Australia so that additional monitoring can be placed on affected Medicare cards, and obtained an injunction from the Supreme Court of New South Wales restraining use or publication of the data. No group has claimed responsibility, and no findings have been made against the company. What follows is not a verdict on Partnered Health. It is what every multi-site health provider should take from a case like this.
Why one intrusion reached 21 practices
Here is the part that should make any practice manager sit up. The attacker did not have to breach 21 clinics. They had to breach one environment that 21 clinics relied on. That is the defining risk of a shared-services model, and it is common in healthcare, where a head office or aggregator provides the IT, the patient management system, the network and the backups for practices that still feel, and trade, as independent businesses.
That model has real benefits. It also quietly moves the security boundary. The question is no longer whether each clinic is secure, but whether the shared centre is, and whether anyone has mapped what a single compromise there could reach. In information security terms this is a question of scope: what sits inside your management system, what data flows where, and who or what can touch it. When the scope on paper does not match how the data actually moves across the network, the gaps are exactly where an intruder ends up with 21 practices’ worth of records from one foothold.
Health data raises the bar, not lowers it
It matters that this is health data. Under the Privacy Act, health and medical information is sensitive information, and it carries a higher expectation of protection than an ordinary contact list. A Medicare or Veteran Card number cannot be cancelled and reissued the way a credit card can, so the harm from exposure is long-lived. Regulators understand this, which is why health has been among the most scrutinised sectors in the OAIC’s breach reporting for years.
The obligation itself is familiar. Australian Privacy Principle 11 requires you to take reasonable steps to protect the personal information you hold. Only last week the OAIC set out what that looks like when it declined to pursue Qantas over a much larger breach, because the airline could show its controls, and its oversight of a third party, were real. A health network holding Medicare numbers and consultation notes is measured against that same standard, and across every site it operates.
Where ISO 27001 fits a multi-site network
This is the problem ISO 27001 is built to solve, and it suits a network particularly well. The standard starts by making you define scope: the boundaries of your information security management system, the assets inside it, and the risks to them. For a group of clinics on shared systems, that step alone surfaces the single points of failure a clinic-by-clinic view hides. From there it puts controls around access, identity, monitoring, backup and incident response, and, crucially, around the third parties and central services the whole network leans on. Then it requires you to prove those controls work, through internal audit and management review, rather than assume they do.
Certification is not the point on day one. Knowing where your real exposure sits is. A network that has done this work can answer a regulator, a patient and an insurer with evidence rather than hope.
What a multi-site health provider should do now
- Map where patient data actually lives. Across every clinic, every shared system and every vendor. You cannot scope what you have not drawn.
- Set your security boundary to match reality. If one central system serves 20 practices, it is the crown jewel, and it should be protected and monitored like one.
- Get access and identity under control. Most multi-site compromises spread through shared or over-privileged access. Least privilege and strong authentication at the centre matter most.
- Assess your practice-management and IT vendors. The systems your clinics share are only as secure as the providers behind them. Ask for their evidence, not their assurances.
- Test the incident response across the network, not one clinic. When a breach hits the shared layer, every site is in scope at once, and the plan has to work that way.
- Start with a gap analysis. An independent gap analysis against ISO 27001 shows where your scope and your reality diverge, before an attacker does.
Frequently asked questions
Does ISO 27001 apply to a GP practice or a clinic network?
Yes. ISO 27001 is sector-neutral and applies to any organisation that holds information worth protecting, and patient health data is squarely that. For a multi-site network it is especially useful, because defining the management system’s scope forces you to confront the shared systems a single-clinic view misses.
Is health information treated differently under Australian privacy law?
Yes. Health and medical information is sensitive information under the Privacy Act, with stronger handling and consent expectations than ordinary personal data. Combined with identifiers like Medicare and DVA numbers that cannot be reissued, that makes the reasonable steps bar under APP 11 higher for health providers, not lower.
We are a small practice inside a larger group. Whose responsibility is security?
Both, and that is the trap. The group usually runs the shared systems, but each practice remains responsible for the personal information it collects and holds. The cleanest way to remove the ambiguity is a single management system with a clearly defined scope that names who owns which control, at the centre and at each site.
Speak with an experienced ISO auditor
If you run a medical practice or a network of them and this case has you wondering where your real exposure sits, we can help you find out. Start with an independent gap analysis against ISO 27001, build toward certification, get practical cyber and information security advisory, or have your practice managers build the system with ISO mentoring. You deal directly with an experienced ISO auditor. Email hello@streamline.business or call us.
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











