Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

One Breach, 21 GP Practices: The Multi-Site Security Scope Problem in Healthcare

Tilt-shift miniature data centre with a glowing microchip, representing the shared central IT that a multi-site clinic network depends on
One intrusion into a shared head-office network exposed patient data from 21 GP practices at once: the multi-site scope problem in healthcare.

A cyber attack on a single company’s head office has exposed patient data from 21 GP practices at once. That number is the story. Not because of who was breached, but because of what it reveals about how a network of medical clinics has to think about security. When many practices sit behind one shared set of systems, the weakest point is no longer any single clinic. It is the centre they all depend on.

What has been confirmed

Partnered Health, which operates more than 60 healthcare clinics across Australia, disclosed on 15 July 2026 that it had detected a malicious actor on its network on 23 June. Its investigation, which it says is ongoing, has confirmed that personal information, including health information, was taken from a number of the clinics in its network. It has named 21 affected practices across five states and territories.

The data confirmed as accessed includes patient names, email addresses, dates of birth and addresses. Medicare numbers, private health insurance details, Veteran Card numbers and concession card numbers may also have been taken, along with medical information such as consultation notes, referral letters and pathology or diagnostic results. Partnered Health has reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, notified Services Australia so that additional monitoring can be placed on affected Medicare cards, and obtained an injunction from the Supreme Court of New South Wales restraining use or publication of the data. No group has claimed responsibility, and no findings have been made against the company. What follows is not a verdict on Partnered Health. It is what every multi-site health provider should take from a case like this.

Why one intrusion reached 21 practices

Here is the part that should make any practice manager sit up. The attacker did not have to breach 21 clinics. They had to breach one environment that 21 clinics relied on. That is the defining risk of a shared-services model, and it is common in healthcare, where a head office or aggregator provides the IT, the patient management system, the network and the backups for practices that still feel, and trade, as independent businesses.

That model has real benefits. It also quietly moves the security boundary. The question is no longer whether each clinic is secure, but whether the shared centre is, and whether anyone has mapped what a single compromise there could reach. In information security terms this is a question of scope: what sits inside your management system, what data flows where, and who or what can touch it. When the scope on paper does not match how the data actually moves across the network, the gaps are exactly where an intruder ends up with 21 practices’ worth of records from one foothold.

Health data raises the bar, not lowers it

It matters that this is health data. Under the Privacy Act, health and medical information is sensitive information, and it carries a higher expectation of protection than an ordinary contact list. A Medicare or Veteran Card number cannot be cancelled and reissued the way a credit card can, so the harm from exposure is long-lived. Regulators understand this, which is why health has been among the most scrutinised sectors in the OAIC’s breach reporting for years.

The obligation itself is familiar. Australian Privacy Principle 11 requires you to take reasonable steps to protect the personal information you hold. Only last week the OAIC set out what that looks like when it declined to pursue Qantas over a much larger breach, because the airline could show its controls, and its oversight of a third party, were real. A health network holding Medicare numbers and consultation notes is measured against that same standard, and across every site it operates.

Where ISO 27001 fits a multi-site network

This is the problem ISO 27001 is built to solve, and it suits a network particularly well. The standard starts by making you define scope: the boundaries of your information security management system, the assets inside it, and the risks to them. For a group of clinics on shared systems, that step alone surfaces the single points of failure a clinic-by-clinic view hides. From there it puts controls around access, identity, monitoring, backup and incident response, and, crucially, around the third parties and central services the whole network leans on. Then it requires you to prove those controls work, through internal audit and management review, rather than assume they do.

Certification is not the point on day one. Knowing where your real exposure sits is. A network that has done this work can answer a regulator, a patient and an insurer with evidence rather than hope.

What a multi-site health provider should do now

  • Map where patient data actually lives. Across every clinic, every shared system and every vendor. You cannot scope what you have not drawn.
  • Set your security boundary to match reality. If one central system serves 20 practices, it is the crown jewel, and it should be protected and monitored like one.
  • Get access and identity under control. Most multi-site compromises spread through shared or over-privileged access. Least privilege and strong authentication at the centre matter most.
  • Assess your practice-management and IT vendors. The systems your clinics share are only as secure as the providers behind them. Ask for their evidence, not their assurances.
  • Test the incident response across the network, not one clinic. When a breach hits the shared layer, every site is in scope at once, and the plan has to work that way.
  • Start with a gap analysis. An independent gap analysis against ISO 27001 shows where your scope and your reality diverge, before an attacker does.

Frequently asked questions

Does ISO 27001 apply to a GP practice or a clinic network?

Yes. ISO 27001 is sector-neutral and applies to any organisation that holds information worth protecting, and patient health data is squarely that. For a multi-site network it is especially useful, because defining the management system’s scope forces you to confront the shared systems a single-clinic view misses.

Is health information treated differently under Australian privacy law?

Yes. Health and medical information is sensitive information under the Privacy Act, with stronger handling and consent expectations than ordinary personal data. Combined with identifiers like Medicare and DVA numbers that cannot be reissued, that makes the reasonable steps bar under APP 11 higher for health providers, not lower.

We are a small practice inside a larger group. Whose responsibility is security?

Both, and that is the trap. The group usually runs the shared systems, but each practice remains responsible for the personal information it collects and holds. The cleanest way to remove the ambiguity is a single management system with a clearly defined scope that names who owns which control, at the centre and at each site.

Speak with an experienced ISO auditor

If you run a medical practice or a network of them and this case has you wondering where your real exposure sits, we can help you find out. Start with an independent gap analysis against ISO 27001, build toward certification, get practical cyber and information security advisory, or have your practice managers build the system with ISO mentoring. You deal directly with an experienced ISO auditor. Email hello@streamline.business or call us.

  • Brisbane 07 3667 8280
  • Sydney 02 8315 7780
  • Melbourne 03 9034 3990

Related reading

  • The OAIC cleared Qantas: what “reasonable steps” actually means
  • 1,205 data breaches: what Australia’s worst year on record tells you
  • ISO 27001 certification cost and timeline in Australia
General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • Tilt-shift miniature of four figures with torches examining an open server rack while a wall clock shows a few minutes to midnight
    Origin Says the Breach Is "Potential". That Word…
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of an electricity substation at dusk, with the cable running to the adjacent building visibly cut
    ASD Wants Critical Infrastructure Isolated for 3…
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • Miniature network operations room with staff at monitoring screens and an incident list on a whiteboard, and a server rack room beyond glass with one cabinet door standing open
    The ACSC Just Handed Your IT Provider a Question. Do…
  • Miniature hotel reception connected to a third-party server room while an auditor reviews the supplier arrangement
    Your Supplier Lost the Data. The Notification Is…
  • Tilt-shift miniature of an operations desk with alerts, illustrating monitoring who and what joins your meetings
    The Uninvited Guest: Why You Should Never Let Bots…

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire