Record Health Sector Data Breaches Are Testing More Than Cyber Security

Record Health Sector Data Breaches Are Testing More Than Cyber Security

In 2025, the Office of the Australian Information Commissioner received 1,205 data breach notifications, an 8 per cent increase over 2024 and the highest annual total since the Notifiable Data Breaches scheme commenced in 2018.

Health service providers were the most affected sector, accounting for 225 notifications, or 19 per cent of the total. Malicious or criminal activity was responsible for 716 of all notifications.

These figures are more than another warning about cybercrime. They test whether healthcare organisations, and the organisations entrusted with health information, have the governance, operational resilience and rehearsed response capability to act effectively when an incident occurs.

Why healthcare presents a distinctive risk profile

Healthcare organisations hold highly sensitive personal and clinical information. The concentration of valuable data makes the sector attractive to malicious actors seeking information they can exploit, sell or use in follow-on attacks.

The risk is also operational. Healthcare providers depend on technology to support appointments, diagnostics, clinical applications, communications and other essential services. Disruption can quickly become a service continuity issue, not simply an IT problem.

The sector also operates within an increasingly connected digital ecosystem. Cloud services, specialist applications, third-party providers, remote access and connected systems can deliver significant benefits. They also increase the number of dependencies that leaders need to understand and govern.

Healthcare therefore sits at the intersection of sensitive data, operational urgency and technology complexity. That combination makes cyber resilience an executive and governance responsibility.

The Australian Clinical Labs case is a governance lesson

The consequences of a significant breach can extend well beyond remediation costs and reputational damage. In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties in relation to a breach involving its Medlab Pathology business and the personal information of more than 223,000 people.

The total included $4.2 million for failing to take reasonable steps to protect personal information, $800,000 for failing to carry out a reasonable and expeditious assessment, and $800,000 for notification failures.

The central lesson is not simply that a breach can attract a substantial penalty. Regulators may examine how an organisation prepared for and responded to an incident, including the quality and speed of its assessment, decisions and notifications. Preventative controls matter, but so do governance and response capability.

What healthcare leaders should be doing now

1. Know your obligations before an incident occurs

Understand when the Notifiable Data Breaches scheme applies, who has decision authority, how serious harm will be assessed, and how notification obligations will be managed.

2. Establish a repeatable incident response process

Define responsibilities, escalation paths, evidence requirements and executive decision points before the organisation is under pressure.

3. Test readiness, not only technology

Exercise incident scenarios involving operational disruption, sensitive information and third-party dependencies. Use the findings to improve both technical controls and management processes.

4. Treat compliance as an operational capability

Maintain records that demonstrate how the organisation identifies, assesses, escalates and responds to incidents. Compliance should be repeatable and evidenced, not improvised.

5. Use authoritative guidance and improve continuously

The OAIC has published a quick reference guide and a self-assessment checklist to help organisations determine whether an assessment or notification is required. Review these resources as part of incident planning and governance. View the OAIC quick reference guide or use the NDB self-assessment checklist.

Building confidence before an incident

Healthcare organisations face increasing expectations from regulators, boards, patients and the broader community. Meeting those expectations requires more than security tooling. It requires clear governance, resilient technology, defined response processes and confidence that those arrangements will work under pressure.

Aryon works with healthcare and other regulated organisations to strengthen cyber resilience, improve operational readiness and build compliance-aligned processes. Our managed IT, cyber security and professional services help organisations make practical, measurable improvements in technology maturity and resilience.

If your organisation needs greater confidence in its preparedness, contact Aryon to discuss the next practical step.

Share this Article!