Select Page

Incident: Thousands of identifiable Northern Territory patient health files sent to overseas-based software vendor in government data breach | ABC News (Australia)

Incident: Thousands of identifiable Northern Territory patient health files sent to overseas-based software vendor in government data breach | ABC News (Australia)

Australian Medical Data Handling Incident, 25 May 2023

Thousands of identifiable Northern Territory patient health files sent to overseas-based software vendor in government data breach

NT Health says the onus is on individuals to check if the privacy of their medical records has been breached.

Source: Thousands of identifiable Northern Territory patient health files sent to overseas-based software vendor in government data breach | ABC News (Australia)
Source: Patients told to contact NT Health following privacy breach of identifiable medical records | ABC News (Australia)

View more incidents from Medical and Health Care sector and other reports from Northern Territory.

The Northern Territory government has breached the privacy of thousands of public health patients by sending identifiable medical records to a software vendor with offices in Europe, South America and China.

Northern Territory Health says the onus is on individuals to check if the privacy of their medical records has been breached by the government.

A preliminary incident report, obtained by the ABC through freedom of information laws, shows the extent of identifiable patient data transferred between NT Health, the Core Clinical Systems Renewal Program (CCSRP) and global software vendor Intersystems between 2018 and 2019.

On Thursday, the ABC revealed that more than 50,000 patients had their identifiable health files sent between two NT government departments in 2018 and 2019 as part of a software system upgrade.

More than 3,000 of those records were then sent to global software vendor Intersystems, which has offices in 27 countries, including in Europe, South America and China.

Some patient items were classed as having very-high or high clinical risk, such as psychology reports and psychiatric facility visits, termination of pregnancy or stillbirth records, and electroconvulsive therapy — also known as electric shock therapy — records.

Chief Minister Natasha Fyles, who was health minister at the time, never made the privacy breach public. In a statement to the ABC, Ms Fyles said the incident was referred to the NT Information Commissioner.

The incident report also revealed that no data governance framework was set by either NT Health or the Acacia project team prior to the transfers.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

AICD submission on SOCI Act proposed reforms

Measure 1 Exemptions Framework: We supported the development of a clearer and more flexible exemptions framework for entities, or classes of … [...]

Foreign control of AI vendors a board-level risk, ASD says

Australian boards should treat the foreign ownership, control and influence of their artificial intelligence (AI) providers as a cyber risk in its … [...]

Super funds to test coordinated cyber attack response

GNGB chief executive Michelle Bower said the exercise had become a bellwether for cooperation across the sector on cyber preparedness. The Gateway … [...]

Exclusive: Kairos ransomware lists Warwick Fabrics NZ as hack victim

Alleged 386-gigabyte data breach includes employee passports, medical reports, and salary data. • Tue, 11 Aug 2026 • Security *]:clear-none … [...]

APRA seeks $8m Bendigo cyber control penalty

The Australian Prudential Regulation Authority (APRA) has commenced Federal Court proceedings against Bendigo and Adelaide Bank, seeking approval for … [...]

AFP assessing report in connection with Perth cable faults

The Australian Federal Police is assessing a report of a potential crime after the owner of two undersea cables laid in protection zones near Perth … [...]

Two subsea communication cables damaged off Perth coast in 'concerning development'

Two subsea cables off the coast of Perth, vital for international communications, suffered a fault over the weekend, and the company that owns them … [...]

Cybersecurity concerns abate ahead of national census

Australians providing sensitive information about their sexual orientation, religion and income in the upcoming census survey are being reassured … [...]

Privacy concerns raised over Australian-first live AI police face scanning trial

An Australian-first trial of live AI facial recognition technology by a police force has been criticised by privacy experts and legal advocates. The … [...]

Origin Energy data leak cybersecurity lessons have experts worried

Three weeks ago, Origin Energy told 900,000 former and current customers that their information had been exposed in a data breach. The major … [...]

What we know about the AI agent hack on a gym booking system | ABC NEWS

An AI agent has hacked a gym website in Australia, becoming the first known case of an autonomous AI cyber attack. The AI assistant found a way to book gym [...]

AI assistant hacks gym website in first known Australian autonomous cyber attack

Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes. It was a task he thought was well suited to this … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading