After Partnered Health, patient data cannot be the password

6 minute read


A patient’s medical information is too valuable, too sensitive and too permanent to be treated as a password once it may have been breached.


The danger in a health data breach is not limited to the files that leave a provider’s system, but it is what those files allow someone to do next.  

The recent cyberattack on Partnered Health may have exposed patient information across 21 Australian clinics, including Medicare and private health insurance details, addresses, consultation notes, referrals and pathology results.  

Experts have warned the data could be sold on the dark web. 

For an affected patient, this is more than a loss of privacy. Their medical record can become a detailed script for someone trying to impersonate them.  

A criminal who knows a person’s name and email address can send a generic scam. A criminal who knows their GP practice, insurer, address, referral history and treatment information can make a call, text or email appear to be part of ordinary care.  

That is the risk Australia’s health sector now needs to prepare for.  

A breach changes the status of the information that has been taken. Details used every day to check a patient’s identity should no longer be relied on alone once they may be in criminal hands. 

The patient file can become the answer sheet 

A patient calling a general practice is often asked to confirm straightforward details before a receptionist discusses an appointment or account. Their date of birth, address or Medicare number may be used to establish who they are. Similar information can help a person recover access to an online portal or manage a record remotely.  

These are reasonable checks when the information is private, they are far less reliable when a person’s patient file may have been exposed.  

Someone who can recite a patient’s date of birth, address, Medicare details and recent treatment history can sound legitimate. But sounding legitimate is not the same as being the patient.  

This distinction becomes critical when the request is consequential. It might involve access to consultation notes or pathology results, a password reset for a patient portal, a change to the phone number or email address attached to a record, or the addition of a family member, carer or other authorised representative.  

A clinic needs more than familiarity with the patient’s information before allowing those actions to take place.  

Healthcare has long understood its obligation to keep patient information confidential, but it now needs to consider what happens when that information is used as the key to unlock further access. 

The risk can follow patients through everyday care 

Australians increasingly manage healthcare across a mix of providers and channels. A patient might visit a GP, receive a referral, attend a pathology provider, fill an electronic prescription, deal with a health insurer and use an online portal in the space of a few weeks.  

Digital services have made this easier, but they have also created more opportunities for a fraudster to pose as a trusted part of that journey. 

After a breach, a text asking a patient to view a result, confirm an appointment or update their details can feel entirely plausible. A phone call that refers to a real clinic, referral or recent treatment may be even harder to question.  

The aim may be to persuade a person to reveal more information, follow a malicious link or accept a change to their record. 

Patients should be alert to this risk, but they cannot be expected to detect every well-crafted impersonation attempt.  

Health providers have a role to play in making genuine communications easy to recognise and suspicious ones easy to challenge. That includes being clear about how they contact patients, what they will never ask for by text or phone, and where a patient can independently verify whether a message or request is real.  

A breach notification should also be the beginning of a patient-protection plan. It should prepare people for the ways their information could be used in the weeks and months that follow, rather than simply confirm what data may have been accessed. 

High-risk requests need a higher standard 

No one wants a visit to the doctor to become another frustrating digital obstacle course. People need quick access to care, and general practices and health services are already under pressure.  

A better approach is to focus stronger identity checks on the moments where the consequences of getting it wrong are highest.  

Booking a standard appointment is different from releasing a full medical record. Confirming a referral is different from resetting access to a patient account. Changing a contact number or adding an authorised representative can have long-lasting implications if the wrong person is making the request. 

The level of identity assurance should reflect that difference.  

Information such as a Medicare number, date of birth and address can be useful context, but it should not be the final test for a sensitive action when that same information may have been exposed.  

This does not mean health providers should respond to a breach by asking patients to email another copy of their passport or driver licence. That simply creates more high-value documents to store across a fragmented health system.  

The better goal is to verify a person for the specific action they are trying to take, while collecting and retaining as little additional data as possible.   

Identity protection is now part of patient safety 

Australia’s digital health future depends on patients trusting that they can access care and manage their information without someone else stepping into their place.  

Cybersecurity remains essential, but a system can be well secured today and still leave patients vulnerable tomorrow if stolen information can be used to pass routine identity checks.  

The Partnered Health incident should prompt a simple question across the sector: if the personal details usually used to identify a patient may now be in criminal hands, what else proves that the person making a sensitive request is genuine? 

The answer will need to work for people with different needs, levels of digital confidence and access to technology. It must also allow health professionals to provide care without unnecessary delay.  

But the principle should be clear – a patient’s medical information is too valuable, too sensitive and too permanent to be treated as a password once it may have been breached. Protecting patients means protecting their records, their privacy and their ability to control what happens in their name. 

Fred Slikker is the managing director at Digidentity. 

End of content

No more pages to load

Log In Register ×