Adelaide's St Andrew's Hospital Confirms Data Breach and Notifies Privacy and Cyber Authorities
St Andrew's Hospital, a private hospital in Adelaide, has confirmed a data breach involving personal information. In a limited statement, the hospital said the breach affected "a group of individuals". The number of people impacted and the circumstances of the incident have not yet been made public.
Hospital CEO Angela McCabe said its investigation had progressed far enough to contact affected individuals directly, in line with the hospital's regulatory obligations. Those people have been given information and support on how to protect their personal details. The Office of the Australian Information Commissioner and the Australian Cyber Security Centre have also been notified. The hospital said it is working with government agencies to apply additional protective measures to help detect and prevent suspicious and fraudulent activity.
Under the Privacy Act, organisations covered by the Notifiable Data Breaches scheme must report breaches likely to cause "serious harm" to the OAIC. The OAIC says such harm can arise from exposure of health information, documents commonly used for identity fraud, and financial information. South Australian Premier Peter Malinauskas said he expected a briefing on the matter, including whether any criminal activity was involved, and that law enforcement agencies would need to assess the situation.