ZIP IT Solutions

Cyber Security

Why Health Practices Are Australia's Top Breach Target

Health service providers reported more data breaches to the OAIC in 2025 than any other industry in Australia, again. Here's why small practices are being targeted and what actually reduces the risk.

Ethan Cook

Ethan Cook · 21 July 2026 · 1 min read

Why Health Practices Are Australia's Top Breach Target

Why Small Health Practices Are Now the Top Target for Data Breaches in Australia

Health service providers reported more data breaches to the Office of the Australian Information Commissioner in 2025 than any other industry in the country. Not one large hospital system hit once. The sector as a whole, covering GPs, allied health clinics, psychologists, physiotherapists, and every other business that holds health information, accounted for 225 of the 1,205 notifications lodged that year, close to one in five of everything reported nationally, ahead of financial services, government agencies, and every other industry (OAIC, 2025).

This isn't a one-off. The OAIC's twice-yearly dashboard has shown health sitting at the top of the list for several reporting periods running, ahead of finance and government agencies each time (OAIC dashboard).

If you run a small allied health practice, it's worth sitting with that for a moment. It's tempting to assume attackers go after the big targets: hospitals, insurers, departments with millions of records on file. In practice, most of those 225 health sector breaches came from small and mid-sized practices, not tertiary hospitals with dedicated security teams. An attacker doesn't need a database of a million patients. A few thousand Medicare numbers, referral letters, and treatment notes is enough to make a practice worth targeting, and it's usually done through the simplest available method rather than anything sophisticated.

Why health data specifically

Health information sits in an unusual category. It's classed as sensitive information under the Privacy Act, which means it carries extra legal weight if it's exposed. It's also durable in a way other data isn't. A stolen credit card gets cancelled within days. A stolen Medicare number, date of birth, and treatment history doesn't expire, and it can be reused for identity theft or fraudulent billing for years after the fact.

Small practices are also, in practical terms, an easier target than a hospital network. Many still run on a shared reception login, no multi-factor authentication, an ageing server or a mix of laptops nobody is actively patching, and no formal process for reviewing any of it. None of that reflects badly on practice owners. Allied health businesses are built around clinical care, and IT has historically been something to set up once and leave alone.

What's actually causing the breaches

Malicious or criminal attacks remain the leading cause of data breaches nationally, responsible for 59 percent of all notifications in the first half of 2025, with cyber incidents such as phishing and compromised credentials driving most of that category (OAIC). Human error is close behind and rising, accounting for 37 percent of notifications in the same period, things like a file sent to the wrong recipient or a folder shared more broadly than intended.

For a practice, this usually plays out as one of a handful of scenarios:

  • A staff email account gets compromised because there's no MFA and the password has been reused somewhere else
  • A phishing email talks someone into clicking a link or handing over a login
  • Ransomware locks up the practice management system and there's no backup that's actually been tested
  • An old, unpatched device gets exploited simply because nobody's been checking for updates

None of these require a sophisticated attacker. They just require an unlocked door.

What actually reduces the risk

The controls that matter most here aren't exotic or expensive. The Australian Cyber Security Centre's Essential Eight sets out eight mitigation strategies that, properly implemented, stop the large majority of these attacks: patching applications and operating systems, restricting admin privileges, controlling which applications can run, hardening user applications, managing Office macro settings, multi-factor authentication, and regular tested backups (cyber.gov.au).

Multi-factor authentication is worth singling out on its own. Microsoft's data on Azure Active Directory accounts found MFA blocks more than 99 percent of automated account compromise attempts (Microsoft Security Blog). If there's one change a practice makes this month, that's the one with the best return for the least effort.

The rest comes down to habits more than tools: knowing which devices are actually used for practice work, keeping them patched, testing that backups restore rather than just assuming they run, and giving staff a calm, clear way to flag something that looks off instead of hoping they'll notice on their own.

Where to start

If you're not sure where your practice sits against any of this, that's the exact gap a structured assessment is built to close. Mapping your current setup against the Essential Eight, identifying the two or three changes that would make the biggest difference, and building a plan that doesn't mean ripping out everything you already have, is a far better starting point than guessing.

For a step-by-step version of the basics covered here, see our cyber security checklist for allied health practices.

Want to apply this to your practice?

We can walk through what this means for your environment on a short call, or start with a Health Check.