On 13 April 2024 MediSecure became aware of a cyber security incident on its systems. It told the public on 16 May. By 3 June the company was in voluntary administration, and the figure that eventually emerged was approximately 12.9 million individuals — a number equivalent to roughly half the population of Australia.
The Office of the Australian Information Commissioner recorded it as the largest number of individuals ever notified to it under the Notifiable Data Breaches scheme.
None of those individuals has been told whether they are among them, and on the company’s own account none ever will be.
The Reason Is Stated Plainly, In The Company’s Own Words
This made it not practicable to specifically identify all individuals and their information impacted by the Incident without incurring substantial cost that MediSecure was not in a financial position to meet.
MediSecure, public statement on the cyber security incident
The company says the affected server held an extremely large volume of semi-structured and unstructured data across a variety of data sets, and that it is unable to identify the specific impacted individuals despite making all reasonable efforts to do so.
This desk takes that at face value. There is no evident reason to doubt it, and administrators have professional obligations that make an invented excuse unlikely. The problem is not that the statement is false. The problem is that it is true.
Notification Turns Out To Be A Solvency-Dependent Right
Australia’s Notifiable Data Breaches scheme obliges an entity to notify individuals at risk of serious harm from an eligible data breach. The obligation attaches to the entity. It does not attach to the data, and it does not survive the entity in any form that produces a letter.
So the practical entitlement reads: you will be told, unless telling you costs more than the organisation has left. That condition is nowhere in the scheme and it governed the outcome completely.
It is worth being precise about who bore the consequence. The people whose Medicare numbers, prescribed medications and healthcare identifiers were in that data set are exactly the ones with no way to find out, and the collapse that removed their notification also removed the entity they might have pursued.
Every Relationship Had Already Ended Before The Breach Was Announced
Read the sequence and the ordinary story of a breach falls apart. By the time anyone was told, the service that generated the records had not run for five months, the contract that sustained it had been gone for a year, and the company itself was three weeks from administration.
The data was the last thing still operating. It had outlived the service, the contract and very nearly the company, and it was the only one of the four that a criminal group had any use for.
Nobody Chose MediSecure, And That Is The Ordinary Case
A patient handed a prescription chose a doctor and chose a pharmacy. Which of the two national exchanges carried the script between them was not a decision available to them, and most would not have been able to name it.
The corpus files this pattern under concentration and has recorded it at 24-0603 in a clinical setting and at 24-0806 for a data broker. What MediSecure adds is the terminal case: an intermediary nobody selected, holding health data nobody could withdraw, dissolving before anybody could be told.
The comparison the desk keeps returning to is 24-1015, where the operator of National Public Data filed for bankruptcy and the records it had assembled stayed in circulation. The mechanism is identical and the sector is not. One assembled data about people who never chose it; the other was handed data by a health system on their behalf.
The Regulator Said The Law Was Behind
The Australian Privacy Commissioner, Carly Kind, said in the OAIC’s published statement that the coverage of Australia’s privacy legislation lags behind the advancing skills of malicious cyber actors, and called reform of the Privacy Act urgent.
This desk would put the gap slightly differently. The failure here was not that the law lagged behind attackers. It was that a notification duty was designed on the assumption that the entity holding it would still exist, still be funded, and still have a reason to care — and all three assumptions failed inside seven weeks.
What a scheme could do about that is a policy question this desk does not answer. What the file establishes is narrower and harder to argue with: the largest notifiable breach in the country’s history produced no notifications, and nothing in the regime made that an exception.
Built on primary documents retrieved and read by this desk: MediSecure’s own public statement on the incident, the Australian Government National Cyber Security Coordinator’s advice, and the OAIC’s statement of 18 July 2024. Quotations from the company statement and the Privacy Commissioner are verbatim from those published sources. The 12.9 million figure originates with MediSecure and is reported by the Coordinator and the OAIC as advised by the company; it is a count of individuals who may have been affected, not of confirmed harm. The comparison to Australia’s population is arithmetic on published population estimates and is not a claim that half of Australians were affected. Administration dates are from ASIC published notices. This file is dated to the day the company became aware; public notification followed on 16 May 2024. Corrections: corrections@forensicpost.com.
- MediSecure cyber security incident — National Cyber Security CoordinatorAustralian Government — Department of Home Affairs
- Statement on MediSecure breachOffice of the Australian Information Commissioner
- Media / public statement on the cyber security incidentMediSecure
- MediSecure Ltd — voluntary administration, published noticeAustralian Securities and Investments Commission
- MediSecure confirms 12.9m Australians impacted by May data breachCyber Daily