Health service providers were the most commonly affected sector in Australia’s 2025 notifications, accounting for 19% of the total — 225 of 1,205.
The Corpus’s Standard Explanation Does Not Fit Here
At 25-0630 this desk argued that US healthcare tops breach tables partly because it is the only sector legally compelled to count, and that comparing sectors by breach volume compares reporting regimes as much as security postures.
That argument depends on healthcare having an obligation others lack. Australia’s scheme is universal — every sector notifies on the same test, to the same regulator, published in the same table.
Health leading a universal register is therefore a stronger finding than health leading a sector-specific one. The corpus made the same correction at 25-1211b, where a leak-site-derived 22% could not be explained by reporting obligations either.
Two Universal-Ish Measures Now Agree
A national all-sector register puts health first at 19%. An attacker-publication dataset puts medical organisations first at 22%, per 25-1211b.
Those are different instruments with different biases pointing the same way. The corpus should upgrade its position accordingly: healthcare concentration is probably real and not merely visible.
Why, Remains The Open Question
This desk set out four candidate properties at 25-1220b — downtime intolerance raising payment probability, constrained funding, a certified estate that cannot be patched, and an unusually deep supplier chain — and noted that none concerns the data itself.
It also recorded the alternative at 25-1215b: the same generalist platforms lead in every sector, so concentration may be affiliate opportunism rather than sector choice. Graded medium: the Australian figure narrows the explanation without settling it.
Compiled from the regulator’s published statistics, listed below. Sector share is of notifications, not of organisations or of individuals affected. Corrections: corrections@forensicpost.com.
- Data breach notifications increase to all-time high in 2025OAIC
- Data breach, cyber security and privacy law updateStephens Lawyers & Consultants