Desk live·
ForensicPost
Breaches/Healthcare/File 25-0802b

Health Providers Top the Australian Table Too

Health service providers accounted for 19% of Australian notifications in 2025 — 225 of 1,205. The corpus has argued this is a reporting artefact. In Australia that argument is weaker.

Constructed geometry · not a chart of case data
JurisdictionAustraliathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAustralian health providers
ActorMultiple
S. Rosler12 min readConfidence: medium2 sources reviewed

Health service providers were the most commonly affected sector in Australia’s 2025 notifications, accounting for 19% of the total — 225 of 1,205.

The Corpus’s Standard Explanation Does Not Fit Here

At 25-0630 this desk argued that US healthcare tops breach tables partly because it is the only sector legally compelled to count, and that comparing sectors by breach volume compares reporting regimes as much as security postures.

That argument depends on healthcare having an obligation others lack. Australia’s scheme is universal — every sector notifies on the same test, to the same regulator, published in the same table.

Health leading a universal register is therefore a stronger finding than health leading a sector-specific one. The corpus made the same correction at 25-1211b, where a leak-site-derived 22% could not be explained by reporting obligations either.

Two Universal-Ish Measures Now Agree

A national all-sector register puts health first at 19%. An attacker-publication dataset puts medical organisations first at 22%, per 25-1211b.

Those are different instruments with different biases pointing the same way. The corpus should upgrade its position accordingly: healthcare concentration is probably real and not merely visible.

Why, Remains The Open Question

This desk set out four candidate properties at 25-1220b — downtime intolerance raising payment probability, constrained funding, a certified estate that cannot be patched, and an unusually deep supplier chain — and noted that none concerns the data itself.

It also recorded the alternative at 25-1215b: the same generalist platforms lead in every sector, so concentration may be affiliate opportunism rather than sector choice. Graded medium: the Australian figure narrows the explanation without settling it.

How we reported this

Compiled from the regulator’s published statistics, listed below. Sector share is of notifications, not of organisations or of individuals affected. Corrections: corrections@forensicpost.com.

Sources
  1. Data breach notifications increase to all-time high in 2025OAIC
  2. Data breach, cyber security and privacy law updateStephens Lawyers & Consultants
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary