I use a GP right here in Dalby. It's an Ochre Medical Centre — same company, Ochre Health, that runs clinics in Kingsthorpe, Oakey and Toowoomba too. Good people, ordinary country practice.
Last month, one of Ochre's clinics — the one down in Tuggeranong, in Canberra — had the private details of more than 25,000 patients exposed. Names, dates of birth, addresses, Medicare numbers, veterans' (DVA) numbers, appointment and billing records. The lot.
Here's the part I want you to sit with, because it's the whole lesson: the clinic's own computers weren't hacked. The way in was a booking app the clinic uses — HotDoc — where two user accounts got compromised. The front door was fine. Somebody came in through a window the clinic didn't even own.
To be clear about the facts, because that matters to me: only the Tuggeranong clinic was affected. There's been no word that the Dalby clinic, or any Queensland Ochre centre, was caught up in it. I'm not telling you our local clinic was breached — it wasn't, as far as anyone has said. I'm telling you the company that looks after my medical records had a sister clinic lose 25,000 people's details through an app, and that should make every one of us out here pay attention.
And it wasn't the only one
While that was still settling, a much bigger one landed. A company called Partnered Health — they run more than 60 medical centres around the country — announced on 15 July that they'd been hit too. So far 21 clinics confirmed affected, and they've said it could be more; they're still working it out.
Names, birthdates, addresses and contact details were definitely taken. Medicare numbers, private health details, veterans' card numbers, and — this is the sensitive one — consultation notes, referral letters and pathology results may have been accessed too. I'm saying "may" on purpose, because that's where the investigation sits; I won't tell you more than the facts allow.
Two of these in a single month. Neither is a tiny operation. This isn't bad luck at one dodgy clinic — it's the shape of the thing.
Why this lands harder out here
There's a comfortable idea in the bush that we're a bit out of range of all this. Too far out, too small, not worth a hacker's time. I understand the instinct. It's wrong.
Your medical records don't live in a filing cabinet in the main street anymore. They live in the same national systems, the same booking apps, the same cloud services that every clinic from Bondi to Birdsville plugs into. When one of those shared bits of plumbing springs a leak, it doesn't check your postcode first. Being remote doesn't move you further from the danger — in a lot of ways it moves you closer, because we've got fewer people around to help sort it out when it goes wrong.
And the mechanism matters. In the Ochre case, the weak point wasn't the doctor, the receptionist, or anything the clinic itself runs. It was a third party — an app the clinic relies on to let you book online. Modern healthcare runs on a stack of these outside services: booking apps, billing systems, pathology portals, reminder-text providers. Every one of them holds a piece of you. You can do everything right, your clinic can do everything right, and you can still be exposed through a supplier you've never heard of.
That's the bit most people miss, and it's the bit Cyber Bushies exists to explain.
What you can actually do
You can't un-leak data that's already out. But you're not powerless, and most of this is simple.
- Assume scammers may now have your details — and expect the phone calls. The most common follow-up to a health breach isn't someone draining your bank account. It's a smooth caller who sounds legit because they know your name, your birthday, maybe your Medicare number, and uses that to talk you into handing over the rest. If a call, text or email about your health, Medicare or a "refund" arrives out of the blue — hang up and ring the organisation back on a number you looked up.
- Get a new Medicare number — not just a new card. A reader pointed out something worth spelling out here: your Medicare number is one of the documents scammers use to prove they're you — it counts toward the 100-point ID check — so a leaked number is a real identity-theft risk, not just a nuisance. Here's the catch most people miss: asking for a replacement card isn't enough, because that keeps the same number and only changes the small issue number on the front. What you actually want is to ask Services Australia to move you to a new Medicare number — a genuinely different one. It's free, and you can do it through your myGov-linked Medicare account or by phone. Veterans: same goes for your DVA details.
- Turn on two-factor (MFA) for myGov and any health logins. It's the single biggest thing that stops a leaked password becoming a broken-into account. If you're not sure how, that's exactly the kind of thing we're here to walk you through.
- Be suspicious of anything that creates urgency. "Act now," "verify immediately," "your account will be suspended" — that pressure is the tell. Real organisations will wait while you check.
- Ask your own clinic a fair question. Next time you're in: "Which outside apps and services hold my information, and what happens if one of them gets breached?" You're allowed to ask. A good clinic will have an answer. The question alone tells them their patients are paying attention.
The point of all this
I didn't write this to frighten anyone off going to the doctor. Go to the doctor. This isn't the clinics being reckless — it's that the whole system now leans on a web of third parties, and almost nobody explains that to the people whose details are riding on it.
That explaining is the whole reason Cyber Bushies is here. Your digital self — your records, your identity, your Medicare number — is worth understanding and worth protecting, whether you're in a capital city or a caravan park in Dalby. Nobody out here should have to find that out the hard way.