
Cyber security framework gaps can be a costly oversight
The health sector again tops the list for data breach notifications, according to the Office of the Australian Information Commissioner’s (OAIC) 2025 figures.1 Malicious or criminal attacks remains the biggest cause at 59%, with phishing (28%), ransomware (21%) and compromised credentials (21%) leading the pack.
CyberCX’s threat Report 20262 names cyber extortion as the most common incident type and warns that AI is lowering the bar for criminals to get started.
In June 2026, the Five Eye cyber agencies released a joint statement,3 on how AI is reshaping the threat landscape. Their message is clear, cyber resilience is now a core business risk, not just an IT problem.
It makes it essential to have a cyber security and privacy framework that is both robust and, tested and found to be working day to day.
This expectation is reinforced by the first tranche of Privacy Act reforms, passed in December 20244, which make clear that complying with Australian Privacy Principle (APP) 11 means having demonstrable technical and organisational measures (TOMs)5 in place to protect personal information. Practices need frameworks that hold up not just on paper, but under closer regulatory scrutiny and more active OAIC enforcements.
Cyber security frameworks: the practical lessons
Private medical practices are entities under the Privacy Act. APP 11 requires them to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modifications or disclosure. “Reasonable steps” covers both technical and organisational measures.6
What counts as technical and operational safeguards?
Technical safeguards are the physical and IT controls that limit information from being accessed or disclosed without authorisation: securing premises, encrypting data, running anti-virus software, enforcing strong passwords, keeping tested backups, restricting access and monitoring for intrusions.
Organisational safeguards are how a practice puts its security plans into action, for example; training staff and maintaining procedures and policies for handling personal information.
There is no one size fits all checklist. What counts as “reasonable” depends on the practice: its size, the nature of its business and how much sensitive information it holds. The Australian Clinical Labs case below shows why that matters. The Avant claims that follow also show how the same gaps play out in everyday practice.
The Australian Clinical Labs case
On 8 October 2025, Australian Clinical Labs (ACL), an ASX listed health provider, agreed to pay $5.8 million in penalties 7, the first time a court has imposed civil penalties under the Privacy Act 1988 (Cth).
Background
In February 2022 ACL suffered a ransomware attack on IT assets it had acquired from Medlab Pathology Pty Ltd (Medlab) three months earlier. The attack exposed the health information of more than 223,000 people, later published on the dark web. Medlab held health, contact, passport and payment details for patients undergoing prenatal genetic testing, fertility assessment and STD testing.
The court’s decision
The federal court found ACL had failed to take reasonable steps to protect patients' information, based on a holistic assessment of its systems, policies and procedures8. The court took into account:
- ACL's size and sophistication, noting ACL turns over more than $600 million a year and employed more than 5,000 staff at the relevant time
- the sensitivity of the information it held
- the potential harm from disclosure and the wider cyber security risk environment.
The court also considered Medlab's undetected IT deficiencies and ACL's over-reliance on third-party providers.
ACL conceded its incident playbooks lacked containment and escalation steps, that the Medlab IT Team had never been trained on them; that there were no controls to detect data exfiltration or unauthorised software; that firewall logs lasted only for an hour; that no data recovery plan existed; and that VPN access didn’t require multifactor authentication.
The judgment gives useful guidance on what the OAIC and courts will treat as “reasonable steps” going forward.
ACL’s $5.8m penalty was made up of:
- a $4.2m penalty for failing to take reasonable steps to protect personal information on Medlab Pathology’s IT systems, a breach of Australian Privacy Principle 11.1 more than 223,000 times
- an $800,000 penalty for failing to quickly assess whether the February 2022 cyberattack was a reportable data breach
- an $800,000 penalty for failing to promptly report the breach to the Australian Information Commissioner.
Penalties under the Act have since increased substantially. The penalty regime which came into effect on 13 December 2022 allows the Court to impose penalties as much as $50 million, three times the benefit derived from the conduct or up to 30% of a business’ annual turnover per contravention.
Lessons from real Avant claims
These Avant case studies show a cyber-attack is no longer a question of "if" but "when". They also show how the right support at the time can limit the damage.
Phishing disguised as a patient message
A practice received a phishing email posing as a message from an existing patient, prompting staff to download a file via a malicious link. Luckily, the compromised mailbox had no administrative rights and wasn’t linked to the patient database. Avant's Risk Advisory Service helped the practice tighten its email controls and meet its OAIC obligations.
Phishing leads account takeover
A staff member clicked a phishing link and entered their login details on a fake page. The stolen credentials were used to send 500 phishing emails, and a legitimate, commercially available third-party email app connected to the mailbox9 let the attacker quickly exfiltrate large volumes of data. Avant guided the practice through the OAIC notification and the patient communications that followed.
Ransomware attack
Staff arrived one morning unable to access Remote Desktop Services or their medical software; their virtual servers had been encrypted, and a ransom note left behind. The attackers had deleted all backups bar one, which was six months out of date. Avant helped the medical practice engage forensic specialists and manage the recovery, from restoring systems to notifying patients.
Summary
From a listed pathology provider to a solo practice, the lesson is the same: a cyber incident tests whether your framework holds up in practice, not just on paper. The fallout can be potentially significant and long-lasting. The Australian Signals Directorate puts the average cost of a breach to a small organisation at $56,000 and rising.¹⁰ Cyber insurance may cover some of that cost, but it won't repair your reputation or your patients' trust.
Avant's Claims and Risk Advisory teams can help members through notification, remediation and recovery. But your best protection is still getting the fundamentals right: a solid cyber security framework, backed by genuine staff training.
More information
For medico-legal advice, please contact us on nca@avant.org.au or call 1800 128 268, 24/7 in emergencies.
For Avant Risk Advisory Services visit avant.org.au/risk-advisory-services.
Further resources
- Office of the Australian Information Commissioner. Notifiable data breaches statistics dashboard [Internet]. 2025 [cited 2026 Jul 14]. Available from: https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breach-statistics-dashboard
- CyberCX. 2026 threat report [Internet]. 2026 [cited 2026 Jul 14]. Available from: https://cybercx.com.au/news/2026-threat-report/
- Australian Signals Directorate. Five Eyes cyber security agencies statement [Internet]. 2026 Jun 22 [cited 2026 Jul 14]. Available from: https://www.asd.gov.au/news/2026-06-22-five-eyes-cyber-security-agencies-statement
- Attorney-General's Department. Explanatory memorandum to the Privacy and Other Legislation Amendment Bill 2024. Canberra: Commonwealth of Australia; 2024. Para 101–102.
- “TOM” the acronym is used in the EU’s General Data Protection Regulation, see https://grcsolutions.io/a-guide-to-gdpr-technical-and-organisational-measures/
- Office of the Australian Information Commissioner. Australian Privacy Principles guidelines: chapter 11, APP 11, security of personal information [Internet]. [cited 2026 Jul 14]. Available from: https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information
- Office of the Australian Information Commissioner. Australian Clinical Labs ordered to pay penalties in relation to Medlab Pathology data breach in first for Privacy Act [Internet]. 2025 Oct 8 [cited 2026 Jul 14]. Available from: https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act
- Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224.
- Kroll. Enterprise applications in M365 used to exfiltrate data [Internet]. [cited 2026 Jul 14]. Available from: https://www.kroll.com/en/publications/cyber/enterprise-applications-in-m365-to-exfiltrate-data
- Australian Signals Directorate. Annual cyber threat report 2024–25 [Internet]. 2025 [cited 2026 Jul 14]. Available from: https://www.cyber.gov.au/sites/default/files/2025-10/Annual%20Cyber%20Threat%20Report%202024-25.pdf
The information in this publication does not constitute legal, financial, medical or other professional advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. Persons implementing any recommendations contained in this publication must exercise their own independent skill or judgement and seek appropriate professional advice relevant to their own particular circumstances. Compliance with any recommendations will not in any way guarantee discharge of the duty of care owed to patients and others coming into contact with the health professional or practice. Avant and its related entities are not responsible to any person for any loss suffered in connection with the use of this information. Information is only current at the date initially published.
Avant Cyber Insurance cover is available to eligible Avant Practice Medical Indemnity Policy holders up to the cessation of their policy and is provided under a Group Policy between Liberty Mutual Insurance Company (ACN 086 083 605) (Liberty) and AIL.