Advertising


News

Telehealth company hit by data breach


Jolyon Attwooll


6/08/2026 4:02:54 PM

Experts are urging GPs and practices to review cyber security plans after a breach may have exposed Updoc patients’ contact details.

hacker on laptop
A new data breach is the latest in several recent cases affecting health companies across Australia.

Patients of telehealth operator Updoc may have had their email and address details leaked, after ‘unauthorised access’ was detected to a third-party system.  
 
The company contacted its customers this week to advise them of the breach.
 
In a statement on Thursday, an Updoc spokesperson said the incident was isolated and involved contact details ‘which may have included the name, email and postal address of account holders’. 
 
‘On Friday 31 July, Updoc identified a brief period of unauthorised access to a third-party system that is used to support its operations,’ they told newsGP.
 
‘Updoc’s own systems were not accessed and no health information, financial information or payment details were involved.
 
‘Updoc took immediate actions to block the unauthorised access and there has been no evidence of access after the initial event.’
 
The telehealth operator said customers did not need to take any immediate action and that login and account security are not affected.
 
‘Updoc apologises to its customers for any concern or inconvenience this event has caused,’ the spokesperson said.
 
Updoc was launched in 2021, and according to its founders has served more than a million patients since.
 
Dr Rob Hosking, Chair of the RACGP Expert Committee – Practice Technology, said the latest breach is a reminder to GPs and practice owners that such attacks are now ‘almost inevitable’, with healthcare organisations often a preferred target.
 
‘It’s highly likely that people are going to try to get into your data,’ he told newsGP.
 
‘Obviously, health data is very popular amongst the bad players, so you’ve got to do everything you can to try and prevent it.’
 
He believes AI is likely to increase the frequency of attempted breaches, pointing GPs to the RACGP’s information security guidelines – and says that as well as prevention, practice managers need to know what to do if a breach occurs.
 
‘The thing is to make sure every practice has their plan in place and people know what to do if it were to happen to them, in terms of notifying the Office of the Australian Information Commissioner that there’s been a data breach, and notifying affected patients as soon as you can,’ he said.
 
‘We’re certainly seeing people stealing data and quite likely that’s being used on the dark web, sold somewhere and identities are being pursued for various purposes.
 
‘All you can do is make sure you’ve got the best systems you can in place, train your staff as best you can so that they don’t inadvertently click on links.’
 
The Updoc breach follows a June incident affecting patients at Partnered Health, with at least 21 clinics around Australia impacted.
 
The breach involved medical information, Medicare numbers, consultation notes, referral letters and pathology in what was described as a ‘very distressing’ cyberattack.
 
Resources to support GPs and general practices’ information security, including preparing for and preventing a cyberattack and how to respond to a breach, are available on the RACGP website.
 

Log in below to join the conversation.


cybersecurity information security telehealth Updoc


newsGP weekly poll Which digital health initiative would have the greatest positive impact on your practice?
 
50%
 
9%
 
22%
 
1%
 
3%
 
12%
Related



newsGP weekly poll Which digital health initiative would have the greatest positive impact on your practice?

Advertising

Advertising

 

Login to comment