What reportedly happened
GO2 Health, a general practice and veteran care clinic in Everton Park, Brisbane, has confirmed one of its internal email inboxes was compromised. It appears to have been a business email compromise phishing attack. According to the clinic, some information sent to that inbox over the previous 12 months may have been accessed, including patients' Department of Veterans' Affairs ID numbers.
GO2 Health says the mailbox is separate from its main patient records system, and that this main system wasn't touched. The clinic notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. It says it has found no evidence the data was published or misused. The incident became public when the ABC reported it on 21 July, well after the clinic first identified the compromise.
Why the gap matters as much as the breach itself
Australia's Notifiable Data Breaches scheme requires organisations to tell affected individuals and the regulator as soon as practicable. That obligation kicks in once they know a breach is likely to cause serious harm. GO2 Health isn't the only recent case where that gap stretched out. Around the same time, Australian GP network Partnered Health confirmed dozens of its clinics were affected by a separate incident. It reportedly took over three weeks to notify patients once it knew.
For a small practice, the actual phishing email is the least surprising part of this story. Phishing happens to well-run organisations too. What varies enormously is what happens in the weeks after. Who decides a breach is serious enough to report. How quickly patients are told. Whether the practice can even work out what was sitting in that inbox in the first place.
What this means for a practice like yours
Most small clinics don't have a mailbox as cleanly separated from clinical records as GO2 Health describes. If anything, the more common risk runs the other way. Referral letters, scanned Medicare cards and patient notes end up living in a reception inbox that was never really designed to hold sensitive health information.
Two things worth checking this week. First, does every account that touches patient information, including a shared reception inbox, have multi-factor authentication turned on. Second, if something like this happened tomorrow, would your practice know within days what that inbox actually contained, or would it take months to find out.
