A telehealth provider with uncompromised systems still had to notify its patients. The way in was a supplier — and that is now the pattern.
On Friday 31 July 2026, Australian telehealth operator Updoc identified a brief period of unauthorised access to a third-party system used to support its operations. The company blocked the access, found no evidence of further intrusion, and began contacting customers the following week. Its own platform was never accessed. No health records, financial information or payment details were involved.
Updoc did close to everything right. It detected the access, contained it quickly, and notified the people affected. And it still had to write to customers of a service that has treated more than a million patients since 2021 — because the exposure did not happen inside the perimeter it controlled.
That is the uncomfortable lesson. Your security posture is not measured by your own systems alone. It is measured by every supplier that touches your operations.
Healthcare and digital health organisations have spent years hardening the systems that obviously matter — practice management software, electronic health records, clinical databases. That work was necessary and it largely holds.
What has changed is everything bolted onto those systems. Booking engines, SMS and email gateways, payment processors, identity providers, analytics, CRM platforms, outsourced support desks, e-prescribing integrations. Each is a legitimate business tool. Each holds or moves patient data. And each is defended to its own vendor's standard, not yours.
An attacker does not need to breach a hardened clinical platform if a smaller supplier with an API key can be breached instead. That calculation is why supply chain compromise keeps appearing in Australian healthcare incidents.
The Updoc exposure was limited to names, email addresses and postal addresses of account holders. That sounds minor next to a clinical record, and in isolation it is far less damaging. But contact data taken from a health service carries something a generic mailing list does not: implied context.
Knowing that a named individual at a specific address used a telehealth service is enough to build a convincing approach. A phishing email referencing a real consultation, a fake prescription notice, an SMS about an outstanding telehealth invoice — all become plausible because the attacker knows the relationship exists. Health context makes low-sensitivity data unusually effective as raw material for fraud.
Dr Rob Hosking, Chair of the RACGP Expert Committee on Practice Technology, told newsGP that stolen data is frequently sold on and that “identities are being pursued for various purposes”. The initial breach is rarely the end of it.
“It's highly likely that people are going to try to get into your data. Obviously, health data is very popular amongst the bad players, so you've got to do everything you can to try and prevent it.”
— Dr Rob Hosking, Chair, RACGP Expert Committee – Practice Technology
Updoc follows a June 2026 incident at Partnered Health affecting at least 21 clinics nationally. That breach was materially worse — it involved medical information, Medicare numbers, consultation notes, referral letters and pathology results, and was described at the time as very distressing for those affected.
Read together, the two incidents make the point. Australian healthcare is being probed continuously, and the RACGP's own position is that attacks of this kind are now close to inevitable. Planning on the assumption that you will not be targeted is no longer a defensible position.
Most practices and digital health operators do not have a spare person to map supplier access or chase security attestations. That is the work we take on.
Updoc's systems were never breached, and it still had to notify its patients. If you cannot currently list every third party with access to your operational or patient data, that inventory is the most valuable security work available to you right now. We will build it with you.