LIVE DEFENSE
Zero Breaches (24h)
← Back to Vault

Beyond the Front Door: What the Updoc Breach Teaches Us About Third-Party Vendor Risk

A telehealth provider with uncompromised systems still had to notify its patients. The way in was a supplier — and that is now the pattern.

On Friday 31 July 2026, Australian telehealth operator Updoc identified a brief period of unauthorised access to a third-party system used to support its operations. The company blocked the access, found no evidence of further intrusion, and began contacting customers the following week. Its own platform was never accessed. No health records, financial information or payment details were involved.

Updoc did close to everything right. It detected the access, contained it quickly, and notified the people affected. And it still had to write to customers of a service that has treated more than a million patients since 2021 — because the exposure did not happen inside the perimeter it controlled.

That is the uncomfortable lesson. Your security posture is not measured by your own systems alone. It is measured by every supplier that touches your operations.

The Perimeter Moved and the Defences Did Not

Healthcare and digital health organisations have spent years hardening the systems that obviously matter — practice management software, electronic health records, clinical databases. That work was necessary and it largely holds.

What has changed is everything bolted onto those systems. Booking engines, SMS and email gateways, payment processors, identity providers, analytics, CRM platforms, outsourced support desks, e-prescribing integrations. Each is a legitimate business tool. Each holds or moves patient data. And each is defended to its own vendor's standard, not yours.

An attacker does not need to breach a hardened clinical platform if a smaller supplier with an API key can be breached instead. That calculation is why supply chain compromise keeps appearing in Australian healthcare incidents.

“Only Contact Details” Is Not a Small Problem

The Updoc exposure was limited to names, email addresses and postal addresses of account holders. That sounds minor next to a clinical record, and in isolation it is far less damaging. But contact data taken from a health service carries something a generic mailing list does not: implied context.

Knowing that a named individual at a specific address used a telehealth service is enough to build a convincing approach. A phishing email referencing a real consultation, a fake prescription notice, an SMS about an outstanding telehealth invoice — all become plausible because the attacker knows the relationship exists. Health context makes low-sensitivity data unusually effective as raw material for fraud.

Dr Rob Hosking, Chair of the RACGP Expert Committee on Practice Technology, told newsGP that stolen data is frequently sold on and that “identities are being pursued for various purposes”. The initial breach is rarely the end of it.

“It's highly likely that people are going to try to get into your data. Obviously, health data is very popular amongst the bad players, so you've got to do everything you can to try and prevent it.”

— Dr Rob Hosking, Chair, RACGP Expert Committee – Practice Technology

Context: This Was Not an Isolated Case

Updoc follows a June 2026 incident at Partnered Health affecting at least 21 clinics nationally. That breach was materially worse — it involved medical information, Medicare numbers, consultation notes, referral letters and pathology results, and was described at the time as very distressing for those affected.

Read together, the two incidents make the point. Australian healthcare is being probed continuously, and the RACGP's own position is that attacks of this kind are now close to inevitable. Planning on the assumption that you will not be targeted is no longer a defensible position.

What Healthcare Providers Should Do Now

  • Inventory every third party with access. You cannot govern what you have not listed. Record each supplier, what data it can reach, how it authenticates, and who internally owns the relationship. Most organisations find integrations nobody remembers approving.
  • Apply least privilege to suppliers, not just staff. Vendor accounts and API keys are routinely over-permissioned at go-live and never revisited. Scope each to the minimum it genuinely needs, and remove access when a contract ends.
  • Put security obligations in the contract. Breach notification timeframes, data residency, subcontractor disclosure and audit rights belong in writing before an incident, not negotiated during one.
  • Rehearse the notification path. Under the Notifiable Data Breaches scheme, an eligible breach requires notification to the Office of the Australian Information Commissioner and to affected individuals. Know who assesses, who decides and who writes to patients — before you need to.
  • Warn patients about follow-on contact. If contact data is exposed, the practical risk to patients is the next message they receive. Tell them plainly what you will and will not ask for.
  • Reassess suppliers on a schedule. A security questionnaire completed at onboarding says nothing about a vendor's posture two years and one acquisition later.

How ACS Approaches Vendor Risk

Most practices and digital health operators do not have a spare person to map supplier access or chase security attestations. That is the work we take on.

  • Assess: We build the third-party inventory, review what each supplier can actually reach, and identify over-permissioned integrations and dormant vendor accounts.
  • Govern: Through our vCIO and strategic governance engagements, supplier risk becomes a standing agenda item with an owner and a review cycle, aligned to Essential Eight maturity and ASD guidance.
  • Respond: We prepare and rehearse the incident response and notification plan, so a supplier's breach becomes a process you follow rather than a crisis you improvise.

Know What Your Suppliers Can Reach

Updoc's systems were never breached, and it still had to notify its patients. If you cannot currently list every third party with access to your operational or patient data, that inventory is the most valuable security work available to you right now. We will build it with you.

Sources

  • newsGP (RACGP) — Jolyon Attwooll, “Telehealth company hit by data breach”, 6 August 2026
  • newsGP (RACGP) — “Medical information stolen in major cyberattack” (Partnered Health, June 2026)
  • RACGP — Information security guidelines, Protecting your practice information
  • Office of the Australian Information Commissioner — Notifiable Data Breaches scheme