AD
RACGP
Medical Forum Logo

Medical Forum

Cyber security reminder as telehealth company hit by data breach

Healthcare organisations are urged to make sure their cyber security processes are up to date as the use of AI and telehealth increases.

woman on computer and phone authenticating identity

It comes as telehealth company Updoc reported a data breach in which patient emails, names and addresses may have been accessed.

A spokesperson confirmed that on July 31 the company identified a brief period of unauthorised access to a third-party system that is used to support its operations.

“The access was isolated and involved contact information, which may have included the name, email and postal address of account holders,” they said.

“Updoc’s own systems were not accessed, and no health information, financial information or payment details were involved.”

Immediate action was taken to block the unauthorised access and no further breaches have been discovered, the company said in a statement.

Customers were not required to take immediate action, and login and account security remain unaffected, it said.

AD

It is the second report of a health data breach in the last few months.

Director of the WA Data Science Innovation Hub Alex Jenkins told Medical Forum it was vital that data security protocols were in place when handling patient information.

“There’s no more sensitive and private information than patient’s health data,” he said.

“GPs everywhere, and all clinicians, have a responsibility to ensure that they’re taking all precautions required to keep that data safe and that they are using services with responsible data storage processes."

He said it was likely that attempts to breach data security would become more common as the use of technology increases in healthcare settings, but that shouldn’t put people off using technology.

“As more of our health services become digital and decentralised, I would expect to then see more issues with cyber security.

“The other thing I would expect to see continue as a trend is the use of AI services to assist clinicians. That also presents an increased risk of breaches simply because of the number and type of services we are doing.”

AD

In June, three clinics in WA were among a number of GPs clinics hit by a cyber attack in which patient records were stolen.

Partnered Health, which runs 57 primary care clinics across Australia, confirmed it had been the subject of a malicious cyber attack, with 21 GP clinics impacted.

Information that may have been accessed included name, date of birth and contact details, as well as medical information and treatment details including consultation notes, referral letters, and pathology or diagnostic results recorded by a GP or other medical professional.

There are a number of resources to help healthcare professionals shore up their cyber security and data protocols.

Digital Health Australia has a range of resources on cyber security awareness for healthcare organisations. You can access those resources here.

Ahpra also has a resource on meeting your professional obligations when using AI in healthcare.

AD