RACGP
Andrea Downey

Andrea Downey

Medicare hack a 'wake-up call' to keep patient data safe

While patient data may not have been accessed, the AI hack of Medicare should be a “wake-up call” to everyone who is responsible for holding health data.

Almost 500 WA GPs to pay back money incorrectly claimed through Medicare

Dr Sean Stevens, Chair of the RACGP Digital Health and Innovation Specific Interest Group, said the event reinforced the importance of ensuring patient data is protected.

“Health information is among the most sensitive and valuable data there is. Unlike a credit card number, it can't be cancelled and reissued. Once a diagnosis, a mental health history or a sexual health result is exposed, it can't be taken back,” he told Medical Forum.

“This should be a wake-up call for everyone who holds health information: government agencies, technology companies, hospitals and general practices alike.”

This week Prime Minister Anthony Albanese confirmed an OpenAI agent hacked Medicare in June, gaining unauthorised access to the Medicare statistics portal operated by Services Australia.

The portal does not contain sensitive patient information but does contain statistics related to Medicare, such as spending.

The Prime Minister said the agent had accessed public and non-public files.

The Australian Institute of Health and Welfare (AIHW) was also hacked in the same incident.

It took OpenAI three months to notify the federal government of the hack.

AD

Dr Stevens, a Perth-based GP who is also a clinical consultant for AI platform Lyrebird, said he was relieved no sensitive information had been accessed but the event was still serious and should be treated as such.

“From what we know, an AI agent was given what appears to have been a routine research task. When a government portal didn't give it the information it wanted, it found its own way past the controls to data it wasn't authorised to access,” he said.

“Nobody instructed it to break in. That is a significant shift from the cyber threats we are used to dealing with.”

He said as AI evolves and becomes more widely used these events may become more common.

“I do think we will see more of this. AI agents are becoming more capable and more autonomous very quickly. Many of our systems were designed to keep out human intruders, not persistent, tireless automated agents.”

Reminder that trust is paramount

While on this occasion no patient information appears to have been accessed, Dr Stevens said it was a timely reminder that keeping patient data safe was a core part of professional practice.

“Trust is the foundation of general practice. Patients tell their GP things they may never tell anyone else, because they trust that information will stay confidential,” he said.

“Every incident like this, even one where no personal data is exposed, chips away at public confidence in digital health and in AI more broadly.

AD

“That matters because AI has real potential to improve care. Tools like AI scribes are already reducing the administrative load on GPs and giving us more time to focus on the patient in front of us.

“If people lose confidence in the technology, they may hold back information from their doctor or opt out of tools that could genuinely help them.

The federal government has launched an investigation into the matter.

The AIHW said in a statement that it was aware its public-facing website was accessed by OpenAI.

“At this stage, there is no evidence the agent accessed any information or data that is not publicly available.

We are working with other relevant agencies across government to support a coordinated response.”

Protecting your patient's data

Dr Stevens said protecting patient information is a core professional and legal obligation, on par with infection control.

He gave some practical steps that he says every practice should be taking.

"First, use multi-factor authentication on everything that touches patient information, including clinical software, email, remote access and government portals.

"Second, make sure data is encrypted, both when stored and when transmitted - that includes backups, laptops and mobile devices.

"Third, keep only what you need, for only as long as you need it. The medical record itself must be retained for the legally required period. But secondary copies should be deleted within a short period of time once they have served their purpose. This includes AI scribe audio and transcripts, exported reports, downloaded files and email attachments."

He said practitioners should also ask the hard questions of any AI or software vendor.

"Where is the data stored? Is it kept in Australia? How long is it retained? Is it used to train AI models?

"Beyond that, keep software up to date, limit access to staff who genuinely need it, train staff to recognise phishing, and have a plan ready for responding to a breach, including your obligations under the Notifiable Data Breaches scheme."

More information on security resources for general practice can be found here.


AD