Brisbane clinic delayed patient breach alert by 3 months after phishing attack

Patients, including veterans receiving psychological treatment, had sensitive personal and medical information exposed for months without their knowledge, delaying their ability to protect themselves through password changes and account monitoring.
They've wasted really precious time for people to protect themselves
A veteran patient reacts to the three-month delay in learning her sensitive health data was exposed.
Mark

Why did it take the clinic so long to tell patients? Was it genuinely difficult to figure out who was affected?

Mimi

The clinic says the investigation took time to identify which patients had emails in that mailbox over the 12-month window. But there's a tension there—they alerted regulators in May, so they knew enough to do that. The delay to patients suggests other priorities were at play.

Mark

What was actually exposed? How sensitive is this information?

Mimi

Department of Veterans Affairs IDs, personal health details, psychological treatment records in some cases. For a veteran receiving mental health care, that's not abstract—it's the most intimate details of their life sitting in an email system. The clinic kept saying the main database was safe, but that misses the point. The email itself was the problem.

Mark

The clinic said they wanted to avoid "undue concern." Is that a fair reason to wait three months?

Mimi

It sounds protective, but it's paternalistic. It assumes patients can't handle the truth or will panic. What it actually does is steal their agency. Amanda couldn't change her passwords or monitor her accounts because she didn't know she needed to. That's not protection—that's delay.

Mark

What's the regulatory picture here? Aren't there rules about this?

Mimi

Yes. Clinics have to notify authorities within 30 days if a breach is likely to cause serious harm. GO2 Health did that. But there's no rule requiring them to notify patients quickly. That's the gap experts are pointing to now. The law protects the regulator's right to know, but not the patient's right to act.

Mark

Is this just a GO2 Health problem, or is it broader?

Mimi

Broader. Partnered Health, a much larger operator, took 22 days to notify patients after a breach affecting 16 clinics. These aren't isolated failures—they're symptoms of how the system treats patient notification as a box to check, not an urgent duty.

Mark

What does Amanda do now?

Mimi

She's changing her Medicare number, trying to get clarity on her veterans card, and she's going to be more cautious about where her data goes. But she's still a patient who needs treatment. The breach hasn't changed that. It's just made her more wary of the people she has to trust.

  • A phishing attack in April silently compromised GO2 Health's email system, exposing Department of Veterans Affairs IDs and personal health records belonging to patients — including veterans in psychological treatment — without their knowledge for nearly three months.
  • The clinic notified regulators in May, satisfying the 30-day legal threshold, but chose to withhold patient notification until July 16, citing the need to accurately identify who was affected before communicating — a delay that cybersecurity experts and patients alike are questioning.
  • For veteran patient Amanda, the three-month gap was not caution — it was lost time: passwords unchanged, accounts unmonitored, and a window to self-protect quietly closed while the clinic refined its list.
  • GO2 Health's breach follows a near-simultaneous incident at Partnered Health, signalling a pattern that is pushing cybersecurity experts to call for mandatory early-stage patient notification laws in Australian medical settings.
  • Amanda has since applied to change her Medicare number, sought guidance on her Veterans Affairs card, and received no reply — left navigating the aftermath of an exposure she was the last to know about.

In the quiet suburb of Everton Park, Brisbane, a phishing attack in April quietly unravelled the private lives of patients at GO2 Health — veterans among them — before anyone thought to tell them. The clinic moved swiftly to contain the breach and dutifully informed regulators within the required window, yet the people most affected waited nearly three months to learn their sensitive health and identity records had been exposed. It is an old tension made newly urgent: the institutional need for certainty before speaking, weighed against the human need to know in time to act.

In April, hackers used a phishing attack to access an email account at GO2 Health, a Brisbane clinic serving general and veteran patients. The clinic discovered the intrusion on April 24 and engaged security experts immediately. The compromised mailbox held a year's worth of sensitive material — Department of Veterans Affairs identification numbers, personal health information, and patient communications — though the clinic confirmed its core patient database was not affected.

GO2 Health notified the Office of the Australian Information Commissioner on May 18, meeting the regulatory requirement to report within 30 days of a breach likely to cause serious harm. But patients themselves were not informed until July 16 — nearly three months after the attack. The clinic explained the delay as a matter of accuracy: investigators needed time to determine precisely who had been affected before sending notifications, to avoid alarming the wrong people with incomplete information.

For veteran Amanda, receiving psychological treatment at the clinic, that reasoning rang hollow. Three months, she said, was three months of opportunity lost — time she and others could have spent changing passwords and monitoring accounts for suspicious activity. She has since applied to change her Medicare number and attempted to contact the clinic about her Veterans Affairs card, without receiving a response.

The incident is the second to strike Australian medical clinics in quick succession, following a breach at Partnered Health affecting 16 of its nearly 60 clinics in June — with patients notified after 22 days. Cybersecurity experts are now pressing for stricter regulations that would compel clinics to alert patients earlier in breach investigations, arguing that the sensitivity of health and veteran data demands a faster standard of transparency. Amanda, for her part, says she will continue seeking treatment — but with sharper questions about how her most private information is being kept.

In April, hackers broke into the email system at GO2 Health, a medical clinic in Brisbane's northern suburb of Everton Park. The breach came through a phishing attack—a common tactic where criminals trick employees into revealing credentials. The clinic discovered the intrusion on April 24 and immediately brought in security experts to contain the damage. But the patients whose information had been exposed didn't learn about it until July 16, nearly three months later.

The mailbox that was compromised contained sensitive material: Department of Veterans Affairs identification numbers, personal health information, and details from patient communications spanning the previous year. The clinic emphasized that the breach was limited to email—the main patient database remained secure. Still, the exposure was real and substantial. GO2 Health, which provides general practice and veteran care services, alerted the Office of the Australian Information Commissioner on May 18, meeting the regulatory requirement to notify authorities within 30 days of discovering a breach likely to cause serious harm. But the patients themselves waited nearly two more months.

The clinic's explanation for the delay centered on accuracy. A spokesperson said the investigation took time to identify exactly which patients had been affected, and the clinic wanted to avoid sending alerts to the wrong people or providing incomplete information. "We wanted to avoid causing undue concern and confusion by notifying the wrong people, or communicating inaccurate information," they said. It's a reasonable-sounding argument, but it left actual patients in the dark for a quarter of a year.

Amanda, a veteran receiving psychological treatment, was among those who eventually received the notification. She understood the clinic's desire to get the details right, but she saw the delay differently. Three months, she said, represented lost opportunity—time her and other patients could have spent changing passwords, monitoring accounts, and taking protective steps. "I think they've wasted really precious time for people to check their accounts and change their passwords," she said. For someone whose sensitive mental health information had been sitting in an exposed mailbox, the window to act had simply closed.

The breach at GO2 Health is the second major incident to hit Australian medical clinics in a matter of days. Partnered Health, a larger operator with nearly 60 clinics, had 16 of them compromised in June and notified patients after 22 days. Cybersecurity experts are now pushing for stricter rules that would require medical clinics to alert patients much earlier in the investigation process, rather than waiting until every detail is confirmed. The argument is straightforward: health information is uniquely sensitive, and the people whose data is at risk deserve to know sooner rather than later.

Amanda has already applied to change her Medicare number and tried to contact GO2 Health to ask whether she should update her Department of Veterans Affairs card as well. She hasn't received a response. Going forward, she said she would continue seeking treatment but with new caution. "I'm still going to be needing to receive treatments, but I think I'm going to be more cautious and ask more questions around how my data is stored." The breach has left her, and others like her, with a harder question to answer: how much do you trust an institution with your most private information when it takes them three months to tell you it's been compromised?

They've wasted really precious time for people to check their accounts and change their passwords.
— Amanda, affected patient and veteran
We wanted to avoid causing undue concern and confusion by notifying the wrong people, or communicating inaccurate information.
— GO2 Health clinic spokesperson
Contact Us FAQ