Full Report
Patients at one of Adelaide’s largest private hospitals are being notified after personal and health-related information was stolen in a cyber incident. St Andrew’s Hospital confirmed it was contacting affected individuals after identifying those whose information had been compromised. In a statement authorised by chief executive Angela McCabe, the hospital said affected patients would receive information about the breach and support to help protect their personal information. “Our investigation into the nature and extent of the incident has now progressed to the point where we can communicate directly with affected individuals, in line with our regulatory obligations,” the statement said. 7NEWS.com.au understands information downloaded in the cyberattack included patients’ full names, phone numbers, residential addresses, email addresses, dates of birth, Medicare card numbers and healthcare identifiers.
Analysis Summary
# Incident Report: St Andrew’s Hospital Data Exfiltration
## Executive Summary
St Andrew’s Hospital, a major private healthcare provider in Adelaide, suffered a cyber incident resulting in the unauthorized access and theft of sensitive patient data. The breach involves highly sensitive medical identifiers and personal information, leading to a large-scale notification process for affected individuals. The hospital is currently working with forensic experts and federal regulators to mitigate the impact and enhance security measures.
## Incident Details
- **Discovery Date:** Not explicitly disclosed (Investigation matured by Oct 8, 2026)
- **Incident Date:** Pre-October 2026
- **Affected Organization:** St Andrew’s Hospital
- **Sector:** Healthcare
- **Geography:** Adelaide, South Australia
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed
- **Vector:** Unknown/Not disclosed in report
- **Details:** Attackers gained unauthorized access to the hospital's digital environment prior to October 2026.
### Lateral Movement
- **Details:** Internal forensic investigations suggest movement through systems containing patient records, though specific technical pathways were not disclosed in the public statement.
### Data Exfiltration/Impact
- **Details:** Sensitive patient data was identified as "downloaded" by the threat actors. Stolen information includes full names, phone numbers, residential addresses, email addresses, dates of birth, Medicare card numbers, and healthcare identifiers.
### Detection & Response
- **Discovery:** Identified via internal security monitoring or post-incident forensic analysis.
- **Response actions taken:** Engaged specialist forensic experts, reported the breach to the Office of the Australian Information Consumer (OAIC) and the Australian Cyber Security Centre (ACSC), and initiated a direct notification campaign to affected patients.
## Attack Methodology
*Note: Specific technical TTPs (Tactics, Techniques, and Procedures) were not disclosed by the hospital.*
- **Initial Access:** Unknown
- **Persistence:** Not disclosed
- **Privilege Escalation:** Not disclosed
- **Defense Evasion:** Not disclosed
- **Credential Access:** Not disclosed
- **Discovery:** Targeted patient databases and health information systems.
- **Lateral Movement:** Not disclosed
- **Collection:** Aggregation of patient PII (Personally Identifiable Information) and PHI (Protected Health Information).
- **Exfiltration:** Data downloaded from hospital systems.
- **Impact:** Data breach and unauthorized disclosure of regulated health identifiers.
## Impact Assessment
- **Financial:** Undisclosed forensic and notification costs; potential regulatory fines under the Privacy Act.
- **Data Breach:** High-volume theft of PII and Medicare identifiers.
- **Operational:** Coincided with the closure of the hospital's emergency department, though the two are not explicitly linked in the report.
- **Reputational:** Significant public and government scrutiny, including comments from the South Australian Premier regarding private sector security obligations.
## Indicators of Compromise
- **Network indicators:** None disclosed.
- **File indicators:** None disclosed.
- **Behavioral indicators:** Large-scale unauthorized data downloads (exfiltration).
## Response Actions
- **Containment measures:** Collaboration with government agencies to implement "additional protective measures."
- **Eradication steps:** Forensic investigation to identify and remove the point of entry.
- **Recovery actions:** Implementing fraud detection support for affected patients and fulfilling regulatory notification obligations.
## Lessons Learned
- **Regulatory Readiness:** The progression of the investigation to a "point of communication" highlights the necessity of having a clear data breach response plan that aligns with OAIC requirements.
- **Third-Party/Private Risk:** Private healthcare facilities are high-value targets due to the permanence of the data (Medicare numbers, DOBs) they hold.
## Recommendations
- **Identity Protection:** Patients should be advised to monitor Medicare records for fraudulent activity and potentially replace compromised identifiers if permitted by authorities.
- **Enhanced Monitoring:** Implement robust egress filtering and Data Loss Prevention (DLP) tools to detect and block large-scale data transfers to unauthorized external IPs.
- **Network Segmentation:** Ensure patient databases are isolated from general hospital office networks to prevent lateral movement.