St Andrew's Hospital, one of Adelaide's largest private hospitals, is notifying patients that an unauthorised third party accessed its servers and downloaded files containing personal information. The hospital's own statement, authorised by chief executive Angela McCabe, confirms that the incident has been reported to the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC). Reports from 7NEWS and The Advertiser say the stolen data includes Medicare card numbers, healthcare identifiers, dates of birth and home addresses. The hospital has not said how many people are affected. ABC News reports that it described them only as "a group of individuals." No threat actor has been named, and no group has publicly claimed the attack.
A note on sourcing: all eight sources for this brief are secondary. Several are copies of the same two original reports, one from ABC News (S2, S4, S7) and one from The Advertiser (S3). No regulator filing or full public statement from the hospital was available. Direct quotes from the hospital come from its statement as reported by ABC and 7NEWS, and from a patient notification letter quoted by The Advertiser.
What Happened
According to the notification letter quoted by The Advertiser, the hospital "became aware that a third party gained unauthorised access to our servers." The hospital says it then started an investigation "with the support of forensic IT experts and other advisers." That investigation found that "a subset of data from our servers was downloaded."
Patients were notified on Thursday 8 October 2026. In the statement reported by ABC and 7NEWS, McCabe said the "investigation into the nature and extent of the incident has now progressed to the point where we can communicate directly with affected individuals, in line with our regulatory obligations." She said the hospital is working with government agencies to "apply additional protective measures, to help detect and prevent suspicious and fraudulent activity."
The hospital has not said when the intrusion happened or when it was detected. That means the gap between compromise and notification is unknown. A summary on Rankiteo, based on the ABC report, says the hospital isolated its systems after discovering the breach and names Chief Information Officer Nathan Crettenden as saying further security measures are being put in place. This detail does not appear in the other sources and has not been independently confirmed.
St Andrew's is a private hospital, so it falls outside state government control. Even so, South Australian Premier Peter Malinauskas said the government expects to be told "exactly what's occurred here and whether or not things have occurred of a criminal nature that might be subject to the South Australian Criminal Code." ABC reported that he expected to be briefed later on Thursday.
The breach was disclosed in the same week the hospital announced it would close its emergency department for financial reasons. The Advertiser reports it will be replaced by an acute assessment centre due to open on 16 November. Nothing in the sources links the two events.
What Was Taken
Sources give the same list of data types. They differ on how much was taken:
- Data types (reported by 7NEWS and The Advertiser, each saying it "understands" this): full names, phone numbers, home addresses, email addresses, dates of birth, Medicare card numbers and healthcare identifiers.
- Scope: The hospital's letter says patient data was "present on one or more files downloaded" and calls it a "subset" of server data. ABC reports that the number of people affected and the circumstances of the breach "are currently unknown."
- Clinical records: None of the sources confirm that diagnoses, treatment notes or other clinical records were taken. One aggregator (Streamline Feed) says a "substantial volume" of data was taken from "deep administrative archives." No other source supports this, and it should be treated as unverified.
Victim count: not disclosed. No source gives a figure.
Healthcare identifiers (Individual Healthcare Identifiers, or IHIs) are permanent national numbers used across Australia's digital health system, including My Health Record. Unlike a password or a card number, they cannot easily be changed. Combined with a Medicare number, date of birth and address, the data is enough for convincing impersonation and targeted phishing.
Why It Matters
- The data lasts a long time. Medicare numbers can be reissued, but healthcare identifiers and dates of birth stay the same. Anyone who receives this data can use it for years.
- It enables healthcare-themed scams. A full name, contact details and Medicare data are ideal for fake messages posing as Medicare, myGov, health insurers or the hospital itself. Expect scams that refer to this breach directly.
- Private hospitals are exposed. Large private operators hold data at national-system scale, but they don't always have the security resources of public health networks. The Premier's comments also highlight a gap in state oversight of private providers.
- The financial context. The breach came as the hospital was cutting services for financial reasons. The sources don't connect the two, but defenders should note the general pattern: organisations under budget pressure often have gaps in security monitoring and response.
- The notification process worked as intended. The hospital notified the OAIC and ACSC and contacted patients directly under the Notifiable Data Breaches scheme. It has not yet said how many people were affected or when the breach happened, and both answers are needed to judge the risk.
The Attack Technique
Unknown. The hospital has said only that a third party "gained unauthorised access to our servers" and downloaded data. None of the sources identify:
- how the attacker got in (stolen credentials, a vulnerable internet-facing service, phishing, or a third-party supplier);
- whether ransomware was used or systems were encrypted (no disruption to clinical services has been reported);
- the threat actor, or any posting on a leak site or ransom demand;
- how long the attacker was inside the network.
Claims in aggregator content that the attack "bypassed the hospital's internal security architecture" are not backed by any detail and should not be read as forensic findings. What is known (unauthorised server access, files copied out, no reported encryption) fits a data-theft-for-extortion pattern. Without confirmation, that is an analyst's assessment, not an established fact.
What Organizations Should Do
- Find and reduce stored identifier data. Locate every file share, export and reporting extract that holds Medicare numbers or IHIs outside the core patient administration system. Ad hoc files like these are often exactly the "one or more files" that end up stolen. Delete or tokenise anything that isn't needed.
- Watch for large outbound data transfers. Set alerts for unusual volumes leaving file servers and database hosts, especially through archive tools, cloud sync clients or rclone-style utilities. Data theft without encryption is easy to miss unless egress is monitored.
- Secure remote access. Require phishing-resistant MFA on VPN, remote desktop gateways and vendor access. Audit dormant and shared accounts. Patch internet-facing appliances against known exploited vulnerabilities as a priority.
- Prepare patient notification in advance. Have notification templates, call-centre scripts and identity-protection arrangements (for example IDCARE referrals) ready before an incident. Make sure your Notifiable Data Breaches assessment process can meet the 30-day assessment window.
- Warn patients about follow-on scams. Tell patients, through channels you already use, that you will never ask for Medicare details or payment by unsolicited SMS or email. Report impersonation domains for takedown quickly.
- Prepare for impersonation of your organisation. Health providers that share patients with St Andrew's should expect phishing that uses its name or refers to the breach. Brief front-desk and billing staff on caller verification steps.
Sources: Patients notified after personal data stolen in cyberattack on St A... | Data breach reported at SA private hospital KhanList | St Andrews Hospital patient records hacked in data breach - Australia | St Andrew’s Hospital: 'Group of individuals' impacted by data breac... | Adelaide’s St Andrew's Hospital Confirms Patient Data Cyber Breach... | Adelaide Hospital Hack: Patient Data Stolen - What You Need to Know... | Data breach reported at SA private hospital — Sovereign News Station | SA Hospital Data Breach: St Andrew's Hospital Reports Cyber Inciden...