GO2 Health – A Veterans' Clinic, ...

GO2 Health – A Veterans' Clinic, One Mailbox, and the Twelve Weeks Nobody Was Told

IA
Tech Talks With Kinsoft di Steven Kinnas
11 ago 2026
23:34

Note sull'episodio

A Brisbane medical practice serving thousands of veterans lost Department of Veterans' Affairs ID numbers from a single email mailbox after a phishing attack — and then took twelve weeks to tell the patients. We walk the confirmed timeline (mailbox accessed in April, discovered 24 April with same-day containment and user alerts, OAIC notified 18 May, patients notified 16 July, ABC story 21 July), what GO2 Health has confirmed was taken, and what remains genuinely unknown — including the number of people affected, which the practice has not published. The lessons transfer to any Australian business: shared mailboxes are undesigned databases holding data your secured systems never see; auto-archiving capped this breach at twelve months and is the cheapest blast-radius control there is; the 30-day OAIC assessment clock governs telling the regulator, not telling people; a two-stage notification gets you vigilance without sacrificing accuracy; and identifiers you didn't issue — DVA, Medicare, concession cards — still need a documented replacement pathway you write before the incident, not during it. Context: the OAIC recorded 1,205 notified breaches last year, 716 from malicious or criminal activity, with health providers the most affected sector at 19%.

Visit www.kinsoft.com.au to talk through your security and IT needs.

Sources: ABC News (Will Murray, 21 July 2026); Cyber Daily (22 July 2026); GO2 Health company statements; The Medical Republic (OAIC spokesperson on the Notifiable Data Breaches scheme, 16 July 2026); OAIC Notifiable Data Breaches statistics.