Medicare AI incident raises cyber security concerns for GPs
24 Sep 2026
The Federal Government has ordered a forensic investigation, supported by the Australian Signals Directorate, into the access of the Services Australia online reports portal in June.
OpenAI reportedly identified the incident in August and contacted Services Australia through a public email address on 10 September.
Prime Minister Anthony Albanese later confirmed the incident and said he had raised Australia’s concerns with OpenAI CEO Sam Altman.
The affected portal allowed users to examine Medicare Benefits Schedule and Pharmaceutical Benefits Scheme data by item number. It has since been taken offline.
Dr Sean Stevens, Chair of the RACGP Specific Interests Digital Health and Innovation group, said the incident showed why human oversight remains important when using AI.
He said doctors and the public need to be able to trust new technology, particularly when it can interact with sensitive information.
Reports indicate the AI agent accessed public and non-public information and wrote files to an internal Services Australia server.
The Prime Minister also said other government organisations may have been affected, including the Australian Institute of Health and Welfare and the Victorian Department of Health.
However, he said there was no evidence that individuals had been affected or that the wider Services Australia network had been compromised.
Dr Stevens said this was a wake-up call for health professionals and encouraged them to protect patient information and avoid keeping data that is not needed.
RACGP President Dr Michael Wright also described the incident as a warning for healthcare professionals.
He said health information is particularly sensitive and that the RACGP is monitoring the investigation.
The Australian Signals Directorate has also issued a high-level cyber security alert for Australian organisations with public-facing websites and applications. It recommends strong authentication and access controls, regular security monitoring, prompt software updates and testing against AI-related threats.
The ASD said there was no indication that the incident represented a wider malicious campaign against Australia. However, it highlighted the need for secure AI deployment and strong cyber security practices.
The Services Australia reports portal is no longer operating. Users are instead directed to spreadsheets on data.gov.au containing Medicare and PBS item information.
Medicare AI incident raises cyber security concerns for GPs
Source: RACGP newsGP; Australian Signals Directorate (ASD)