Updoc Data Breach Prompts Cyber Security Reminder for General Practices
06 Aug 2026
Updoc notified customers of the incident this week after detecting a brief period of unauthorised access on 31 July.
The company said the breach may have exposed the names, email addresses and postal addresses of some account holders. It confirmed that its own systems were not accessed and that health information, financial details and payment data were not involved.
Updoc said it acted immediately to stop the unauthorised access and found no evidence of further activity after the initial incident.
The company also advised customers that no immediate action is required, as account logins and security have not been affected. It apologised for the concern and inconvenience caused.
Founded in 2021, Updoc says it has provided telehealth services to more than one million patients across Australia.
Dr Rob Hosking, Chair of the RACGP Expert Committee – Practice Technology, said cyberattacks have become an ongoing risk for healthcare organisations because health data is highly valuable to cybercriminals.
He encouraged GPs and practice owners to regularly review their cyber security measures, train staff to recognise potential threats and ensure they have a clear response plan for data breaches.
Dr Hosking said practices should know how to notify the Office of the Australian Information Commissioner and inform affected patients promptly if a breach occurs.
The incident follows a cyberattack on Partnered Health in June, which affected at least 21 clinics across Australia and exposed sensitive medical information, including Medicare numbers, consultation notes, referral letters and pathology results.
The RACGP provides guidance and resources to help general practices improve information security, reduce cyber risks and respond effectively to data breaches.
Updoc Data Breach Prompts Cyber Security Reminder for General Practices
Source: newsGP