Updoc is an Australian online telehealth platform that gives Australian consumers remote access to Australian medical professionals, allowing them to secure health referrals, prescriptions, and medical certificates without needing to visit a clinic. According to the company, over 500,000 Aussies are users of the service.
In an email to patients, Updoc announced it had noted a security incident that may have impacted personal data.
“On Friday, 31 July, we identified a brief period of unauthorised access to a third-party system that we use to support our operations,” the email said.
“The access was isolated and involved contact information which may have included your name, email and postal address.”
The company said that its own systems were not breached and that data such as financial information, payment details and health data were not involved in the incident.
“We took immediate actions to block the unauthorised access and can confirm there was no evidence of access after the initial event,” it said.
Updoc customers have been advised that they don’t need to do anything except remain wary of scammers sending follow-up correspondence.
“You should always remain aware of any unexpected emails or letters about your account,” customers were told.
“You should treat these with caution and forward anything suspicious to us. We will never ask for a password via email.”
A spokesperson speaking with the media reiterated that no financial data was impacted.
“Updoc took immediate actions to block the unauthorised access and there has been no evidence of access after the initial event,” a spokesman said, as seen by news.com.au.
“Updoc apologises to its customers for any concern or inconvenience this event has caused.”
Kash Sharma, managing director ANZ at BlueVoyant, spoke with Cyber Daily about the incident, outlining what the breach means for patients and how cyber attacks impact health organisations.
“The Updoc breach where attackers gained access to a third-party system rather than Updoc’s own infrastructure, is a reminder that healthcare organisations don’t just need to secure their own front door,” he said.
“They need visibility into every vendor and system that touches patient data, because attackers don’t need to breach the hospital or clinic directly when a smaller supplier in the chain offers an easier way in.
“This matters because patient data is uniquely valuable to attackers, it’s permanent. You can cancel a credit card, but you can’t reissue a date of birth or a medical history. Even ‘low sensitivity’ fields like names and addresses are gold for follow-on phishing and identity fraud, which is exactly why healthcare supply chains are such an attractive target.”
Sharma also commented on how frequent these incidents are occurring, with the Partnered Health attack only having taken place in June this year.
“And this isn’t an isolated incident – it’s the second healthcare breach in Australia in a matter of weeks, following the Partnered Health attack in June, and that frequency should be setting off alarm bells across the sector. Healthcare holds some of the richest data of any sector but historically the weakest visibility into third-party risk, and every incident like this is a signal that the current approach isn’t keeping pace with the threat,” he said.
“Organisations can’t afford to wait for their own breach notification; they need continuous monitoring of their vendor ecosystem now, not annual questionnaires, because attackers are increasingly going through the supply chain, not the front door.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.