Brisbane Medical Clinic Took Three Months to Tell Patients Their Emails Were Read by Hackers

GO2 Health notified the regulator in May but did not warn affected patients until July, raising questions about Australia's 30-day disclosure rules and whether they go far enough.

ThreatVectr Newsdesk· 3 min read
Extreme close-up of a glowing laptop screen displaying a clean, minimal medical website interface, soft blue and white tones, the screen reflected in a pair of
Share

Key points

  • GO2 Health, a general practice and veteran care clinic in Everton Park, Brisbane, confirmed its main email inbox was broken into in April 2024 via a phishing attack, where criminals sent fake emails to trick staff into handing over access.
  • Patients' Department of Veterans' Affairs (DVA) ID numbers and other personal information sent to the inbox during the previous 12 months were potentially read by the hackers.
  • The clinic notified Australia's privacy regulator, the Office of the Australian Information Commissioner (OAIC), on 18 May, but affected patients did not receive a warning email until 16 July.
  • Australian law requires organisations holding private information to alert the OAIC within 30 days if a breach is likely to cause serious harm, but no equivalent deadline exists for notifying the people actually affected.

A Brisbane medical clinic waited nearly three months to tell patients that criminals had accessed their private emails, ABC News Australia reported this week. The incident at GO2 Health in Everton Park comes less than a week after a separate breach at Partnered Health affected 16 clinics across the country.

The attack started with a phishing email. A staff member was tricked into giving criminals access to the clinic's main email inbox sometime in April. The clinic says it discovered the breach and contained it on 24 April, the same day it alerted staff who used that mailbox.

Why did patients wait so long to find out?

GO2 Health says it needed time to work out exactly which patients' information sat inside the inbox, and it did not want to alarm the wrong people. The clinic told Threat Vectr it alerted the OAIC on 18 May, within the 30-day window set by Australia's Privacy Act. Patient notifications went out on 16 July.

That gap troubles at least one affected patient. Amanda, a veteran receiving psychological treatment at the clinic, says the delay cost people a chance to act.

"I think they've wasted really precious time for people to check their accounts and change their passwords," she told ABC News Australia.

The clinic's core patient records system was not broken into. The exposed data came only from emails sent during the 12 months before the attack, because the inbox used an auto-archive that deletes older messages. Even so, Amanda says veteran patients routinely send sensitive mental-health and DVA claims information by email, meaning a full year of that material was potentially exposed.

Amanda has since applied to change her Medicare number and has asked GO2 Health whether she also needs a new DVA card. She had not received a reply at the time of publication.

What should affected patients do now?

If you received a notification from GO2 Health, four steps are worth taking. First, change the password on any email account you used to contact the clinic. Second, contact Services Australia to ask about replacing your Medicare card. Third, contact the Department of Veterans' Affairs if your DVA number was mentioned in any email you sent the clinic. Fourth, watch for unexpected letters, calls, or emails asking for personal details, which can be a sign that stolen information is being used.

Cybersecurity experts have called for rules requiring clinics to notify patients early in an investigation, not only after it concludes. Australia's current framework sets a hard deadline for reporting to the regulator, under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988, but leaves patient notification timing to the organisation's judgment. That gap is now under fresh scrutiny.

© 2026 Threat Vectr