💥 Fed cuts sparks mid cap boom! ProPicks AI scores with 4 stocks +23% each. Get October’s update first.Pick Stocks with AI

Sexual health and fertility details leaked in ACL data breach

Published 30/11/2023, 12:39 pm
© Reuters.  Sexual health and fertility details leaked in ACL data breach

ASX-lister Australian Clinical Labs (ACL) is facing potentially multi-million dollar fines for its inadequate protection of sensitive financial and health data.

This follows a cyberattack in 2022 that resulted in the theft of customer data, including information on sexually transmitted disease screenings.

The Australian Information Commissioner, in a statement filed in the Federal Court, has accused ACL of having insufficient cybersecurity protections and not promptly informing authorities and customers about the breach.

Exposed patient details from the breach were subsequently leaked onto the dark web.

Data breach

The legal action initiated on November 3 by the Office of the Information Commissioner relates to a breach at Medlab Pathology, acquired by ACL in late 2021.

This breach occurred in February 2022 but the Office of the Australian Information Commissioner (OAIC) wasn’t notified until July 10. Approximately 21.5 million individuals were affected, with more than 100,000 having their personal, health and credit card information compromised.

Medlab, which provided services in New South Wales and Queensland, including prenatal genetic testing, fertility assessments and diagnostics for sexually transmitted infections, reportedly had minimal cybersecurity measures.

The OAIC's filing highlighted ACL's failure to conduct adequate cybersecurity assessments before acquiring Medlab.

Facing penalties

ACL faces penalties under the older Privacy Act rules, which can impose fines up to A$2.2 million per contravention.

The OAIC's filing revealed that Medlab's systems were breached via a phishing email by a group known as Quantum.

Despite ACL's substantial revenue and workforce, their cybersecurity capabilities were deemed minimal, and their response to the breach was described as chaotic.

The OAIC asserts that ACL did not take reasonable steps to protect the personal information it held, considering the nature of the sensitive data and the resources available to the organisation. ACL has stated that it will vigorously defend against the action.

Read more on Proactive Investors AU

Disclaimer

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.