Pulse ·

Updoc data breach: what telehealth patients need to know

Verdict Yes — worth knowing about

Telehealth company Updoc notified customers this week after detecting unauthorised access to a third-party system on 31 July 2026. Contact details — name, email address, and postal address — may have been exposed. Health records, Medicare numbers, and financial data were not affected.

Healthcare organisations are a high-value cyberattack target. The RACGP advises all general practices to have a documented incident response plan covering notification of the Office of the Australian Information Commissioner. The Updoc breach follows a more serious June 2026 incident at Partnered Health involving medical records and Medicare data across 21 clinics.

What just happened

Telehealth operator Updoc notified its customers this week after detecting a brief period of unauthorised access to a third-party system on 31 July 2026. Contact details — name, email address, and postal address — may have been exposed for some account holders.

Updoc has said the breach was isolated to that third-party system. Their own systems were not accessed. Health information, Medicare numbers, financial information, and payment details were not involved. Login credentials and account security are not affected.

Updoc launched in 2021 and has served more than one million patients. It contacted customers this week and says it has blocked the access and found no evidence of ongoing unauthorised entry.

This is the second significant healthcare data incident in Australia in recent months. A June 2026 breach at Partnered Health affected at least 21 clinics around Australia and was considerably more serious — involving medical records, Medicare numbers, consultation notes, referral letters, and pathology results in what clinics described as “very distressing.”


A pattern, not a one-off

Dr Rob Hosking, Chair of the RACGP Expert Committee on Practice Technology, put the current environment plainly: cyberattacks on healthcare organisations are now “almost inevitable.” Health data is among the most valued targets in the criminal data market — it can be used for identity theft, insurance fraud, and targeted social engineering in ways that financial data alone cannot.

Dr Hosking flagged that AI tools are likely to accelerate the frequency of attempted breaches — not because individual attacks are becoming more complex overnight, but because automated, targeted phishing and credential-harvesting campaigns can now be run at scale with less technical effort.

Healthcare is a structurally attractive target for two reasons. First, health data is sensitive and time-critical — a clinic cannot simply go offline the way a retail operation might absorb disruption. Second, the sector has historically underinvested in cybersecurity infrastructure relative to financial services, leaving more attack surface exposed.


Both-and

Telehealth has expanded access in ways that matter

Before framing this only as a risk story, it is worth being honest about what telehealth platforms like Updoc have done. They have extended access to general practice consultations for patients in rural and remote Australia, for people with mobility limitations, and for anyone whose circumstances make attending a physical clinic difficult or impossible.

That access has real clinical value. Some of those consultations would not have happened at all without the platform. The convenience and accessibility that telehealth provides is not a trivial thing to trade away. The relevant question is whether the data handling practices are proportionate to the trust patients are placing in these systems.

The exposure here is bounded — but context matters

Updoc is saying the right things publicly. The breach was limited to contact information, the system was secured quickly, and no clinical or financial data was involved. In isolation, a name, email, and postal address in the wrong hands is a manageable risk — particularly relative to a breach that includes medical records and Medicare numbers.

The context that changes the calculation: health data and contact data are frequently used together by malicious actors. If someone already holds data from a previous health breach — and given the frequency of healthcare incidents over recent years, many Updoc patients may also have been affected by earlier events — adding current contact details creates a richer profile for targeted fraud or social engineering.

This is not alarmism. It is how the data brokerage ecosystem operates in practice. Each individual breach looks manageable in isolation. The cumulative picture is what erodes trust.

Third-party systems are everyone’s risk

One structural feature of this incident is worth naming: the breach involved a third-party system Updoc uses to support its operations, not Updoc’s own systems. That is an increasingly common pattern in healthcare data incidents. Organisations invest in securing their own infrastructure and leave the exposure surface in the supplier and integration layer.

For any GP practice or health organisation considering digital tools: the RACGP information security guidelines specifically address third-party risk, including what to ask of vendors about their security posture before integrating their systems.


My two cents

As a patient using any telehealth platform — or as a GP running a practice that uses third-party digital systems — this week is a reasonable prompt to ask some questions worth settling before they become urgent.

For patients: if you are an Updoc user, you should have received a notification this week if your data was involved. In the weeks following any publicly disclosed breach, be alert to unexpected contact claiming to be from health providers. Phishing attempts routinely follow disclosed breach events because the attacker knows the contact details are confirmed as current. If something looks unusual, verify directly through the organisation’s official website before clicking anything.

For general practices: the legal obligation under Australia’s Notifiable Data Breaches scheme is to notify the Office of the Australian Information Commissioner and affected patients as soon as practicable after a qualifying breach. Whether your practice has a documented incident response plan — who calls the OAIC, who contacts patients, in what order, with what script — is a question worth settling before you need the answer.

Dr Hosking’s underlying point is accurate and worth sitting with: these attacks are coming. The question is not whether a breach attempt reaches your organisation but whether the response infrastructure is ready when it does.

Verdict: yes — worth knowing about if you use telehealth services or manage a general practice.


Sources cited

  1. Attwooll J. Telehealth company hit by data breach. newsGP, RACGP, 6 August 2026. https://www1.racgp.org.au/newsgp/professional/telehealth-company-hit-by-data-breach

Frequently asked questions

  • What should I do if I am an Updoc patient?

    If Updoc holds your contact details and the breach involved you, you should have received a direct notification from Updoc this week. In the weeks following any publicly disclosed data breach, be alert to unexpected contact purporting to be from health providers — phishing attempts frequently target people whose contact details are confirmed as live. If you receive suspicious emails or calls claiming to be from a health service, do not click any links and contact the organisation directly through their official website to verify.

  • What is a notifiable data breach in Australia?

    Under the Notifiable Data Breaches scheme, Australian organisations that hold personal information are required to notify both the Office of the Australian Information Commissioner and affected individuals when a data breach is likely to result in serious harm. Organisations must notify as soon as practicable after becoming aware of a qualifying breach. The scheme applies to most private sector organisations and many government agencies.