16
Jul

Cyber Insurance In Healthcare

A large Australian medical group of general practitioner and skin cancer clinics was the victim of cyber hackers in June 2026 as reported in the media.  The criminals stole personal details such as names, dates of birth, addresses and Medicare numbers, as well as GP consultation notes, referral letters and pathology results.  Clinics across Sydney, Melbourne, Canberra and the Queensland coast were victims of the attack.

The company secured an interim injunction from the Supreme Court of NSW ordering that the stolen data not be used or published, but the international location of many hackers may limit the effectiveness of the injunction. They reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement.

The number of cyber attacks on Australians is high. The Office of the Australian Information Commissioner logged 1205 data breach notifications in 2025, an 8 per cent rise on the year before.  The Australian Institute of Criminology and Australian Cyber Security Centre have recorded a cybercrime roughly every six minutes.

Cyber insurance is a product that can assist businesses against the financial, operational, and reputational risks of cyber incidents.  If a cyber event or system failure happens at or within a policyholder’s business then a policy may be triggered to respond, depending on the coverage purchased. Cyber events could include:

  1. Ransomware / cyber extortion : Attacks or threatened attacks against IT, coupled with ransom demands.
  2. Hacking : Malicious or unauthorised IT access to IT.
  3. Crimeware : Malware designed to cause harm to IT.
  4. Miscellaneous errors : Unintentional actions directly compromising security attributes of information assets.
  5. Insider and privilege misuse : Unapproved or malicious use of organisations’ IT by insiders or external misuse through collusion.
  6. Physical theft and loss : Information assets going missing, through misplacement or malice.
  7. Point of sale intrusion : Remote attack against IT where retail transactions are conducted.
  8. Privacy error : Acts or omissions that lead to unauthorised disclosure of data including non-electronic data.
  9. Web app attacks : Attacks targeting web applications or associated information technology systems.
  10. Cyber espionage : Unauthorised network or system access linked to state affiliated or criminal sources.
  11. Denial of service : Attacks intended to compromise the availability of information technology systems.
  12. Payment card skimming : Involving a skimming device being physically implanted through tampering into an item of IT that reads data from a payment card.

A cyber insurance policy may provide cover for first-party and third-party costs if there is a cyber event at or within an insured’s business.

The information above is general in nature and not specific to any business’s own needs, goals or circumstances. The coverage offered by each insurer can be found in their Product Disclosure Statement (PDS) or policy wording and any notations on any policy schedule.  The PDS must be read carefully before buying insurance to note the risks, benefits and costs of the coverage.  Experien General Insurance Services acts as a broker for many different insurers and can liaise with them on your behalf to arrange coverage and maintain coverage. If you would like quotes for cyber insurance or business insurance please don’t hesitate to contact us at any time. General insurance services are provided by Experien General Insurance Services Pty Ltd ABN 77 151 269 279 AFS Licence No. 430190 (EGIS) trading as Experien Insurance Services. EGIS arranges insurance and is not an insurer.