The corporate launched a press release on its web site – which is now in any other case inactive – this afternoon confirming the breach concerned “private and well being data”.
“We have now taken quick steps to mitigate any potential affect on our techniques,” it mentioned.
“Whereas we proceed to collect extra data, early indicators recommend the incident originated from certainly one of our third-party distributors.”
The corporate supplied a system to permit healthcare professionals like GPs to ship prescriptions to sufferers electronically.
Its brand incorporates the tagline: “eScripts. Despatched. Safe. Protected.”
It has not been used since November 15 for brand spanking new digital prescriptions after the federal Well being Division made eRx the only real e-script supplier however has remained on-line for sufferers to entry current paperwork.
MediSecure firm mentioned it had contacted authorities businesses and helps them “handle the impacts of the incident”.
“MediSecure understands the significance of transparency and can present additional updates through our web site as quickly as extra data turns into accessible,” it mentioned.
“We recognize your endurance and understanding throughout this time.”
The Nationwide Cyber Safety Coordinator mentioned earlier right now it was knowledgeable by MediSecure of the incident yesterday.
“Yesterday afternoon I used to be suggested by a industrial well being data organisation that it was the sufferer of a large-scale ransomware knowledge breach incident,” Cyber Safety Coordinator Lieutenant-Common Michelle McGuinness mentioned in a press release.
“I’m working with businesses throughout the Australian authorities, states and territories to coordinate a whole-of-government response to this incident.
“The Cyber Safety Centre is conscious of the incident and the Australian Federal Police (are) investigating.”
Federal Cyber Safety Minister Clare O’Neil mentioned the federal government is responding to the information breach.
“I’ve been briefed on this incident in latest days and the federal government convened a Nationwide Coordination Mechanism concerning this matter right now,” she mentioned this afternoon.
“Michelle McGuinness is main work throughout the Australian authorities to help the corporate in managing this large-scale ransomware incident.
“Updates will likely be supplied sooner or later. Hypothesis at this stage dangers undermining vital work underway to help the corporate’s response.”
McGuinness mentioned the investigation was nonetheless in its early phases, and extra updates will likely be supplied quickly.
“We’re within the very preliminary phases of our response and there’s restricted element to share at this stage,” she mentioned.
“However I’ll proceed to offer updates as we progress whereas working intently with the affected industrial organisation to deal with the impacts brought on by the incident.”
Full assertion from MediSecure
Cyber safety incident/knowledge breach
MediSecure has recognized a cyber safety incident impacting the non-public and well being data of people. We have now taken quick steps to mitigate any potential affect on our techniques.
Whereas we proceed to collect extra data, early indicators recommend the incident originated from certainly one of our third-party distributors.
MediSecure takes its authorized and moral obligations severely and recognize this data will likely be of concern. MediSecure is actively aiding the Australian Digital Well being Company and the Nationwide Cyber Safety Coordinator to handle the impacts of the incident. MediSecure has additionally notified the Workplace of the Australian Data Commissioner and different key regulators.
MediSecure understands the significance of transparency and can present additional updates through our web site as quickly as extra data turns into accessible. We recognize your endurance and understanding throughout this time.