Data breach at St Andrew’s Hospital in Adelaide affects patients’ personal information
Consensus Summary
St Andrew’s Hospital in Adelaide has confirmed a data breach exposing personal and health-related information of an undisclosed number of patients. The breach, reported by both ABC and 7NEWS, involved sensitive details such as full names, phone numbers, residential addresses, email addresses, dates of birth, Medicare card numbers, and healthcare identifiers. The hospital’s CEO, Angela McCabe, stated that the investigation had progressed sufficiently to allow direct notification of affected individuals, in line with regulatory obligations. Both outlets agree the breach was reported to the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre, with the hospital now working with government agencies to implement additional security measures.
The breach follows a period of heightened cybersecurity concerns globally, as noted by South Australian Premier Peter Malinauskas. While the hospital operates independently of state government control, Malinauskas emphasized the need for law enforcement to assess whether any state laws were breached. The incident also coincides with broader discussions about legislative protections for patient data in private healthcare settings. The hospital’s statement highlights its commitment to supporting affected individuals and preventing fraudulent activity, though the exact circumstances and extent of the breach remain unclear.
Key figures in the response include CEO Angela McCabe, who outlined the hospital’s actions in a statement authorized by ABC and 7NEWS. Premier Malinauskas, quoted by ABC, indicated the state government would be briefed 'later today' and expressed concern about potential criminal implications. While 7NEWS notes the hospital’s apology to patients, ABC focuses more on the regulatory and investigative aspects of the breach. Both sources agree the breach was confirmed on Thursday, though 7NEWS ties it to the hospital’s recent announcement of closing its emergency department 'just days after' the breach.
The coverage diverges slightly in emphasis, with ABC detailing the timeline of the breach confirmation ('Thursday morning' and 'later on Thursday') and the premier’s expectations for a briefing, while 7NEWS links the breach to the hospital’s financial struggles and operational changes. Neither source provides a specific number of affected individuals, though both describe the breach as affecting 'a group of individuals.' The lack of a precise figure underscores the ongoing uncertainty surrounding the breach’s full scope and impact.
As investigations continue, the next steps involve further collaboration between the hospital, government agencies, and law enforcement to assess potential legal violations and strengthen cybersecurity measures. The premier’s comments suggest a focus on criminal accountability, while the hospital’s actions center on notifying patients and mitigating fraud risks. The unresolved questions include the exact number of affected individuals, the full circumstances of the breach, and whether additional legislative protections will be proposed to safeguard patient data in private hospitals.
✓ Verified by 2+ sources
Key details reported by multiple sources:
- St Andrew’s Hospital reported a data breach affecting 'a group of individuals'
- The breach involved personal and health-related information, including full names, phone numbers, residential addresses, email addresses, dates of birth, Medicare card numbers, and healthcare identifiers
- The Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre were notified of the breach
- St Andrew’s Hospital CEO Angela McCabe stated the investigation had progressed to the point where affected individuals could be directly notified
- South Australian Premier Peter Malinauskas said the state government expected to be briefed on the breach 'later today'
- The hospital is working with government agencies to apply additional protective measures to detect and prevent suspicious or fraudulent activity
Points of Difference
Details reported by only one source:
- SA Premier Peter Malinauskas said he is expecting to be briefed on the breach 'later on Thursday' and 'Thursday morning'
- The hospital confirmed the breach 'on Thursday morning'
- The breach was described as 'affecting a group of individuals' without specifying the exact number
- The hospital apologized to affected individuals (implied through regulatory obligations but not explicitly stated in 7NEWS)
- The breach occurred 'just days after' St Andrew’s announced it would close its emergency department due to financial unsustainability
- The hospital explicitly apologized to affected patients with the statement: 'We sincerely apologize for any concern this incident has caused.'
- The article mentions that the hospital operates outside state government control, which may limit direct oversight
Where the reporting differs
Details that conflict, or appear in only some outlets:
- ABC states the breach was confirmed 'on Thursday morning' and the premier expects a briefing 'later on Thursday' and 'later today,' while 7NEWS does not specify a date for the breach confirmation or briefing beyond 'just days after' the emergency department closure announcement.
Source Articles
Data breach reported at SA private hospital
An Adelaide private hospital has notified individuals and cyber security authorities of a data breach of personal information.
Patients notified after personal data stolen in cyberattack on St Andrew’s Hospital in Adelaide
Medicare numbers, healthcare identifiers, home addresses and dates of birth may have been taken.
More Technology stories
Alan Jones trial over alleged sexual assaults and grooming of minors between 2003 and 2020
OpenAI AI agents hack Australian government websites, sparking inquiry and distrust
Australian soldier dies in NT training rollover; ADF suspends Supacat troop carrier use
Joshua Kerry charged with terror plot against Nigel Farage after murdering Ann Widdecombe
Comedian Judith Lucy announces breast cancer diagnosis and double mastectomy plans
Asos app users receive hacker notifications, shares drop amid data breach claims
Latest cross-verified stories
Australia’s 2026 federal election migration policy debate and party proposals
Tennessee botched execution of Christa Pike leaves her alive after lethal injection
France student protests over education conditions escalate into violent clashes
Reality TV star Sam Wood charged with domestic violence, facing bail hearing and career fallout
Former Prince Andrew Mountbatten-Windsor challenges police search warrants linked to Epstein case
Teenager critically injured in botched arson attack in Melbourne's Taylors Hill
Browse all stories from October 2026 in the archive.