St Andrew's Hospital, Adelaide, confirms a personal-information data breach affecting "a group of individuals"; OAIC and ACSC notified (8 Oct)
St Andrew's Hospital, a private hospital in Adelaide, said on Thursday 8 October 2026 that it had been investigating a breach of personal information affecting "a group of individuals". Chief executive Angela McCabe said the investigation had progressed far enough for the hospital to contact affected people directly, in line with its regulatory obligations, and that they had been given information on how to protect their personal information. The hospital says it has notified the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre, and is working with government agencies to apply extra measures to detect and prevent suspicious and fraudulent activity. The number of people affected, what kind of information was involved and how the breach happened have not been disclosed. South Australian Premier Peter Malinauskas said the state government expected to be briefed later on 8 October, including on whether anything criminal had occurred. Wire: ABC News 8 Oct; no hospital web notice found at the time of this check.
- Product
- St Andrew's Hospital (Adelaide private hospital) patient or individual personal information
- Versions
- n/a — incident; scope and data types not yet disclosed
- Exploited in Australia?
- unknown
- Patch to
- If St Andrew's Hospital contacts you, follow its steps and treat calls, texts or emails that mention a hospital stay, Medicare or health fund details as possible scams; verify through a number you already hold. Private hospitals and health providers: health information is a notifiable 'serious harm' category under the Notifiable Data Breaches scheme, so keep the assessment clock and OAIC statement ready before you need them.
Primary: ABC News — 'Group of individuals' impacted by data breach at SA hospital (8 Oct 2026) · Vendor: St Andrew's Hospital, Adelaide (official site)
