Viw Magazine

Men's Weekly

.

  • Written by Robert Merkel, Lecturer in Software Engineering, Monash University
Hackers exploited a weakness in the web-based booking system of Family Planning NSW to infect the system with ransomware. Shutterstock

Family Planning NSW has taken its website offline for a “security update” after learning that hackers breached its booking system two weeks ago. The organisation notified its clients via email, and journalist Lauren Ingram, who was personally affected by the data breach, shared the notification on Twitter.

The letter stated that:

These databases contained information from around 8,000 clients who had contacted Family Planning NSW through our website in the past two and a half years, seeking appointments or leaving feedback.


Read more: After the Medicare breach, we should be cautious about moving our health records online


Family Planning NSW offers reproductive and sexual health services, and the breach has sparked fears that sensitive personal information about clients could have been compromised.

In this case, the risk to patients is not as severe as it could have been. Medical practices typically keep the actual medical records of patients separate from online booking systems.

However, the information in the booking system is still sufficient to assist with identity fraud. Furthermore, for some patients, there are very serious risks merely in disclosing that they are patients of such services:

Ransomware is a common form of cybercrime

According to the notification, hackers exploited a weakness in the web-based booking system of Family Planning NSW and demanded a Bitcoin ransom.

We don’t know the full details of this particular attack, but the information in the notification letter indicates the attackers may have used some kind of ransomware. Ransomware is malicious software that electronically locks up (encrypts) the data on a computer system. If no backup is available, the only way to access the data is to pay the ransom for the key to unlock (decrypt) the data.


Read more: Defending hospitals against life-threatening cyberattacks


Ransomware authors do not typically attempt to read the contents of the information they hold to ransom – their business model involves denying access to information, not making use of it. However, ransomware that has sufficient access to scramble data, has sufficient access to steal that information. Therefore, while it is more likely than not that no information was actually copied, it cannot be guaranteed.

Technically sophisticated attackers will sometimes use what appears to be one type of attack (such as ransomware) to disguise their real intentions. Security professionals who specialise in “incident response” (IR), are able to assess this risk when an apparent ransomware attack has occurred. I expect that in a high-profile data breach like this, IR specialists have been consulted.

Oversight of medical privacy could be inadequate

It is not feasible for patients of a medical practice to assess the adequacy of the security and privacy processes – and nor should they. Patients aren’t expected to assess the skill of a surgeon to operate, or whether the instrument sterilisation processes are adequate!

Instead it is the legal and ethical obligation of medical practices, and the bodies that accredit them, to ensure their technology and processes are adequate to protect privacy and security. All medical practices are required to implement the Australian Privacy Principles specified in the Privacy Act, regardless of size (most other small businesses are not). Medical practices are also subject to mandatory reporting of data breaches.

Some of the representative bodies of medical specialities attempt to assess privacy and security as part of practice accreditation. In the case of general practitioners, the Royal Australian College of General Practitioners’ accreditation standards require practices to develop privacy and security procedures and policies. They also provide a more detailed information security standard.

Unfortunately, it’s not at all clear how rigorously these policies and procedures are actually checked, both for their adequacy and whether they are actually followed.

My informal inquiries in the sector suggest that at the very least accreditation processes do not focus heavily on the technical aspects of privacy and security. My own general practitioner is fully accredited by the RACGP via one of its approved accreditation assessment partners, but does not even have a privacy policy on its website.

More evidence that the health sector has work to do in this area comes from the new mandatory notification requirement for data breaches. Since its introduction earlier this year, the health sector has had more notifications than any other sector.

What can patients do?

As in many other aspects of healthcare, patients generally have to place their trust in the competence and diligence of the professionals. But patients who believe they face particularly high risks do have some options to protect themselves.

The Australian Privacy Principles require that, where practicable, patients should be able to interact with a medical practice anonymously, or under a pseudonym. The RACGP accreditation material (PDF link) recommends practices set up procedures to support this.

Even if a pseudonym is not for you, it is prudent to consider minimising the amount of information you provide on medical booking services, which are inherently more vulnerable than medical record systems not exposed to the public internet.


Read more: Why has healthcare become such a target for cyber-attackers?


A major change to the way your medical data is managed is on the way – and one with serious privacy implications. The My Health Record is a centralised repository of personal healthcare information, maintained by the Australian government. It is designed to improve healthcare by improving access to patient information for doctors, as well as facilitate research.

However, the combination of improved access to records and less-than-perfect information security practices in the health sector is likely, in my view, to increase the risk of privacy breaches.

You have the chance to opt out of the My Health Record system during a three-month window between July 16 and October 15. After this date, a record can be rendered inaccessible but not completely deleted. This data breach, and the rate at which they are occurring throughout the healthcare sector, further reinforces my intention to opt out.

Robert Merkel does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.

Authors: Robert Merkel, Lecturer in Software Engineering, Monash University

Read more http://theconversation.com/the-latest-health-data-breach-is-one-reason-why-ill-be-opting-out-of-myhealthrecord-96644

The Importance Of Professional Fiberglass Boat Repair For Strength, Safety And Long-Term Performance

Boats made from fiberglass are known for their durability, lightweight structure and smooth performance. However, even the strongest vesse...

Why Choosing the Right Cosmetic Clinic Bundoora Matters for Confidence and Care

Personal appearance can influence confidence, comfort, and overall wellbeing. Many people seek treatments to enhance features, refresh the...

Best Home Care Package Meal Providers: A Comprehensive Guide for Australian Seniors

As we age, maintaining proper nutrition becomes increasingly important, yet preparing healthy meals can become challenging for many older Au...

The Benefits Of Residential Solar Power Systems For Long-Term Energy Savings And Sustainability

Many homeowners are turning to residential solar power systems as a practical way to reduce rising electricity costs, improve energy inde...

Paint Protection Film Brisbane: The Ultimate Guide to Protecting Your Vehicle

Brisbane's harsh subtropical climate, with its intense UV rays, summer storms, and coastal conditions, can wreak havoc on your vehicle's pai...

The Complete Guide to Name Tags: Types, Benefits, and Best Practices

Whether you're organising a corporate conference, managing a retail team, or hosting a networking event, name tags play a crucial role in fa...

How Family Court Lawyers Can Guide You Through High-Conflict Parenting Disputes

High-conflict parenting disputes can be draining, unpredictable and emotionally overwhelming, especially when communication has broken dow...

Why Professional Evaporative Cooling Repair Is Important for Reliable Performance and Summer Comfort

Evaporative cooling is widely used in many homes. However, like any cooling system, it can experience wear, blockages, or mechanical fault...

How 3pl Companies Support Business Growth Through Efficient Warehousing And Fulfilment Solutions

As customer expectations continue to rise, businesses rely heavily on streamlined logistics to deliver products quickly and accurately. Ma...

Restoring Rental Spaces To Perfection Before Moving Out

A stressful part when leaving a rented home is ensuring the space is spotless and ready for inspection. A professional's help becomes invalu...

Why More Aussies Are Choosing Pontoon Boats To Launch a Waterside Lifestyle

Soaking up the long, sunny days of summer is a classic Australian pastime, and there’s no better way to do it than aboard a boat. But wh...

Building Bespoke Spaces: Why a Custom-Driven Approach Truly Matters

When it comes to creating a home that’s a perfect fit for your lifestyle, a Fiteni Homes-style approach offers unmatched flexibility and...

Refining Facial Contours with Modern Surgical Techniques on the Gold Coast

When we think of rejuvenation and restoring youthful contours, a targeted solution such as a face lift can be transformational. For those ...

Term Deposits Australia: A Complete Guide to Fixed-Rate Savings

For Australians seeking a safe, predictable way to grow their savings, term deposits australia options provide an attractive solution. Off...

Emergency Gate Repairs in Melbourne: Keeping Your Property Secure and Functional

A malfunctioning gate can be more than an inconvenience — it can compromise your property’s security, accessibility, and safety. Acros...

Chatswood Tutoring: Empowering Students to Achieve Academic Excellence

Education is more competitive today than ever before, and students face constant pressure to perform well across multiple subjects and exa...

Top Tips When Searching for Caravans for Sale in Perth

Western Australia is built for road trips. With its sweeping coastline, desert tracks and endless sunshine, there’s no better way to exp...

From Gaps to Glamour: Exploring Dental Bridge and Cosmetic Dentist Brisbane Options

A healthy, complete smile has the power to boost confidence, improve speech, and enhance overall oral function. However, the unexpected lo...

Achieving Your Healthiest, Straightest Smile in Blackburn

Your life can be genuinely transformed by a confident, healthy smile that enhances your overall well-being and self-esteem. Blackburn dent...

Hobart Smile Secrets: Achieving Perfection with All-on-4 and Porcelain Veneers

Hobart smiles, rebuilt and refined Hobart’s waterfront, sandstone facades, and the sweep of kunanyi, Mount Wellington, set a high bar f...

hacklink hack forum hacklink film izle hacklink หวยออนไลน์matbetสล็อตเว็บตรงgamdom girişpadişahbetMostbetpradabetmatbetpin updizipalholiganbettrendbetcocktail glassesligobetcasibommarsbahis girişpusulabet girişbetnanotürk ifşaBets10pusulabetpusulabetpusulabetGrandpashabet色情marsbahisnakitbahisholiganbetPusulabet Güncel Girişpusulabet girişjojobet girişYakabet1xbet girişjojobetgrandpashabetbetofficeenjoybetpradabettaraftariumholiganbetgiftcardmall/mygiftultrabetkavbetfixbetbets10palacebetmeritkingcasibommeritkingbetistcasibomteknoloji haberlericasibom girişJojobetmadridbetmadridbetPorno İzleFast Payout Casinoscasibom girişsweet bonanzameritkinggalabetcasibomcasibom girişjokerbetjokerbetyakabetCasibombetpuankingroyalUltrabet girişdinamobetmasterbettingvdcasinoSekabet girişmarsbahisbetkolikultrabetprimebahismeritkingprimebahismeritkingbets10yakabetyakabetyakabetjojobetprizmabetkulisbetSahabetaertyercasibompusulabetvbetsahabetcolor pickerkavbetkralbet girişmavibetmavibetmavibetbetnano girişcratosslot girişคลิปโป๊Marsbahis GirişCasibomholiganbetdeneme bonusu veren siteleronwinonwinizmir escortbetnanoantalya escortbetnano giriştimebetbetnanobetnano girişbahiscasinobahiscasinoultrabetbets10matbetcasibomroyal reelscasibomstarzbet girişKayseri Escortjojobet girişjojobetbetasusmilanobetmilanobetbettiltcasibomAresbetaviator gamesonbahistimebettimebettimebetvoidturkistanbul escort telegramcasibombetparkpantheraproject.netprimebahiscrown155 casinohb88aussuper96 loginholiganbethiltonbethiltonbetkavbetcasibom한국야동pusulabetสล็อตpadişahbetcasibomgiftcardmall/mygift주소모음 주소모아spin2u loginneoaus96 casino loginPadişahbetStreameastgalabetmarsbahisjojobetcasibombets10ff29 casinoMMA Streamholiganbetstakemate77best e-wallet pokies 2025破解工具топ 10 казинорейтинг лучших казиноholiganbetcasibomdeneme bonusu veren siteler rehnerijojobetmostbetbatumi real estateJojobet 1112mostbetbahis siteleri 2025matbetjojobetwww.giftcardmall.com/mygiftjojobetcasibomcasibomgiftcardmall/mygiftasdsadasdasdasdasfdasfasfsadfasdfsdfasdasdasdasdkingroyal girişjojobetbahiscasinobetasusлучшие казино на деньгиpin upcasino med Klarnaholiganbetcasibomwww.mcgift.giftcardmall.com balancegiftcardmall/mygiftwww.giftcardmall.com/mygift activatetm menards loginmeybetpalacebetmeritbetcasibompusulabetcasibomcasibomcratosroyalbetci girişprizmabetprizmabetultrabetultrabetcasibomhazbetjojobetJojobetjojobet hacklink hack forum hacklink film izle hacklink หวยออนไลน์matbetสล็อตเว็บตรงgamdom girişpadişahbetMostbetpradabetmatbetpin updizipalholiganbettrendbetcocktail glassesligobetcasibommarsbahis girişpusulabet girişbetnanotürk ifşaBets10pusulabetpusulabetpusulabetGrandpashabet色情marsbahisnakitbahisholiganbetPusulabet Güncel Girişpusulabet girişjojobet girişYakabet1xbet girişjojobetgrandpashabetbetofficeenjoybetpradabettaraftariumholiganbetgiftcardmall/mygiftultrabetkavbetfixbetbets10palacebetmeritkingcasibommeritkingbetistcasibomteknoloji haberlericasibom girişJojobetmadridbetmadridbetPorno İzleFast Payout Casinoscasibom girişsweet bonanzameritkinggalabetcasibomcasibom girişjokerbetjokerbetyakabetCasibombetpuankingroyalUltrabet girişdinamobetmasterbettingvdcasinoSekabet girişmarsbahisbetkolikultrabetprimebahismeritkingprimebahismeritkingbets10yakabetyakabetyakabetjojobetprizmabetkulisbetSahabetaertyercasibompusulabetvbetcolor pickerkavbetkralbet girişmavibetmavibetmavibetbetnano girişcratosslot girişคลิปโป๊Marsbahis GirişCasibomholiganbetdeneme bonusu veren siteleronwinonwinizmir escortbetnanoantalya escortbetnano giriştimebetbetnanobetnano girişbahiscasinobahiscasinoultrabetbets10matbetcasibomroyal reelsstarzbet girişKayseri Escortjojobet girişjojobetbetasusmilanobetmilanobetbettiltcasibomAresbetaviator gamesonbahistimebettimebettimebetvoidturkistanbul escort telegramcasibombetparkpantheraproject.netprimebahiscrown155 casinohb88aussuper96 loginholiganbetcasibom한국야동pusulabetสล็อตpadişahbetcasibomgiftcardmall/mygift주소모음 주소모아spin2u loginneoaus96 casino loginPadişahbetStreameastgalabetmarsbahisjojobetcasibombets10ff29 casinoMMA Streamholiganbetstakemate77best e-wallet pokies 2025топ 10 казинорейтинг лучших казиноholiganbetcasibomdeneme bonusu veren siteler rehnerijojobetmostbetJojobet 1112mostbetbahis siteleri 2025matbetjojobetwww.giftcardmall.com/mygiftjojobetcasibomgiftcardmall/mygiftasdsadasdasdasdasfdasfasfsadfasdfsdfasdasdasdasdkingroyal girişjojobetbahiscasinobetasusлучшие казино на деньгиpin upcasino med Klarnaholiganbetcasibomwww.mcgift.giftcardmall.com balancegiftcardmall/mygiftwww.giftcardmall.com/mygift activatetm menards loginmeybetpalacebetmeritbetcasibompusulabetcasibomcasibomcratosroyalbetci girişultrabetultrabethazbetjojobetJojobetjojobet