Cyber Security Incident
Ascot Vale Health Group (AVHG) was recently alerted to activity on our systems which indicated a potential cyber incident had occurred.
Unfortunately, our investigations have identified that a subset of data held by AVHG was accessed and taken from our systems by an unauthorised third party.
This data may have included some of your personal information.
Please note our core patient database has not been affected and our medical centre remains open to all patients, so that we can continue to provide the highest quality care.
We take the privacy and protection of personal information very seriously.
This statement outlines the types of personal information that may have been affected, the steps we have taken to date, and the steps that individuals can take to reduce the impact to their personal information.
What information may have been impacted?
Based on our investigation, we have been able to identify the following types of personal information relating to you that may have been impacted:
- Contact information (eg: name, address, email and/or phone number)
- Date of birth
- Medicare Card Number, Centrelink Customer Registration Number and/or Concession Card Number
- Medical Record Number (AVHG's numerical system to identify individual patients)
Importantly, our core patient database, where the majority of patient health information is stored, has not been affected.
Please note that we generally do not collect or store patient identity documents or financial information.
What actions has AVHG taken?
Once aware of the incident, we worked urgently to contain the threat and investigate what occurred. We also engaged external cyber security experts to assist with our investigation and response to the incident.
We have followed the recommendations made by our cyber security experts and are confident that all appropriate steps have been taken to remediate the incident.
We have also reported the incident to the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC).
What do you need to do now?
Please carefully read this communication and the below Fact Sheet section, which provides detailed advice on steps to take to help protect your information.
Conclusion
We regret that this incident has occurred, and we would like to apologise for any concern or inconvenience this may cause you.
If you would like any more information about this incident, including the information affected, please contact cyberincident@avhg.com.au
FACT SHEET - STEPS YOU CAN TAKE TO PROTECT YOURSELF FROM HARM
AVHG encourages individuals take the following steps to reduce the risk of harm associated with the potential access to their personal information:
Look out for Scammers, including suspicious emails, texts, phone calls or messages on social media. Never click on any links that look suspicious and never provide your passwords or any personal information.
Consider changing your online passwords. Use strong passwords and enable multi-factor authentication for your online accounts where possible.
If your Medicare card number has been affected, this number alone cannot be used to verify your identity or access your Medicare account. However, if you are concerned about the security of your Medicare account, you can contact Medicare to obtain a replacement card free of charge. You can do this by:
- using your Medicare online account through myGov
- the Express Plus Medicare mobile app
- calling the Medicare program
If you are concerned about the security of your Centrelink account you can contact Services Australia to put additional authentication measures in place.
If your concession card has been impacted, you do not need to get a replacement card, and you can continue to use it as usual.
Please visit www.servicesaustralia.gov.au/databreach for more information on how you can protect your personal information (especially your Medicare, Centrelink or MyGov online accounts) after a data breach.
You can also find further information about online safety, cyber security and helpful tips to protect yourself at the following websites: