Why Medibank is refusing to reveal the findings of its cyber attack review

The private health insurer is refusing to reveal the findings of an external review into a high-profile cyber attack on the company, which breached the private information of about 10 million customers.

Two women walk past Medibank store.

Private health insurer Medibank is refusing to reveal the findings of a review into a high-profile cyber attack. Source: Getty / Muhammad Farooq

Key Points
  • Medibank has refused to reveal findings of a review into a major cyber attack.
  • The cyber attack breached the private information of about 10 million customers.
  • The private health insurer said it plans to implement all review recommendations.
Medibank won't reveal the findings of an external review into a due to security fears.

The private information of about 10 million customers was released onto the dark web following a cyber hack in October 2022.

Consultancy firm Deloitte was recruited by the health insurance giant to investigate the incident and make recommendations about potential improvements to Medibank's IT processes and systems.
In a statement to the ASX on Friday, Medibank said it had received the review findings and it planned to implement all recommendations. The company did not outline details of the recommendations.

A spokeswoman for the company told AAP the review would not be made public as it contained confidential and sensitive information about cyber security measures.

"We don't think it's in the interests of our customers or the broader Australian community to publicly release their findings given the security risks this would pose, not only to Medibank but other Australian businesses," she said.
Data stolen by the hackers included names, phone numbers, Medicare numbers and sensitive health information.

Medibank chairman Mike Wilkins said the company was focused on making sure customers had the security they expected and deserved.
"The board will continue to oversee the completion of steps to implement the recommendations to enhance systems and processes even further," he said.

Medibank shareholders and customers launched separate class actions following the hack.

Share
Published 28 April 2023 1:24pm
Source: AAP



Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world