Victorian Doctors Seek Answers From OpenAI and Governments Over Medicare Breach

By Rex Widerstrom
Rex Widerstrom
Rex Widerstrom
Rex Widerstrom is a New Zealand-based reporter with over 40 years of experience in media, including radio and print. He is currently a presenter for Hutt Radio.
October 1, 2026Updated: October 1, 2026

The Australian Medical Association (AMA) Victorian branch has called on OpenAI and the Victorian and federal governments to explain how they will protect patient health data following a security incident in which an OpenAI agent gained unauthorised access to a Medicare statistics portal.

While the doctors’ group noted that no personal information appears to have been accessed, AMA Victoria President Dr Simon Judkins asked, “What happens next time if an AI agent gains access to a system containing sensitive clinical information?”

Judkins said the breach raised serious questions for doctors and patients.

“Confidentiality remains absolutely critical to maintaining a trusted relationship between a doctor and their patient, and increasingly that depends on the security of the digital systems we use every day,” he said.

“Patients and doctors need confidence that unauthorised access will be detected quickly and reported immediately … Why did it take nearly three months for Australian authorities to be notified?”

Prime Minister Anthony Albanese said the agent reached the Medicare Statistics Reporting Service portal, run by Services Australia, on June 18.

It accessed public and non-public files after finding a way around existing blocks. Albanese said no personal information is believed to have been accessed, though official investigations remain ongoing.

OpenAI notified the Australian government on Sept. 10 via an email sent to a public mailbox, according to the prime minister.

Services Australia subsequently reported the breach to the Australian Cyber Security Centre on Sept. 15.

“It took until Sept. 10 before there was any notification,” Albanese said, adding that “there will obviously be legal consequences on it.”

Other Agencies Affected

OpenAI confirmed its agents also accessed sites belonging to the Australian Institute of Health and Welfare (AIHW) and NSW Bureau of Crime Statistics and Research.

At the Victorian Department of Health, the company stated that agents used an exposed access key to retrieve aggregate statistics, though medical records were not accessed.

The AMA said that federal investigations are examining the agent’s interactions across multiple government systems.

The company has since apologised. “We should have handled our response better. We are sorry and working to do better in the future,” OpenAI stated, committing to establish a task force on AI control.

OpenAI has also committed to having its chief strategy officer, Jason Kwon, appear before a Joint Select Committee inquiry in Sydney on Oct. 6.

Mounting Cybersecurity Concerns

Australia has previously experienced major breaches involving health information, including the 2022 Medibank cyberattack, in which data including names, dates of birth, addresses, phone numbers, and Medicare numbers of millions of Australians was accessed.

In 2024, a separate attack on electronic prescriptions provider MediSecure exposed personal and health information, prompting a federal investigation.

Dr Mukesh Haikerwal, a former AMA Victoria and federal AMA president, said governments must also consider what safeguards are needed.

“The clear question to ask is whether the Federal and Victorian governments are satisfied that our health systems are adequately protected against unauthorised access by AI?” he said.

“What safeguards are in place for hospital records, My Health Record and electronic prescribing?”

An Australian Signals Directorate report found only 22 percent of surveyed government entities met all eight key cybersecurity measures in 2025.

The Epoch Times has sought comment from Services Australia and the Victorian Department of Health.