Data leak

HealthEngine Patient Privacy Breach β€” Australia, Data Sold to Lawyers Without Consent (OAIC)

πŸ“… 2018-01-01 🏒 HealthEngine patient appointment booking platform (Australia)
Primary Source β†—

Incident Details

HealthEngine, Australia’s largest health appointment booking platform with over 17 million users across approximately 60,000 healthcare practices, was found by Australian regulators to have improperly shared patient data with third parties without meaningful patient consent. Specifically, HealthEngine shared health condition information from approximately 59,000 patients with personal injury law firm Slater & Gordon for commercial lead generation purposes β€” patients would book a GP appointment, disclose their health condition, and this information was shared with lawyers without adequate disclosure. The Australian Competition and Consumer Commission (ACCC) took action in the Federal Court, reaching a $2.9 million settlement β€” then one of Australia’s largest digital health privacy penalties. The Australian Information Commissioner (Angelene Falk) found HealthEngine had interfered with privacy by sharing identifiable health information for secondary commercial purposes. The ACCC also found HealthEngine had made misleading claims about how patient review data was handled, including editing negative patient reviews before publication and using modified reviews in advertising without disclosure. The company was required to notify all affected patients, implement a privacy compliance programme, and provide enhanced transparency about data sharing. The case established important precedents about consent requirements for commercial monetisation of health data in Australia and contributed to the development of Australia’s revised Privacy Act reforms.

Technical Details

Initial Attack Vector
HealthEngine shared patient appointment and health data with Slater & Gordon law firm and health insurance funds without adequate patient consent, using fine print in terms of service that patients were unlikely to read; separately, HealthEngine edited negative reviews posted on its platform before publication
Vendor / Product
HealthEngine patient appointment booking platform (Australia)

Timeline

  1. 2018-01-01 Breach occurred
  2. 2019-05-15 Publicly disclosed
  3. 2019-05-15 Customers notified