One item today, and it lands on a deal already on the watch list. Partnered Health, the general practice and skin cancer network that Bupa agreed to buy for about $450m on 18 June, told patients on 15 July that an attacker had accessed its systems on 23 June, five days after the deal was announced and while the acquisition still needs ACCC and Foreign Investment Review Board clearance. The group has written to patients at 21 clinics across five states and territories, has confirmed that data was taken from 16 of them, and has an interim NSW Supreme Court injunction against the use or publication of the stolen material. For a buyer mid-clearance this is deal-execution risk, cyber liability and notifiable-breach exposure landing on top of the ACCC and FIRB conditions. The register has not otherwise moved: no new Australian GP practice acquisition has reached it since Partnered Health's own 3 July Ryan Plaza notification, which sits at Phase 1 with submissions concluded and its determination period ending 14 August.
Partnered Health told patients on 15 July that an attacker had accessed its systems on 23 June. Bupa had agreed to buy the Quadrant-owned network for about $450m on 18 June, as AFR Street Talk reported, so the breach occurred five days into a transaction that still needs ACCC clearance and Foreign Investment Review Board approval. The group has written to patients at 21 clinics across New South Wales, Victoria, Queensland, Western Australia and the ACT, has confirmed that data was taken from 16 of them, and is still investigating the remaining five (three in Western Australia, two in Victoria). Named examples include North Canberra Family Practice in the ACT and Joondalup City Medical Group in Western Australia.
The company says the accessed data may include names, dates of birth, addresses and contact details, Medicare, private health insurance, veteran and concession card numbers, and medical information such as consultation notes, referral letters and pathology or diagnostic results. It has reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement, and has obtained an interim injunction from the Supreme Court of New South Wales restraining the use or publication of the accessed data. Partnered Health runs about 71 clinics nationally across the group (Bupa's 18 June release said 68 primary care plus three urgent care; the ACCC filing for the Ryan Plaza matter describes 67 primary care), spanning general practice, skin cancer, allied health and mental health, with brands including Jobfit, Baseline Onsite, New View Psychology, NewPsych Psychology and Australian EAP.
For the buyer this is deal-execution risk on a corporate GP acquisition caught mid-clearance. Cyber liability, notifiable-breach exposure under the OAIC scheme, remediation cost and possible warranty or price consequences now sit on top of the ACCC and FIRB conditions the deal already carried. It is also a reminder that cyber security is a standing operating and due-diligence burden for any acquirer of a multi-site GP network, where the value of the asset and the sensitivity of the data it holds move together.
The register has not otherwise moved. Checked directly on the ACCC register today, the only GP practice matter under the mandatory merger regime is still Partnered Health's own bid for the 11-GP Medicine on Second clinic at Maroochydore (MN-15027), lodged by group entity PH Medical Centres and effective 3 July. It remains at Phase 1 initial assessment with submissions concluded and no determination published, and the determination period ends 14 August. The larger Bupa-Partnered Health parent transaction has still not appeared on the register as a separate notification.
Own a practice and thinking about your exit, this year or in three? Write to kate.marie@mediusglobal.com.au, in confidence.
Buying, lending or researching? The full operator dataset behind the Zoo is licensed: get the full data.