One item today, and it is fresh detail on a deal already on the watch list rather than a new transaction. Coverage published on Friday afternoon, after that day's scan, adds detail to the data breach that sits over Bupa's pending acquisition of Partnered Health. Partnered Health has now named the 21 affected clinics across five states and territories, five where it is still investigating and 16 where healthcare-record data may be affected. Where a clinic held it, the information at risk can include Medicare numbers, private health insurance and Veteran Card (DVA) numbers and clinical records, not only names and contact details. The patient-management software provider Best Practice has been cleared: it confirmed Partnered Health as a customer but said its platform was not compromised and it is not part of the incident response. Partnered Health holds an interim NSW Supreme Court injunction against use or publication of the data, and the 22-day gap between detection on 23 June and disclosure on 15 July still draws expert criticism, though it sits inside the OAIC's 30-day assessment window. For the buyer the direction is unchanged and the scope firmer: this stays a live diligence and regulatory-exposure question at the target, not a change to deal timing. The register has not moved: no new Australian GP practice acquisition since Partnered Health's own 3 July Ryan Plaza notification (MN-15027), checked directly this morning, still at Phase 1 with submissions concluded and its determination period ending 14 August.
Coverage published on Friday 17 July, after that morning's scan, adds detail to the data breach at Partnered Health, the general practice and skin cancer network Bupa agreed to buy on 18 June for a figure AFR Street Talk reported at about $450m. Partnered Health has now named the 21 affected clinics, spanning New South Wales, Victoria, Queensland, Western Australia and the Australian Capital Territory, metropolitan and regional, including Sydney, Melbourne, Canberra, the Gold Coast and the Sunshine Coast. Its patient statement splits them into five clinics where it is still investigating the extent of any impact and 16 where information forming part of a patient's healthcare record may have been affected.
Where a clinic held it, the information at risk can include names, dates of birth, addresses and contact details, Medicare numbers, private health insurance details, Veteran Card (DVA) numbers, concession card numbers and clinical records: consultation notes, referral letters and pathology or diagnostic results. The inclusion of insurer and DVA card numbers is the element the sector has picked up, since a fund member who attended an affected practice can raise downstream notification questions for their insurer. Partnered Health has obtained an interim injunction from the Supreme Court of New South Wales restraining use or publication of the accessed data, and has reported the incident to the Australian Cyber Security Centre, the OAIC and law enforcement.
The patient-management software vendor Best Practice was named alongside the incident and has been cleared. Best Practice confirmed that Partnered Health is a customer but said its platform was not compromised and that it is not involved in the incident response. The breach was detected on 23 June and disclosed to patients on 15 July, a 22-day gap that experts have again called unacceptable, though the OAIC's window of about 30 days to assess whether a breach is likely to cause serious harm before notifying places the delay inside the statutory period.
For the buyer the direction is unchanged and the scope firmer. Naming 21 clinics, confirming insurer and DVA data among the categories at risk and holding a court injunction all point to a material cyber and regulatory exposure at the target during a live acquisition. Under the amended Privacy Act a non-serious interference now carries a maximum civil penalty of $3.3m for a body corporate and a serious one up to $50m or 30% of adjusted turnover, and a statutory tort for serious invasions of privacy is in force. Neither Bupa nor Partnered Health has said publicly whether the breach engages representations and warranties or a material adverse change clause in the acquisition agreement, and it should not be assumed either way. The deal remains subject to ACCC and FIRB approval, with Bupa's only public timing marker the settlement 'expected later this year' that The Medical Republic reported on 16 July, the outlet's wording rather than a quoted Bupa statement.
The register has not otherwise moved. Checked directly on the ACCC register this morning, the only general practice matter under the mandatory merger regime is still Partnered Health's own bid for the 11-GP Medicine on Second clinic at Maroochydore (MN-15027), lodged by group entity PH Medical Centres and effective 3 July. It remains at Phase 1 initial assessment with submissions concluded and no determination published, and the determination period ends 14 August; a Phase 1 decision was flagged for the second half of July and has not yet appeared. The Bupa-Partnered Health parent transaction has still not surfaced as a separate notification, so the ACCC and Foreign Investment Review Board approvals the Bupa deal needs remain outstanding. The filing describes the PH Primary Care Group as 67 general practice clinics and medical centres engaging about 570 GPs, majority owned by Quadrant Private Equity through QPE Fund 6.
Own a practice and thinking about your exit, this year or in three? Write to kate.marie@mediusglobal.com.au, in confidence.
Buying, lending or researching? The full operator dataset behind the Zoo is licensed: get the full data.