AHPRA Leaked 136 Clinicians' Emails In One Webinar Invite
On 29 July 2026, an AHPRA webinar invitation exposed the private email addresses of 136 clinicians to every other invitee. AHPRA apologised the same day, and the breach became public on 6 August 2026. The mistake is the same one that shows up on unaudited clinic contact forms every day.

Key Takeaways
- AHPRA apologised to affected clinicians on 29 July 2026, the same day a webinar invitation exposed their addresses; the breach was first reported publicly on 6 August 2026
- 136 clinicians, including doctors, nurses and radiologists, had their private email addresses shared with every other invitee, according to ABC News
- The exposed invite list was for a webinar scheduled for 26 August 2026 on substance misuse health notifications, a topic invitees expected to stay confidential
- Australian regulators logged 595 data breach notifications in the second half of 2024, and human error caused 170 of them (29 percent), per the OAIC
- “Email sent to the wrong recipient” was the single biggest human error cause, at 71 cases (42 percent of the human error category)
- Health service providers reported 121 breaches (20 percent of every notification lodged), the highest of any sector
- AHPRA notified the National Health Practitioner Ombudsman after the breach and apologised individually to each affected clinician
AHPRA apologised to affected clinicians on 29 July 2026, the same day a webinar invitation it sent exposed their private email addresses to each other. The breach became public on 6 August 2026, when newsGP reported it. The regulator that clinics answer to got caught by the same mistake that trips up a badly built contact form: one recipient field showing everyone’s address to everyone else.
Here’s the part that should worry you more than the headline. The Office of the Australian Information Commissioner logged 595 data breach notifications in the back half of 2024, and email sent to the wrong recipient was the single biggest human error cause among them. Health service providers reported more breaches than any other sector.
Picture your own clinic’s enquiry form. Where does a submission actually go? Who else sees the follow-up email? If you can’t answer that in one sentence, you have the same gap AHPRA just apologised for, except the addresses on your list are patients, not practitioners.

What Actually Happened at AHPRA
On Wednesday 29 July 2026, AHPRA sent an invitation for a webinar scheduled for 26 August 2026, on addiction and recovery for practitioners with substance misuse related health notifications. The invitation exposed every invitee’s private email address to every other invitee. newsGP described dozens of medical professionals affected. ABC News later put the confirmed number at 136 practitioners, including doctors, nurses and radiologists.
AHPRA’s own statement, quoted by newsGP, was direct: “AHPRA has apologised for an error made during the scheduling of a webinar that resulted in private email addresses being shared with other invitees.” AHPRA said it alerted those affected, asked them to delete the email, apologised individually, and notified the National Health Practitioner Ombudsman. Health Minister Mark Butler called the breach “totally unacceptable,” according to Medical Republic.
The sensitivity compounds the exposure. This was a list of clinicians connected to a health notification for substance misuse, a category most people would want kept private from colleagues, let alone strangers on an invite thread.
Takeaway: the exact mechanism that caused this, one recipient field that showed everyone’s address to everyone else, is a build detail, not a policy decision. It fails the same way whether the sender is a national regulator or a solo-practitioner clinic.
The Same Mistake Happens Constantly
AHPRA’s slip is not an outlier. It’s the most common way Australian organisations leak personal information by accident. The OAIC’s Notifiable Data Breaches Report for July to December 2024 recorded 595 total notifications: 404 (69 percent) from malicious or criminal attacks, 170 (29 percent) from human error, and 12 (2 percent) from system faults.
Inside that human error category, one cause towers over the rest: personal information sent to the wrong recipient by email, at 71 cases, 42 percent. Unauthorised disclosure, an unintended release or publication, was next at 39 cases, 23 percent. Every other cause combined made up the remaining 60 cases, 35 percent.
Health service providers reported 121 breaches in the same six months, 20 percent of every notification logged, more than any other sector.
Takeaway: the biggest privacy risk on a clinic’s books usually isn’t a hacker. It’s an email sent to the wrong list, and health services report that failure more than any other industry.
Where This Breaks on a Clinic Website
Trace a real enquiry form submission end to end and the exposure points show up fast.
- The form itself. Where does a submitted name, phone number and email actually land? A shared inbox, a spreadsheet, a CRM. Every hop is a place the address can end up on a list someone forgets to hide.
- The follow up tool. Most clinics use a third party service for confirmations and reminders. Some send one email per contact. Others, especially a quick group send rather than a proper mail merge, put every recipient in the same “to” or “cc” field.
- The export. Anyone with access to the booking system or marketing tool can usually export the full contact list, rarely logged, rarely time-limited.
- The retention period. Enquiry records often sit indefinitely because nobody set a deletion rule, so an old lead can still be sitting in the list a group email gets pulled from.
RockingWeb checks each of those four points against what your clinic’s published privacy policy actually promises when we review a clinic’s site.
Takeaway: the breach mechanism is the same no matter the sender. A form that funnels contacts into a shared list, sent through a tool that defaults to group visibility, is one keystroke away from repeating AHPRA’s mistake with your own patients’ details.
The Build-Side Checklist
Four checks, one afternoon:
| Risk point | What to check | Fix |
|---|---|---|
| Transactional email | Does a confirmation or reminder ever go to more than one address at once? | Force individual sends, never a group “to” or “cc” field |
| Marketing lists | Is a shared inbox or CRM export ever used as a mailing list? | Route all bulk sends through a tool with BCC or per-recipient merge by default |
| List exports | Who can export the full contact list, and is it logged? | Restrict export permission and keep an access log |
| Retention | Is there a rule for deleting old enquiry records? | Set and enforce a retention limit that matches the privacy policy |
None of this requires a rebuild. It’s a configuration review of tools most clinics already have.
Takeaway: every one of these checks is a website and workflow question, not a legal one, and every one of them can be verified without touching a patient record.
Why the Privacy Policy Still Matters
A clinic’s privacy policy is a promise about what happens to a visitor’s information after they hit submit. If that policy says data is handled securely, and the enquiry form actually feeds a shared inbox that ten staff can export at will, the policy and the build have drifted apart. AHPRA’s statement described “an error made during the scheduling,” a process failure, not a system designed to leak. Most clinic websites carry the same risk: not a deliberate choice, just a default nobody checked. Clinics building or rebuilding a cosmetic clinic website can set BCC-by-default and individual sends as the starting configuration, rather than retrofitting it after a mistake.
Takeaway: a privacy policy is only as good as the workflow behind it. Read the policy on your own website today and ask whether the actual form-to-inbox path matches what it promises.
FAQ
Did AHPRA’s privacy breach involve patient data, or only practitioner data?
Only practitioner data. The exposed addresses belonged to the 136 clinicians invited to the webinar, not patients. The same mistake happens on clinic side forms too, usually exposing patient contact details instead.
What is the difference between a CC field and a BCC field, and why does it matter for a clinic contact form?
CC, carbon copy, shows every recipient’s address to every other recipient. BCC, blind carbon copy, hides them. A tool that emails a group, whether a webinar invite or a booking confirmation batch, exposes every address unless it uses BCC or sends one email per person.
How common is email sent to the wrong recipient as a cause of data breaches in Australia?
It was the single largest human error breach cause reported to the OAIC in the second half of 2024, accounting for 71 of 170 human error notifications, 42 percent of that category, out of 595 total breach notifications for the period.
How do I check whether my clinic’s own enquiry or booking form has this same exposure risk?
RockingWeb can trace exactly where a form submission lands, which third party tool sends the follow up, and whether that tool defaults to individual sends or a shared recipient list. Get in touch if you want yours checked.
Get Your Clinic’s Form and Email Flow Checked
RockingWeb traces every enquiry and booking form on a clinic website end to end: where the data lands, which tool sends the follow up, and whether the published privacy policy matches the real build.
Sources and References
ABC News - exclusive investigative report by Charlotte Grieve, published 6 August 2026, primary source for the 136 practitioners figure
newsGP (RACGP) - primary report, published 6 August 2026, including AHPRA’s verbatim statement
Medical Republic - secondary source, repeats the 136 clinicians figure and the Health Minister’s comment, published 7 August 2026
Office of the Australian Information Commissioner - Notifiable Data Breaches Report, July to December 2024, source for all breach statistics
Related reading:
- AHPRA Advertising Complaints Hit 380 a Year: the regulator’s own enforcement numbers
- AHPRA Cosmetic Surgery Hotline Complaints: what gets reported through AHPRA’s complaints line
- Meta’s New Ad Rules Won’t Save You From a $120K AHPRA Fine: another case where a platform’s rules and AHPRA’s rules diverge
For a website and email workflow that keeps patient details where they belong, see Cosmetic Clinic Websites or talk to us about your clinic’s form and booking setup.

Vikas Thakur
Founder of RockingWeb. 16 years building for companies like TPG, iiNet and Monadelphous, now focused on websites and marketing that comply with AHPRA's advertising guidelines and still book patients.
![Dentures Cost Australia: Full vs Partial Price Data [2026]](/assets/ahpra-social-media-rules-cosmetic-clinics-LFCez6qC.png)




