1 in 5 Australian Data Breaches Hit Health Providers in 2024
Health service providers, the category dental practices fall under, accounted for 121 of the 595 data breaches reported to Australia's privacy regulator in the second half of 2024, 20% of the total. It was the top sector for the third straight reporting period.

On this page 9
- Key Takeaways
- The Sector That Keeps Topping the List
- Why “Health Service Provider” Already Means Your Practice
- What’s Actually Driving the Breaches
- A Real Example, Not a Hypothetical
- What This Means for a Practice’s Booking System and Forms
- FAQ
- Get Your Practice’s Website and Forms Checked
- Sources and References
Key Takeaways
- Health service providers reported 121 of the 595 data breaches notified to the OAIC in the second half of 2024, 20% of the total and the highest of any sector
- Health providers topped the sector list in three consecutive OAIC reporting periods: 22% (July-December 2023), 19% (January-June 2024) and 20% (July-December 2024)
- The Privacy Act’s $3 million small business turnover exemption does not apply to health service providers, including dental practices, regardless of size
- Malicious or criminal attack was the leading cause among breaches with a known source, at 404 of 586 notifications (69%) in the second half of 2024
- Human error caused 170 notifications (29%) of the same known-source total, more than 10 times the 12 caused by system faults
- In April 2026, a ransomware group listed a Queensland dental practice as a breach victim, claiming records on more than 500 patients
- No OAIC report publishes a dental-specific breach count. Dental practices sit inside the broader “health service providers” category alongside hospitals, GPs and allied health
Health service providers reported more data breaches to Australia’s privacy regulator than any other sector for the third straight reporting period, according to the Office of the Australian Information Commissioner. In the second half of 2024, that was 121 breaches out of 595 total notifications, 20% of everything reported nationally. A dental practice sits inside that category the moment it holds a patient’s health information, and the law treats it that way regardless of chair count. There is no separate dental line item in the OAIC’s data. This is the closest verified figure to a “dental breach rate,” and it comes with a real caveat worth stating plainly. Here is what the number actually says, and what it means for the forms and booking systems on a dental practice’s own website.
The Sector That Keeps Topping the List
The OAIC publishes a breach report every six months, ranking every reporting sector by notification count. Health service providers have finished first in each of the last three reports.
| Reporting period | Health sector notifications | Share of total | Total notifications |
|---|---|---|---|
| July-December 2023 | 104 | 22% | 483 |
| January-June 2024 | 102 | 19% | 527 |
| July-December 2024 | 121 | 20% | 595 |
Every other sector, including the Australian Government and the finance industry, moved up and down that ranking across the same three reports. Health service providers did not.
Takeaway: health service providers have been the single most breached sector in Australia for at least 18 straight months, and a dental practice reports into that same category.
Why “Health Service Provider” Already Means Your Practice
Most small businesses with annual turnover of $3 million or less sit outside most of the Privacy Act’s obligations. The OAIC’s own guidance carves out an explicit exception for health service providers: businesses that provide services related to physical, emotional, psychological or mental health, holding health information, are covered in full regardless of turnover.
Dentistry is a health service. A dental surgery holding patient health records is a health service provider under that definition, the same as a GP clinic or a physiotherapist, whether it has one chair or twenty. That means the full Australian Privacy Principles apply, including the obligation to notify affected patients and the OAIC when an eligible data breach occurs, and it applies from the day a practice opens, not once it crosses a revenue threshold.
Takeaway: a practice cannot rely on being small to sit outside data breach notification law. If it holds health information, the full set of obligations already applies.
What’s Actually Driving the Breaches
Across every sector the OAIC tracked in the second half of 2024, malicious or criminal attack was the dominant cause among the 586 notifications with a known source: 404, 69% of that total. Human error accounted for 170 notifications, 29%. System faults made up the remaining 12, just 2%.
The OAIC’s public reporting doesn’t break that cause split down by individual sector, so it isn’t possible to say precisely what share of the 121 health sector breaches were attacks versus mistakes. What’s verifiable is that a practice’s exposure runs on two separate tracks: an external one (someone breaking in) and an internal one (someone sending the wrong file to the wrong address), and nationally the external track accounts for more than two in three reported breaches.
Takeaway: the biggest single risk to a practice’s patient data is an outside attacker, not an internal mistake, though internal mistakes still account for close to three in ten breaches nationally.
A Real Example, Not a Hypothetical
In April 2026, the ransomware group Gunra listed Eric Davis Dental, a practice with locations at Margate Beach and Forest Glen in Queensland, as a breach victim on its leak site. The group claimed to hold files on more than 500 patients, including referral letters, DNA results and billing documents. The practice disputed the claim, stating its own review with an IT security provider found no evidence of a system compromise.
Whichever account turns out to be accurate, the listing itself is the point. A dental practice’s name being posted on a ransomware group’s site is now something that happens to Australian dental practices specifically, not just to hospitals or health insurers making national headlines. RockingWeb reviews a practice’s website and forms for the same basic security gaps that show up in these listings, alongside the advertising rules a compliant build has to satisfy.
Takeaway: ransomware groups already target Australian dental practices by name. Whether every claim holds up, the exposure is current, not theoretical.
What This Means for a Practice’s Booking System and Forms
A dental practice’s website is usually the single biggest collector of patient health information outside the practice management system itself. Online booking forms, new patient intake forms and contact forms routinely ask for medical history, Medicare or health fund details, and reasons for visiting, all of which count as health information under the Privacy Act.
Three practical points follow directly from the data above, without stepping into legal advice about what any specific practice must do:
- Every form that collects health information is inside the scope of the Notifiable Data Breaches scheme, regardless of the practice’s size or turnover.
- Attackers are the leading cause of breaches nationally, which makes the practice management software, booking plugins and any third-party integration connected to the website part of the attack surface, not just the website’s own code.
- A breach doesn’t need to be confirmed to cause damage. A ransomware group’s public listing, disputed or not, is already the kind of event a patient, a journalist or a competitor can find with a search.
A compliant clinic website build separates the marketing site from patient data collection, minimises what a public-facing form stores, and documents where every submitted form’s data actually goes, the same groundwork that makes an eventual breach notification faster to complete rather than a scramble to reconstruct after the fact. For dental practices specifically, this sits alongside the advertising rules covered in our breakdown of AHPRA’s advertising requirements for cosmetic dentistry, since both obligations apply to the same website at the same time.
Takeaway: the booking form on a dental practice’s homepage is a health information system under the Privacy Act, whether or not anyone on staff thinks of it that way.
FAQ
Does the Notifiable Data Breaches scheme apply to a small dental practice?
Yes. The Privacy Act’s small business exemption, which excuses businesses with $3 million or less in annual turnover from most privacy obligations, does not apply to health service providers. A dental surgery holds health information regardless of its size, so it is covered in full, including the requirement to notify the OAIC of an eligible data breach.
Which sector reports the most data breaches in Australia?
Health service providers, according to the OAIC’s own six-monthly Notifiable Data Breaches reports. The sector topped every list for three straight reporting periods, from July-December 2023 through July-December 2024, at 22%, 19% and 20% of total notifications.
What causes most of the data breaches reported to the OAIC?
Across all sectors, malicious or criminal attack was the leading cause among the 586 notifications with a known source, at 404 (69%) in the July-December 2024 period. Human error accounted for 170 notifications (29%) and system faults for 12 (2%). The OAIC’s public reporting does not break this cause breakdown down by individual sector.
Has an Australian dental practice actually been targeted by ransomware?
Yes. In April 2026, the Gunra ransomware group listed Eric Davis Dental, a Queensland practice with locations at Margate Beach and Forest Glen, as a breach victim, claiming files on more than 500 patients. The practice disputed the claim, stating its own review found no evidence of a system compromise.
Get Your Practice’s Website and Forms Checked
RockingWeb reviews cosmetic dental practice websites against current AHPRA advertising rules and basic data handling practice, at no cost, with findings delivered within five business days.
Talk to us about your practice’s websiteSources and References
OAIC - Notifiable Data Breaches Report, July-December 2024: 121 health sector notifications, 20% share, 595 total, and the malicious attack/human error/system fault breakdown
OAIC - Notifiable Data Breaches Report, January-June 2024: 102 health sector notifications, 19% share, 527 total
OAIC - Notifiable Data Breaches Report, July-December 2023: 104 health sector notifications, 22% share, 483 total
OAIC - Small business guidance: confirms the small business exemption does not apply to health service providers regardless of turnover
GRM Law (secondary source) - Privacy Obligations for Healthcare in Australia: names dental surgeries explicitly as a covered health service provider type
Cyber Daily - Exclusive: Gunra ransomware lists Eric Davis Dental as breach victim: the named April 2026 incident, including the practice’s dispute of the claim
Related reading:
- AHPRA Advertising Rules for Cosmetic Dentistry: the dental-specific advertising rules that apply alongside data handling obligations
- Cosmetic Clinic Websites: compliant website builds for AHPRA-regulated practices
- How Many Dentists Are in Australia?: the workforce data behind the sector this report affects

Vikas Thakur
Founder of RockingWeb. 16 years building for companies like TPG, iiNet and Monadelphous, now focused on websites and marketing that comply with AHPRA's advertising guidelines and still book patients.





