Cybersecurity Policy Report, Australia Files Civil Penalty Proceeding Against Medibank, (Jun 6, 2024)
Organizations Mentioned:Medibank Private Limited
The Office of the Australian Information Commissioner (OAIC) has filed civil penalty proceedings in federal court against Medibank Private Ltd. over a 2022 data breach that resulted in unauthorized access to the personal information of 9.7 million Australians.
Medibank is a health insurance provider that collects and holds customers’ personal and sensitive health information. The proceedings follow an investigation into Medibank’s privacy practices with the Commissioner alleging that from March 2021 to October 2022, Medibank failed to take reasonable steps to protect the personal information of Australians from misuse and unauthorized access. The investigation focused on whether Medibank’s acts or practices “were an interference with privacy or a breach of Australian Privacy Principle (APP) 11.1.”
Under APP 11.1, Medibank is required to take reasonable steps to protect the information it holds from “misuse, interference and loss, as well as from unauthorized access, modification or disclosure.” The investigation considered Medibank’s practices in managing and securing the personal information it held and “whether such steps were reasonable in the circumstances to protect the personal information from unauthorized access.”
The federal court can impose a civil penalty up to AU$2.2 million (US$1.47 million) for each violation.
News: InternationalLegislation DataPrivacy DataSecurity DataBreach LitigationEnforcement