The Times Australia
The Times World News

.

I've given out my Medicare number. How worried should I be about the latest Optus data breach?

  • Written by Bruce Baer Arnold, Associate Professor, School of Law, University of Canberra

Medicare card numbers are the latest personal details to be exposed as part of the Optus data breach[1].

Optus has confirmed[2] this affects 14,900 valid Medicare numbers that have not expired, and a further 22,000 expired card numbers.

But this isn’t the first time Australians’ Medicare numbers have been exposed. And some privacy and cybersecurity experts have long been concerned[3] about the security of our health data.

Here’s what you can do if you’re concerned about the latest Medicare breach, and what needs to happen next.

What’s the big deal?

Your Medicare number gives you access to subsidised services across Australia’s health system. Most Australians have a number, whether or not they use these services.

Your Medicare card (as a plastic card or digitally, on your phone) is an official identifier. So alongside a driver’s licence, tax file number, birth certificate and passport, it can also be used as “proof of identity”. You may have supplied your Medicare number when opening a bank account, or signing up for a phone plan.

The idea is to minimise the chance people are using fake identities to wrongfully gain benefits from governments and business, including taking part in criminal activities such as money laundering.

Businesses and agencies are not meant to match your Medicare number with other data (eroding your privacy) other than in exceptional[4] circumstances.

But they commonly accept sight of the physical/digital card bearing the number as proof of who you claim to be and risk data breaches by retaining copies of what they saw. Optus was such a business.

Read more: The 'Optus hacker' claims they've deleted the data. Here's what experts want you to know[5]

What should happen to protect your Medicare number?

In theory, your Medicare number is protected by a number of different types of legislation – both national and at the state/territory level.

There are privacy laws[6]. These are meant to prevent businesses and government agencies from unauthorised[7] use of Medicare and other official identifiers for profiling people. These laws are also meant to prevent undisclosed sharing with other entities, such as individuals or businesses.

Then there are cybersecurity[8] and other criminal laws[9]. These also aim to prevent unauthorised access, sale and sharing of your Medicare[10] number and other data (known as metadata[11]) stored by telecommunication providers.

Read more: What should Australian companies be doing right now to protect our privacy[12]

Has this happened before?

Medicare numbers have been breached before, in 2017[13]. An official inquiry[14] noted trade in stolen Medicare numbers on the dark web.

The 2017 breach was apparently much larger, but the Optus numbers may grow as the investigation continues.

Experts have also raised concern[15] about the government’s authorised release in 2016 of apparently de-identified health data. In fact, patient details could be identified, using a number of simple steps.

These two earlier examples should have meant both health agencies and businesses have taken extra care about their obligations to safeguard health data.

Read more: After the Medicare breach, we should be cautious about moving our health records online[16]

What if your Medicare number has been exposed?

Unauthorised use of a Medicare number doesn’t necessarily result in large-scale identity crime.

For instance, Minister for Government Services Bill Shorten has said[17] a Medicare number alone cannot unlock access to someone’s myGov account (and therefore access to someone’s welfare or tax details).

However, the Optus data breach – and future data breaches in the public and private sector – does provide Australian and overseas criminals with a set of identifiers (including passport and driver’s licence numbers), that can be used for a range of identity crimes, such as impersonating someone else.

Optus is advising affected customers[18] to replace their Medicare card, at no cost, via their Medicare online account at myGov, the Express Plus Medicare mobile app, or by calling Medicare on 132 011.

Further details are available via Services Australia[19].

Read more: What does the Optus data breach mean for you and how can you protect yourself? A step-by-step guide[20]

What else needs to happen?

As with many data breaches, details about what happened at Optus, how and who is affected are only slowly trickling out.

The Office of the Australian Information Commission[21] – the national privacy regulator – needs to run a rigorous and detailed investigation and release its findings publicly.

This needs to be accompanied by a hard-hitting independent inquiry of what happened at Optus. This requires IT expertise, which the Office of the Australian Information Commission may not have. Such an inquiry would also demonstrate Optus’ commitment to learn from any failures.

As we have seen before, businesses and government agencies cannot assume a data breach “won’t happen to them”. We need to find out what happened at Optus to ensure the future privacy of some of our most personal data.

References

  1. ^ Optus data breach (www.theguardian.com)
  2. ^ has confirmed (www.optus.com.au)
  3. ^ long been concerned (theconversation.com)
  4. ^ exceptional (www.health.gov.au)
  5. ^ The 'Optus hacker' claims they've deleted the data. Here's what experts want you to know (theconversation.com)
  6. ^ privacy laws (www.servicesaustralia.gov.au)
  7. ^ unauthorised (www.oaic.gov.au)
  8. ^ cybersecurity (www.homeaffairs.gov.au)
  9. ^ criminal laws (www.austlii.edu.au)
  10. ^ Medicare (www.sciencedirect.com)
  11. ^ metadata (eprints.qut.edu.au)
  12. ^ What should Australian companies be doing right now to protect our privacy (theconversation.com)
  13. ^ in 2017 (theconversation.com)
  14. ^ inquiry (www.servicesaustralia.gov.au)
  15. ^ raised concern (pursuit.unimelb.edu.au)
  16. ^ After the Medicare breach, we should be cautious about moving our health records online (theconversation.com)
  17. ^ has said (twitter.com)
  18. ^ advising affected customers (www.optus.com.au)
  19. ^ Services Australia (www.servicesaustralia.gov.au)
  20. ^ What does the Optus data breach mean for you and how can you protect yourself? A step-by-step guide (theconversation.com)
  21. ^ Office of the Australian Information Commission (www.oaic.gov.au)

Read more https://theconversation.com/ive-given-out-my-medicare-number-how-worried-should-i-be-about-the-latest-optus-data-breach-191575

Times Magazine

Building a Strong Online Presence with Katoomba Web Design

Katoomba web design is more than just creating a website that looks good—it’s about building an online presence that reflects your brand, engages your audience, and drives results. For local businesses in the Blue Mountains, a well-designed website a...

September Sunset Polo

International Polo Tour To Bridge Historic Sport, Life-Changing Philanthropy, and Breath-Taking Beauty On Saturday, September 6th, history will be made as the International Polo Tour (IPT), a sports leader headquartered here in South Florida...

5 Ways Microsoft Fabric Simplifies Your Data Analytics Workflow

In today's data-driven world, businesses are constantly seeking ways to streamline their data analytics processes. The sheer volume and complexity of data can be overwhelming, often leading to bottlenecks and inefficiencies. Enter the innovative da...

7 Questions to Ask Before You Sign IT Support Companies in Sydney

Choosing an IT partner can feel like buying an insurance policy you hope you never need. The right choice keeps your team productive, your data safe, and your budget predictable. The wrong choice shows up as slow tickets, surprise bills, and risky sh...

Choosing the Right Legal Aid Lawyer in Sutherland Shire: Key Considerations

Legal aid services play an essential role in ensuring access to justice for all. For people in the Sutherland Shire who may not have the financial means to pay for private legal assistance, legal aid ensures that everyone has access to representa...

Watercolor vs. Oil vs. Digital: Which Medium Fits Your Pet's Personality?

When it comes to immortalizing your pet’s unique personality in art, choosing the right medium is essential. Each artistic medium, whether watercolor, oil, or digital, has distinct qualities that can bring out the spirit of your furry friend in dif...

The Times Features

How much money do you need to be happy? Here’s what the research says

Over the next decade, Elon Musk could become the world’s first trillionaire[1]. The Tesla board recently proposed a US$1 trillion (A$1.5 trillion) compensation plan, if Musk ca...

NSW has a new fashion sector strategy – but a sustainable industry needs a federally legislated response

The New South Wales government recently announced the launch of the NSW Fashion Sector Strategy, 2025–28[1]. The strategy, developed in partnership with the Australian Fashion ...

From Garden to Gift: Why Roses Make the Perfect Present

Think back to the last time you gave or received flowers. Chances are, roses were part of the bunch, or maybe they were the whole bunch.   Roses tend to leave an impression. Even ...

Do I have insomnia? 5 reasons why you might not

Even a single night of sleep trouble can feel distressing and lonely. You toss and turn, stare at the ceiling, and wonder how you’ll cope tomorrow. No wonder many people star...

Wedding Photography Trends You Need to Know (Before You Regret Your Album)

Your wedding album should be a timeless keepsake, not something you cringe at years later. Trends may come and go, but choosing the right wedding photography approach ensures your ...

Can you say no to your doctor using an AI scribe?

Doctors’ offices were once private. But increasingly, artificial intelligence (AI) scribes (also known as digital scribes) are listening in. These tools can record and trans...