Skip to content
Ransomware News

Ransomware Group incransom Hits: PARTNERED HEALTH GROUP

Admin
HookPhish team

Summary

In the latest cybersecurity news, PARTNERED HEALTH GROUP — an organization based in AU — has fallen victim to a ransomware attack conducted by the group incransom. This data breach, discovered on 2026-07-30T16:30:13.670561+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization PARTNERED HEALTH GROUP
Threat Group incransom
Summary PARTNERED HEALTH GROUP — Australia
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Industry: Healthcare — Primary Care, Occupational Health,
Psychology, Telehealth
Headquarters: Australia (NSW, QLD, VIC, WA, ACT)
Owner: Quadrant Private Equity
Clinics: 60+ nationwide
Brands: Partnered Health Medical Centres, Jobfit,
Baseline Onsite, New View Psychology, NewPsych,
Australian EAP, Fuel Your Life, Northcare Physio,
TeleWell
Website: partneredhealth.com.au

PENDING ACQUISITION: Bupa — ~$450,000,000 AUD
Announced July 2, 2026 (Australian Financial Review)
ACCC and FIRB regulatory approval pending.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
BREACH SUMMARY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Date of access: 23 June 2026
Data exfiltrated: 3.2 TB
Total files: 2,298,203
Servers accessed: 21 (9 AD Controllers + 11 Best Practice
Medical Servers + 1 Central SQL Server)
SQL Databases: ZedMed.mdf, Payroll.mdf, DocPays.mdf,
VectraplexECG.mdf, BPM.mdf + 1,104 SQL backups
Clinics compromised: 21 locations across 5 states/territories
Patient records: 17,727+ named patient files identified
Staff HR files: Full employee records including passports,
AHPRA registrations, tax declarations
Period of data: 1999 — 2026 (27 years)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
WHAT WE HAVE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

▪ Complete patient medical records from 21 GP clinics —
consultation notes, referral letters, pathology results,
diagnostic imaging reports, prescriptions

▪ Full SQL database dumps — ZedMed (patient management),
Payroll (all staff salaries), DocPays (doctor payments),
VectraplexECG (cardiac/ECG monitoring data)

▪ 11 complete Best Practice patient database backups —
one per clinic — including BPSPatients, BPSDocuments
(up to 48 document partitions per clinic)

▪ Staff HR files — employment contracts, passport scans,
AHPRA medical registrations, tax file declarations,
superannuation details, performance reviews

▪ Bupa corporate data — direct billing agreements,
fund tables for all Australian states, patient invoices,
corporate program documents (Bronze/Silver/Gold),
and active Bupa web portal session cookies

▪ Financial records — QuickBooks databases (2004-2026),
Medicare billing, DVA remittances, private health fund claims

▪ Clinical governance — full RACGP accreditation files,
patient consent templates, internal clinical audit data

▪ 27 years of accumulated medical data (1999-2026) across

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TO PARTNERED HEALTH / QUADRANT PRIVATE EQUITY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Partnered Health was given the opportunity to resolve this
matter privately and protect patient data. Instead of acting
in the interest of their patients, they spent 22 days in
silence, hired lawyers, and obtained a court injunction that
has no practical effect outside Australian jurisdiction.

Their public statement of July 15 describes the breach as
affecting “some” data from “some” clinics. This is misleading.

The reality: 3.2 terabytes. 2.3 million files. 21 servers.
27 years of patient medical history. Every clinic server
in their network was accessed. Complete SQL database dumps
were taken including the central patient management system
and payroll for every employee.

And critically — the data includes Bupa’s own corporate
information: billing agreements, fund pricing tables for
every Australian state, named patient invoices, and active
browser session cookies from Bupa’s login, corporate,
and web portals.

We understand this acquisition matters. $450 million is
a significant transaction. A full data publication would
create material regulatory complications with the ACCC
and FIRB review process. We trust the board and advisors
at Quadrant understand what that means.

This is not a threat. This is a deadline.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DEADLINE: [DATE + 10 DAYS]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Partnered Health has 10 days to resume negotiations
and reach a settlement.

If no agreement is reached:

Stage 1 — Complete file tree listing (2.3M files)
+ all HR/staff records published

Stage 2 — SQL databases (ZedMed, Payroll, ECG)
released for download

Stage 3 — Bupa corporate data, fund tables,
billing agreements, session data published.
ACCC, FIRB, and Bupa executive leadership
notified directly.

Stage 4 — Full 3.2 TB data dump made available
for public download.

Date of Breach 2026-07-30T01:00:00+00:00
Discovery Date 2026-07-30T16:30:13.670561+00:00
Region AU
Business Sector Healthcare

 

How to reduce your ransomware risk

Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:

Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions