Patient data allegedly downloaded by NSW Health employee

Picture: ACS - supplied

 

Article Excerpt:

Cybercrime investigators are examining whether patient data was improperly shared after a NSW Health nurse was charged over an alleged data breach involving the unauthorised access and download of patient records.

The man, who was employed by the Northern Sydney Local Health District, was taken in by authorities to the Manly Police Station where he was charged with “access/modify restricted data held in computer”.

This charge – which carries a maximum penalty of two years’ imprisonment – relates to the act of accessing or modifying data which is guarded by protective measures (such as passwords) on a computer system.

In a statement given to Information Age, a spokesperson for Northern Sydney Local Health District (NSLHD) said a staff member has been "stood down and has no further access to NSW Health systems or facilities".

"NSLHD would like to reassure patients this is not a cyber security attack," they said.

Further topics discussed in this article include:

  • Worker stood down following initial investigation

  • Devices uncovered in Frenchs Forest

  • Why steal the data?

Evan Vougdis, our Head of Cyber Threat Intelligence and Response contributed expert insights to this article:

Evan Vougdis, head of cyber intelligence, response and recovery at Sydney-based cybersecurity firm NSB Cyber, also noted the value wasn’t just in the data itself.

“NSW Health systems hold categories of information that people would pay to keep private,” Vougdis told Information Age.

“[This includes] current addresses for people who work hard to stay off the public record.”

Vougdis, who routinely works on insider threat cases, explained not all workers who misappropriate confidential data are driven by money.

“In my experience the most common motive isn't money, it's curiosity,” he said.

“Someone looks up a neighbour, an ex, a colleague, a name they recognised on a patient list.

“Access on its own tells you almost nothing about intent.

"What separates a sticky-beak from a commercial motive is what happens next, and that's what a device examination is actually looking for.”

Source: Information Age - ACS - Thursday 30 July 2026
Author: By Leonard Bernardone
Reference: NSW nurse charged over alleged data breach

Read the full article here.

To explore NSB Cyber’s Threat Intelligence services, including ransomware response and negotiation, head here.

Next
Next

NSB Cyber Partners with Emergence Insurance to Deliver Cybersecurity Services