Health Service Providers Remain the Top Sector to Report Data Breaches in H2-2024
The Office of the Australian Information Commissioner (OAIC) recently released its Notifiable Data Breaches report covering the period of July-December 2024. The report provides a comprehensive overview of the notifications received under the Notifiable data breaches scheme, including the key causative factors leading to the breaches.
Key Observations:
- Health service providers were the top sector to notify data breaches during the second half of 2024 with a total of 121 reported data breaches.
- Concerningly, this is a continuation of the trend observed in previous years’ reporting.
- Approximately 60% (72 incidents) were caused by malicious or criminal attacks, of which 69% were directly attributed to cyber-attacks.
- The top 3 cyber-attack types against health service providers during this period included phishing, comprised credentials, and ransomware.
- 56% of breaches were identified within 10 days, whereas only 47% of victim entities performed notification within 10 days.
- Evidently, health service providers continue to be targeted by cyber-attackers owing to the sensitivity of the underlying data, criticality of operations, and an often-suboptimal level of cybersecurity measures. This, therefore, mandates a more deliberate approach to cybersecurity.
Overview
Concerningly, health service providers were the top sector to notify data breaches during the second half of 2024 with a total of 121 reported data breaches. Unfortunately, this is a continuation of the trend seen over the last few years whereby health service providers have consistently been in the lead – albeit for the wrong reasons.

However, it must be acknowledged that the comparative analysis between sectors is slightly skewed, owing to disparities in average revenue between sectors. This is because the $3 million annual turnover criteria of the Privacy Act does not apply to health service providers and thus it is not a like-for-like comparison.
Nonetheless, of the 121 reported breaches, approximately 60% (72 incidents) were caused by malicious or criminal attacks, of which 69% were attributed to cyber-attacks.
Evidently, health service providers continue to be targeted and impacted by cyber-attacks owing to the sensitivity of the underlying data, criticality of operations, and an often-suboptimal level of cybersecurity measures. Based on the finding’s of the OAIC’s report, the top 3 cyber-attack types against health service providers during this period included phishing, comprised credentials, and ransomware.

However, on a more positive note, health service providers had the greatest percentage (47%) of breaches that were notified within 10 days, compared to the other top 5 reporting sectors. This potentially shows that health service providers possess a slightly more advanced understanding of their reporting obligations compared to the other sectors.
Conclusion
While the escalating threat landscape, and particularly the increase in threats against healthcare are cause for concern, the corresponding mitigative measures are highly achievable for organisations of all sizes.
JustProtect recommends that heath service providers adopt a deliberate approach to cybersecurity, which encompasses key elements such as endpoint security, phishing protection, multifactor authentication, regular updates, backups and user account management.
References
- The Office of the Australian Information Commissioner (2025), Notifiable Data Breach Report: July to December 2024.
