Medibank
An insurer's file moves through support organisations you never named and stays about six years by default, held as long as the insurer determines a need. The no-sale promise is pinned to a definition of selling that permits a lot of sharing.
Reported incidents
Sued by the privacy regulator after 9.7 million members' data was posted online
2024-06-05Affected Medibank and ahm customer systems
The Australian Information Commissioner filed civil penalty proceedings in the Federal Court against Medibank, a health insurer, over its October 2022 data breach. The Commissioner alleges that from March 2021 to October 2022 Medibank failed to take reasonable steps to protect the personal information of 9.7 million Australians. Attackers accessed the data of millions of current and former customers of Medibank and its subsidiary ahm and released it on the dark web. The regulator said Medibank holds sensitive health information as a core part of its business.
People affected typically ask Medibank to confirm whether their information was included, and which categories.
The verified route
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.