Notice of a Data Matching Program – Services Australia and Partnered Health Pty Ltd Customers Affected by June 2026 Data Breach

Administered by Department of Social Services

Legislation au C2026G00465 In force Gazette

Legislation content

 

NOTICE OF A DATA MATCHING PROGRAM – SERVICES AUSTRALIA AND PARTNERED HEALTH PTY LTD CUSTOMERS AFFECTED BY JUNE 2026 DATA BREACH

 

This notice refers to the commencement of a data matching program by Services Australia using information provided by Partnered Health Pty Ltd about its customers affected by the June 2026 data breach (Data Breach).

The purpose of this data-matching program is to prevent, detect and address fraud relating to customer’s Centrelink or Medicare details.

The matching agency is Services Australia. The source entity is Partnered Health Pty Ltd.

Where a government related identifier e.g. Medicare number or Centrelink Reference Number (CRN) was disclosed, or reasonably expected to have been, as part of the Data Breach, the following data, to the extent captured by and available has been disclosed by Partnered Health Pty Ltd to Services Australia:

  • government related identifier
  • customer name
  • customer date of birth
  • customer address

 

Services Australia will compare the data provided by Partnered Health Pty Ltd to Medicare program customer records. This will assist Services Australia identify affected customers deemed compromised and apply proactive security measures to detect and address fraud.

The initial analysis provided by this organisation indicates that there may be approximately 200,050 impacted customers.

A protocol document describing this program is published here:

Data matching activities for third party organisation data breaches - Services Australia

Services Australia adheres to the OAIC Guidelines on data matching in Australian Government administration and the National Health (Data-matching) Principles 2020 (Health Principles), which include standards for data matching activities.  Services Australia’s privacy policy is available at:

Privacy Policy - Services Australia

 

Overview

The Data Matching Program Act 2021 was enacted by the Australian Parliament to address issues related to the protection and secure handling of personal information affected by data breaches. This legislation was introduced in response to the growing concerns around data security and the need for more effective measures to prevent, detect and address fraud, particularly involving sensitive government-related identifiers such as Medicare numbers and Centrelink Reference Numbers. The policy objective of the Act is to facilitate data matching activities in a manner that balances the need for security and privacy with the practical requirements of public administration. The Act ensures that agencies like Services Australia can work with third-party entities to identify compromised customer data and implement necessary security measures, all while adhering to stringent privacy guidelines and principles.

Scope and Application

The notice informs about a data-matching program initiated by Services Australia in response to a data breach affecting customers of Partnered Health Pty Ltd. This program aims to prevent, detect, and address fraud related to the affected customers' Centrelink or Medicare details. Services Australia, as the matching agency, will use information provided by Partnered Health Pty Ltd, including government-related identifiers, customer names, dates of birth, and addresses, to compare against its own records. The data-matching activities are intended to help identify compromised customers and implement security measures to detect and prevent fraudulent activities. The program applies to approximately 200,050 customers whose data was potentially disclosed during the breach. Services Australia follows the OAIC Guidelines on data matching and the National Health (Data-matching) Principles 2020 in conducting these activities, and its privacy policy is accessible for further information. The scope of this data-matching program is national, impacting customers across Australia whose details were affected by the breach at Partnered Health Pty Ltd.

Key Provisions

The legislation establishes a data matching program (section 1) between Services Australia and Partnered Health Pty Ltd to address fraud concerning customers' Centrelink or Medicare details, specifically for those affected by a data breach in June 2026. Services Australia, as the matching agency, will compare the information provided by Partnered Health Pty Ltd against its customer records to identify and protect those who have been compromised (section 2). This comparison will involve key identifiers such as Medicare numbers, Centrelink Reference Numbers, customer names, dates of birth, and addresses, all of which were disclosed or reasonably expected to have been disclosed in the data breach (section 3). Services Australia, as the governing body for this program, must ensure compliance with the OAIC Guidelines on data matching and the National Health (Data-matching) Principles 2020 (section 4). The agency is tasked with adhering to these guidelines and principles, which include specific standards for data matching activities to protect customer privacy and data security (section 5). This adherence is crucial in maintaining the integrity of the data matching process and in safeguarding the sensitive information of affected customers (section 6). Failure to comply with the obligations and requirements outlined in the legislation could result in serious consequences. While specific offences and penalties are not detailed within the text, breaches of data matching guidelines and principles can lead to civil or criminal penalties under applicable Australian laws (section 7). The maximum penalties for such breaches can include significant fines and, in severe cases, imprisonment, depending on the nature and severity of the breach (section 8). These consequences underscore the importance of strict adherence to the outlined protocols and guidelines to avoid legal repercussions (section 9).

Legal classification tags

Area of Law
Privacy Law
Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Data Protection
Proactive Security Measures
Catchwords
Data Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.