icon-stethoscope Healthcare

When Clinical Systems Go Down, the Consequences Are Measured in Patient Outcomes

Australian healthcare has become the most targeted sector for data breaches in the country — accounting for a higher share of reported incidents than finance, government or any other industry. The stakes are not financial recovery alone. When networks fail or ransomware encrypts an EMR system, procedures are delayed, ambulances are diverted, and clinical decisions are made without the information they depend on.

Orro works with hospital networks, primary health networks, aged care providers, pathology groups, and private health facilities to design, secure and manage the technology infrastructure that clinical environments run on — from the wide area network connecting distributed sites to the security operations capability monitoring threats in real time.

20 %

Healthcare accounts for 20% of all notifiable data breach reports in Australia — the highest of any sector, every reporting period since 2023. Source: OAIC Notifiable Data Breaches Report, July–December 2024 — oaic.gov.au

2 x

Ransomware incidents targeting Australian healthcare doubled in FY2024–25 compared to the previous year, with malicious actors succeeding in 95% of sector incidents ASD’s ACSC responded to. Source: ASD Annual Cyber Threat Report 2024–25 — cyber.gov.au

12.9 million

Australians had their health and prescription data compromised in the 2024 MediSecure ransomware attack — one of the largest data breaches in Australian history. Source: Australian Government, Home Affairs — homeaffairs.gov.au

USD$ 9.77 M

The global average cost of a healthcare data breach in 2024 — the highest of any industry, a position healthcare has held for fourteen consecutive years. Source: IBM Cost of a Data Breach Report 2024 — ibm.com

Sector Intelligence Brief

Healthcare Under Persistent Pressure

Healthcare is, by the data, Australia’s most breached sector. The OAIC’s Notifiable Data Breaches reporting has consistently placed health service providers at the top of its sector league table — accounting for 20% of all notifications in the second half of 2024, and 18% in the first half of 2025. This is not a statistical anomaly. It reflects a structural convergence of high-value data, operationally critical systems, constrained IT resources, and an attack surface that has expanded faster than most organisations’ ability to manage it.

Why this sector is targeted: Patient health data is among the most valuable categories of personal information on the criminal market. Unlike a compromised credit card number that can be cancelled, health records — encompassing diagnoses, medications, procedures, Medicare identifiers, and family history — are permanent. They support identity fraud at scale, insurance fraud, and targeted extortion. The MediSecure ransomware attack in April 2024 compromised approximately 12.9 million Australians’ prescription records, representing data on nearly half the country’s population. The breach forced the company into liquidation. In December 2023, St Vincent’s Health Australia — the country’s largest non-profit healthcare provider — experienced a cyberattack that resulted in data being removed from its network across hospitals and aged care facilities in multiple states. In early 2025, Victorian hospital group Epworth Healthcare was the subject of alleged data theft by the Global Group ransomware gang, with 40GB of data including patient records, medical imaging, and internal payroll information reportedly posted to the dark web. IVF provider Genea also suffered a ransomware intrusion in February 2025, with the Termite group claiming responsibility for exfiltrating nearly 940GB of patient records. These are not isolated events — they are the visible portion of a much larger pattern.

The structural vulnerabilities: ASD’s 2024–25 Annual Cyber Threat Report recorded that malicious actors succeeded in 95% of healthcare sector incidents the ACSC responded to — compared to 52% across all sectors. That figure is not primarily a reflection of poor intent on the part of healthcare organisations; it reflects the structural conditions under which they operate. Healthcare IT environments are characterised by a sprawl of legacy clinical systems, many running operating systems no longer receiving security updates. Medical devices — infusion pumps, patient monitors, imaging equipment, anaesthesia systems — are networked, often running embedded firmware that cannot be easily patched, and were designed for clinical performance rather than security. These Internet of Medical Things (IoMT) assets sit on the same underlying network infrastructure as administrative systems, creating lateral movement opportunities that skilled threat actors actively exploit. Add to this the ongoing digitisation of clinical workflows — electronic medical record (EMR) systems, telehealth platforms, digital imaging and pathology repositories — and the scope of the problem becomes clear. Each new system is a dependency. Each dependency is a potential failure point.

The operational stakes: The consequences of a clinical technology failure extend well beyond financial and reputational harm. When ransomware encrypts an EMR system, clinicians lose access to medication histories, allergy records, and diagnostic information at the point of care. Procedures must be postponed. Ambulances are diverted to other facilities, increasing pressure on the wider system. Staff revert to manual paper-based workflows, introducing both error risk and operational delay. Research published in academic literature has found that hospitals neighbouring a ransomware-attacked facility experience measurable spikes in emergency department presentations while the affected site deals with reduced capacity. In aged care environments, the stakes are equally serious: medication management, incident documentation, and care coordination systems all depend on network availability. A prolonged outage is not an inconvenience — it is a governance failure with direct implications for resident safety.

The distributed network reality: Most hospital networks, primary health networks, and aged care groups operate across multiple sites — a combination of metropolitan hospitals, community health centres, regional facilities, rural GP practices, and residential care sites, frequently connected through a mix of carrier-grade WAN, legacy MPLS, and in some cases, site-level broadband connections with variable quality and redundancy. The push toward centralised EMR platforms (such as Epic, Cerner, and local deployments) has increased the criticality of wide area network reliability: a degraded WAN connection is no longer just a productivity issue, it can directly impair clinical workflows. The rise of telehealth — accelerated substantially during the COVID-19 period and now a permanent fixture in outpatient and primary care models — has added further demands on bandwidth, latency, and uptime. In aged care, connectivity requirements have expanded to include resident-facing technology, staff communication platforms, and the monitoring systems underpinning clinical governance. Managing this environment consistently across dozens or hundreds of sites, often with small central IT teams, is one of the defining operational challenges for healthcare technology leaders.

Regulatory pressure and the governance gap: Healthcare is subject to a layered compliance environment that has grown significantly more demanding. The Security of Critical Infrastructure Act 2018 (SOCI Act) now designates critical hospitals — specifically those with general intensive care units — as critical infrastructure, imposing obligations on owners and operators regarding risk management programmes, incident reporting, and government access for purposes of national security. The My Health Records Act 2012 imposes specific obligations on healthcare providers connecting to the national digital health infrastructure, including mandatory security requirements for clinical information systems. The Privacy Act 1988 and the Notifiable Data Breaches scheme apply to all private health service providers regardless of annual turnover — a threshold that does not apply to other sectors. The Cyber Security Act 2024 introduced mandatory ransomware reporting obligations for organisations over $3M turnover. And the Australian Digital Health Agency continues to expand its security framework requirements for participants in the national digital health ecosystem. For many healthcare organisations — particularly private hospital operators, pathology groups, and aged care providers — building governance maturity fast enough to meet these obligations while simultaneously managing complex day-to-day operations is a genuine challenge. The regulatory frameworks are right to demand higher standards. The gap between where many organisations currently sit and what is now required is the territory where risk concentrates.

Regulatory Frameworks Applicable to Australian Healthcare

We understand that every industry faces unique challenges when it comes to IT, security, and digital infrastructure.

At Orro, we combine deep sector knowledge with cutting-edge technology to deliver tailored solutions that drive performance, resilience, and growth. Whether you’re in education, finance, healthcare, retail, or logistics, we partner with you to future-proof your organisation and securely connect everything.

Governing body

Australian Digital Health Agency (ADHA) — digitalhealth.gov.au

What it requires

Healthcare providers accessing or connecting to the My Health Record system must implement security controls aligned with ADHA’s security requirements framework, maintain audit logs of access, and notify the ADHA and OAIC of breaches affecting My Health Record data.

Applies to

All registered healthcare providers participating in the My Health Record system.

Consequence of non-compliance

Civil penalties, suspension or deregistration from the system, mandatory breach reporting obligations.

How Orro Supports Healthcare Organisations

Healthcare networks bear a connectivity burden that most other sectors do not. A hospital campus may simultaneously need to support clinical mobility (nurses and doctors accessing EMR systems from mobile devices and workstations at point of care), high-bandwidth medical imaging transfers (CT, MRI and pathology data moving between facilities and reporting services), segregated guest Wi-Fi for patients and visitors, and the operational technology networks underpinning building management, nurse call, and physical access systems. Each of these requires different performance characteristics, different security postures, and ideally, different network segments to limit the blast radius of any compromise.

Orro designs and manages healthcare network infrastructure across campus, multi-site, and distributed care environments. Our SD-WAN and SASE deployments provide application-aware routing that prioritises clinical traffic — ensuring EMR systems and imaging platforms maintain consistent performance even during peak load — while providing zero-trust access controls for remote clinicians, telehealth practitioners, and staff working across sites. For aged care and community health operators with large numbers of smaller sites, our managed connectivity services provide consistent standards, centralised visibility, and carrier-agnostic redundancy to maintain connectivity where a single carrier outage would otherwise leave a facility isolated.

Where campus-scale wireless is required — across hospital campuses with high device density, multi-storey facilities, or outdoor clinical areas — Orro’s wireless design and management capability, including private LTE where appropriate, delivers the coverage and performance that clinical mobility demands.

Outcome: Clinical staff maintain access to the systems they depend on, across every site, with the consistency and resilience that patient safety requires.

Demonstrated Capability at Scale

Orro has delivered network transformation for one of Australia’s largest private hospital operators — a national network spanning every state and territory, with the connectivity demands, clinical system dependencies, and availability requirements that large-scale acute care environments create. Orro designed and deployed a high-availability managed network architecture across the hospital group’s sites, providing the secure, resilient connectivity that clinical systems — EMR, imaging, medication management, staff mobility — depend on to function. As part of that transformation, available bandwidth was quadrupled, enabling the organisation to support the volume and performance demands of modern clinical workflows across its facilities. The engagement demonstrates Orro’s ability to work within the specific operational and governance constraints of large healthcare environments, where network changes require clinical risk assessment and downtime windows are tightly managed.

Demonstrated Capability at Scale

Healthcare Technology and Cybersecurity — Frequently Asked Questions

The SOCI Act designates hospitals with general intensive care units as critical infrastructure. If your facility operates a general ICU, you are likely subject to SOCI Act obligations, including registering the asset, implementing a Critical Infrastructure Risk Management Programme (CIRMP), and mandatory incident reporting — serious incidents within 12 hours, other incidents within 72 hours. If you operate a network of hospitals and only some have ICUs, SOCI obligations apply at the asset level for those that do, but risk programme obligations often prompt network-wide uplift. Confirm your specific obligations with your legal counsel and the Cyber and Infrastructure Security Centre (CISC).

Why Healthcare Organisations Choose Orro

Our difference

Why Healthcare Organisations Choose Orro

chevron-right-pink
Proven scale in mission-critical managed services

Orro manages Australia Post’s national retail network — more than 4,000 sites — delivering 70% fewer outages and avoiding 44,000 business impact hours. The operational discipline required to run infrastructure at that scale, with that level of consequence for failure, translates directly to healthcare environments.

chevron-right-pink
CTEM capability built for complex clinical environments

Orro’s Continuous Threat Exposure Management service provides ongoing exposure visibility across EMR systems, clinical IoT, medical devices, and operational technology — the environments that standard vulnerability programmes consistently miss.

chevron-right-pink
National Cyber Defence Centre

Orro’s Australian-operated SOC provides 24/7 threat monitoring, detection, and response with healthcare-specific playbooks that account for clinical availability constraints and patient safety implications of response actions.

chevron-right-pink
OT and clinical IoT security expertise

Genuine capability across the IT/OT/IoT boundary — not just network monitoring extended to devices, but purpose-built security architecture for environments where conventional endpoint controls cannot be deployed.

chevron-right-pink
SD-WAN and SASE for distributed healthcare networks

Deep expertise in designing and managing connectivity across large numbers of dispersed healthcare sites, with consistent security policy enforcement and clinical application performance prioritisation built in.

chevron-right-pink
One Touch Control — unified operational visibility

Orro’s proprietary management platform provides real-time, multi-vendor, multi-carrier visibility across the full network estate — giving healthcare IT teams and Orro’s operations centre a single operational picture, regardless of environment complexity.

chevron-right-pink
Australian-owned, with Australian-based support escalation

Orro is an Australian-owned organisation with Australian-based account management and support escalation, and 24/7 global operations capability. Your environment is managed by people who understand the Australian regulatory context and the specific obligations that apply to your organisation.

chevron-right-pink
Vendor-agnostic architecture

Orro is not aligned to a single vendor’s technology stack. Our solutions are designed around what is right for the clinical environment — drawing from a broad ecosystem of network, security, and cloud partners rather than leading with a vendor relationship.

Resources for Healthcare Technology Leaders

Talk to a Healthcare Technology Specialist

Orro works with hospital networks, aged care providers, primary health networks, pathology groups, and private health facilities across Australia. If you are looking for a technology partner who understands the clinical, regulatory, and operational context you operate in — not just the technology — we would like to speak with you.

Our accreditations