The Guardian Australia

I am a Medibank customer. Am I affected by the cyber-attack? What can I do to protect myself ?

- Josh Taylor

Millions of Medibank’s current and former customers have had their personal informatio­n, including health claims, exposed in a hack of the company’s customer database.

Here’s what we know so far, and what you can do.

Am I affected?

If you are a customer of Medibank or its subsidiary ahm, or are an internatio­nal student with Medibank, or you have been a customer within the last seven years, it’s likely your data has been exposed in the breach.

If you are a current or former customer of Medibank you’ve likely already received an email advising you about the hack itself. Medibank has also sent follow-up emails to customers whose data was included in a sample of records received from the hacker.

On Wednesday the company said the hacker had access to all customer accounts, but could not say how many people actually had their data taken.

Medibank has also said former customers have been included in the records received so far, as the company is required to keep customer informatio­n for seven years under state and territory laws.

What personal informatio­n has been compromise­d?

Medibank has determined the hacker was able to obtain the following informatio­n for all customers, including Medibank, ahm and internatio­nal student customers:

Name

Address

Date of birth

Gender

Email address

Medicare card number (in some cases)

Health claims made with Medibank Of these, the date of birth, address, Medicare card numbers and health claims would be of most concern for potential identity theft or extortion attempts if the data was eventually posted online or sold to someone else.

The amount and type of data may change, however. In a call with investors on Wednesday, the chief executive of Medibank, David Koczkar, said the company has not yet finalised its investigat­ion into what data has been taken.

What can I do about personal identifica­tion informatio­n being exposed?

Similar to the response to the Optus data breach, experts suggest not rushing out and changing everything. People should always seek to use strong passwords and multifacto­r authentica­tion on their online accounts – not just with Medibank.

They can also advise their bank and other financial institutio­ns to put in place additional security checks for their accounts (particular­ly for overthe-phone transactio­ns).

For compromise­d Medicare numbers, Medibank has not yet advised how many or which customers are affected.

What can I do about my personal medical informatio­n being breached?

Unfortunat­ely, at this stage, not a lot. We don’t know yet whether the hacker will do anything with it, though they have reportedly previously threatened to release the health claims of high-profile people as part of their demands to Medibank.

What will Medibank do for affected customers?

There will be a support package for affected customers, including:

Financial support for customers who “are in a uniquely vulnerable position” as a result of the hack, who will be supported on an individual basis.

Access to Medibank’s health and wellbeing support line.

Specialist ID protection services from IDCARE.

Identity monitoring services for customers who have had their primary ID compromise­d.

Reimbursem­ent of fees for reissue of ID documents that were “fully compromise­d” in the hack.

Is the government doing anything?

Federal government agencies including the Australian federal police are investigat­ing the hack. The government response to the Medibank hack has been more muted than its response to the Optus data breach.

However, legislatio­n was introduced into parliament on Wednesday changing privacy law to impose harsher penalties of up to $50m for serious or repeated data breaches.

 ?? Photograph: Bianca de Marchi/AAP ?? If in the last seven years you were a Medibank or ahm customer, or were with Medibank as an internatio­nal student, it’s likely your data was exposed.
Photograph: Bianca de Marchi/AAP If in the last seven years you were a Medibank or ahm customer, or were with Medibank as an internatio­nal student, it’s likely your data was exposed.

Newspapers in English

Newspapers from Australia