Your leading voice in digital health news
Twitter X Logo

Opinion: In connected healthcare, identity assurance cannot remain disconnected

30 July 2026
By Fred Slikker, Managing Director, Digidentity
Image: iStocl

The recent cyberattack on Partnered Health is a reminder that the impact of a health-data breach does not end when an organisation restores its systems or notifies affected patients. Reports indicate sensitive information from patients across 21 clinics may have been exposed, including Medicare and private-health insurance details, addresses, consultation notes, referrals and pathology results. That information is deeply personal. It can also be highly useful to someone seeking to impersonate a patient, access further records or make a fraudulent request appear legitimate.

Fred Slikker. Image supplied.

For Australia’s digital-health sector, the incident highlights a challenge that goes beyond cybersecurity: the information used to identify a patient may be the same information that has just been compromised. A name, date of birth, address and Medicare number may once have been reasonable details to use in a routine identity check. But if those details are potentially available to criminals, they cannot be relied on alone when someone asks to access a record, recover an account or change the details connected to it. The sector has invested heavily in making health information more available when and where it is needed. The next challenge is ensuring the person seeking access is genuinely the patient, or genuinely authorised to act for them.

Connected care creates more identity moments

For most Australians, healthcare no longer happens in one place. A patient may book a GP appointment online, receive a digital referral, visit a pathology provider, collect an electronic prescription, communicate with a specialist and manage information through a patient portal or app. Their care may also involve a private health insurer, an aged-care provider or a family member acting in a support role. This is progress. Timely, connected information can improve care and reduce the administrative burden on patients and clinicians. But every new digital service creates another point at which identity, access and authority need to be established. 

Too often, these checks are designed as isolated processes. One provider stores a copy of a driver licence. Another relies on a knowledge-based question. A third sends a password-reset link to the email address already held on file. Each process may seem reasonable on its own, but the combined experience can be difficult for patients and inconsistent for providers. It also creates opportunities for criminals. Someone who knows a patient’s Medicare details, recent referral or treatment history can sound convincing when they call a practice, contact a health insurer or respond to a message about a pathology result. The more information they have, the easier it is to pass checks based on information alone. A breached medical file can become an answer sheet for the questions a health service asks to establish trust.

Identity is different from authority

Healthcare organisations also need to separate two questions that are often treated as one: is this person who they say they are, and are they authorised to make this request? That distinction matters across everyday care. A parent, guardian, carer or nominated representative may legitimately need access to information or need to manage an appointment. A clinician may need access to a record to provide care. An administrator may need to update contact details. Each situation involves a different level of access and a different basis for authority. Knowing someone’s personal details does not demonstrate either identity or authority.

This becomes especially important when an interaction changes the patient’s control of their information. A request to reset a portal password, change a mobile number, update consent preferences, add a representative or release a full record should trigger a higher level of assurance than booking an appointment. The practical challenge is to make those safeguards strong enough to prevent impersonation without turning care into an obstacle course for patients or another administrative burden for already stretched health services.

Design for higher-risk actions, not more friction everywhere

The answer is not to demand a passport or driver licence for every interaction. Nor is it to respond to a breach by asking patients to email fresh copies of identity documents to every provider they use. That approach simply creates more stores of high-value documents across a fragmented health system. It also places the burden on patients to repeatedly prove themselves, even when the care they need is routine or urgent. A better model is proportionate identity assurance.

Low-risk actions, such as booking an appointment or receiving general service information, can remain simple. Higher-risk actions should require stronger verification. For example, a service might introduce an additional, trusted confirmation step before a patient’s contact details are changed, portal access is recovered or sensitive records are released. The key is to assess the consequence of getting the decision wrong. If a request could give someone control of a patient’s account, expose clinical information or alter who can act on their behalf, it deserves more than a check of details that may already be circulating after a breach.

This approach also supports better data minimisation. Rather than collecting and retaining full copies of passports and licences, a service should be able to receive the assurance it needs for the specific task: that the person has been verified, and that they are authorised to take that action.

Trust will determine the value of digital health

Australia’s digital-health agenda depends on patients being willing to use connected services and share information across their care journey. That trust is built through more than secure systems. Patients need confidence that someone else cannot use their own personal and medical information to step into their place.

The Partnered Health incident should prompt health leaders to review what happens after a breach, not only how to prevent one. Which patient details are used as evidence of identity? Which processes rely on those details alone? What happens when a caller seeks to change the phone number, email address or authority connected to a record? Those questions will become more important as health services become increasingly connected.

Healthcare cannot treat personal information as a permanent password. Once sensitive data may be in criminal hands, the sector needs a way to establish identity and authority that does not depend on asking patients to repeat the contents of a compromised file.

Leave a Reply

Your leading voice in digital health news

Twitter X

Your leading voice in digital health news 

Keep your finger on the pulse with full access to all articles published on 
pulseit.news
Subscribe from only $39
magnifiercrossmenuchevron-down