PARTNERED HEALTH GROUP
β Listed in the last 48hAbout the organisation
PARTNERED HEALTH GROUP β Australia βββββββββββββββββββββββββββββββββββββββββββββββββ Industry: Healthcare β Primary Care, Occupational Health, Psychology, Telehealth Headquarters: Australia (NSW, QLD, VIC, WA, ACT) Owner: Quadrant Private Equity Clinics: 60+ nationwide Brands: Partnered Health Medical Centres, Jobfit, Baseline Onsite, New View Psychology, NewPsych, Australian EAP, Fuel Your Life, Northcare Physio, TeleWell Website: partneredhealth.com.au PENDING ACQUISITION: Bupa β ~$450,000,000 AUD Announced July 2, 2026 (Australian Financial Review) ACCC and FIRB regulatory approval pending. βββββββββββββββββββββββββββββββββββββββββββββββββ BREACH SUMMARY βββββββββββββββββββββββββββββββββββββββββββββββββ Date of access: 23 June 2026 Data exfiltrated: 3.2 TB Total files: 2,298,203 Servers accessed: 21 (9 AD Controllers + 11 Best Practice Medical Servers + 1 Central SQL Server) SQL Databases: ZedMed.mdf, Payroll.mdf, DocPays.mdf, VectraplexECG.mdf, BPM.mdf + 1,104 SQL backups Clinics compromised: 21 locations across 5 states/territories Patient records: 17,727+ named patient files identified Staff HR files: Full employee records including passports, AHPRA registrations, tax declarations Period of data: 1999 β 2026 (27 years) βββββββββββββββββββββββββββββββββββββββββββββββββ WHAT WE HAVE βββββββββββββββββββββββββββββββββββββββββββββββββ βͺ Complete patient medical records from 21 GP clinics β consultation notes, referral letters, pathology results, diagnostic imaging reports, prescriptions βͺ Full SQL database dumps β ZedMed (patient management), Payroll (all staff salaries), DocPays (doctor payments), VectraplexECG (cardiac/ECG monitoring data) βͺ 11 complete Best Practice patient database backups β one per clinic β including BPSPatients, BPSDocuments (up to 48 document partitions per clinic) βͺ Staff HR files β employment contracts, passport scans, AHPRA medical registrations, tax file declarations, superannuation details, performance reviews βͺ Bupa corporate data β direct billing agreements, fund tables for all Australian states, patient invoices, corporate program documents (Bronze/Silver/Gold), and active Bupa web portal session cookies βͺ Financial records β QuickBooks databases (2004-2026), Medicare billing, DVA remittances, private health fund claims βͺ Clinical governance β full RACGP accreditation files, patient consent templates, internal clinical audit data βͺ 27 years of accumulated medical data (1999-2026) across βββββββββββββββββββββββββββββββββββββββββββββββββ TO PARTNERED HEALTH / QUADRANT PRIVATE EQUITY βββββββββββββββββββββββββββββββββββββββββββββββββ Partnered Health was given the opportunity to resolve this matter privately and protect patient data. Instead of acting in the interest of their patients, they spent 22 days in silence, hired lawyers, and obtained a court injunction that has no practical effect outside Australian jurisdiction. Their public statement of July 15 describes the breach as affecting "some" data from "some" clinics. This is misleading. The reality: 3.2 terabytes. 2.3 million files. 21 servers. 27 years of patient medical history. Every clinic server in their network was accessed. Complete SQL database dumps were taken including the central patient management system and payroll for every employee. And critically β the data includes Bupa's own corporate information: billing agreements, fund pricing tables for every Australian state, named patient invoices, and active browser session cookies from Bupa's login, corporate, and web portals. We understand this acquisition matters. $450 million is a significant transaction. A full data publication would create material regulatory complications with the ACCC and FIRB review process. We trust the board and advisors at Quadrant understand what that means. This is not a threat. This is a deadline. βββββββββββββββββββββββββββββββββββββββββββββββββ DEADLINE: [DATE + 10 DAYS] βββββββββββββββββββββββββββββββββββββββββββββββββ Partnered Health has 10 days to resume negotiations and reach a settlement. If no agreement is reached: Stage 1 β Complete file tree listing (2.3M files) + all HR/staff records published Stage 2 β SQL databases (ZedMed, Payroll, ECG) released for download Stage 3 β Bupa corporate data, fund tables, billing agreements, session data published. ACCC, FIRB, and Bupa executive leadership notified directly. Stage 4 β Full 3.2 TB data dump made available for public download.
What the listing means
PARTNERED HEALTH GROUP appeared on the incransom leak site on 30 July 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 37 claims in the last 30 days and remains active.
Recommended actions
- Treat any unsolicited message referencing PARTNERED HEALTH GROUP as suspicious β leaked data gets weaponised for phishing within days.
- If you hold an account with this organisation, change the password now and enable two-factor authentication.
- Other Healthcare organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach β check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/UEFSVE5FUkVEIEhFQUxUSCBHUk9VUEBpbmNyYW5zb20=