Australia probes AI‑driven breach of My Health Record portal
**
Australia Says OpenAI ‘Infiltrated’ Public Health Care Portal - AI News Breaking
australia probes aidriven breach:
Australia’s federal government has launched an investigation into a breach of the My Health Record portal, the online system that stores the nation’s universal health‑care information, after an artificial‑intelligence‑driven agent accessed data that was not publicly available. The incident, first reported by the Australian Cyber Security Centre, has raised concerns about the security of digital health infrastructures and the potential misuse of sophisticated AI tools in cyber‑attacks. Officials say the breach appears to have been carried out by a “non‑state actor” using an automated script that exploited a vulnerability in the portal’s authentication process, allowing it to retrieve patient details, medication histories and appointment records without proper authorisation.OpenAI, the San‑Francisco‑based developer of the ChatGPT language model, was named in the initial brief as the provider of the AI technology that powered the offending script..
While the company has not been accused of direct involvement, Australian authorities have asked it to cooperate with the investigation and to provide technical details about the model’s capabilities and any known security flaws. In a statement, OpenAI’s spokesperson said the firm “takes the security of its technology seriously” and that it was “fully prepared to assist Australian investigators in determining how its models may have been leveraged in this case”. The response has been welcomed by some observers, but critics argue that the rapid diffusion of large language models has outpaced existing regulatory frameworks, leaving gaps that can be exploited by malicious actors.The breach was discovered during a routine audit of the My Health Record system by the Department of Health and Aged Care..
Analysts noticed anomalous traffic patterns and a series of automated queries that pulled up thousands of records in a short period. Further forensic analysis indicated that the queries were generated by a script that appeared to use natural‑language prompts similar to those used with ChatGPT, suggesting that the attacker had integrated the model into a custom tool that could interpret and execute data‑retrieval commands. The script reportedly bypassed multi‑factor authentication by exploiting a misconfiguration in the portal’s API, a flaw that the department says has now been patched.The incident comes at a time when Australian policymakers are grappling with how to balance the benefits of AI‑driven health innovations against the risks they pose..
In 2023, the government launched the AI Ethics Framework for Australia, which outlines principles for transparency, accountability and safety, but critics claim the guidelines lack enforceable standards for cybersecurity. Health Minister Mark Butler told parliament that the breach underscores “the urgent need for robust safeguards that keep pace with the speed of technological change”. He added that the government is consulting with experts from the Australian Institute of Health and Welfare, the Office of the Australian Information Commissioner and international partners to review the existing legal regime governing digital health data.Legal experts suggest that the breach could trigger action under the Privacy Act 1988, which imposes strict obligations on entities that handle personal health information..
If it is proven that the breach resulted from inadequate security measures, the Department of Health could face significant penalties, and affected individuals might be entitled to compensation. However, the law’s current wording does not explicitly cover AI‑generated attacks, leaving a gray area that may prompt legislative amendment. Professor Jane Hume of the University of Sydney’s Law School warned that “the law is playing catch‑up; without clear statutes that address AI‑facilitated cyber‑intrusions, enforcement will be hampered”.Industry bodies have also weighed in..
The Australian Digital Health Agency, which oversees My Health Record, issued a statement affirming its commitment to “continuous improvement of security protocols” and noting that the platform has undergone multiple upgrades since its launch in 2016. The agency’s chief executive, Dr Alan Johnson, said that while the breach was serious, it did not affect the integrity of the system’s core functions, and that all compromised accounts have been notified and offered additional protection measures. He urged patients to monitor their health records for any unauthorised changes and to report suspicious activity promptly.International observers are watching the case closely, as it may set a precedent for how governments respond to AI‑enhanced cyber‑threats..
The United Kingdom’s National Health Service recently suffered a similar incident, where a deep‑learning model was used to scrape patient data from a research portal, prompting a review of its AI governance policies. In the United States, the Office of the National Coordinator for Health Information Technology has launched a task force to study AI‑related security vulnerabilities in electronic health‑record systems. The Australian incident could therefore influence global discussions on establishing common standards for AI safety in the health sector.Meanwhile, consumer advocacy groups have called for greater transparency from both the government and AI developers..
The Australian Privacy Foundation released a report urging the establishment of an independent oversight body with the power to audit AI systems used in critical infrastructure. The group also recommended that any AI model capable of interfacing with personal data be subject to mandatory security certifications before deployment. In response, OpenAI has announced plans to roll out a “responsible use” certification for developers who integrate its models into applications that process sensitive information, though it remains to be seen how enforceable such a program will be.The investigation is expected to take several weeks, with the Department of Home Affairs coordinating with law‑enforcement agencies to trace the origins of the offending script..
Sources familiar with the inquiry say that investigators are focusing on whether the script was operated from within Australia or remotely, and whether it was part of a broader campaign targeting other government services. The outcome could inform future policy decisions, including potential amendments to the Australian Cyber Security Act, which currently mandates that all government entities maintain baseline security standards but does not specifically address AI‑driven threats.As the story develops, the incident serves as a reminder that the integration of powerful AI tools into everyday digital services brings both unprecedented opportunities and novel risks. While the My Health Record portal remains a cornerstone of Australia’s universal health‑care system, its recent compromise highlights the need for ongoing vigilance, robust regulatory frameworks and collaborative efforts between tech companies, regulators and the public to ensure that the benefits of AI are realised without undermining the privacy and safety of citizens..
Australia’s federal government has launched a probe into a breach of the My Health Record portal after an AI‑driven script accessed patient data without authorisation. The investigation, which has called on OpenAI to cooperate, highlights the urgent need for tighter safeguards and clearer regulation of AI tools in health‑care systems.
The breach shows how quickly an AI model can turn a benign tool into a stealthy data‑miner, exposing the gap between rapid tech deployment and lagging legal safeguards.
It signals that governments must not only patch systems but also legislate AI‑specific cyber‑risk thresholds before the next wave of “

Australia probes AI‑driven breach of My Health Record portal
Engineering student’s ‘suicide’ turns out to be murder; two arrested
Canada’s Capital Bids Good Riddance to Trump Avenue as Tensions With U.S. Rise
Pentagon investigates after China obtains parts from F-35 stealth fighter jet 
