Quick answer
A cyberattack hit Medlab Pathology (which Australian Clinical Labs had acquired). Health, contact, Medicare and credit-card details of ~223,000 people ended up on the dark web. The regulator fined the business $5.8 million for three failings: weak security, being too slow to assess the breach, and being too slow to notify. The lesson that should worry every business owner: two of the three failings were about the response — not the hack.
WHAT HAPPENED
A breach, then a slow response.
The timeline is as instructive as the penalty:
- ▸ Dec 2021 — Australian Clinical Labs (ACL) acquires the assets of Medlab Pathology.
- ▸ Feb 2022 — a cyberattack hits Medlab's IT systems, which had significant security weaknesses.
- ▸ Jun 2022 — the Australian Cyber Security Centre warns ACL that 86 GB of stolen data has been published on the dark web.
- ▸ Jul 2022 — ACL notifies the Privacy Commissioner — months after the attack.
- ▸ Oct 2022 — ACL tells the public (via an ASX announcement), around three months after telling the regulator.
- ▸ Nov 2023 — the regulator (OAIC) launches Federal Court proceedings.
- ▸ 2025 — the Court approves a $5.8 million penalty (plus a $400,000 costs contribution).
WHY THE FINE
It wasn't just the breach — it was the response.
The $5.8 million penalty broke down into three parts, and this is the detail every business should sit with:
- ▸ $4.2m — weak security. Failing to take reasonable steps to protect people's personal information (Australian Privacy Principle 11).
- ▸ $800k — slow assessment. Failing to reasonably and quickly assess whether it was a notifiable ("eligible") data breach.
- ▸ $800k — slow notification. Failing to notify the Commissioner as soon as practicable.
In other words, $1.6 million of the fine had nothing to do with the hack itself — it was about being unprepared to assess and report it. You can't always stop a determined attacker, but how you respond is entirely within your control.
THE LESSONS
Five takeaways for any business.
- ▸ You can't outsource accountability. ACL hired a third party to investigate, but the Court was clear: the buck stops with the business. A great IT partner does the work — but the responsibility is always yours, so choose one you can trust to get it right.
- ▸ Speed is a legal obligation. Under the Notifiable Data Breaches scheme, you must assess a suspected breach quickly (generally within 30 days) and notify the regulator and affected people "as soon as practicable". Dragging your feet is its own offence.
- ▸ When you buy a business, you buy its cyber risk. ACL inherited Medlab's weak systems. Cyber due diligence matters in any acquisition or merger.
- ▸ "Reasonable steps" now has teeth. The Court has started to define what adequate security looks like. Ageing, basic protection is no longer a defence.
- ▸ The fines are only going up. Privacy Act penalties rose sharply in late 2022 and again in late 2024, and the regulator is pursuing more cases (Medibank and Optus among them). $5.8m could look modest next time.
"But we're too small for the regulator to care." The Privacy Act applies to businesses turning over more than $3 million a year, and to all health service providers regardless of size — but that misses the point. Every business holds personal information about customers and staff, and for a smaller business the reputational and financial hit of a mishandled breach is often more existential, not less. Preparation is far cheaper than the alternative.
GET AHEAD OF IT
The good news: this is preparable.
Everything that cost ACL can be addressed in advance. In practice, that means:
- Reduce the oddsLayered, maintained cyber security — MFA, modern endpoint protection, patching and 24/7 monitoring — so an attack is far less likely to land, and far more likely to be caught early. See our Essential Eight guide.
- Have a breach plan readyA tested incident-response and data-breach plan, so if the worst happens you can assess and notify fast — turning a potential penalty into a well-handled event.
- Know your obligationsUnderstand what personal information you hold, where it lives, and what the Notifiable Data Breaches scheme requires of you.
- Have a partner who can act at 2amWhen it counts, you want senior engineers responding in minutes — not a slow, "significantly lacking" investigation like the one the Court criticised.
Source & further reading. This article draws on Federal Court proceedings and legal analysis by McCullough Robertson:
First Privacy Act data breach — Australian Clinical Labs. It's general information, not legal advice — for advice on your obligations, speak to a qualified lawyer.