27 July 2026
Cyber security incidents can have significant operational, legal and reputational impacts for general practices — particularly when sensitive patient information is involved.
To support practice teams, EMPHN is sharing a recorded webinar, Anatomy of a Ransomware Attack on a Medical Centre, which provides a practical, real-world walkthrough of a ransomware attack affecting a general practice.
On this page:
Recorded webinar: Anatomy of a Ransomware Attack on a Medical Centre
The webinar explores each critical stage of the incident, from the initial phishing email and system lockout through to the restoration of services and forensic investigation.
Featuring redacted examples of ransom emails and forensic reports, the webinar provides valuable insights into the attackers’ tactics and how the clinic responded.
The presentation highlights the exposure of sensitive patient data on the dark web, as revealed by forensic analysis, and discusses the uncertainty around the full extent of data exfiltration. It also addresses the clinic’s obligations under Australia’s Notifiable Data Breach legislation, including the requirement to notify all affected patients about the breach and the potential sale of their information.
Through this recorded webinar, practice teams will learn how to:
- Identify key stages of a ransomware attack
- Understand effective incident response practices
- Recognise cyber security compliance obligations
- Consider the operational, legal and reputational risks of a cyber incident
- Strengthen organisational cyber resilience
- Implement practical cyber defence strategies
By dissecting the attack in detail, this session delivers practical lessons on incident response, regulatory compliance, and the importance of cyber resilience in healthcare. Participants will leave with a deeper understanding of the operational, legal, and reputational impacts of ransomware—and actionable strategies to strengthen their own defences.
Practice teams can watch the webinar and use the accompanying Cyber Security Audit Checklist from Data Box for Practices to review and strengthen their current cyber security arrangements.
Additional resources
Register now: Health Sector Townhall on cyber resilience
The National Office of Cyber Security within the Department of Home Affairs is hosting a webinar, Health Sector Townhall: Strengthening Cyber Resilience across Australia’s Health Sector, on 6 August 2026.
Hear from Australian Government officials and industry representatives about the evolving cyber threat landscape and learn practical steps your organisation can take to strengthen its cyber resilience. Register for this upcoming webinar below.
Health Sector Town Hall
By National Office of Cyber Security, Department of Home Affairs
Cyber security training and support for healthcare providers
The Australian Digital Health Agency offers free cyber security training for healthcare providers, including eLearning courses, guides and fact sheets.