MEDISECURE INCIDENT RESPONSE

IDCARE as Australia’s national identity and cyber support community service has been engaged to assist individuals who have concerns about the exposure of their personal information.

IDCARE’s Role in Supporting You

IDCARE is an independent charity focused on supporting community members that have concerns about their personal, account or credential information.

We are extending our support to impacted persons of the MediSecure data breach via the provision of expert advice and IDCARE specialist Case Management services are available.

IDCARE Case Managers work every day with community members who experience the compromise or exploitation of their personal information. They understand the real risks, concerns and needs of our community.

General recommendations are provided below. If you have specific concerns or seek further guidance on the recommendations, please submit a Get Help Form and indicate that your query is in relation to the MediSecure data incident.

Note that IDCARE's National Case Management specialises in cases where individuals believe they have experienced identity exploitation and misuse or have grave concerns about this risk.

What Happened?

MediSecure, an e-script service provider, experienced a cyber incident in mid-April 2024.
As a result of this incident, information provided to the company prior to November 2023, including prescriptions, health information, and other personal details, may have been exposed for impacted individuals.

Technical and forensic investigations are ongoing. Updates may be provided as those investigations progress. Stay abreast of developments on the Department of Home Affairs' website.

General Advice and Guidance

The exposure of personal information such as name, date of birth, and contact details can heighten risks around scammer engagement. In fact, notifications about a breach itself can also heighten risks, as scammers can seek to impersonate the breached organisation when engaging with notified persons.


Remain scam vigilant by:

  • Assuming that communications you receive may be from a scammer.
  • Make your own enquiries using an alternative contact method to the one they used.
  • Never give remote access to your devices if asked by someone who engages you.
  • Keep your passwords and codes to yourself. Sharing these with scammers may mean you breach the terms and conditions of the account providers (such as your bank) and any chance of recovering funds highly unlikely.
  • Staying abreast of the latest scams by visiting Scamwatch or by subscribing to IDCARE’s free community awareness bulletin, Cyber Sushi

If you believe you have responded to a scam engagement, please complete an IDCARE Get Help form to request assistance.

Response Recommendations by Credentials

IDCARE has formed response recommendations relating to the credentials potentially exposed as a result of the MediSecure cyber incident. IDCARE has been informed that not all attributes were exposed for each individual impacted. Please refer to your incident notification for specifics on what information of yours was exposed.

Join the global list of organisations making a real difference in people’s lives by supporting our service.

Copyright © 2025, IDCARE. All Rights Reserved.

ABN 84 164 038 966