Home All Victims PARTNERED HEALTH GROUP

PARTNERED HEALTH GROUP

incransom

This record tracks a ransomware attack claimed by the incransom group against PARTNERED HEALTH GROUP. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.

Window Zero

EXPOSURE GAP

Window Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.

-61days
t1 · Published t2 · Disclosed
Jul 30, 2026May 30, 2026
Country
Australia
Business Category
Healthcare / Pharma
Employees
101-1000
Discovered
2026-07-30
Published
July 30, 2026
Disclosed / Notified
May 30, 2026
Victim ID
WqqUe1bRHxAQ

Attack Summary

PARTNERED HEALTH GROUP — Australia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Industry: Healthcare — Primary Care, Occupational Health, Psychology, Telehealth Headquarters: Australia (NSW, QLD, VIC, WA, ACT) Owner: Quadrant Private Equity Clinics: 60+ nationwide Brands: Partnered Health Medical Centres, Jobfit, Baseline Onsite, New View Psychology, NewPsych, Australian EAP, Fuel Your Life, Northcare Physio, TeleWell Website: partneredhealth.com.au PENDING ACQUISITION: Bupa — ~$450,000,000 AUD Announced July 2, 2026 (Australian Financial Review) ACCC and FIRB regulatory approval pending. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ BREACH SUMMARY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Date of access: 23 June 2026 Data exfiltrated: 3.2 TB Total files: 2,298,203 Servers accessed: 21 (9 AD Controllers + 11 Best Practice Medical Servers + 1 Central SQL Server) SQL Databases: ZedMed.mdf, Payroll.mdf, DocPays.mdf, VectraplexECG.mdf, BPM.mdf + 1,104 SQL backups Clinics compromised: 21 locations across 5 states/territories Patient records: 17,727+ named patient files identified Staff HR files: Full employee records including passports, AHPRA registrations, tax declarations Period of data: 1999 — 2026 (27 years) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ WHAT WE HAVE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ▪ Complete patient medical records from 21 GP clinics — consultation notes, referral letters, pathology results, diagnostic imaging reports, prescriptions ▪ Full SQL database dumps — ZedMed (patient management), Payroll (all staff salaries), DocPays (doctor payments), VectraplexECG (cardiac/ECG monitoring data) ▪ 11 complete Best Practice patient database backups — one per clinic — including BPSPatients, BPSDocuments (up to 48 document partitions per clinic) ▪ Staff HR files — employment contracts, passport scans, AHPRA medical registrations, tax file declarations, superannuation details, performance reviews ▪ Bupa corporate data — direct billing agreements, fund tables for all Australian states, patient invoices, corporate program documents (Bronze/Silver/Gold), and active Bupa web portal session cookies ▪ Financial records — QuickBooks databases (2004-2026), Medicare billing, DVA remittances, private health fund claims ▪ Clinical governance — full RACGP accreditation files, patient consent templates, internal clinical audit data ▪ 27 years of accumulated medical data (1999-2026) across ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ TO PARTNERED HEALTH / QUADRANT PRIVATE EQUITY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health was given the opportunity to resolve this matter privately and protect patient data. Instead of acting in the interest of their patients, they spent 22 days in silence, hired lawyers, and obtained a court injunction that has no practical effect outside Australian jurisdiction. Their public statement of July 15 describes the breach as affecting "some" data from "some" clinics. This is misleading. The reality: 3.2 terabytes. 2.3 million files. 21 servers. 27 years of patient medical history. Every clinic server in their network was accessed. Complete SQL database dumps were taken including the central patient management system and payroll for every employee. And critically — the data includes Bupa's own corporate information: billing agreements, fund pricing tables for every Australian state, named patient invoices, and active browser session cookies from Bupa's login, corporate, and web portals. We understand this acquisition matters. $450 million is a significant transaction. A full data publication would create material regulatory complications with the ACCC and FIRB review process. We trust the board and advisors at Quadrant understand what that means. This is not a threat. This is a deadline. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ DEADLINE: [DATE + 10 DAYS] ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health has 10 days to resume negotiations and reach a settlement. If no agreement is reached: Stage 1 — Complete file tree listing (2.3M files) + all HR/staff records published Stage 2 — SQL databases (ZedMed, Payroll, ECG) released for download Stage 3 — Bupa corporate data, fund tables, billing agreements, session data published. ACCC, FIRB, and Bupa executive leadership notified directly. Stage 4 — Full 3.2 TB data dump made available for public download.

Leak Screenshots

SAMPLE

Proof-of-breach screenshots the operator posted from the stolen data. Previews are redacted and locked — the originals are available on HaveIBeenRansom.

file_tree.png
finance_2024.xlsx
passport_scan.jpg
contract_signed.pdf
Sign in or explore HaveIBeenRansom to view the full leak gallery.
View leak gallery →

Dark Web Exposure

Cross-referenced against HaveIBeenRansom's dark-web index of ransomware leaks, breaches & infostealer logs.
0
found in Infostealer logs
0
found in Traditional breaches
0
found in Ransomware leaks
Emails exposed
••••
Internal
•••
External
•••
Distinct leaks
••
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
Full exposure is locked
See every breached email, the internal-vs-external split and each leak source behind this victim.
Want the complete picture — passwords, machines, full leak files? It's all searchable on HaveIBeenRansom.
Search this victim →
Original Post View Group: incransom
Legal Disclaimer: This ransomware victim record reflects information published on the operator's leak site. Breach.house does not acquire, download, host, access or redistribute unlawfully obtained data. It indexes only publicly visible information posted by ransomware, breach and infostealer operators and open web sources, without accessing the underlying stolen content. The service supports public awareness, legitimate research and cyber-resilience.