Ransomware victim disclosure
← All victimsPARTNERED HEALTH GROUP
Claimed by Incransom · listed 8 hours ago
Status timeline
- ListedJul 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Australia
- Sector
- Healthcare
- Listed on leak site
- Jul 30, 2026
About the victim
AI dossier — public-source company profilePartnered Health Group operates 60+ primary care, occupational health, psychology, and telehealth clinics across five Australian states and territories under multiple brands including Partnered Health Medical Centres, Jobfit, Baseline Onsite, New View Psychology, and others. Owned by Quadrant Private Equity, the group is pending acquisition by Bupa for approximately AUD $450 million (announced July 2026).
- Industry
- Healthcare — Primary Care, Occupational Health, Psychology, Telehealth
- Address
- Australia (NSW, QLD, VIC, WA, ACT) — 60+ clinic locations nationwide
- Employees
- 51-200
Attack summary
Severity: critical — Confirmed exfiltration of 3.2 TB spanning 27 years of sensitive health records (17,727+ patient files), staff personally identifiable information (passports, tax files, medical registrations), and regulated healthcare databases. Includes Australian healthcare system data (Medicare, DVA), AHPRA-regulated practitioner records, and Bupa corporate/financial data. Scale, sensitivity, regulatory jurisdiction (Australian Privacy Act, HIPAA-equivalent), and impact on pending $450M acquisition elevate toincransom claims to have exfiltrated 3.2 TB of data (2.3 million files) from 21 servers across 21 clinic locations on 23 June 2026, including complete patient medical records spanning 27 years (1999–2026), full SQL database dumps (ZedMed, Payroll, DocPays, VectraplexECG), staff HR records with passports and tax declarations, and Bupa corporate billing data and session cookies. The group is threatening staged publication unless negotiations resume within 10 days.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records (17,727+ named files)
- Consultation notes, referral letters, pathology results
- Diagnostic imaging reports and prescriptions
- Complete ZedMed patient management database
- Payroll database (all staff salaries)
- DocPays database (doctor payments)
- VectraplexECG cardiac/ECG monitoring data
- 11 Best Practice clinic patient database backups
- Staff HR files (employment contracts, passports, AHPRA registrations, tax declarations, superannuation)
- Bupa corporate data (billing agreements, fund tables, patient invoices, session cookies)
- QuickBooks financial records (2004–2026)
- Medicare billing and DVA remittances
- RACGP accreditation files and clinical audit data
What the group claims
PARTNERED HEALTH GROUP — Australia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Industry: Healthcare — Primary Care, Occupational Health, Psychology, Telehealth Headquarters: Australia (NSW, QLD, VIC, WA, ACT) Owner: Quadrant Private Equity Clinics: 60+ nationwide Brands: Partnered Health Medical Centres, Jobfit, Baseline Onsite, New View Psychology, NewPsych, Australian EAP, Fuel Your Life, Northcare Physio, TeleWell Website: partneredhealth.com.au PENDING ACQUISITION: Bupa — ~$450,000,000 AUD Announced July 2, 2026 (Australian Financial Review) ACCC and FIRB regulatory approval pending. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ BREACH SUMMARY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Date of access: 23 June 2026 Data exfiltrated: 3.2 TB Total files: 2,298,203 Servers accessed: 21 (9 AD Controllers + 11 Best Practice Medical Servers + 1 Central SQL Server) SQL Databases: ZedMed.mdf, Payroll.mdf, DocPays.mdf, VectraplexECG.mdf, BPM.mdf + 1,104 SQL backups Clinics compromised: 21 locations across 5 states/territories Patient records: 17,727+ named patient files identified Staff HR files: Full employee records including passports, AHPRA registrations, tax declarations Period of data: 1999 — 2026 (27 years) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ WHAT WE HAVE ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ▪ Complete patient medical records from 21 GP clinics — consultation notes, referral letters, pathology results, diagnostic imaging reports, prescriptions ▪ Full SQL database dumps — ZedMed (patient management), Payroll (all staff salaries), DocPays (doctor payments), VectraplexECG (cardiac/ECG monitoring data) ▪ 11 complete Best Practice patient database backups — one per clinic — including BPSPatients, BPSDocuments (up to 48 document partitions per clinic) ▪ Staff HR files — employment contracts, passport scans, AHPRA medical registrations, tax file declarations, superannuation details, performance reviews ▪ Bupa corporate data — direct billing agreements, fund tables for all Australian states, patient invoices, corporate program documents (Bronze/Silver/Gold), and active Bupa web portal session cookies ▪ Financial records — QuickBooks databases (2004-2026), Medicare billing, DVA remittances, private health fund claims ▪ Clinical governance — full RACGP accreditation files, patient consent templates, internal clinical audit data ▪ 27 years of accumulated medical data (1999-2026) across ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ TO PARTNERED HEALTH / QUADRANT PRIVATE EQUITY ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health was given the opportunity to resolve this matter privately and protect patient data. Instead of acting in the interest of their patients, they spent 22 days in silence, hired lawyers, and obtained a court injunction that has no practical effect outside Australian jurisdiction. Their public statement of July 15 describes the breach as affecting "some" data from "some" clinics. This is misleading. The reality: 3.2 terabytes. 2.3 million files. 21 servers. 27 years of patient medical history. Every clinic server in their network was accessed. Complete SQL database dumps were taken including the central patient management system and payroll for every employee. And critically — the data includes Bupa's own corporate information: billing agreements, fund pricing tables for every Australian state, named patient invoices, and active browser session cookies from Bupa's login, corporate, and web portals. We understand this acquisition matters. $450 million is a significant transaction. A full data publication would create material regulatory complications with the ACCC and FIRB review process. We trust the board and advisors at Quadrant understand what that means. This is not a threat. This is a deadline. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ DEADLINE: [DATE + 10 DAYS] ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Partnered Health has 10 days to resume negotiations and reach a settlement. If no agreement is reached: Stage 1 — Complete file tree listing (2.3M files) + all HR/staff records published Stage 2 — SQL databases (ZedMed, Payroll, ECG) released for download Stage 3 — Bupa corporate data, fund tables, billing agreements, session data published. ACCC, FIRB, and Bupa executive leadership notified directly. Stage 4 — Full 3.2 TB data dump made available for public download.
Sources
Source
Indexed 8 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

