$5.8 Million Fine. No Multi-Factor Auth. No Excuse.

Pathology worker at a lab workstation with red data-breach alerts on screen

Estimated Exposure: 223,000 patients. $5.8 million penalty.

What Happened: Australian Clinical Labs got breached in 2022. Hackers walked through the front door — no multi-factor authentication, firewall logs kept for only one hour, no proper incident response plan. 223,000 patient health records stolen. Medication histories that reveal mental illness, fertility treatment, gender transition. All posted for sale on the dark web. The Federal Court didn’t just fine them — they broke it down: $4.2 million for not securing data. $800,000 for not investigating. $800,000 for not reporting it fast enough. First civil penalty ever imposed under the Privacy Act. The court said they “failed to act with sufficient care and diligence.”

Message: Australian regulators: ignorance is not a defence. Negligence has a price tag.

Source: Federal Court of Australia [2025] FCA 1224, OAIC prosecution

The Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties following the 2022 Medlab Pathology data breach.

Read the OAIC account of the case.

Get Certified Before
You're the Next Headline

Every story on this page started the same way — a published vulnerability, a site nobody was watching, and weeks before anyone noticed. The free scan looks at your site from the outside, the same way an automated scanner does. It costs nothing, there is no obligation, and it takes about thirty seconds to start.

Scan My Site — Free