Most Recent
In high-stakes breach case, OAIC says Medibank failed to implement ‘basic’ security controls
Privacy & Cybersecurity 2024-06-19 11:34 pm By Cindy Cameronne

Medibank failed to put in place baseline security measures, including multi-factor authentication, to safeguard sensitive information from a hacker in 2022, who stole an IT contractor’s credentials and logged in to the health insurer’s private network three months before the company learned its data was compromised, the OAIC says.

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Medibank can’t ‘have it both ways’ with Deloitte report, class action says
Privacy & Cybersecurity 2024-06-03 11:35 pm By Cindy Cameronne

A class action has argued Medibank cannot claim legal professional privilege over three Deloitte reports after disclosing them to reassure the market and customers after a massive 2022 data breach.

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Medibank board engaged KWM, Deloitte for review after class action rumours, court told
Class Actions 2024-05-23 11:35 pm By Cindy Cameronne

The chair of the Medibank board has given evidence that he engaged King & Wood Mallesons to commission expert reviews in the wake of a cyberattack, including three reports by Deloitte, after hearing rumours of class action investigations in October 2022. 

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

‘A war on two fronts’: No relief in sight for companies battling multiple privacy class actions
Privacy & Cybersecurity 2024-02-28 11:01 pm By Cindy Cameronne

More companies may find themselves in the position of Medibank — which recently failed to stay representative proceedings before the privacy regulator while a related class action is on foot — so long as the laws remain unchanged, and law firms are willing to gamble on privacy class actions.

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Medibank can’t halt class action-style complaint to OAIC over data breach
Privacy & Cybersecurity 2024-02-22 2:22 pm By Cindy Cameronne

A judge has dismissed a bid by Medibank to restrain the Office of Australian Information Commissioner from proceeding with a class action-style complaint on behalf of millions of the private health insurer’s customers affected by an October 2022 data breach.

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Russian citizen hit with first-ever cyber sanctions over Medibank breach
Privacy & Cybersecurity 2024-01-23 1:45 pm By Cindy Cameronne

The federal government has used its cyber sanction powers for the first time against a Russian individual identified as responsible for an attack against private health insurer Medibank that exposed almost 10 million customer records.

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Lawyers can lose focus on clients’ interests in competing class actions, court says
Class Actions 2023-06-30 5:29 pm By Cindy Cameronne

A judge has cautioned two law firms running competing shareholder class actions over last October’s cyber attack on Medibank that they must keep their focus on the best interests of clients and group members, saying lawyers can lose sight of that duty when arguing for their case. 

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Medibank’s woes worsen as fifth data breach class action filed
Class Actions 2023-06-29 3:41 pm By Christine Caulfield

Medibank is now facing five class actions over last October’s cyber attack that left exposed the personal data of 9.7 million customers, this one by shareholders of the private health insurer.

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Medibank’s capital requirement lifted to $250M after data breach
Privacy & Cybersecurity 2023-06-27 2:53 pm By Gareth Baker

The Australian Prudential Regulation Authority has raised Medibank’s capital adequacy requirement by $250 million, following last year’s cyber attack against the private health insurer, which exposed the personal details of 10 million customers. 

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.

Class actions pile up over Medibank data breach
Privacy & Cybersecurity 2023-05-05 6:45 am By Christine Caulfield

Private health insurer Medibank has been served with a second class action over a data breach exposing the personal details of 10 million customers.

Subscribe for instant access to all Lawyerly content.

Already a subscriber?

Lost your password?

Contact us to enquire about group subscriptions.