You may think that cyber-attacks are only relevant to much larger businesses, but this is a misconception. According to the Office of the Australian Information Commissioner (OAIC), the majority of cybercrime reports in 2023-24 came from small businesses. Key findings from Cyber Wardens 2024 research also shows 82% of small businesses have either been exposed to or experienced a cyber incident.

 

Small businesses in focus

Cyber criminals know that small businesses often do not have the robust IT controls and protections that are employed at large businesses. It is also likely that a successful cyber-attack against a small business will significantly impact that businesses operation. These factors make small businesses an easier and far more common target for cyber criminals, who employ ransomware attacks or aim to steal personal data.

 

Cyber risk in healthcare

The health sector is another key target for cybercrime. As healthcare clinics retain significant amounts of data regarding their patients, including identification and financial information, this makes them a lucrative target for cyber criminals.

 

Healthcare and social assistance has become the most targeted non-government sector for cyber incidents in Australia, according to the Office of the Australian Information Commissioner (OAIC)’s 2023-24 report.

 

Below is an overview of recent cyber incidents effecting health businesses in Australia:

  • February 2025 – a regional indigenous medical corporation had their internal systems accessed by an unauthorised person.
  • January 2025 – a medical imaging business was the victim of a ransomware attack which compromised financial and patient data.
  • November 2024 – a Victorian metropolitan medical centre had their systems compromised by a ransomware gang and data, inclusive of CCTV footage of patients, was published on the dark web.
  • October 2022 – a private health insurer was targeted with a ransomware attack which placed 9.7 million people at risk of having their medical histories, passports and drivers licence numbers released on the dark web.

 

Tips for mitigating risk

As outlined above, cyber incidents can occur at any level of business, from large healthcare operations to sole practitioners. Podiatrists can follow some basic practical tips to mitigate their risk:

  1. Carefully consider what information your practice obtains from patients, how that information will be stored and how long you will keep that information for (noting your obligations under the National Law and Shared Code of Conduct).
  2. Keep the software you use in your practice up to date. This means ensuring that you accept and implement all software updates and that you are not using outdated or legacy versions of software.
  3. Ensure that you and any staff or contractors are using strong passwords or phrases that are unique to that piece of software in your practice.
  4. Where possible, set up multi-factor authentication. This ensures that even where a password may be compromised, there is another line of protection.
  5. Ensure that you carefully evaluate any emails, texts or calls for scams or potential phishing attacks. This can include checking the actual email address of the sender, reviewing the communication style (such as typos) and any suspicious changes in a person’s details, including financial details. Remember: if in doubt, you should call the person you are corresponding with to ensure that it is actually them.
  6. Consider obtaining external IT support for your business. An external IT provider will be able to assist you to set up appropriate protections for your business, keep you and your systems up to date on current cyber issues and offer appropriate training to you and your staff to avoid cyber incidents.

 

Finally, it is recommended that you have a plan or policy that documents how a cyber-attack will be managed by your business in the event of one occurring. Often in these scenarios time is of the essence, and having a written plan will allow you to move quickly to protect your business and your patients.

 

What can Cyber Liability Insurance do?

While Cyber Liability Insurance can’t stop a cyber incident from happening, it can help by providing cover for financial loss suffered because of a cyber-related incident – such as data-recovery costs and business interruption costs.

 

APodA members can purchase Cyber Liability Insurance with BMS. Visit the APodA insurance page to learn more or log in to the BMS Portal via APodA’s ‘My Membership‘ page to get a quote.

 

This article is facilitated by BMS, with information on tips for mitigating risk by Scott Shelly and Alexander Sheridan of Barry Nilsson.

Barry Nilsson communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. You must be a current Australian Podiatry Association (APodA) member to be eligible to register for the APodA Member Insurance Program. You must be part of the APodA Member Insurance program in order to access additional cover. If your membership ceases you will not be offered renewal when your policy expires. In offering this insurance to our members APodA is a distributor of BMS Risk Solutions Pty Ltd (BMS) AFSL 461594, ABN 45161187980. The insurance is issued by BMS under authority with the insurer. When acting under this authority BMS acts as agent for the insurer and not as your agent. This is general advice only and BMS has not considered whether it was suitable for your personal circumstances, current objectives, needs or financial situation. Please read the Policy Wording/Product Disclosure Statement and the BMS Terms of Engagement which contains the Financial Services Guide before making a decision about purchasing this policy. As a distributor, APodA receives an annual payment from BMS which is used for insurance related marketing and professional development activities to support our members.
[mo_oauth_login]