Australian Telehealth Provider Updoc Reports Data Breach Affecting Patient Contact Information
Updoc, an Australian telehealth platform offering 24/7 online health support, has confirmed a data breach involving unauthorized access to a third-party system used in its operations. The incident exposed customer contact details, including names, email addresses, and postal addresses, though the company stated its own systems remained secure.
In an email sent to affected customers on Wednesday, Updoc clarified that no health or financial data was compromised. The breach was swiftly contained, with the company confirming no further unauthorized access occurred after the initial incident. Updoc apologized for the inconvenience but advised customers that no immediate action was required.
Founded in 2021 and generating $10 million in annual revenue, Updoc is the third Australian company to report a cybersecurity incident since early July. Earlier breaches included Partnered Health, where patient health records across 21 clinics in five states were compromised, and energy retailer Origin, which confirmed the theft of customer data, including partial credit card and bank account details.
Updoc TPRM report: https://www.rankiteo.com/company/up-doc
"id": "up-1785990348",
"linkid": "up-doc",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Unknown',
'industry': 'Healthcare',
'location': 'Australia',
'name': 'Updoc',
'size': 'Annual revenue: $10 million',
'type': 'Telehealth Platform'}],
'attack_vector': 'Unauthorized access to third-party system',
'customer_advisories': 'No immediate action required for customers',
'data_breach': {'personally_identifiable_information': 'Names, email '
'addresses, postal '
'addresses',
'sensitivity_of_data': 'Low (no health or financial data)',
'type_of_data_compromised': 'Customer contact details'},
'description': 'Updoc, an Australian telehealth platform, confirmed a data '
'breach involving unauthorized access to a third-party system '
'used in its operations. The incident exposed customer contact '
'details, including names, email addresses, and postal '
'addresses. No health or financial data was compromised.',
'impact': {'data_compromised': 'Customer contact details (names, email '
'addresses, postal addresses)',
'identity_theft_risk': 'Potential',
'payment_information_risk': 'None',
'systems_affected': 'Third-party system'},
'references': [{'source': 'Updoc customer email notification'}],
'response': {'communication_strategy': 'Email notification to affected '
'customers',
'containment_measures': 'Swift containment; no further '
'unauthorized access after initial '
'incident'},
'title': 'Updoc Telehealth Data Breach Affecting Patient Contact Information',
'type': 'Data Breach'}