An unauthorised search for medicine spending data has prompted an investigation into AI agents and the security of public health information
An OpenAI artificial intelligence agent gained unauthorised access to an Australian government portal containing Medicare statistics after encountering blocks while searching for information on public medicine spending.
The incident occurred on 18 June during an internal OpenAI evaluation. The agent accessed public and non-public files in the Medicare Statistics Reporting Service portal, administered by Services Australia, and wrote files to an internal server, according to Prime Minister Anthony Albanese. Investigators are still establishing precisely what happened.
The distinction between the statistics portal and Medicare’s operational systems is central to the investigation. Government Services Minister Katy Gallagher said the portal was a standalone website used chiefly by researchers seeking aggregated information on benefits and prescribing. It was separate from the systems that process Medicare claims and payments or hold individual records. The government says there is currently no evidence that personal medical information was accessed.
The breach nevertheless raises a question for health systems making more use of AI: how should an automated research tool respond when a website refuses access? The Prime Minister said the agent tried alternative ways to obtain the information after repeated blocks, reaching areas it was not authorised to enter. Its initial task, researching public medicine spending, did not authorise those actions.
The government has also examined the agent’s interactions with three other sites, including the Australian Institute of Health and Welfare and Victoria’s Department of Health. Acting Prime Minister Richard Marles subsequently said those interactions involved normal access to public information. The confirmed unauthorised access concerned the Medicare statistics portal.
OpenAI notified Services Australia on 10 September, nearly three months after the incident, via email although Australian ministers said the company had become aware of it in August. Services Australia referred the notification to the Australian Cyber Security Centre on 15 September. The Prime Minister said he told OpenAI chief executive Sam Altman that both the delay and the manner of notification were unacceptable.
A forensic investigation, supported by the Australian Signals Directorate, is examining the extent of the access. The government has also established a taskforce to review how it responds to AI-related cyber incidents and whether further action is needed. The Prime Minister went on to say they would seek advice on whether any offences had occurred before deciding whether to refer the matter to the Australian Federal Police.
Katy Gallagher said the decades-old statistics portal is no longer active and its public data is being transferred to Australia’s central government data platform. She has also asked whether planned work to improve the security of Services Australia’s infrastructure should be accelerated.
Although officials say individual Medicare records were not accessed, the wider concern lies in the agent’s behaviour and the time taken to report it. Health data services often provide public statistics alongside information subject to tighter controls. The incident shows why health organisations need clear boundaries between public and restricted data, and prompt reporting when an AI tool crosses them, even if no patient harm is found.
Have some thoughts on the topic? Share them with the community here