NDIA staffer charged with leaking participants’ data, acting NDIA provider also arrested
Company Breach Information: 28 November 2023 NDIA detects data breach
Company Media Release: 28 November 2023 Two charged following fraud investigations
Source: NDIA data breach claimed to impact 11,000 “records” | iTnews
Source: NDIA staffer charged with leaking participants’ data | iTnews
Featured Breach Series: HWL Ebsworth Lawyers
View more incidents relating to Insider Threats, and other Australian National Disability Insurance Scheme incident reports.
The National Disability Insurance Agency (NDIA) staffer charged in connection with a data breach is alleged to have shared around 11,000 “records” with at least one service provider associated with the scheme.
Update Jan 19 2004: 644 NDIS users not told which medical records leaked, seven months after HWL Ebsworth hack | iTnews
Almost 650 National Disability Insurance Scheme (NDIS) participants and prospective participants have still not been told which of their health records were leaked on the dark web in June last year.
NDIA was also caught up in the HWL Ebsworth breach this year, which exposed information recorded in dozens of federal agencies’ systems earlier this year.
NDIA is the government organisation that implements and manages the NDIS National Disability Insurance Scheme, which is the scheme that provides funding and services for people with disabilities, their families and carers.
Government services minister Bill Shorten stated “It appears … the charge is that this person is alleged to have provided about 11,000 records, not all participants, to providers.”
He noted it was “not a cyber breach” of the agency, but instead a case of insider threat.
Some of the information disclosed on participants included “full name, date of birth, gender address, including postcode,” but that “in a small number of cases … further details [were] disclosed.”
The agency also did not disclose when it first detected the unauthorised disclosure of participants’ of the National Disability Insurance Scheme (NDIS). Saying it “believes this incident is financially motivated” and that all impacted individuals would be directly contacted by the NDIA.
Related

