QIMR Berghofer skin cancer study data exposed in Datatime breach

Organization
QIMR Berghofer Medical Research Institute
Exploit
Third-Party Data Breach
Industry
Medical Research

Participants in QSkin, a long running Queensland skin cancer research project run by the QIMR Berghofer Medical Research Institute, were told in March 2023 that their details may have been caught up in a breach at one of the institute's contractors.

The contractor, Datatime, had been engaged to handle a 2021 postal survey, printing and scanning forms on the institute's behalf. Datatime reported a cyber incident on its systems in November 2022. QIMR Berghofer said Datatime held the names and addresses of 9,749 people who were sent the mail out, and that 1,128 of those who completed and returned forms also had their Medicare numbers with the contractor. No genetic data was held by Datatime. The study's lead investigator, Professor David Whiteman, told participants that their survey responses may also have been accessed, and that the institute could not give categorical confirmation either way.

QIMR Berghofer identified the affected participants and contacted them directly by email, acting on advice from the Office of the Information Commissioner Queensland, and notified the Office of the Australian Information Commissioner. Datatime said it had also notified the OAIC, the Australian Cyber Security Centre and the Australian Federal Police.

Datatime said that after an investigation by internal and external security specialists it had concluded no private data was released into the public domain and that there had been no further contact from the attackers. The institute apologised to participants and said it was tightening accreditation requirements for suppliers.

Sources