SKIP TO MAIN CONTENT
Australia

What we do and don't know about the OpenAI hack on Medicare

An OpenAI agent "scaled the fence" into a Medicare portal.

ChatGPT website displayed on a phone screen and OpenAI logo displayed on a screen in the background
An OpenAI agent hacked a Medicare portal in June, the government has just announced. Source: NurPhoto / Getty

6 min read

Published

Updated

By Alexandra Koster

Source: SBS News


Skip to article content

In brief

  • The government says an OpenAI agent "scaled the fence" of a Medicare portal, accessing statistics but no patient records.
  • But we still don't know how the agent hacked the system, why it took almost three months for the government to be told.

An OpenAI artificial intelligence agent hacked into a Medicare website and took months to notify the government.

Deputy Prime Minister Richard Marles confirmed on Thursday that the agent gained unauthorised access to the Medicare portal in June.

The government was not told until 10 September.

Marles said the incident was "very serious" but had a "relatively minor" impact.

A task force is now underway, but big questions remain: how the agent got in, why it took so long to raise the alarm, and what regulations might come in next.

News that makes sense

Your trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Here's what we do and don't know about OpenAI's hack on Medicare.

How did the OpenAI AI agent hack the Medicare portal?

An OpenAI artificial intelligence agent gained access to the Medicare Statistics Reporting Service, a public portal that contains data and statistics, while researching public medicine spending on 18 June.

The federal government is aware of three other systems that may have been affected by the breach, including the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.

The incident occurred while the model was being trained, where, according to deputy prime minister Richard Marles, the agent "scaled the fence" and accessed part of a Medicare portal.

OpenAI told the government it became aware of the incident in August in an email sent to the public Services Australia inbox on 10 September.

Marles said ministers had known for less than a week and wanted to understand the impact before going public.

Did the OpenAI Medicare breach expose personal data?

While Marles said it was a "very serious incident", he also said its impact was "relatively minor".

"We are talking about aggregated medical statistics. No individual's medical data was accessed here," Marles said, adding the Medicare system itself had not been compromised.

The portal itself is a standalone, decades-old, public-facing site used mostly by researchers and academics, Government Services Minister Katy Gallagher said.

"It is not in any way related to Medicare in terms of claims, payments, or processing individual information. So, it's a completely different system," she said.

Gallagher said that "at this stage" no personal information was involved and the data has since been moved to the more secure data.gov.au and the portal is offline.

The government has launched a rapid task force involving the Australian Signals Directorate (ASD), the AI Safety Institute, and the Office of AI, who will examine the incident, the security of government networks, and the legal arrangements in place.

When was the federal government told about the Medicare hack?

There's a lot of discussion around the timelines of when the incident occurred, when the government found out, and when that information was released to the public.

OpenAI discovered the breach in August during a review of a number of its AI agents going rogue on tasks.

It informed the Australian government on 10 September by emailing a mid-level public inbox at Services Australia.

Services Australia received the information on 11 September and, after verification that the notification was legitimate, reported the incident to the ASD Cyber Security Centre on 15 September.

Gallagher was advised of the incident on 17 September, and she, Marles, and Home Affairs Minister Tony Burke held a number of discussions with Services Australia and ASD over the weekend of 19-20 September.

On Wednesday (local time), Prime Minister Anthony Albanese spoke to OpenAI CEO Sam Altman in New York about the incident and to express his disappointment about the length of time it took to notify the government and how the notification occurred.

What questions remain about the OpenAI Medicare breach?

We don't know how the AI agent got into the portal.

Dr Dominic Meagher, a research fellow at ANU Crawford School, said he would like to know the "technicalities of how they actually hacked" the portal, including a "technical report" from the ASD, rather than the government.

We also don't know exactly what information was accessed. The government says it was aggregated, non-sensitive statistics, but Marles conceded "we don't know everything yet".

We also don't know why it took so long — roughly three months — for the incident to be made public, with Marles saying it wasn't clear whether Altman was aware of the incident when the two met in late August, and that it wasn't discussed.

It's also unclear whether laws have been broken — something the task force will be examining.

Professor Toby Walsh, chief scientist of the AI Institute and Scientia professor of AI at UNSW, said OpenAI should be prosecuted.

"OpenAI had — and for all we know has — terrible agent governance. I believe we ought to be prosecuting the company," Walsh told SBS News. "We would prosecute humans who did such hacking."

Meagher argues a criminal lens is the wrong one because there was no criminal intent, instead arguing that it looks more like an industrial — or workplace safety — hazard.

He encouraged workplace-safety-style rules, including immediate reporting duties, duties of care for company officers, and licensing for high-risk labs.

ACT senator David Pocock called the incident "concerning but ultimately unsurprising" and said it showed how slow the government has been to put safeguards in place for AI in high-risk settings.

Justin Allen from cybersecurity firm Huntress said rules alone won't work. "You can't enforce a rule against something you can't detect yourself," he said, adding that regulation needs to be funded alongside real detection capability.

Meagher said the broader question is whether incidents like this will become frequent, and how they're contained. "It looks increasingly frequent."

— With additional reporting by the Australian Associated Press.


For the latest from SBS News, download our app and subscribe to our newsletter.


Get SBS News straight to your inbox

Sign up now for daily news from Australia and around the world. You can also subscribe to Insight's weekly newsletter for in-depth features and first-person stories.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Follow SBS News

Download our apps

Listen to our podcasts

Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS

SBS World News

Take a global view with Australia's most comprehensive world news service

Stream now

Watch the latest news videos from Australia and across the world