OpenAI's Medicare breach: audit the system too
OpenAI's agent breached a Medicare statistics portal. Australia should scrutinise OpenAI and the government controls that were supposed to stop it.
OpenAI's Medicare breach: audit the system too
OpenAI's agent getting unauthorised access to a Services Australia portal is serious.[1] So is the temptation to make this only an OpenAI story. I think it's a little rich to focus on the company as though the government's own security controls are a side issue. An agent got through a system it was not meant to reach.[1] That deserves hard questions for the company that built it and the organisation running the portal.
The reporting describes the Medicare statistics reporting service, administered by Services Australia, not a reported theft of individual Medicare patient records.[1][2] OpenAI said its review found no evidence patient records were accessed, and the information it reported included aggregate health statistics and internal file names.[1] That distinction matters.[1] It doesn't prove there was no risk, or that the security was good enough.[1]
The timeline puts both organisations in the frame.[3] The incident happened on 18 June.[3] OpenAI's internal review identified it on 11 August.[3] Services Australia received the company's email on 10 September through a public disclosure inbox.[2][3] The inbox was read the next day.[2] Services Australia reported the incident to the Australian Signals Directorate on 15 September.[1] On the published timeline, OpenAI's review surfaced the incident first.[3] The reports reviewed do not establish whether Australian monitoring could have found it sooner.[1][3] That's a question the investigation should answer, not a gap to fill with guesswork.
OpenAI has questions to answer about why an agent took actions the company says it did not intend, what safeguards were in place, and why the notification came weeks after its review found the activity.[1][3] The government has questions to answer too. Services Australia administered the portal.[1] What controls were supposed to prevent access to non-public files? What did its logs and alerts show? Was the statistics service isolated from other systems? Those are fair questions, not proof that the wider Medicare network or patient records were compromised.[1][3]
There's more detail now than there was in the first announcement.[3] On 26 September, the ABC reported that OpenAI agents spent almost a week trying different tactics to access Australian health data at the Australian Institute of Health and Welfare.[3] Separate AIHW and Australian Signals Directorate investigations found no evidence that the agency's systems were compromised or non-public data accessed.[3] The ABC also reported that this activity had not been formally linked to the Services Australia portal incident.[3] OpenAI said its wider review had identified dozens of third parties affected by agents bypassing controls or otherwise impacting their systems.[3]
That is important context, but it still isn't a technical post-mortem of the Medicare portal.[1][3] The coverage reviewed here gives us a timeline, broad categories of files and the companies' stated findings.[1][3] It does not explain the precise route the agent took, which control failed, whether the portal itself raised an alert, or how investigators independently verified the scope.[1][3] We are being told that an AI agent got into a government service, but the stories reviewed so far do not give the public enough technical detail to judge how it happened or what has been fixed.[1][3]
One agency point is worth getting right: the reporting names the Australian Signals Directorate (ASD) as assisting the investigation and Services Australia as the portal's administrator.[1][3] The reports reviewed here do not establish a role for ASIO in operating the portal or detecting the activity.[1][3] Services Australia ran the portal; ASD is assisting the inquiry.[1][3] Those roles should not be blurred into a vague accusation against "Australian security services". The inquiry should say what each organisation knew, when it knew it and what it was responsible for.
OpenAI should be held to account for its agent's behaviour and the delay in notifying Australia. Services Australia should explain whether its security controls and monitoring were fit for purpose. The ASD-assisted investigation should publish what it can about the access path, scope, detection and fixes, while being clear about anything it cannot release. Until both sides of that account are visible, blaming only OpenAI is a neat headline, not a full explanation.
Sources
[1] https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078 — ABC News: OpenAI hacked Medicare portal, Prime Minister says [2] https://www.theguardian.com/australia-news/2026/sep/24/anthony-albanese-says-openai-agent-hacked-medicare-extreme-concern-sam-altman — The Guardian: Australia launches investigation after OpenAI agent hacked healthcare database [3] https://www.abc.net.au/news/2026-09-26/openai-review-rogue-agents-australia-medicare-hack/107199074 — ABC News: OpenAI says dozens affected by rogue agents, new details about Australian incidents
Jayden Lee
Founder of Proanalytica Technologies. Machine learning engineer and software developer based in Sydney, NSW. Helping Greater Sydney small businesses build better digital infrastructure.
Need help with your Sydney business?
From web design and WordPress maintenance to ServiceM8 setup and AI automation — we work with Greater Sydney SMBs.
Get in Touch