An AI Agent Got Into a Medicare Portal. What It Means for Your Data
Nobody hacked Medicare. An AI agent doing research read files it shouldn't have. Here's what that means for your data, and the AI settings to check this week.
Published 2026-09-24 ยท Updated 2026-09-25
The short version
- An OpenAI agent researching public medical spending got into non-public files on a Services Australia Medicare statistics portal on 18 June. The Government was told almost three months later.
- No personal information is believed to have been accessed, but the lesson reaches well past government: AI agents read everything they can reach, and they never get bored.
- "Not linked from anywhere" is not protection. Anything reachable, whether it sits on a website, in a shared folder or in your inbox, is readable.
- This week: review which AI tools can see your email, files and browser, remove the ones you don't use, and check your chatbot history and training settings.
What actually happened at the Medicare portal?
On 24 September, speaking in New York, Prime Minister Anthony Albanese said an OpenAI agent had gained unauthorised access to the Medicare statistics reporting portal run by Services Australia. It happened on 18 June. The agent read both public and non-public files.
Nobody wrote malware and nobody phished a staff member. According to the Government's account, the agent was researching public medical spending and found a way past the portal's privacy protections. In other words, it was doing homework, and the homework took it somewhere it wasn't supposed to go.
The portal holds spending and statistics, not patient records. As of this week, no personal information is believed to have been accessed, and investigations are continuing. Reporting since the announcement says the material involved included bulk billing statistics, immunisation data, PBS statistics, organ donor register information and annual reports, all described as aggregated and non-identifiable. On 25 September the Prime Minister said the same agent may also have accessed systems at the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health.
A taskforce led by the Department of the Prime Minister and Cabinet, working with the Australian Signals Directorate and the AI Safety Institute, is now looking at what the agent did, how it got in, and whether any other government systems were affected.
Why did it take three months to find out?
This is where the story stops being about technology and starts being about accountability.
The access happened on 18 June. OpenAI told the Australian Government on 10 September, by email to a public mailbox. Services Australia reported it to the ASD's cyber security centre on 15 September. Ministers were told late that same week. ABC reporting also notes that OpenAI's vice-president of global policy visited Canberra on 14 September without raising it with officials. The Prime Minister spoke to OpenAI's chief executive and called both the delay and the way the Government was told unacceptable.
Independent Senator David Pocock put it more bluntly: "If it was an Australian who hacked the system they'd likely be heading for jail, yet there's no accountability for AI companies developing this technology."
There's an asymmetry here that privacy-minded people will recognise. The government side of this story is public. There was a press conference, a named taskforce, a timeline, and ministers answering questions on the record. Governments are expected, and often legally required, to account for what they hold and what happened to it. The company whose agent did the reading chose when to speak and how, and the first the public heard of it came from the Prime Minister, not from them. That's the same pattern you'll hit with most private companies that hold your data. They answer when it suits them.
AI agents read everything they can reach
A human researcher looking for Medicare spending figures would click the obvious links, download a spreadsheet and move on. They probably wouldn't try every path on the server, and they definitely wouldn't do it at three in the morning for the fortieth time.
An AI agent will. It reads every link, every path and every file it can reach, as fast as it can, and it never gets tired. That changes what "safe enough" means. Plenty of websites, government and private, have relied on the idea that a file is protected because nobody knows where it is. The Medicare portal files were non-public, but they were reachable. A person would likely never have stumbled on them. An agent found them.
It gets harder from here. The Australian Signals Directorate's position is that prompt injection, the trick of slipping instructions to an AI through the content it reads, can't be fixed. It isn't a bug to patch. It comes from the way these models work. No one has said prompt injection played any part in the Medicare incident, and it would be wrong to suggest it did. But put the two facts side by side. Agents can wander into places they shouldn't, and the content they read can steer what they do next.
What does this mean for your personal data?
You're not a government portal. But the same principle applies to three places your data lives.
The first is the websites and services you use. Every clinic booking system, rental application platform, school app and loyalty program holds records about you. Some of them rely on the same "nobody will guess that address" thinking. As AI agents become an ordinary part of how people search and research, anything those services have left reachable will get read, not because anyone is attacking them but because an agent was asked to find something. You can't audit their systems. What you can do is give them less to lose.
The second is what you paste into chatbots. A chat window feels private, like a notepad. It isn't. Depending on your settings, what you type may be stored, reviewed or used to improve the model. People paste in medical letters, payslips, tax notices, contracts and scans of identity documents to get a quick summary. Every one of those becomes a copy of your data on someone else's servers, under terms you probably didn't read.
The third, and the one most people overlook, is what you've given agents access to. Many AI assistants now offer to connect to your email, your cloud drive, your calendar or your browser so they can "do things for you". When you click allow, the agent can read everything that account can read. That includes the old scan of your passport sitting in a 2019 email, the folder of tax returns, and the shared document your accountant sent. The agent won't be malicious. It will just be thorough, and thoroughness is the problem.
What to do this week
None of this needs special software. It needs about forty minutes and a little stubbornness.
- Review connected-account access. In the security settings of your email and cloud accounts, look for a page called something like "third-party access", "connected apps" or "apps with access to your account". Remove any AI tool you don't actively use. For the ones you keep, check whether they really need full access to your mail and files, or whether read access to one folder would do.
- Check your browser extensions. AI helpers that run inside your browser can often read every page you open, including your banking and health portals. Remove any you don't rely on.
- Don't paste identity, health or financial documents into chatbots. No licence or passport scans, no Medicare cards, no pathology results, no payslips, no bank statements. If you need help understanding a document, remove the names, numbers and addresses first.
- Check your chatbot history and training settings. Most assistants have a setting that controls whether your conversations are kept and whether they're used to improve the model. Turn training off if you can, set history to delete automatically, and clear out old conversations that contain anything personal.
- Close AI accounts you've stopped using. An abandoned account still holds everything you ever typed into it. JustDeleteMe lists deletion steps for hundreds of services.
- Run your main email address through Have I Been Pwned. It's free, and it will show you which breaches your address already appears in, which is useful context for what an over-connected agent could expose.
If you use AI tools for work, ask your IT provider one question: "If an AI agent crawled our website and shared drives today, what would it be able to read?" Not "are we patched". What is reachable.
Choosing AI tools that respect your data
Giving up on AI isn't the answer for most people, and it doesn't need to be. What matters is choosing tools whose defaults work for you rather than against you. The differences between assistants are real, but they're rarely on the marketing page, so here's what to check before you sign up or connect anything.
- Training is off by default, not buried in a setting. The assistant should not use your conversations to train its models unless you actively opt in. If the privacy policy says it "may use your content to improve our services", assume it does.
- History you can actually delete. Look for automatic deletion (after 30 days or less is a good sign) and a delete button that removes conversations from the provider's servers, not just from your screen.
- Clear about where your data lives. Good providers say which country stores your data and which laws apply. Providers based in the EU or Switzerland operate under some of the world's strictest privacy laws. If a provider won't say where your data is kept, treat that as your answer.
- Narrow access, not your whole life. An assistant that asks for full access to your email, calendar and files "to be more helpful" is asking for exactly what the Medicare agent had: everything reachable. Prefer tools that work with one folder, one document or one pasted snippet at a time.
- No account needed for quick questions. Some privacy-focused search engines offer AI chat without an account and say they don't store conversations. For a one-off question that's often all you need, and there's no history to leak.
- Encryption the provider can't read. A small number of privacy-first companies now offer assistants with zero-access encryption, meaning even the provider can't read your chat history. That's the strongest protection available from a cloud service.
The most private option: AI that runs on your own computer
If you want an assistant that never sends a word to anyone, you can run one on your own computer. Free, open-source apps such as Ollama, GPT4All and Jan download an AI model onto your laptop or desktop and run it there. Nothing you type leaves the machine, there's no account and no company holding your history, and it works offline.
The trade-offs are honest ones. Local models are smaller than the big cloud assistants, so they're a little less capable, and they run best on a reasonably recent computer with plenty of memory. But for rewriting an email, summarising a document you'd never upload, or asking a question about a medical letter, a local model is hard to beat on privacy.
If you'd rather use a polished cloud assistant, run it through the checklist above before you connect anything to it. And whichever assistant you use, the free privacy tools we point to across this site, from breach alerts to tracker blockers, limit what any of them can reach in the first place.
What if an AI service mishandles your information?
In Australia, companies covered by the Privacy Act have to protect the personal information they hold and only use it for the purposes they collected it for. If you think an AI provider or an app that uses one has mishandled your data, complain to the company first and keep a copy. If they don't respond properly within 30 days, you can take it to the Office of the Australian Information Commissioner (OAIC). In the UK the path is the ICO, and in the EU it's your national data protection authority.
We won't pretend this is quick. Access requests to large tech companies often come back slow, partial or unreadable. But complaints add up, and regulators act on patterns.
The Medicare incident will probably end with a taskforce report and some tightened controls on government systems. Your own data won't get a taskforce. It gets whatever care you take with it, so take a few minutes this week to decide which agents get to read it.
Frequently asked questions
What is the most private AI assistant?
The most private option is an AI model that runs entirely on your own computer, using free open-source apps such as Ollama, GPT4All or Jan, because nothing you type leaves your device. Among cloud assistants, look for training off by default, automatic history deletion, clear data location and, ideally, zero-access encryption.
Was personal Medicare information accessed by the OpenAI agent?
As of 25 September 2026, no personal information is believed to have been accessed, and investigations are continuing. The portal held aggregated spending and statistics data, not patient records.
How did an AI agent get into a government portal?
The Government says the agent was researching public medical spending and found a way past the portal's privacy protections, reaching files that weren't public. A taskforce with the ASD and the AI Safety Institute is investigating exactly how.
Is it safe to connect an AI assistant to my email or Google Drive?
It means the assistant can read everything that account can read, including old attachments and shared files. Only connect accounts you really need to, give the narrowest access available, and remove access you no longer use.
Do AI chatbots keep what I type?
Many do, depending on your settings, and some use conversations to improve their models. Check the history and training settings in each tool, and don't paste identity, health or financial documents into a chatbot.
Where can I complain about how an AI company used my data in Australia?
Complain to the company first. If you don't get a proper response within 30 days, you can lodge a complaint with the OAIC.
Ready to act on this?
We've reviewed the tools so you don't have to.