The Question at Hand
When Partnered Health's 21 clinics experienced a breach affecting medical records across Sydney, Melbourne, and Canberra, they obtained an interim injunction from the New South Wales supreme court. This legal move illustrates governance in action. However, once data is exfiltrated, it's out there for good. This situation poses a critical question for healthcare data protection officers: Should cybersecurity remain with IT infrastructure teams, or should it be integrated into clinical operations alongside patient safety protocols? This isn't just about reporting structures; it's about whether you treat data protection as a compliance checkbox or as a core component of patient care.
The Case for Keeping Cybersecurity in IT Operations
Most healthcare organizations manage cybersecurity as a technology function for practical reasons. Your IT team already handles network architecture, access controls, and endpoint protection. They understand Technical and Organisational Measures at the system level and know how to configure security in your electronic health record system, implement emergency access, and maintain audit logs for reviews.
This separation also prevents operational overload for clinical staff. Physicians and nurses shouldn't be configuring firewalls or reviewing threat intelligence. They need to focus on patient outcomes, not technical details. Centralizing cybersecurity expertise allows you to standardize controls, negotiate better vendor contracts, and build consistent incident response capabilities.
There's also the skills argument. Clinical staff receive minimal cybersecurity training in their education. Just as you wouldn't ask your security team to interpret pathology results, you shouldn't ask your clinical team to design defense strategies. Specialization exists for a reason.
The Case for Embedding Cybersecurity in Clinical Workflows
However, the IT-centric model has limitations. Medical records can sell for up to US$250 per record on the dark web. This isn't because attackers value medical data abstractly, but because these records contain immutable identifiers. As one expert noted in the Partnered Health case, "It's pretty hard to change your medical history once it's bolted out the door."
When clinical staff don't view cybersecurity as part of patient care, they make risky decisions. They might share credentials to speed up handoffs, access records from unsecured networks, or click phishing links because they're trained to respond quickly to urgent messages.
In 2019, the Victorian auditor general accessed sensitive patient data at three hospitals using basic hacking tools. The vulnerability wasn't sophisticated; it was due to fundamental hygiene failures because cybersecurity was separate from patient care.
If you treat data protection as a clinical responsibility, you change the approach. Physicians already follow protocols to prevent infections and dosing errors. These aren't IT functions; they're embedded in care standards because patient safety depends on them.
The same logic applies to data protection. When you access a patient record, you're handling Protected Health Information that could disrupt lives if exposed. That's not just an IT problem; it's a care delivery issue.
Where Practitioners Actually Land
Most healthcare DPOs I've spoken with don't choose one model exclusively. They build hybrid structures where IT owns the infrastructure layer, while clinical leadership owns the behavioral layer.
In practice, this means your IT team configures access controls and monitors data exports. Meanwhile, your clinical operations team trains staff to recognize social engineering, enforces clean desk policies, and incorporates data handling into quality improvement metrics.
The key is accountability. If a breach occurs because a physician clicked a phishing link, your IT team can't prevent that with better firewalls. Clinical leadership must treat that incident like a medication error: with root cause analysis, corrective action, and integration into ongoing training.
Some organizations formalize this with a Clinical Information Governance Committee that includes both IT security and clinical leadership. They review high-risk activities, assess new diagnostic tools for data exposure, and make joint decisions about third-party data sharing.
Our Take
Cybersecurity belongs in both IT and clinical operations, but clinical integration is often underestimated. Your firewall configuration is important, but breaches like the Partnered Health and 2022 Medibank incidents didn't occur due to a lack of technical controls. They happened because data protection wasn't treated as a patient safety issue.
Here's what that means operationally: include data handling in your clinical competency assessments. When onboarding new staff, don't just provide HIPAA training modules. Embed data protection scenarios into clinical simulations. Make it as routine as hand hygiene.
Build your breach response plan with clinical workflows in mind. When unauthorized access is discovered, your notification to the supervisory authority under the 72-hour requirement should include clinical leadership. They need to assess patient safety implications, not just regulatory exposure.
Stop treating cybersecurity budgets as an IT line item. If you're investing in diagnostic equipment to improve patient outcomes, allocate funds proportionally to protect the data those machines generate. Medical information remains sensitive, whether digital or on paper.
The injunction Partnered Health obtained might prevent publication on clearnet sites, but it won't stop dark web sales. Once data is gone, legal remedies can't restore it. Your only defense is preventing breaches, and that requires everyone handling patient data to see protection as their responsibility.



