NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

OpenAI Agent Hacks Australian Medicare Portal

An artificial intelligence (AI) agent developed by OpenAI gained unauthorized access to an Australian Medicare statistics reporting service portal and obtained non-public data. The same AI agent also accessed three other government systems as part of its autonomous research activities: the web portals of the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.

An AI agent is an autonomous system that uses an AI model to plan, make decisions, and execute tasks to solve complex problems in response to a prompt from a user or different AI system. In this case, the AI agent was part of an internal model used by OpenAI’s research team for conducting internet-based research into healthcare spending.

While attempting to compile health and medical statistics, the AI agent encountered certain blocks preventing access to data. While the AI agent had no authority to access non-public data, it successfully circumvented the blocks to access data in the Medicare statistics database and also wrote data to the server.

The incident occurred in June 2026; however, OpenAI learned about the issue in August, when in-depth checks of the AI agent’s activity identified actions that were not intended. According to OpenAI, no evidence was found to indicate any patient records were accessed. The data accessed was limited to aggregate health statistics and internal file names. OpenAI informed the Australian government about the incident on September 10, 2026. OpenAI is conducting an extensive review of “misaligned model activity,” and the investigation is ongoing. OpenAI said it is committed to transparency and will share what it learns as the investigation continues.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“The Medicare Statistics Reporting Portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending. No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Australia Prime Minister Anthony Albanese said. “Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable.”

OpenAI has been criticized for the delay in notifying the Australian government. The notice was only received on September 10, and then it was sent to an infrequently checked public mailbox. The Australian Signals Directorate’s Cyber Security Centre found out about the incident on September 15, 2026.

The government has launched a taskforce to conduct an immediate review into the incident to determine whether existing processes are sufficient for responding to AI-related cyber threats, and to assess cybersecurity controls on public-facing websites and apps to determine how they can be improved to counter AI-related threats.

There is growing concern among researchers and tech leaders that advances in artificial intelligence are happening too quickly, and there are insufficient guardrails in place. The AI models currently being developed have demonstrated that they are able to circumvent security measures to gain access to protected data, including exploiting system vulnerabilities to complete the assigned tasks. If a human did the same, it would be considered hacking, and that individual would likely face criminal charges. The law has yet to be tested when the actor is an autonomous AI agent, although it is unlikely that there will be any charges against OpenAI since the data access was unintentional and not malicious.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist