On 23 June 2026, Partnered Health discovered a malicious actor had been inside its systems. Patients didn’t get an SMS notification until 22 days later — by which point Medicare numbers, pathology results, consultation notes and DVA card details tied to sixteen clinics were already exposed.
The intrusion is one story.
The 22-day silence is the governance story: who owned the decision to escalate, what evidence they were waiting on, and why internal challenge wasn’t fast enough to force the call sooner.
The 30-second take
The lesson from Partnered Health isn’t that healthcare holds sensitive data — every board already knows that.
The real test is whether an organisation can trace a weak signal into its own escalation, disclosure and supplier-management paths before a regulator, customer or journalist forces the question.
The 2026 Allianz Risk Barometer, drawn from more than 3,300 risk professionals across almost 100 countries, shows why this matters well beyond one sector: cyber incidents are the top-ranked global business risk for the fifth year running, with their highest-ever score, and artificial intelligence has rocketed from #10 to #2 as adoption outpaces the controls meant to govern it. Political risk climbed to its highest-ever position at #7.
Three forces that used to sit in separate parts of the risk register are now converging inside the same operating model — and most organisations’ governance hasn’t caught up.
Two real tests of the same governance question
Partnered Health (Australia, 2026): the GP clinic operator confirmed a malicious actor accessed patient data on 23 June but didn’t notify affected patients until 22 days later. Cybersecurity experts have called the delay unacceptable, noting it gave attackers ample time to copy and distribute stolen data before patients could act.
The 2026 Allianz Risk Barometer: AI’s jump from #10 to #2 in a single year is the largest mover in the survey’s history, happening at the same time cyber risk is scoring higher than ever and geopolitical risk is rated the most plausible “black swan” scenario facing business in the next five years.
Read together, the message is blunt:
the risks most likely to test an organisation’s governance are no longer isolated.
A cyber incident, an ungoverned AI tool and a geopolitical shock can now hit the same operating model within the same reporting period — and each one tests the same underlying question: can leadership trace a decision back through ownership, evidence and challenge, fast enough to matter?
Questions to ask your organisation
- If a similar breach happened today, how many days would pass between discovery and disclosure — and who has the authority to make that call?
- Where would a cyber, AI or geopolitical shock most plausibly enter your operating model first: pricing, claims, suppliers, or customer service?
- Can you trace a recent decision back through ownership, evidence and challenge, or does the paper trail stop at “the process says…”?
- Does your monitoring surface weak signals early enough to act on them, or only after a regulator or customer already has?
- Is internal challenge visible and independent, or does it disappear once a decision has momentum?
- When did your board last stress-test a converging scenario — cyber plus AI plus geopolitical — against your actual supplier and claims exposure, rather than three separate register entries?
The Partnered Health timeline is a governance case study, not just a cybersecurity one.
Run your organisation’s escalation and evidence chain through the Innovation of Risk Reading Room before the next weak signal becomes a headline.

