22 Days of Silence: The Governance Failure Inside a Data Breach

On 23 June 2026, Partnered Health discovered a malicious actor had been inside its systems. Patients didn’t get an SMS notification until 22 days later — by which point Medicare numbers, pathology results, consultation notes and DVA card details tied to sixteen clinics were already exposed.

The intrusion is one story.

The 22-day silence is the governance story: who owned the decision to escalate, what evidence they were waiting on, and why internal challenge wasn’t fast enough to force the call sooner.


The 30-second take

The lesson from Partnered Health isn’t that healthcare holds sensitive data — every board already knows that.

The real test is whether an organisation can trace a weak signal into its own escalation, disclosure and supplier-management paths before a regulator, customer or journalist forces the question.

The 2026 Allianz Risk Barometer, drawn from more than 3,300 risk professionals across almost 100 countries, shows why this matters well beyond one sector: cyber incidents are the top-ranked global business risk for the fifth year running, with their highest-ever score, and artificial intelligence has rocketed from #10 to #2 as adoption outpaces the controls meant to govern it. Political risk climbed to its highest-ever position at #7.

Three forces that used to sit in separate parts of the risk register are now converging inside the same operating model — and most organisations’ governance hasn’t caught up.


Two real tests of the same governance question

Partnered Health (Australia, 2026): the GP clinic operator confirmed a malicious actor accessed patient data on 23 June but didn’t notify affected patients until 22 days later. Cybersecurity experts have called the delay unacceptable, noting it gave attackers ample time to copy and distribute stolen data before patients could act.

The 2026 Allianz Risk Barometer: AI’s jump from #10 to #2 in a single year is the largest mover in the survey’s history, happening at the same time cyber risk is scoring higher than ever and geopolitical risk is rated the most plausible “black swan” scenario facing business in the next five years.

Read together, the message is blunt:

the risks most likely to test an organisation’s governance are no longer isolated.

A cyber incident, an ungoverned AI tool and a geopolitical shock can now hit the same operating model within the same reporting period — and each one tests the same underlying question: can leadership trace a decision back through ownership, evidence and challenge, fast enough to matter?

Questions to ask your organisation

  • If a similar breach happened today, how many days would pass between discovery and disclosure — and who has the authority to make that call?
  • Where would a cyber, AI or geopolitical shock most plausibly enter your operating model first: pricing, claims, suppliers, or customer service?
  • Can you trace a recent decision back through ownership, evidence and challenge, or does the paper trail stop at “the process says…”?
  • Does your monitoring surface weak signals early enough to act on them, or only after a regulator or customer already has?
  • Is internal challenge visible and independent, or does it disappear once a decision has momentum?
  • When did your board last stress-test a converging scenario — cyber plus AI plus geopolitical — against your actual supplier and claims exposure, rather than three separate register entries?

The Partnered Health timeline is a governance case study, not just a cybersecurity one.

Run your organisation’s escalation and evidence chain through the Innovation of Risk Reading Room before the next weak signal becomes a headline.

More from the Reading Room

APRA’s Corporate Plan Reinforces the Focus on AI Governance

The wrong response to increasing AI risk is to stop people using AI. That does not remove the risk. It often pushes AI use underground,...

Regulators continuous focus on delivering effective risk management

APRA’s licence conditions followed Deloitte findings of longstanding and pervasive non-financial risk weaknesses at Bendigo and Adelaide Bank. Bendigo Bank has announced a three-year, $70 million rectification program, while APRA retains a $50 million operational-risk capital add-on and requires independent assurance and board attestation.

The Hidden Cost of Poor Transparency in Insurance

ASIC's 2026 Report 838 shows that 31% of consumers who contacted their insurer obtained a lower renewal premium without changing cover. AFCA's complaint data adds a practical signal for boards testing car-insurance pricing and renewal transparency.

Beyond the Label: Importance of Accountability

An eight-month forensic investigation by Four Corners revealed widespread mislabelling and adulteration in food products sold in Australia, including tomato paste sourced from China’s Xinjiang region and seafood falsely promoted as Australian. In response, the ACCC launched an inquiry into misleading conduct, spotlighting the urgent need for stronger accountability and supply chain transparency to protect consumers.