OpenAI’s Medicare Incident Raises Health Security Questions

An AI agent’s unauthorised access to Australian government systems, including parts of the country’s Medicare infrastructure, is raising fresh questions over how healthcare organisations can protect patient data amid the rise of increasingly autonomous AI systems.
The incident, which took place in June 2026, reportedly involved an OpenAI agent tasked with researching Australian health and medicine spending statistics.
During the process, the agent accessed public and non-public files across several government systems, including Medicare, the Australian Institute of Health and Welfare, the Victorian Department of Health and the New South Wales Bureau of Crime Statistics and Research.
OpenAI said it identified the activity in August while conducting an “extensive review” of activity by its models. Australian authorities were not informed until September 2026.
- 18 June 2026: An OpenAI AI agent gained unauthorised access to Australia’s Medicare Statistics Reporting Service portal.
- 10 September: Services Australia was first notified by OpenAI, almost three months after the incident occurred.
- 4 government websites: The AI model interacted with the Medicare portal, the Australian Institute of Health and Welfare, Victoria’s Department of Health and NSW’s Bureau of Crime Statistics and Research.
- No patient records accessed: Although the investigation is ongoing, OpenAI says its review found no evidence that patient records or personal Medicare information were accessed.
The company said its models were attempting to find answers and statistics for an internal evaluation when they took actions that had not been intended.
While OpenAI has said that no patient data was accessed, the Australian Signals Directorate is supporting an ongoing investigation into the incident.
For healthcare organisations, the episode highlights a particular challenge: AI systems are increasingly being given the ability to search, retrieve and act on information across complex digital environments, while healthcare data is among the most sensitive information held by public and private organisations.
Healthcare's expanding attack surface
The incident reportedly began with a relatively straightforward research task around Australian health statistics. However, according to Australian Prime Minister Anthony Albanese, the model continued looking for alternative routes when it encountered access restrictions.
The Prime Minister said the agent “didn't accept no for an answer” and that, in pursuing its objective, it attempted alternative ways to obtain information before gaining unauthorised access to other areas.
The model also reportedly wrote files into an internal server.
That behaviour is particularly significant for healthcare organisations adopting agentic AI. Unlike conventional software, AI agents can be designed to interpret objectives, determine their own next steps and interact with multiple systems to complete a task.
As these capabilities become embedded within electronic health records, clinical workflows, patient-facing services and administrative systems, the distinction between an AI tool that simply provides information and one that can actively take action becomes increasingly important.
For healthcare organisations adopting agentic AI, the incident highlights the importance of understanding not only what an AI system has been instructed to do, but how it behaves when carrying out that task.
“The Australian Medicare incident raises two important questions for security leaders,” says Findlay Whitelaw, Field CISO at global cybersecurity firm Exabeam. “How do we know when AI agents start operating outside their intended authority, and how quickly would we recognise it?”
She continues: “That's the challenge as organisations give AI agents greater autonomy. We cannot rely solely on what an agent has been instructed to do. We need visibility into what it actually does, particularly when its behaviour changes or it starts crossing established boundaries.”
“The delay in identifying and reporting the incident also reinforces the importance of independent monitoring and clear accountability,” Findley adds. “As agents become more capable, our ability to detect and respond to unexpected behaviour needs to keep pace.”
“We cannot rely solely on what an agent has been instructed to do. We need visibility into what it actually does. ”
What does the incident mean for healthcare?
Healthcare systems are increasingly becoming testbeds for AI, from clinical decision support and medical imaging to patient triage, drug discovery and administrative automation.
Simultaneously, healthcare organisations typically operate across large, interconnected technology estates, bringing together electronic patient records, laboratory systems, medical devices, pharmacy platforms, public health databases and third-party applications.
An autonomous system interacting with these environments therefore presents a different set of risks from a conventional chatbot.
The Australian incident also illustrates why permissions and boundaries need to be considered alongside the capabilities of AI models. An agent may be given a legitimate objective, but its interpretation of how to achieve that objective can extend beyond what its developers or users anticipated.


