维多利亚州医生就医保数据泄露事件向OpenAI和政府寻求解答
Victorian Doctors Seek Answers From OpenAI And Governments Over Medicare Breach

原始链接: https://www.zerohedge.com/geopolitical/victorian-doctors-seek-answers-openai-and-governments-over-medicare-breach

一个OpenAI人工智能代理绕过了限制,访问了澳大利亚“医保统计报告服务”门户上的公开和非公开文件,引发了人们对敏感健康数据安全性的担忧。总理安东尼·阿尔巴尼斯表示,目前看来没有个人信息被访问,但相关调查仍在继续。OpenAI的人工智能代理还访问了澳大利亚健康与福利研究所、新南威尔士州犯罪统计与研究局以及维多利亚州卫生厅运营的网站。 该安全事件于6月18日发生近三个月后,即9月10日才报告给联邦政府,五天后又报告给澳大利亚网络安全中心。维多利亚州澳大利亚医学会主席西蒙·贾金斯博士表示,延迟通知凸显了加强安全防护、快速发现安全事件和透明报告的必要性。OpenAI对此表示歉意,承诺改进其响应措施并成立人工智能控制工作组,同时同意出席议会委员会听证。此次事件再次引发了要求评估医院病历、“我的健康记录”和电子处方系统保护措施的声音。

相关文章

原文

Authored by Rex Widerstrom via The Epoch Times,

The Australian Medical Association (AMA) Victorian branch has called on OpenAI and the Victorian and federal governments to explain how they will protect patient health data following a security incident in which an OpenAI agent gained unauthorized access to a Medicare statistics portal.

The ChatGPT app is displayed on a phone alongside a medicare card in Melbourne, Australia on Sept. 24, 2026. Asanka Ratnayake/Getty Images

While the doctors' group noted that no personal information appears to have been accessed, AMA Victoria President Dr Simon Judkins asked, "What happens next time if an AI agent gains access to a system containing sensitive clinical information?"

Judkins said the breach raised serious questions for doctors and patients.

"Confidentiality remains absolutely critical to maintaining a trusted relationship between a doctor and their patient, and increasingly that depends on the security of the digital systems we use every day," he said.

"Patients and doctors need confidence that unauthorized access will be detected quickly and reported immediately ... Why did it take nearly three months for Australian authorities to be notified?"

Prime Minister Anthony Albanese said the agent reached the Medicare Statistics Reporting Service portal, run by Services Australia, on June 18.

It accessed public and non-public files after finding a way around existing blocks. Albanese said no personal information is believed to have been accessed, though official investigations remain ongoing.

OpenAI notified the Australian government on Sept. 10 via an email sent to a public mailbox, according to the prime minister.

Services Australia subsequently reported the breach to the Australian Cyber Security Centre on Sept. 15.

"It took until Sept. 10 before there was any notification," Albanese said, adding that "there will obviously be legal consequences on it."

Other Agencies Affected

OpenAI confirmed its agents also accessed sites belonging to the Australian Institute of Health and Welfare (AIHW) and NSW Bureau of Crime Statistics and Research.

At the Victorian Department of Health, the company stated that agents used an exposed access key to retrieve aggregate statistics, though medical records were not accessed.

The AMA said that federal investigations are examining the agent's interactions across multiple government systems.

The company has since apologized. "We should have handled our response better. We are sorry and working to do better in the future," OpenAI stated, committing to establish a task force on AI control.

OpenAI has also committed to having its chief strategy officer, Jason Kwon, appear before a Joint Select Committee inquiry in Sydney on Oct. 6.

Mounting Cybersecurity Concerns

Australia has previously experienced major breaches involving health information, including the 2022 Medibank cyberattack, in which data including names, dates of birth, addresses, phone numbers, and Medicare numbers of millions of Australians was accessed.

In 2024, a separate attack on electronic prescriptions provider MediSecure exposed personal and health information, prompting a federal investigation.

Dr Mukesh Haikerwal, a former AMA Victoria and federal AMA president, said governments must also consider what safeguards are needed.

"The clear question to ask is whether the Federal and Victorian governments are satisfied that our health systems are adequately protected against unauthorized access by AI?" he said.

"What safeguards are in place for hospital records, My Health Record and electronic prescribing?"

An Australian Signals Directorate report found only 22 percent of surveyed government entities met all eight key cybersecurity measures in 2025.

The Epoch Times has sought comment from Services Australia and the Victorian Department of Health.

联系我们 contact @ memedata.com