Healthcare organisations in Australia spent 2024 managing the highest cyber breach rate of any sector – 102 incidents in the second half alone, at an average cost of $10.93 million each.
Most businesses tend to focus cybersecurity efforts internally: endpoint security, staff training and access management. All necessary measures, but they share a common limitation: they only protect data once it’s inside your organisation.
But in healthcare, the majority of sensitive data you deal with is patient information that comes from external referrers. Typically, those referrers will send referrals to you based on what technology they have, what their platforms will allow and what they can afford.
If you’re receiving referrals through multiple channels – healthcare secure messaging, email, fax and file transfers – you’re managing security across pathways you didn’t select and can’t directly control. But you’re still liable for protecting the data.
Why do referrals fragment?
Consider what arrives when a comprehensive referral comes through – it’s not just clinical notes. Often, there’s diagnostic imaging files that exceed 50MB, video assessments, case histories spanning months of treatment and pathology reports. Each component carries different technical requirements and file sizes.
Healthcare secure messaging platforms handle this complexity through pricing and technical constraints.
Some charge per-page, making comprehensive transmission expensive – a 40-page case history carries 40 times the cost of a two-page referral. On others, file size restrictions can block large imaging transfers entirely. Video content is often shared via a separate file transfer service.
Let’s say you receive 400 referrals every month from 60 different external providers. Managing 24,000 patient data transmissions every year through multiple channels is resource-heavy and opens up dangerous security gaps. This isn’t a handful of isolated instances where someone chose email over healthcare secure messaging; it’s systematic fragmentation playing out thousands of times across your referral network. Your support staff waste hours tracking down missing information across disconnected systems while your clinical staff treat patients from incomplete records.
Compliance issues compound
The operational burden is one consequence. The regulatory exposure is another.
Demonstrating appropriate security controls becomes difficult if referral records sit across disconnected platforms: the referring practice’s secure messaging logs, their email server, your fax records and random file transfer services. You may find yourself piecing together an audit trail retrospectively, months after the data arrived, from fragmented paper and online systems that don’t communicate with one another.
The shifting regulatory landscape
These challenges come amid increased cybersecurity scrutiny of larger businesses in Australia. Following a series of high-profile breaches – Medibank’s compromise of 9.7 million records, MediSecure’s 2024 ransomware incident – Privacy Act reforms have established penalties of up to $50 million or 30% of adjusted turnover for serious interference, alongside expanded Office of the Australian Information Commissioner (OAIC) investigatory powers.
Recent enforcement actions, such as the OAIC’s recent $5.8 million penalty against Australian Clinical Labs for inadequate cybersecurity investment, signal that regulators are assessing organisational approaches to security controls, not simply breach outcomes.
So, while you can’t control external referrers’ technology choices, you are expected to minimise security risk. Accepting referrals through multiple fragmented channels increasingly leaves you exposed.
Healthcare secure messaging: what to look for
The solution isn’t to mandate what channels external providers use – that’s neither practical nor within your control. Instead, invest in a healthcare secure messaging platform that eliminates the technical and financial barriers causing fragmentation.
This is where payload-agnostic capability becomes important. With a platform like ReferralNet, you can send any file type – DICOM imaging, multi-month case histories etc – for the same cost. Whether you send one page or thirty, it is charged as a single document. This eliminates the economic pressure pushing referrers towards insecure alternatives.
But capability and pricing mean nothing if referring providers can’t connect to your secure platform. When technical compatibility creates friction – for example, systems that can’t communicate, file formats that won’t translate or integration that requires manual workarounds – providers will default to email because they know it works.
Standards compliance solves this.
Platforms built to observe Clinical Document Architecture (CDA), Health Level 7 (HL7) and Fast Healthcare Interoperability Resources (FHIR) standards ensure referring providers’ disparate systems can connect with yours. Here’s a quick run down:
- CDA preserves document format and meaning across different platforms
- HL7 enables real-time messaging between incompatible systems
- FHIR allows clinical information to move between modern applications without corruption.
When your healthcare secure messaging system is compliant with these three standards, a GP practice using one messaging system can send referrals seamlessly to your system, even if it’s on a different platform.
In Australia, only three providers are currently compliant across these three standards. ReferralNet is one of them and we also offer payload-agnostic capability and onshore data storage.
Multi-channel referral pathways aren’t an operational inconvenience you can manage around. They’re a compliance exposure that grows more expensive as wasted admin time stacks up, the number of cyber breaches rise and regulatory penalties escalate. The infrastructure choice you make either consolidates that risk or compounds it. Join them today – find the right plan for you.

