By Jason Symons, Partner, Carolyn Nguyen, Lawyer, Mitchell Riley-Meijer, Incident Response Manager and Max Feng, Lawyer
Following the Medibank data breach in October 2022, the Federal Court recently handed down its decision in McClure v Medibank[1] to address whether Medibank could claim and maintain privilege over all expert reports and communications obtained in responding to the data breach. The Court found that reports in which the legal purpose was not predominant, could not be protected by legal professional privilege.
Between August and October 2022, Medibank suffered a significant cyber incident, in which cyber criminals accessed its IT environment and stole sensitive personal and medical information affecting millions of Medibank’s customers.
Medibank engaged technical forensic experts CrowdStrike, Threat Intelligence, CyberCX, and Deloitte to assist in responding to the data breach. These engagements resulted in Medibank obtaining various reports, and communications between Medibank’s lawyers and the experts. It is important to note that these engagements occurred at different times, as Medibank was responding to the changing landscape and demands of the data breach.
Medibank sought to claim and maintain privilege over all the expert reports and communications, on the basis they were prepared for the dominate purpose of obtaining legal advice as part of the legal proceedings. The applicants contested that Medibank had waived privilege in respect of three reports prepared by Deloitte:
(together, the Deloitte Reports).
It was necessary for the Federal Court to consider on a document-by-document basis as to whether each document was subject to legal professional privilege. A key consideration for the Court was understanding the purpose in which the relevant documents were created and prepared.
The Court acknowledged that the documents were prepared with several purposes in mind, including legal, operational, regulatory and public or stakeholder relations. However, for Medibank to be successful in their claim for legal professional privilege, the relevant documents had to be created and prepared with the dominant purpose of obtaining legal advice and that this purpose would prevail over all the other purposes.
On 7 March 2025, Justice Rofe concluded that the documents prepared by CrowdStrike, Threat Intelligence, and CyberCX were subject to legal professional privilege, as Medibank was able to prove that the documents were created and prepared with the dominant purpose of obtaining legal advice.
We now turn our attention to the remaining Deloitte Reports. The Deloitte Engagement Letter was issued by its external lawyers on 15 November 2022, and included the following paragraph in the scope of work:
“In order for us to provide the legal advice and assistance to Medibank as outlined above, we require Deloitte to provide expert forensic assistance and cyber expertise to us, and we hereby retain you for this purpose.”
Despite the expressed term in the Engagement Letter, the Court found that the Deloitte Reports were not protected by legal professional privilege, as the legal purpose was not the dominant purpose. Instead, it was found that the regulatory and public or stakeholder relations prevailed over the legal purpose.
Medibank has sought leave to appeal the Court’s decision in waiving privilege over the Deloitte Reports.
The PIR Report was commissioned by Medibank shortly after the data breach to help the organisation understand what happened, how it responded, and what improvements were needed. It covered the attack timeline, the effectiveness of Medibank’s response, and strategic recommendations for cyber resilience.
The RCA Report provided a technical breakdown of how the cyber criminals infiltrated Medibank’s systems. A key finding was that the actors gained access via stolen credentials for a user account that did not have multi-factor authentication (MFA) enabled. This lapse had been flagged in prior assessments in 2020 and 2021 but was not remediated.
Both reports covered off on key aspects of the response from Medibank (and its independent response experts), including the technical and procedural steps used to contain, eradicate, and recover from the incident. Deloitte translated this technical information into business-level language for executive consumption.
The CPS 234 Report, however, was commissioned by Medibank to assess its compliance with information security obligations. This audit-style report reviewed Medibank’s security controls, governance structures, and risk management practices. It identified deficiencies, particularly in identity and access management.
Although APRA-related reports are typically regulatory in nature, Medibank again attempted to assert privilege. The Court found that the report was intended to demonstrate compliance and identify areas for improvement—not to support legal advice. Accordingly, privilege was not upheld.
This decision reaffirmed the Federal Court’s 2023 decision of Singtel Optus[2], in which it was concluded that:
“It is not sufficient to show a substantial purpose or that the privileged purpose is one of two or more purposes of equal weighting; rather it must be predominant and be the paramount or most influential purpose. The ordinary meaning of dominant purpose indicates the need for a ruling, prevailing or most influential purpose.”
This decision serves as a reminder that the pre-forensic stage of responding to a data breach is crucial. The intent and purpose of a technical report needs to be established from the outset. The role of forensic experts in cyber incident response is undoubtedly important, but the purpose of the lawyers ‘in the room’ must be paramount if the technical findings are of a confidential nature, or may potentially expose additional vulnerabilities within the organisation if made public.
In addition to the technical reports, the legal purpose will also need to be threaded into communications with the technical experts and external lawyers. If it is intended to be used to provide legal advice, every effort should be made to ensure that that the legal purpose is maintained. Otherwise, parties run the risk of waiving confidentiality and privilege if it is found that the legal purpose is not predominant.
[1] McClure v Medibank Private Limited [2025] FCA 167.
[2] Robertson v Singtel Optus Pty Ltd [2023] FCA 1392.
If you would like further information or have any queries regarding other matters, please do not hesitate to contact: