It's not just about the lack of security.

This too

"Patients control access to the record, so they can switch off their entire record and make it only available using a pin code, or use that process with individual documents," Dr Hambleton said.

Patients can get an SMS or email anytime someone new accesses their record — but it is up to individuals to set up those privacy and access settings.

Robert Merkel, a software engineering lecturer at Monash University, said he was worried the safeguards were not in place by default.

"I am concerned that most people simply aren't going to be aware of those privacy controls," Dr Merkel said.
Because the they didn't have many people sign up for this, they are going to blanket sign up everyone and have those that wish to opt out do so. Absolutely backwards way of doing this.