Medibank Private Limited (MPL) Earnings Call Transcript & Summary
October 25, 2022
Earnings Call Speaker Segments
David Koczkar
executiveGood morning all, and thank you for joining us at such short notice. I'll begin by acknowledging the traditional owners and custodians of country throughout Australia and their connections to land, sea and community. I join you today from Naarm, the home of the Wurundjeri Woiwurrung Peoples. I pay my respects to their elders past, present and emerging, and I extend my respect to all elders of the lands on which we work and live. I'm joined today by Medibank's executive team, including our Group Executive of Technology and Operations, John Goodall and our Group Executive CFO and Group Strategy, Mark Rogers. As you know, on Friday, we entered a voluntary trading suspension as we continued to investigate the impact and implications of the cybercrime announced on 13 October. This morning, we provided an update to our investigation, and I will take a few moments to run through what we've now learned through our investigation and what we are doing in response, before Mark provides an update of how this will impact our FY '23 outlook. Since yesterday's announcement, our investigation has now established the criminal had access to all ahm customers' personal data and significant amounts of health claims data, all international student customers' personal data and significant amounts of health claims data, all Medibank customers' personal data and significant amounts of health claims data. As previously advised, we have evidence that the criminal has removed some of our customers personal and health claims data, and it is now likely that the criminal has stolen further personal and health claims data. As a result, we expect that the number of affected customers could grow substantially. Again, I apologize unreservedly to our customers. This is a terrible crime. This is a crime designed to cause maximum harm to the most vulnerable members of our community. Our priority is to continue working to understand the specific data that has been taken for each of our customers so that we can contact them directly to let them know. Yesterday, we announced a comprehensive customer support package for affected customers. Given that the stress this crime is causing our customers, we will also defer premium increases for Medibank and ahm customers until 16 January 2023. The investigation into the cybercrime event is continuing, with particular focus on identifying which systems and networks were accessed and what data was removed by the criminal. The cybercrime event is subject to a criminal investigation by the Australian Federal Police. Medibank continues to work with specialized cybersecurity firms, the Australian Cyber Security Centre and government stakeholders. I'll now pass to Mark to provide you a business operations update and a first quarter trading performance update and changes to our FY '23 outlook, Mark?
Mark Rogers
executiveThanks, David. Normal business operations have been maintained with customers continuing to access health services. Given the uncertainty around this cybercrime incident, we're providing a trading update for the first quarter of FY '23 and updating our FY '23 outlook. Net resident policyholder growth for the first quarter was 14,600. On a rolling 12-month basis, this equates to growth of 3.2%, which is above the previously announced FY '23 outlook of approximately 2.7%. Given the uncertain impact of the cyber event, today, we've withdrawn our FY '23 outlook for policyholder growth and we'll provide a further update at the half year '23 results. Underlying net claims expense per resident policy unit continues to track below the FY '23 outlook of 2.3%. This has resulted in further permanent net claim savings due to COVID of approximately $62 million, and these savings will offset the cost of the deferral of premium increases for Medibank and ahm customers to 16 January 2023. PHI management expense productivity initiatives remain in line with the FY '23 outlook and our expectation for inflation remains unchanged. Importantly, our business remains strongly capitalized. And at 30 September 2022, our health insurance capital ratio was 13.4% and unallocated capital was approximately $150 million. APRA has released the final private health insurance capital standards, which were effective from 1 July 2023. And we continue to expect the implementation of these standards will not negatively impact our capital position. Based on our current actions in response to the cybercrime event, noting that Medibank does not have cyber insurance, we currently estimate $25 million to $35 million of pre-tax nonrecurring costs will impact earnings in 1H '23. These nonrecurring costs do not include further potential customer and other remediation, regulatory or litigation-related costs. The cybercrime event continues to evolve. And at this stage, we are unable to predict with any certainty the impact of any future events on Medibank, including the quantum of any potential customer and other remediation, regulatory or litigation-related costs. We will provide further updates as appropriate, including at the AGM. And I'll now hand the call back to David.
David Koczkar
executiveThanks, Mark. Now I'll just hand over the call for any questions you may have. Thank you.
Operator
operator[Operator Instructions] Your first question comes from Andrew Buncombe with Macquarie.
Andrew Buncombe
analystMaybe just a quick one for my clarification. I understand that you say in the release that your systems have not been encrypted by ransomware. Maybe if I can ask it a little bit differently, please. Has Medibank been asked to pay a ransom?
David Koczkar
executiveThanks, Andrew, for the question. Given the sensitive nature of this event, I can't go into any detail. I won't comment on this. This is subject to a criminal investigation.
Andrew Buncombe
analystThat's all right. And then my second question was just in relation to the $25 million to $35 million charge. Is that going to be removed from underlying NPAT? Or how should we think about that potentially impacting the dividend?
Mark Rogers
executiveSo Andrew, we haven't made a decision on how we actually report that number within the financials other than to say we'll be fully transparent on the cost at the half year results. It's too early also for us to actually determine how we'll strike the first half and the second half dividend. That will really depend on the underlying business momentum and the level of unallocated capital at the time.
Operator
operatorYour next question comes from Matt Dunger with Bank of America.
Matthew Dunger
analystJust if we can go back onto the $25 million to $35 million of cost. Can you talk to us about what that includes and what the composition of that cost is? And also you're saying [indiscernible] in the first half of '23. Do you expect to end all of the $25 million to $35 million in first half of '23 as well?
Mark Rogers
executiveThanks, Matt. So there are -- in broad terms, there are 3 buckets that comprise the $25 million to $35 million of costs. So firstly, there's a customer communication and customer service costs. So contacting our customers and providing support when they call into us. So obviously, there will be a significant additional load in our contact centers as a consequence of this event. The second cost bucket includes 2 components. Firstly, it's the experts we are [ boarding ] to support us thus far on this incident and those that will support us between now and the end of the first half as we look to recover from this incident, and that includes additional technology costs and investment as we look to strengthen our environment. And the third and most significant cost is actually to protect our customers' identities. And so we've made a significant provision in those numbers for ID monitoring and ID replacement costs. And that third bucket is the largest of the 3 buckets, Matt. In terms of whether it's a provision or actual cash cost, I'd expect the vast majority of those costs will actually be spent in the first half.
Matthew Dunger
analystAnd if I could just ask a follow-up on how many customers you expect might take up the hardship that you've offered?
David Koczkar
executiveI won't give out specific numbers because there's a number of different packages, Matt, so it will get complicated. But in sizing that, there are a number of other recent examples and a number of service providers we work with that provide these services to customers in other incidents, and they have provided what the range of take-up rates have been historically. So we've relied on the service providers and their experience to guide us on each of the individual take-up rates. But of course, there will be -- every incident will be different. So there is some volatility in those numbers, and that's why we provided a range.
Operator
operatorYour next question comes from Andrew Goodsall with MST Marquee.
Andrew Goodsall
analystJust in terms of the work that you're doing, I guess, on your systems at the moment, would that ultimately provide a longer-term or more permanent fix? Or is that a different level of expense that you might incur in the future?
David Koczkar
executiveI might just get -- thanks, Andrew. I might get John to talk about the systems, and then Mark to pick up the comment about how we're thinking about costs.
John Goodall
executiveYes, Andrew, it's John. I think definitely some of the tools we've deployed forensically right now will likely -- we'll retain, but some we won't. So I think part of the analysis we're doing and probably the longer-term planning is which we'll keep and which will let go. Mark?
Mark Rogers
executiveYes, then on the cost side -- Andrew, so let's be clear, we're not talking about changing our IT infrastructure, we're not talking about replacing customers or other software systems, what we're talking about is whether there's incremental investment on IT security. So I think it's important in that context. We're not talking about infrastructure or systems replacements.
Andrew Goodsall
analystAll right. So I mean that -- I presume that's sort of something that rolls off the back of this, but there's not -- what you're saying it's not a major change or cost coming forward -- going forward?
David Koczkar
executiveWell, I think I'd just say that we have launched a full investigation into this event, and it's too early to really be definitive. And obviously, we'll share what we know when we know it.
Andrew Goodsall
analystGot it. And a quick one. Just -- and I guess this is probably a difficult question, but just your sense of containment, how they sort of comes to a close in a sense for you or just is it a long drag? Just anything you could -- color you could add on your thought -- your thinking around that. .
David Koczkar
executiveWell, I think the first aspect which has not changed since we spoke last Monday is the containment of the ransomware or encryption of our systems, and John can talk about that. Our priority now is to safeguard our customers and their data given we now know that data has been stolen. And this is a deliberate malicious attack on our customers and some of the most vulnerable members of our community. So we will continue to work with government, with our cybersecurity experts, with the AFP and ACSC as this unfolds. Maybe, John, you could address the point on the encryption and ransomware.
John Goodall
executiveYes. So I'll call out a couple of things. We've engaged the real best technology experts in the field, and that's people called CrowdStrike, Microsoft Threat Intelligence and the ACSC, and we're absolutely following their advice on how we manage and recover from this. And it's worth calling, CrowdStrike and Microsoft provide global services responding to these exact types of incidents. And they've been the guys who've deployed specialized forensic tools to assist with our investigation, to contain the threat, to strengthen our network and enable additional ongoing real-time monitoring. So we're absolutely following their advice.
Operator
operatorYour next question comes from Elizabeth Miliatis with Jarden.
Elizabeth Miliatis
analystThe first one is just a clarification on the wording in your release. There's a comment on the first page, where you've noted that data was initially taken but then the criminal had stolen further data. Just wanted to confirm whether the criminal continue to have access to any of your systems subsequent to your initial discovery of the attack? Or was it sort of a multi-day period once you had found them out? Or did you manage to sort of kick them out of your systems and contain that?
David Koczkar
executiveYes. Thanks for the question, Elizabeth. So we -- our systems discovered unusual activity now 2 weeks ago. And our -- when we were able to update you all last Monday, we were -- we said that we had contained the ransomware threat, which is what John has gone into around encryption of systems and ability to support customers in our ongoing operations. At that time, we had no evidence that customer data had been removed from our business. It was only subsequent to that on the following Wednesday, so now 1 week ago, that the criminal contacted us and sent a sample file. Then over the last few days, we received subsequent sample files from the criminal. And that's why as we learn and understand those files and conduct our investigation, we provide further updates. I think I've committed -- and we've committed all throughout that as soon as things become clear to us, we'll make it clear to our stakeholders and these updates are a point in time.
Elizabeth Miliatis
analystOkay. Got it. And then just a second question, going back to the costs that you'll incur, the $25 million to $35 million. You noted that a portion of that within the IT spend will sort of likely continue as its extra monitoring that you've implemented. Are you able to quantify that number on a sort of longer-term basis?
Mark Rogers
executiveIt's still a little early to say how much that will be. But if I can just dimensionalize the cost bucket, that is one of the smaller cost buckets of technology spend, it's one of the smaller cost buckets. So even if all the costs we're expecting to incur in this period continued, that wouldn't be material in the context of our total management expenses.
Elizabeth Miliatis
analystOkay. Are you -- just one final question on those costs. Are you able to sort of break down the $25 million to $35 million broadly across those 3 buckets that you alluded to earlier?
Mark Rogers
executiveYes, the third bucket, which is the ID protection is the majority of the cost. And then the other 2 buckets, they're broadly equal across the balance of the 50%.
Operator
operatorYour next question comes from Siddharth Parameswaran with JPMorgan.
Siddharth Parameswaran
analystJust 2 questions, if I can. I just want to clarify just, David, your response to the question from Elizabeth just around the continuation of whether the hacker is still in your system. You provided an update saying that you've had more details provided by the hacker on the data they have, but just are you clear that they're not in your system still? Or could they still be there?
David Koczkar
executiveYes. So I'll just hand over to John. But the evolving nature of our communications really is, as we understand the data that has been removed. So that's why that keeps evolving, and I explained that we received one piece of evidence from the criminal last Wednesday, and another set of sample files over the last few days, which has given rise to these announcements. But John, that's the first part of the question.
John Goodall
executiveYes, I'll go back to what I said before, the tools we've deployed basically are set up to prevent that -- prevent entry into the system, to prevent malicious activity on the system. And all the feedback we're getting from the eyes on glass, if you like, that are monitoring the system telling us that the hacker is not in our network.
Siddharth Parameswaran
analystBut I just want to clarify because, a week ago, you said that you were assured that they could only access ahm, an international students data. And just the fact that we now understand that they seem to access all policy data or potentially all data, have you worked out why there is a difference? Have you at least closed the gap there?
David Koczkar
executiveSo we said last week that -- in fact, in the days after we first detected the unusual activity. The unusual activity was located in the infrastructure, is what we knew, that supported the ahm international students customer management system. That's why we actually brought that system down and rebuilt that system on new infrastructure in the first, I think, 2 days of this event. At the time of last Monday, when we talked to you last, Sid, we had no evidence that any data had been removed from our environment. It was only after that on the following Wednesday morning, so a week ago, that we received communication from the criminal and a sample file that we then analyzed and understood that had come -- was forced data from ahm customers.
Siddharth Parameswaran
analystOkay. So I mean really what I'm just trying to understand is whether you have your hands around where the breach was and whether you've closed it? Or is it just you're monitoring to see whether there is no more data going out? I'm just trying to understand whether you've understood where the breach was or whether you're not clear on that.
John Goodall
executiveYes. Look, I think what I can say -- and again, it's an ongoing forensic analysis. Everywhere we've identified a breach, it's not paused. Everywhere we've identified entry, they're closed. So the nature of the ongoing investigation is that we discover new things there. But these are all historical events that we're talking about here. And yes, everywhere that forensics has identified, we've addressed.
Siddharth Parameswaran
analystOkay. And just personal data, does it mean credit card data?
David Koczkar
executiveSo the personal data is name, address -- we've shared this before, name address and Medicaid numbers, in some instances, date of birth, gender. And health claims data is just that, it is the claim. It has a diagnostic code and a procedure code in some instances. We have no evidence that credit card data has been removed. But I will be very clear to say we are continuing to investigate. And as soon as it becomes clear to us if that changes, we will make it clear.
Operator
operatorYour next question comes from Vanessa Thomson with Jefferies.
Vanessa Thomson
analystWe see that Energy Australia is imposing 12 character passwords on their people. Is that something that your members are likely to be dealing with going forward?
John Goodall
executiveI don't think we've decided -- I think we will come up with a lot of actions out of this to strengthen the perimeter. And certainly, password effectiveness will be one of them. But I don't think we've made that call right here.
Vanessa Thomson
analystAnd then just one last question. On -- I think back to the NRIs again, the upper end of the range at $35 million. But you've also flagged that the numbers affected customers is likely to increase. Are we likely to see that range extend to [indiscernible]?
Mark Rogers
executivePart of the reason we provided a range is given the uncertainty on how many customers will be ultimately affected at the end state. I'd say probably in the second half of '23, the biggest point of contention is what is the regulatory litigation or other customer remediation costs. I think they are completely separate in a slightly different time frame than dealing and containing the current incident. And far to really just speculate on what those costs may be, what -- how much they may be and whether any of those costs would be covered by insurance.
Operator
operatorYour next question comes from Sean Laaman with Morgan Stanley.
Sean Laaman
analystCertainly not an IT person. But just to clarify the comments earlier, you've identified where the breaches have occurred. But do you know yet how the breaches have occurred?
David Koczkar
executiveThanks, Sean, for your question. I'll hand over to John.
John Goodall
executiveYes. Look, I think that's part of the ongoing investigation. And I think that's absolutely -- where we want to get to is not just closing the door temporarily, but making sure that we've got permanent solutions in place across all parts of our network. So that is absolutely part of the ongoing investigation.
David Koczkar
executiveI'll just add, Sean, I've been in contact with a significant number of other companies. And as I said before, we're working hand-in-hand with government entities. And I've been clear all along that we'll share -- obviously, have some learnings here, and John has talked about what we'll do with them. I think we'll also share what we can with other companies across Australia and other institutions. Cybercrime is an ever-present threat and we need to do what we can as a community to protect ourselves and the data of our citizens.
Sean Laaman
analystSure. Just a couple of more follow-ups. You mentioned that you don't have cyber insurance. I imagine premiums have gone up a touch, but [indiscernible] that up in the future?
David Koczkar
executiveSo maybe why we didn't take up cyber insurance, basically 3 components, Sean. It's cost, which costs went up significantly over the last couple of years. It's coverage, so how much cover you can actually get in terms of the total amount of exposure plus the risk share. And probably more importantly is the actually ability to make a claim. So notwithstanding the fact we didn't have cyber insurance, I wouldn't have expected had we -- based on the policies we saw over the last couple of years, that the majority of costs that we're currently calling out in the $25 million to $35 million would have even been covered.
Sean Laaman
analystSure. Got it. And one last one, if I may. The outreach program, I guess, to members. What's the -- and thank you for giving us some policyholder guide growth at the end of September, but what's your feeling or early sense on what member attrition that could be as a result of this incident?
Mark Rogers
executiveWell, I think it's far too early to be able to speculate on lapse. Because ultimately, the -- we may not know that a customer is actually leaving us until their new fund provides a transfer certificate. The best lead indicator I have a sentiment is the acquisition numbers we had last week. Which notwithstanding what's happened over the last 1.5 weeks, the acquisition numbers were still pretty strong last week. But there's a lot to play out here. We're not calling it yet. There's still -- obviously, there is lapse risk. There's still risk to acquisition in the coming months, and that's why we've actually pulled our policyholder outlook in the short term. We'll provide an update at the half year results.
David Koczkar
executiveSorry, just to add, to build on that, what Mark said. Again, what our customers, what we are is our #1 priority here is to safeguard them, their welfare and their data, do everything we can to work with the government and with our experts to do that. So that's really our main focus right now, and that's what we're assuring our customers.
Operator
operatorYour next question comes from Nigel Pittaway with Citi.
Nigel Pittaway
analystJust first of all, I'm sorry if I've missed this, but can I just be clear, the amount of the cost of the premium deferral? Is that the $62 million? Or is it less than the $62 million?
Mark Rogers
executiveYes. So permanent claim savings we've had year-to-date to September was $62 million, and the cost of the premium increase deferral is within plus or minus $1 million to $2 million of that. So Nigel, there will be no net impact to our P&L in the first half as a consequence of the premium increase deferral.
Nigel Pittaway
analystOkay. And then maybe a sort of bigger picture question. I mean, David, you've obviously sort of always sort of focused on the customer. Customer initiatives have been core to the strategy. You've obviously championed high levels of advocacy, et cetera. So I was just sort of interested, obviously with what's happened, how are you thinking about those initiatives moving forward? And maybe you could also sort of include any comments on things such as advertising. Is your tendency to want to go harder? Or do you sort of withdraw and go quiet for a while? I mean how are you thinking about the way you sort of modify your strategy on the back of what's happened?
David Koczkar
executiveYes. Thanks, Nigel. Look, I think it is really too early to be specific. Right now, our team's focus is absolutely, as it always has been, always will be, on what our customers need from us right now. That is to safeguard them, their welfare, to keep them informed about the information that's clear to us, and to do everything we can to inform them and ensure they're vigilant with the cybercrime. I think that is our absolute focus as this continues to unfold. And I think that is what they expect and that is what we will continue to do.
Operator
operatorThere are no further questions at this time. That does conclude our conference for today. Thank you for participating. You may now disconnect.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Medibank Private Limited transcript — plus 253,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Medibank Private Limited earnings transcripts and 253,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.