INFORMATION SECURITY AND PRIVACY

At HCF, the health and safety of our members is our highest priority and we take the responsibility of protecting your personal information very seriously. 

An illustration collage of security and fraud based imagery on a dark ruby background.

Security features to your online member services

How to use multi-factor authentication

Protecting your information


Safeguarding your personal information against potential cyber security threats is our priority. That’s why we continuously invest in comprehensive cyber capabilities to protect your information. We monitor our systems for unusual activity around the clock and regularly conduct robust security testing. We’ve also implemented governance processes and controls to manage cyber risks to ensure the protection and security of personal information.

Visit the Australian Cyber Security Centre for news and alerts, and tips on how to stay safe online.

Privacy at HCF

We’re committed to protecting your privacy and managing your information in accordance with the HCF Privacy Policy, as well as our obligations under relevant state legislation dealing with privacy and health records.

A photo of a man and woman reviewing a piece of paper for suspected fraud activity.

How to practice safe digital habits

Practicing good digital habits is important to keeping you safe.

An illustration of a fraudster with an alert banner on a dark ruby background.

The importance of being alert at all times

HCF will never contact you and ask for your password or personal information without verifying your identity first.

If you’ve noticed any suspicious activity or communications from HCF, please report it immediately to our Fraud Response Team by calling us on 1800 727 721 or emailing fraudresponseteam@hcf.com.au.

Concerned about the potential misuse of your information?


You can contact IDCARE, Australia’s national identity and cybersecurity community support service if you have any concerns relating to the use of your personal information. IDCARE provides free and anonymous support, as well as information and resources on how to protect your personal information. Call 1300 432 273 or visit the IDCARE Learning Centre.

You can also refer to Scamwatch for more news, alerts and help about scams. 

The importance of fraud awareness

Health insurance fraud is wide-ranging and can include identity fraud, when someone uses your personal details without your permission to gain financial benefit. We continuously monitor member accounts for unusual activity to help protect you and your data.

How we protect your data

Multi-factor authentication is a security measure that requires 2 or more verification methods to confirm your identity when you log in to the My Membership app or online member services. It's one of the most effective ways to protect your valuable information and account from unauthorised access.

Many organisations have adopted multi-factor authentication, an essential protection measure in today’s cyber security and safety landscape. Multi-factor authentication makes it harder for cyber criminals to access your personal information by adding another layer of verification to the log in experience.

To help prevent unauthorised access to your HCF online accounts and add another layer of security to your HCF membership, we’ve added mandatory multi-factor authentication to our online log in experience.

This means you'll need to enter a one-time code when you log in to the My Membership app or online member services. This code is valid for 5 minutes before it expires. If the code expires before you use it, you'll need to request a new one from the log in screen.

If the email or mobile number linked to your policy is wrong, you can change it by contacting our team by calling 13 13 34 or by visiting a branch.

Yes, you can still use multi-factor authentication if you don’t have a smartphone or mobile device. If you don’t have a mobile device, it’s important to make sure the email linked to your policy is correct, as this is where we’ll send your one-time code. If the email is incorrect, get in touch with our team by calling 13 13 34 or by visiting a branch.

The code should arrive instantly, though there are many factors that might impact how long it takes to receive your code, like where you’re located, your mobile or service provider and your signal strength.

Yes, you can still use biometrics to log in to your membership account. Once your biometrics have been accepted, you’ll be prompted to enter a one-time code.

When you log in from a mobile device, desktop, or laptop, we’ll remember that device or browser after you successfully authenticate. The email you receive is simply a notification asking you to confirm that it was you who logged in. Once a device or browser has been recognised and trusted, future logins from that same device or browser will be smoother and more convenient, while still maintaining the security of your account.

Multi-factor authentication is a security measure that requires 2 or more verification methods to confirm your identity when you log in to the My Membership app or online member services. It's one of the most effective ways to protect your valuable information and account from unauthorised access.

Many organisations have adopted multi-factor authentication, an essential protection measure in today’s cyber security and safety landscape. Multi-factor authentication makes it harder for cyber criminals to access your personal information by adding another layer of verification to the log in experience.

To help prevent unauthorised access to your HCF online accounts and add another layer of security to your HCF membership, we’ve added mandatory multi-factor authentication to our online log in experience.

This means you'll need to enter a one-time code when you log in to the My Membership app or online member services. This code is valid for 5 minutes before it expires. If the code expires before you use it, you'll need to request a new one from the log in screen.

If the email or mobile number linked to your policy is wrong, you can change it by contacting our team by calling 13 13 34 or by visiting a branch.

Yes, you can still use multi-factor authentication if you don’t have a smartphone or mobile device. If you don’t have a mobile device, it’s important to make sure the email linked to your policy is correct, as this is where we’ll send your one-time code. If the email is incorrect, get in touch with our team by calling 13 13 34 or by visiting a branch.

The code should arrive instantly, though there are many factors that might impact how long it takes to receive your code, like where you’re located, your mobile or service provider and your signal strength.

Yes, you can still use biometrics to log in to your membership account. Once your biometrics have been accepted, you’ll be prompted to enter a one-time code.

When you log in from a mobile device, desktop, or laptop, we’ll remember that device or browser after you successfully authenticate. The email you receive is simply a notification asking you to confirm that it was you who logged in. Once a device or browser has been recognised and trusted, future logins from that same device or browser will be smoother and more convenient, while still maintaining the security of your account.