The Commonwealth Bank is under a potential data breach in which customers’ medical information is suspected of being exposed and misused.

Medical information supplied by an unknown number of customers to CommInsure was made available to other arms of the bank, according to staff who decide whether to approve or decline loan applications.

Although the issue was discovered in July, the bank had not informed its CommInsure customers about the unauthorised access of personal medical information.

Â