MediRemindeScript Security · Australia 2026

eScript SMS in Australia —
Scam or Legitimate?

Since eScripts replaced paper prescriptions, scammers have used the same SMS format to steal personal and financial details from Australians. The messages look identical. Here's how to tell the difference instantly — and what to do if you've already clicked.

Store your real eScripts safely in MediRemind — free on iOS and Android.

Download on the App StoreGet it on Google Play
Scan with your phone
MediRemind app showing how to safely save and organise legitimate eScript SMS messages
⚠ The MediSecure breach — why scams are now more targeted

In May 2024, MediSecure — one of Australia's two authorised eScript delivery platforms — suffered a data breach affecting approximately 12.9 million Australians. Prescription data including names, medications, and contact details was exposed. Scammers can now send fake eScript SMS messages that include your actual name and medication — making them far more convincing than generic phishing. This is not a hypothetical risk.

What is an eScript SMS?

A legitimate eScript SMS is sent automatically by your GP's prescribing software the moment they write a digital prescription. It contains a unique QR code link — you present it at any Australian pharmacy to have your medication dispensed. No paper, no printing.

These messages are sent through government-approved prescription delivery platforms: eRx (erx.com.au) and the Australian Digital Health Agency platform (scripts.digitalhealth.gov.au). Your GP's software — Best Practice, Medical Director, Cliniko, Genie, and others — connects to one of these platforms to send the token.

What a legitimate eScript SMS looks like

The format varies slightly between platforms but always follows this pattern:

Example — eRx platform (legitimate)

"Your prescription from Dr [Name] is ready. Tap the link to view your eScript token: https://erx.com.au/token/XXXXXXXX. Show this at any pharmacy."

Example — Digital Health Agency platform (legitimate)

"[Patient name], your prescription has been sent electronically. Your token: https://scripts.digitalhealth.gov.au/.... Present at pharmacy."

✓ Signs it's genuine

Arrives within hours of a GP consultation you actually attended

Link goes to erx.com.au, scripts.digitalhealth.gov.au, or your GP's known clinical software domain

Contains your name and the name of your prescribing doctor

Does NOT ask for payment, banking details, passwords, or personal ID

Does NOT tell you to download a separate app to 'unlock' or 'access' the prescription

Does NOT ask you to confirm your Medicare number, date of birth, or address to proceed

The sending number is Australian (04xx or an SMS short code registered to a health provider)

Red flags — how to spot a fake eScript SMS

⚠ Warning signs — stop before clicking if you see these

The link goes to a domain you don't recognise — anything other than erx.com.au, scripts.digitalhealth.gov.au, or your GP's known systems

The SMS asks you to enter credit card, banking, or Medicare details to 'activate' or 'receive' the script

You receive an eScript for a medication you didn't discuss with your GP

The prescription is for a controlled drug (opioids, benzodiazepines, stimulants) sent out of nowhere — real scripts for these are tightly controlled

The SMS creates urgency: 'expires in 2 hours', 'respond now', 'your prescription will be cancelled'

The sender number is international, withheld, or doesn't match any you've received from your GP clinic before

The message includes a shortened URL (bit.ly, tinyurl, etc.) rather than a full health platform domain

You're asked to pay a 'dispensing fee' via the link before collecting the medication

The message says your medication is 'on hold' or 'pending verification' and asks you to click to release it

Legitimate vs scam — side-by-side comparison

Feature✓ Legitimate eScript SMS⚠ Scam SMS
Link domainerx.com.au or scripts.digitalhealth.gov.auUnknown domain, shortened URL, or lookalike
Payment requested?Never — dispensing is handled at the pharmacy counterYes — often asks for a fee to 'release' the script
Personal info required?None — just show the QR codeAsks for Medicare number, DOB, card details
TimingSent within hours of a GP appointmentRandom — no recent GP visit
MedicationSomething you discussed with your doctorMay be random, or a controlled drug
App download required?Never — QR link opens in browserOften asks you to install an unknown app
Urgency language?No — prescriptions are valid for 12 monthsYes — 'expires soon', 'act now'
Sender numberAustralian number or known health SMS short codeInternational, withheld, or random

Store your real eScripts in MediRemind — so you always know exactly which scripts are genuine before you get to the pharmacy

Download on the App StoreGet it on Google Play
Scan with your phone

Free · Secure · Works at every chemist in Australia

Why are eScript scams so convincing in 2026?

Australia's PBS dispenses over 300 million prescriptions per year. Since the nationwide rollout of eScripts, Australians are conditioned to expect prescription SMS messages — so the message format alone triggers no suspicion. A convincing eScript SMS has dramatically higher click rates than a typical phishing message because recipients expect it.

The 2024 MediSecure breach made this significantly worse. With millions of Australians' names and medication histories now in circulation on dark web marketplaces, scammers can craft messages that include your correct name, your GP's suburb, and a medication you actually take. These are no longer generic blasts — they can be targeted.

Common scammer objectives include: harvesting Medicare numbers for medical identity fraud, redirecting to fake online pharmacies that take payment without dispensing medication, harvesting credit card details, or installing malware via a fake "eScript app" download.

What to do if you receive a suspicious eScript SMS

1
Do not click the link

If anything about the message feels off — timing, domain, urgency — don't click. A legitimate eScript will still be valid when you follow up with your GP.

2
Screenshot the message

Capture the full SMS including the sender number before you delete anything. This becomes evidence if you report it.

3
Call your GP directly to verify

Use a number you already have for the clinic — not a number in the suspicious SMS. Ask whether they sent a prescription and confirm the link domain matches what they issued.

4
Report to Scamwatch

Go to scamwatch.gov.au and submit a report. The more reports filed, the faster the ACCC can issue public warnings and work with telcos to block the sending numbers.

5
Forward the SMS to 0429 999 888

This is the ACMA's SMS scam reporting number. Forwarding the message helps authorities track and shut down scam SMS campaigns.

6
Report to the ACSC

If you believe it was targeted at you specifically (your name, your medication), report to the Australian Cyber Security Centre at cyber.gov.au/report. This is especially relevant post-MediSecure breach.

What to do if you already clicked a suspicious link

Scenario: Did not enter any information

Lower risk. Close the browser tab immediately. Run a security scan on your device. Monitor your accounts for unusual activity over the next 30 days.

Scenario: Entered your Medicare number or DOB

Contact Services Australia on 132 011 and report that your Medicare details may have been compromised. They can flag your account and monitor for fraudulent claims.

Scenario: Entered credit card or banking details

Call your bank immediately — most have 24/7 fraud lines. Ask them to freeze the card and reverse any unauthorised transactions. Change passwords on any linked accounts.

Scenario: Downloaded an app from the link

Delete the app immediately. If it requested device permissions (contacts, location, camera, microphone), factory reset is the safest option. Report to ACSC at cyber.gov.au/report.

The authorised eScript platforms in Australia

There are only a small number of government-approved platforms that can legitimately send eScript SMS messages in Australia. Any link from an eScript SMS should go to one of these domains:

erx.com.au — eRx Script Exchange — one of Australia's two main eScript networks
scripts.digitalhealth.gov.au — Australian Digital Health Agency — the government's eScript platform
fred.com.au — Fred IT Group — GP software provider that delivers eScript tokens
bestpractice.com.au — Best Practice software — eScript delivery within their clinical platform

If the link in the SMS goes anywhere other than these domains, treat it as suspicious until you have confirmed it with your GP directly.

Keep your real eScripts safe and organised in MediRemind — not in your SMS

Free to download · 30-day free trial

Scan with your phone

Frequently asked questions

Q

Are all eScript SMS messages in Australia safe?

A

No. Scammers send fake eScript SMS messages to harvest personal details or redirect users to fraudulent websites. Always verify the link goes to a recognised Australian health platform before clicking, and never enter payment details to access a prescription.

Q

What do I do if I already clicked a suspicious eScript link?

A

If you clicked but did not enter any personal information, the risk is lower. If you entered personal or financial details, contact your bank immediately, change any related passwords, and report to Scamwatch at scamwatch.gov.au and ACSC at cyber.gov.au/report.

Q

Can scammers get my medications using a fake eScript?

A

Fake eScript links cannot access real prescription tokens from the Australian health system. A genuine eScript is issued by your GP through approved clinical software — a scammer cannot create a dispensable prescription. Their goal is typically to steal your personal or financial information.

Q

How do I report an eScript scam in Australia?

A

Report to Scamwatch (scamwatch.gov.au), the ACSC (cyber.gov.au/report), and forward the suspicious SMS to 0429 999 888 (the ACMA SMS scam reporting number).

Q

What legitimate platforms send eScript SMS messages in Australia?

A

The main authorised platforms are eRx (erx.com.au) and the Australian Digital Health Agency (scripts.digitalhealth.gov.au). Any link to a different domain should be verified with your GP before clicking.

Q

Why are eScript scams so convincing?

A

Australians now expect SMS messages containing prescription links after a GP visit. After the 2024 MediSecure data breach, scammers have access to real names and medication data for millions of Australians, making fake messages highly personalised and harder to detect.

Q

What happened in the MediSecure data breach?

A

In May 2024, MediSecure — one of Australia's eScript delivery platforms — suffered a major breach affecting approximately 12.9 million Australians. Prescription records including names, medications, and contact details were exposed. Scammers can use this data to send convincing fake eScript messages that include your correct details.

Keep your real eScripts safe and organised in MediRemind — not in your SMS

Free to download · 30-day free trial

Scan with your phone
Further Reading

Related guides

Keep your real eScripts safe and organised.

Save legitimate eScript tokens as they arrive. Know exactly what you have, what's real, and what's coming up for renewal — all in one secure app.

Download on the App StoreGet it on Google Play
Scan with your phone