Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

New Zealand Privacy Commissioner Orders Security Fixes After Manage My Health Cyberattack

New Zealand Privacy Commissioner Orders Security Fixes After Manage My Health Cyberattack

By
Key Takeaways
  • Compliance Notices Issued: New Zealand Privacy Commissioner Michael Webster has issued compliance notices to Manage My Health and Health NZ over failures to meet Rule 5 requirements of the Health Information Privacy Code at the time of the December 2025 cyberattack.
  • Seven Security Weaknesses Identified: The Commissioner identified seven areas where security protections were ineffective. Manage My Health has since improved three, covering multi-factor authentication, user access restrictions and controls against unauthorized external access.
  • Different Obligations for Each Organization: Manage My Health must address requirements under Rule 5(1)(a), concerning safeguards for health information, while Health NZ must address Rule 5(1)(b), concerning protections when information is provided to a service provider.
  • Deadlines Set for Remediation: Health NZ has until January 29, 2027, to make the required changes. Manage My Health has until August 31, 2027, to complete its requirements, some of which have already been completed.
  • Northland Patients Heavily Affected: The Commissioner said 90% of the affected patients whose data was stolen live in Northland, drawing particular attention to the impact on Māori communities.
Deep Dive

New Zealand’s Privacy Commissioner has ordered Manage My Health and Health New Zealand to strengthen their handling of patient data, nine months after a cyberattack exposed weaknesses in the systems meant to protect some of the country’s most sensitive personal information. Commissioner Michael Webster issued separate compliance notices to the two organizations on September 23, following the first phase of his investigation into the December 2025 Manage My Health cyber incident. The inquiry found that, at the time of the attack, both organizations had failed to comply with security requirements under Rule 5 of the Health Information Privacy Code.

Manage My Health’s notice concerns Rule 5(1)(a), which requires health agencies to maintain safeguards that are reasonable in the circumstances to prevent the loss, misuse or disclosure of personal information. Health NZ’s notice concerns Rule 5(1)(b), which places an obligation on health agencies to do everything reasonably within their power to prevent the unauthorized use or disclosure of health information before giving it to a service provider.

In other words, the Commissioner’s findings do not stop with the security of the company holding the data. They extend to the organization that entrusted the data to it. The notices follow the Commissioner’s Phase 1 report, published in May, into the cyber incident that struck Manage My Health in late December 2025. In developing the requirements now imposed on the organizations, Webster identified seven areas where security protections had been ineffective.

Manage My Health has since improved three of them. Those changes concern the effectiveness of multi-factor authentication controls, restrictions on users’ access to information and controls against unauthorized external access.

Health NZ has until January 29, 2027, to make the changes required by its compliance notice. Manage My Health has until August 31, 2027, to complete all of the requirements imposed on it, although the Commissioner said some have already been completed.

“New Zealanders rightly expect any agency collecting, holding, using or storing their sensitive health information to maintain high standards of privacy and data protection,” Webster said.

That expectation carries particular weight in this case. Webster said the breach affected “many people, whanau, and communities,” and singled out its impact on Māori in Northland. According to the Commissioner, 90% of the affected patients whose data was stolen live in Northland.

Health information leaves little room for complacency. A compromised password is one thing. A medical history belongs to a different order of privacy altogether, bound up with illnesses, treatments and facts about a person that may remain sensitive long after the technical weakness that exposed them has been fixed.

For Manage My Health, compliance means making or completing the privacy improvements necessary to satisfy Rule 5(1)(a). The provision requires safeguards proportionate to the circumstances surrounding the information being held. The Commissioner has now specified the actions the company must take to meet that standard.

Health NZ faces a different question. Its obligations concern what an organization must do before patient information is placed in the hands of a service provider. Rule 5(1)(b) requires a health agency to do everything reasonably within its power to prevent unauthorized use or disclosure before making that information available to another organization.

The result is a regulatory response that places responsibility on both sides of the relationship. Outsourcing the handling of information does not outsource the obligation to protect it.

“These Compliance Notices will ensure, and confirm to me, that Manage My Health and Health NZ are treating patient data securely and it will give New Zealanders assurance that we take these breaches seriously and that strengthening systems is vitally important,” Webster said.

There is a practical difference between discovering a weakness after an attack and proving that it has been properly repaired. The compliance notices are intended to close that distance. Manage My Health has already addressed some of the weaknesses identified after the incident. It must now complete the rest. Health NZ, meanwhile, must demonstrate that its own practices for protecting information entrusted to service providers meet the requirements of the Code.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong