Manage My Health, Health NZ get compliance notices for cyber attack

‘Breach affected many people, whanau, and communities’: Privacy Commissioner Michael Webster

Manage My Health, Health NZ get compliance notices for cyber attack

Michael Webster, privacy commissioner, has issued compliance notices to Manage My Health (MMH) and Health New Zealand for failing to adhere to the security requirements of r 5 of the Health Information Privacy Code 2020 during a cyber incident in late December 2025. 

“New Zealanders rightly expect any agency collecting, holding, using or storing their sensitive health information to maintain high standards of privacy and data protection,” Webster said in a media release from the Office of the Privacy Commissioner (OPC). 

The first compliance notice specifies the actions MMH should take to abide by r 5(1)(a), which requires health agencies to ensure reasonable privacy protections for preventing the loss, misuse, or disclosure of personal information. 

The first compliance notice requires MMH to complete all requirements by 31 August 2027. The OPC recognised that MMH has already fulfilled some. 

Meanwhile, the second compliance notice identifies the adjustments Health NZ should make to meet r 5(1)(b), which requires health agencies to do everything reasonably within their power to avoid unauthorised use or disclosure before giving a service provider health information. 

The second compliance notice sets the deadline for Health NZ’s required changes at 29 January 2027. 

“These Compliance Notices will ensure, and confirm to me, that Manage My Health and Health NZ are treating patient data securely and it will give New Zealanders assurance that we take these breaches seriously and that strengthening systems is vitally important,” Webster said. 

Manage My Health’s improvements thus far

When developing the requirements under the compliance notices, Webster pointed to seven areas with ineffective security protections. The OPC acknowledged that MMH has improved in these three areas since the cyber attack: 

  • ensuring effective multi-factor authentication (MFA) controls 
  • restricting user access to information 
  • controlling unauthorised external access 

“Health information by its nature is sensitive personal information and this breach affected many people, whanau, and communities,” Webster said in the OPC’s media release. “I am thinking particularly of Māori in Northland, where 90 percent of the affected patients live whose data was stolen.” 

Events following December 2025 cyber attack

On 1 January 2026, MMH notified the OPC about the December 2025 cyber incident involving the access to, the theft of, and the putting up for sale of New Zealanders’ sensitive health information. 

On 5 January 2026, Health Minister Simeon Brown announced that the Ministry of Health would lead a review, commencing by 30 January, regarding MMH’s and Health NZ’s response to the cybersecurity breach concerning patient information. 

On 21 January 2026, Webster confirmed that he would be launching an inquiry under s 17(1)(i) of the Privacy Act 2020 to look into the breach. On 27 January 2026, he published the terms of reference for his inquiry. 

On 27 May 2026, in the results of the first phase of his independent inquiry into the cyber incident, Webster found that MMH and Health NZ breached the Privacy Act. 

On 23 July 2026, the High Court of New Zealand acceded to MMH’s request for a permanent injunction over stolen patient data after previously issuing an interim injunction. 

Enjoy this story? Read the latest TMT (telecoms, media, technology) news on the main page!