Investigation to cover security safeguards, steps to avoid future incidents
Michael Webster, New Zealand’s privacy commissioner, has announced that he will be conducting an inquiry under s 17(1)(i) of the Privacy Act 2020 regarding the serious cybersecurity breach impacting Manage My Health Limited (MMH).
In a media release, Webster confirmed that the Office of the Privacy Commissioner (OPC) clearly needs to investigate the pertinent privacy issues, given the incident’s scale, the health and personal information’s sensitivity, and some systemic issues identified.
Webster explained that the inquiry will help him decide whether the proper security safeguards were implemented, why the protections were not in place if they were not, and what measures could prevent similar incidents from recurring.
The OPC noted that the privacy commissioner usually investigates privacy issues engaging the public interest through inquiries under s 17(1)(i) of the Privacy Act.
“New Zealanders rightly expect any agency collecting, holding, using or storing their sensitive health information to maintain high standards of privacy and data protection,” Webster said in the OPC’s media release.
The OPC shared that it was presently consulting with the parties involved about the draft terms of reference, as required by the applicable legislation. The OPC added that it expected to release the relevant details on 28 January 2026.
In a statement from earlier this month, the OPC announced that it learned about the cybersecurity breach of MMH’s platform on 1 January. The OPC noted that Webster would likely see the need for an investigation, depending on additional information from MMH.
The OPC’s prior statement noted that the investigation would likely consider:
The OPC emphasised that failing to take reasonable steps to avoid breaches from occurring could merit compliance action, including a direction containing measures the affected agencies should adopt to enhance their systems and processes.
In its prior statement, the OPC noted that it was supporting MMH and other relevant agencies, which were making efforts to contain and investigate the breach’s size and scope and identify and inform the impacted individuals and agencies.
The OPC expressed its expectations for MMH and other health agencies to: