Compliance · · 3 min read

Privacy notices issued after Manage My Health cyber incident

New Zealand’s Privacy Commissioner has ordered Manage My Health and Health NZ to strengthen protections after a December 2025 health-data breach.

New Zealand Privacy Commissioner Michael Webster has issued formal Compliance Notices to Manage My Health and Health NZ over security failures linked to a cyber incident in late December 2025, according to reporting by Scoop.

The notices follow the first phase of the Commissioner’s investigation, published in May 2026. That report found that the organisations did not meet the security obligations required under rule 5 of the Health Information Privacy Code at the time of the incident.

The orders set out changes each organisation must make to protect health information. Manage My Health has until 31 August 2027 to complete every requirement in its notice, although some of the work has already been finished. The material supplied by the Privacy Commissioner does not give a separate completion date for Health NZ.

Seven areas of concern

In preparing the notices, the Privacy Commissioner identified seven areas in which security arrangements had not been effective. Since the incident, Manage My Health has improved three of those areas. One of the areas identified concerns the operation of multi-factor authentication, known as MFA, which adds an extra verification step when a person signs in.

The notices are intended to turn the findings from the investigation into specific obligations. They are published on the Office of the Privacy Commissioner’s website, alongside the Phase 1 Report into the cyber incident.

The first notice applies to Manage My Health. It requires the company to make or finish privacy and security improvements so it meets rule 5(1)(a) of the Health Information Privacy Code. That provision requires health agencies to maintain safeguards that are reasonable in the circumstances and designed to prevent personal information from being lost, misused or disclosed without authority.

The precise actions required of Manage My Health are listed in its Compliance Notice. The order is focused on the protections surrounding information held by the service and on correcting the weaknesses identified through the Commissioner’s inquiry.

Health NZ’s responsibilities

The second notice is directed at Health NZ and concerns rule 5(1)(b) of the Code. This provision applies when a health agency gives health information to an outside service provider.

Under the rule, the agency must take every step reasonably within its power to prevent the information from being used or disclosed without authorisation before it is provided to that service provider. Health NZ’s notice specifies the changes it must make to meet that obligation.

The separate notices reflect the different responsibilities held by the two organisations. Manage My Health’s order addresses safeguards required of the agency holding and handling personal information, while Health NZ’s order concerns the protections that must be in place before health information is shared with a provider.

Impact on patients

Webster said people should be able to expect strong privacy and data-protection practices from any organisation that collects, stores, uses or holds sensitive health information. He said the breach affected patients, families and communities, with particular concern for Māori in Northland.

The Commissioner said 90 percent of the affected patients whose data was stolen live in Northland. The location of those patients adds a significant community dimension to the incident, beyond the technical security failures identified in the investigation.

The Compliance Notices are intended to provide assurance that both organisations are addressing the weaknesses and treating patient information securely. They also give the Privacy Commissioner a formal way to require improvements rather than relying only on voluntary action.

Scoop reported that the notices and the Phase 1 Report are available through the Office of the Privacy Commissioner. The documents provide the detailed requirements for Manage My Health and Health NZ and explain the regulatory rules on which the orders are based.

privacyhealth datacybersecuritymanage my healthhealth nzdata breachnew zealand

Continue reading

Read this in another language