Blog

Manage My Health, Health NZ issued compliance notices

New Zealand Privacy Commissioner Michael Webster has issued compliance notices to Health NZ and Manage My Health over security failings identified following the December 2025 Manage My Health cyber attack.

The notices relate to failures to comply with security requirements under rule 5 of the Health Information Privacy Code at the time of the attack.

Health NZ has until January 29, 2027 to make the required changes, while Manage My Health has until August 31, 2027 to complete all requirements in its notice. Some of Manage My Health’s requirements have already been completed.

The notices follow the Privacy Commissioner’s Phase 1 report into the incident, released in May. The Commissioner identified seven areas where security protections had been ineffective.

Manage My Health has since made improvements in three areas, covering the effectiveness of multi-factor authentication controls, restricting user access to information and controlling unauthorised external access.

Privacy Commissioner Michael Webster said New Zealanders expected organisations holding sensitive health information to maintain high standards of privacy and data protection.

“Health information by its nature is sensitive personal information and this breach affected many people, whānau, and communities,” Mr Webster said.

“I am thinking particularly of Māori in Northland, where 90 percent of the affected patients live whose data was stolen.”

Mr Webster said the compliance notices would provide assurance that Manage My Health and Health NZ were strengthening their systems and treating patient data securely.

The Manage My Health notice requires the company to make or complete privacy improvements to comply with rule 5(1)(a) of the Health Information Privacy Code.

The rule requires health agencies to have safeguards that are reasonable in the circumstances to prevent the loss, misuse or disclosure of personal information.

Health NZ’s notice relates to rule 5(1)(b), which requires a health agency to do everything reasonably in its power to prevent the unauthorised use or disclosure of health information before providing that information to a service provider.

The Privacy Commissioner published both compliance notices alongside the announcement.