New Zealand's Privacy Commissioner has used compliance notices to dictate how a health agency must vet, contract with and monitor providers holding patient data. The move follows a breach affecting around 99,416 people.
Privacy Commissioner Michael Webster issued the notices to patient portal provider Manage My Health (MMH) and to Health New Zealand. Both were found to have breached rule 5 of the Health Information Privacy Code 2020, which covers the storage and security of health information.
The notices follow Phase 1 of the Commissioner's Manage My Health Inquiry, which examined the cyber attack on the MMH portal on 31 December 2025.
"New Zealanders rightly expect any agency collecting, holding, using or storing their sensitive health information to maintain high standards of privacy and data protection," said Webster. "These Compliance Notices will ensure, and confirm to me, that Manage My Health and Health NZ are treating patient data securely."
Criminal threat actors extracted information from a single module of the portal, called "My Health Documents". The compromised material amounted to 403,730 Health NZ documents and 22,609 documents uploaded by patients.
Around 91% of affected individuals were Health NZ patients in Northland. This reflected a unique arrangement under which Northland hospital discharge documents were made available to patients through the MMH portal.
According to the notices, almost 40% of people in Northland are Māori. The Commissioner found the breach was therefore likely to have had a disproportionate effect on Māori.
The MMH notice states that the hackers published at least some of the information on the dark web. "The circumstances of the breach mean the information can never be recovered," it says.
Health NZ: the outsourcing failures
The Health NZ notice (CN 02/2026a), dated 22 September 2026, finds the agency breached rule 5(1)(b). That rule requires a health agency to do everything reasonably within its power to prevent misuse of information it gives to a service provider.
The Commissioner found Health NZ did not conduct sufficient due diligence before engaging MMH. There were "serious problems" with the quality of privacy risk assessments, and the project team relied too heavily on MMH's own assessments of security and privacy.
The 2023 steering group for expanding the portal to Northland hospitals had no direct privacy or security representation. The contracts between Health NZ and MMH "were not fit for purpose and did not contain appropriate protections for patient information," the notice states.
Health NZ has since stopped providing patient information to MMH. However, it has told the Commissioner it is likely to consider other digital solutions for sharing hospital information with patients.
The notice therefore sets out how any replacement project must be run. It requires a senior-led steering group that includes privacy and technical security expertise, with privacy and security as standing agenda items.
Initial privacy assessments of providers, and a privacy impact assessment at the design stage, must be carried out independently of any provider. The privacy impact assessment must be reviewed annually once the project is live.
Each shortlisted provider must be independently assessed against the Health Information Security Framework before contract. Providers must also give a live demonstration of compliance.
Contracts must include enforceable security obligations, breach notification duties, regular assurance reporting and audit powers. Health NZ must also consult the Office of the Privacy Commissioner before implementation.
Health NZ must complete the actions by 29 January 2027 and supply its project plan by 12 February 2027.
Manage My Health: seven control failures
The MMH notice (CN 01/2026) is dated 28 August 2026. It finds the company breached rule 5(1)(a) by failing to maintain reasonable security safeguards. The Phase 1 report identified seven areas where protections were ineffective.
These were multifactor authentication, identity and access management, web security, patch and vulnerability management, system acquisition and development, logging and monitoring, and data leak prevention.
MMH has already implemented MFA, identity and access management and web security controls. The notice addresses the remaining four areas.
Logging, monitoring and data loss prevention controls must be in place by 30 November 2026. These must detect bulk data access, export activity and anomalous access patterns, and allow MMH to quantify what was accessed during an incident.
Vulnerability management and secure development standards are due by 26 February 2027. MMH must also supply a second round of penetration testing evidence by 31 August 2027.
The Commissioner noted that MMH reported 1.8 million registered users at the time of the breach. He considered there was "a real likelihood of a repeat of the breach" because the company's remediation steps had not been independently verified.
Both organisations may appeal to the Human Rights Review Tribunal within 15 working days. The Commissioner can bring enforcement proceedings if the required steps are not completed.
Phase 2 of the inquiry will examine the impacts of the breach. It is likely to cover whether patients authorised the creation of their portal accounts. It will also look at retention and deletion of information, and the quality of breach communications.
It will also consider whether notifications to the Commissioner and affected patients met Privacy Act requirements, and whether the breach disproportionately affected Northland Māori.