Our website uses cookies so we can analyse our site usage and give you the best experience. Click "Accept" if you’re happy with this, or click "More" for information about cookies on our site, how to opt out, and how to disable cookies altogether.

We respect your Do Not Track preference.

Privacy Commissioner Michael Webster has issued both Manage My Health (MMH) and Health NZ with a Compliance Notice for failing to comply (at the time of the cyber attack in December 2025) with the security requirements of rule 5 of the Health Information Privacy Code.

Go straight to the Compliance Notices.

The Notices were issued following the Commissioner’s Phase 1 Report (May 2026) into Manage My Health’s cyber incident in late December 2025

In developing the Compliance Notice requirements, the Privacy Commissioner identified seven areas where security protections were ineffective. Since the incident, Manage My Health has improved three of those, which relate to: 

1.    the effectiveness of multi-factor authentication (MFA) controls
2.    restricting user access to information
3.    controlling unauthorised external access. 

The Compliance Notices, which are published below, set out what Manage My Health and Health NZ need to improve to comply with rule 5 of the Health Information Privacy Code. 

Health NZ have until 29 January 2027 to make the changes.

Manage My Health have until 31 August 2027 to complete all requirements in the Notice. Some have already been completed.

Mr Webster said, “New Zealanders rightly expect any agency collecting, holding, using or storing their sensitive health information to maintain high standards of privacy and data protection.

“Health information by its nature is sensitive personal information and this breach affected many people, whanau, and communities,” he said.

“I am thinking particularly of Māori in Northland, where 90 percent of the affected patients live whose data was stolen, said the Privacy Commissioner.

“These Compliance Notices will ensure, and confirm to me, that Manage My Health and Health NZ are treating patient data securely and it will give New Zealanders assurance that we take these breaches seriously and that strengthening systems is vitally important,” said Mr Webster.

The first Compliance Notice outlines that Manage My Health needs to make or complete privacy improvements to comply with rule 5(1)(a) of the Code. This rule requires health agencies to ensure there are safeguards in place that are reasonable in the circumstances to prevent loss, misuse or disclosure of personal information. The specific actions are set out in the Compliance Notice.

The second Compliance Notice outlines changes that Health NZ needs to make to comply with rule 5(1)(b) of the Health Information Privacy Code. This rule requires a health agency to do everything reasonably in its power to prevent unauthorised use or disclosure of health information before giving that information to a service provider. 

Compliance Notice documents

Read the Health NZ Compliance Notice, due on 12 February 2027 (opens to PDF, 327KB).

Read the Manage My Health Compliance Notice, due on 27 March 2027 (opens to PDF, 294KB).

Read the Phase 1 Report into the Manage My Health cyber incident.