Health NZ given until January to overhaul third-party digital procurement processes
2 hours ago
NEWS - eHealthNews editor Rebecca McBeth

Health New Zealand | Te Whatu Ora must overhaul how it procures and manages third-party digital services before procuring any future digital solution for sharing hospital discharge information with patients.
Privacy Commissioner Michael Webster has issued both Health NZ and Manage My Health (MMH) with Compliance Notices for failing to comply with the security requirements of rule 5 of the Health Information Privacy Code.
Health NZ’s notice says it has until the end of January 2027 to implement a project plan addressing governance, privacy risk management, information security, and contracting processes in order to prevent unauthorised use or disclosure of patient health information by or through third-party service providers.
The notice follows the Privacy Commissioner's inquiry into the MMH cyber security breach on 31 December 2025 which resulted in the private health information of 99,000 New Zealanders being accessed, stolen and put up for sale. Around 91 percent of those affected were Health NZ patients in Northland.
"These Compliance Notices will ensure, and confirm to me, that Manage My Health and Health NZ are treating patient data securely and it will give New Zealanders assurance that we take these breaches seriously and that strengthening systems is vitally important," says Webster.
The Commissioner found that Health NZ did not conduct sufficient due diligence before engaging MMH and there were “serious problems with the quality of the privacy risk assessments”.
“The way in which the MMH system would manage the information provided by Health NZ was insufficiently understood by Health NZ and key technical issues were not identified,” the notice says.
“The breach of the Code was particularly serious, given the sensitivity of the affected health information and the resulting cyber security breach having impacted public trust and confidence in the health sector’s use of patient portals.”
Health NZ must consult with the OPC before any replacement project is implemented, and must review privacy impact assessments prior to any expansion of scope beyond the Northland region.
Bevan McKenzie, Health NZ chief financial officer, says the organisation is doing assurance assessments of patient portals, including MMH, and work is progressing on a third party risk management framework and an incident response guide. “Health NZ is taking a risk-based approach to this work, beginning with patient portals and building more consistent assurance processes for higher-risk third-party services across Health NZ,” he says.
“The specific arrangement under which Northland hospital discharge information was provided through Manage My Health has already ceased”.
The Commissioner's inquiry identified seven areas where MMH’s security protections were ineffective at the time of the breach.
These are; multifactor authentication (MFA), identity and access management, web security, patch and vulnerability management, system acquisition and development, logging and monitoring, and data leak prevention.
Since the incident, MMH has already addressed three of those areas, improving MFA controls, restricting user access to information and controlling unauthorised external access.
The notice gives MMH a deadline of 31 August 2027 to complete the remaining work.
Image: Privacy Commissioner Michael Webster
If you would like to provide feedback on this news story, please contact the editor Rebecca McBeth.
You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.
Read more Information Governance news
Return to eHealthNews.nz home page
|