
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>eHealthNews.nz</title>
<link>https://www.hinz.org.nz/news/default.asp</link>
<description><![CDATA[  
    #right {display: none;}
    #left {width: 100%;}
    .ViewTable1 th {
	background-color: #e61920;
	color: #fff;
	font-size: 14px !important;
	font-weight: bold;
	text-transform: none;
	border-top: transparent;
	border-bottom: transparent;
	height: 30px;
	line-height: 30px;
	padding: 5px;
}
 
 Sign up&nbsp;to our  FREE eNewsletter  to receive weekly news updates in your inbox.   SEARCH TIPS:    Filter by topic category using the dropdown list above  Go to the  SECTOR UPDATES  page to see a list of all press releases  Go to the  VIEWS &nbsp;page to see a list of links for all opinion columns published in eHealthNews  Go to the  FEATURES &nbsp;page to see a list of all articles published in eHealthNews  Enter a key word into the search box on any hinz webpage (click on search icon - find it on top right above menu bar)  Browse the latest articles on the  eHealthNews.nz  home page  ]]></description>
<lastBuildDate>Thu, 23 Jul 2026 04:06:54 GMT</lastBuildDate>
<pubDate>Thu, 16 Jul 2026 19:35:00 GMT</pubDate>
<copyright>Copyright &#xA9; 2026 Health Informatics New Zealand</copyright>
<atom:link href="https://www.hinz.org.nz/news/news_rss.asp?cat=16118" rel="self" type="application/rss+xml"></atom:link>
<item>
<title>My View - Health service implications of draft Digital Accessibility Standard</title>
<link>https://www.hinz.org.nz/news/news.asp?id=731337</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=731337</guid>
<description><![CDATA[<p><b style="font-size: 12px; color: #666666;"><i>VIEW - Chandra Harrison, Director, Access Advisors&nbsp;</i></b></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><img alt="Chandra Harrison, director, Access Advisors" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/View-Chandra-Harrison.png" style="border: 5px solid #ffffff; width: 250px; float: right; margin: 1px; height: 172px;" /><strong>A new <a href="https://www.digital.govt.nz/standards-and-guidance/nz-government-web-standards/digital-accessibility-standard/draft-das" target="_blank">Digital Accessibility Standard (DAS)</a> is intended to replace the current Web Accessibility Standard in early 2027. Released for public consultation on July 13, it will broaden the focus beyond websites to encompass all digital technology. This is a significant shift that will have implications across the health sector.&nbsp;</strong></span></span></p><p><span style="color: #666666;">For health organisations, accessibility is not simply a compliance issue, it is a patient safety, quality of care, and equity issue. Every day, patients and whānau rely on digital tools to access health information, book appointments, communicate with providers, attend virtual consultations, complete forms, and manage their wellbeing.&nbsp;<br /></span></p><p><span style="color: #666666;">If these systems are not accessible, people can be excluded from essential services.&nbsp;<br /></span></p><p><span style="color: #666666;">The broader scope the proposed DAS is designed to ensure accessibility is considered across all digital technologies, not just web. This includes patient portals, mobile applications, telehealth platforms, clinical software, self-service kiosks, online forms, digital documents, internal staff systems, and potentially connected medical devices that include digital interfaces.&nbsp;<br /></span></p><p><span style="color: #666666;">Many health providers have already invested in digital transformation programmes, but accessibility has not always been included from the beginning.&nbsp;<br /></span></p><p><span style="color: #666666;">As a result, organisations may discover barriers such as PDFs that cannot be read by screen readers, online forms that cannot be completed using a keyboard, poor colour contrast, inaccessible mobile apps, or video content without captions.&nbsp;<br /></span></p><p><span style="color: #666666;"><strong>Implications for telehealth</strong><br /></span></p><p><span style="color: #666666;">Telehealth platforms will need to be viewed not just as video conferencing tools, but as complete digital health services that must be accessible from appointment booking through to follow-up care.&nbsp;<br /></span></p><p><span style="color: #666666;">The draft Digital Accessibility Standard is likely to increase expectations that video consultations, waiting rooms, chat functions, captions, consent processes, patient forms, mobile apps, clinical documents, and post-consultation information can all be used independently by disabled people.&nbsp;<br /></span></p><p><span style="color: #666666;">For health providers, this means accessibility will need to become a core consideration when selecting, configuring, and managing telehealth solutions, helping to ensure that digital care does not unintentionally exclude patients who are blind, Deaf, neurodivergent, have low vision, use assistive technology, or have mobility, cognitive, or communication impairments.</span></p><p><span style="color: #666666;">These barriers can affect people with blindness or low vision, hearing loss, physical disabilities, learning disabilities, neurodivergence, cognitive impairments, and temporary injuries.&nbsp;<br /></span></p><p><span style="color: #666666;"><strong>Taking stock</strong><br /></span></p><p><span style="color: #666666;">Accessible digital services improve experiences for everyone, not just disabled people. The draft standard presents an opportunity for health organisations to take stock of where they are today.&nbsp;<br /></span></p><p><span style="color: #666666;">The health industry should be asking themselves:</span></p><ul><li><span style="color: #666666;">Are our websites accessible and usable?</span></li><li><span style="color: #666666;">Are our patient-facing documents available in accessible formats?<br /></span></li><li><span style="color: #666666;">Can people complete key tasks without a mouse?<br /></span></li><li><span style="color: #666666;">Do our digital procurement processes include accessibility requirements?<br /></span></li><li><span style="color: #666666;">Are accessibility checks built into our design, development, and testing processes?<br /></span></li><li><span style="color: #666666;">Can disabled patients independently access our digital services?</span></li></ul><p><span style="color: #666666;">Organisations that start addressing these questions now will be better positioned for future requirements and will deliver better outcomes for the communities they serve.<br /></span></p><p><span style="color: #666666;">If you are unsure how your organisation measures up against the proposed requirements, now is a good time to seek independent advice. Access Advisors can help health organisations assess websites, digital tools, software, documents, and procurement practices against recognised accessibility standards.&nbsp;<br /></span></p><p><span style="color: #666666;">Early assessment can identify risks, prioritise improvements, and help ensure that accessibility is embedded into future digital projects.<br /></span></p><p><span style="color: #666666;"><strong>Get involved</strong><br /></span></p><p><span style="color: #666666;">Digital accessibility is ultimately about ensuring everyone can access healthcare information and services with dignity and independence. We encourage all health organisations to review the draft Digital Accessibility Standard, provide feedback before the consultation closes, and start planning for a more accessible digital future.<br /></span></p><p><span style="color: #666666;">The consultation is open until 7 August and the Government has specifically invited views on what should be included in the new standard, making this an important opportunity for health providers, clinicians, digital teams, disability advocates, and technology vendors to share their experiences and perspectives.&nbsp;</span></p><p><span style="color: #666666;"><em>Note -&nbsp;The draft standard does not currently apply to Crown agents, but will be issued as "guidance" to Health NZ.</em></span></p><div>&nbsp;</div><p><span style="color: #666666;"></span><em style="color: #666666;">If you want to contact eHealthNews.nz regarding this View, please email the editor <a href="mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</em><span style="color: #666666;"></span></p><p>&nbsp;</p><p><span style="color: #666666;"><b>Read more <a href="https://www.hinz.org.nz/page/eHN-views" target="_blank">VIEWS</a></b></span></p><div><hr style="color: #333333;" /></div><p><strong><strong style="color: #666666;"><span style="font-size: 18px; color: #ff0000;">Return to </span></strong><strong style="color: #666666;"><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></strong></p>]]></description>
<pubDate>Thu, 16 Jul 2026 20:35:00 GMT</pubDate>
</item>
<item>
<title>Health orgs to map data collection under new health privacy rule</title>
<link>https://www.hinz.org.nz/news/news.asp?id=730150</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=730150</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS&nbsp;&nbsp;- eHealthNews editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="Privacy Commissioner Michael Webster" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/2026.06.29-Privacy-Commissi.jpeg" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" /></span></p><p><span style="color: #666666;">Health organisations should start mapping how they collect patient information indirectly now, in preparation for compliance with the new Rule 3A of the Health Information Privacy Code, says&nbsp;<span style="color: #666666;">Privacy Commissioner Michael Webster.</span><br /></span></p><p><span style="color: #666666;">Speaking at the Future of Healthcare in Aotearoa Conference on June 25, he also said health organisations need to be sure of where patient data ends up before rolling out AI tools, saying sensitive health information could be feeding into AI training models without patient knowledge and consent.<br /></span></p><p><span style="color: #666666;">Rule 3A came into force on May 1 as part of the Privacy Amendment Act and directly affects how health organisations handle information gathered from third parties, including referrals, other health agencies and external platforms.<br /></span></p><p><span style="color: #666666;">Webster talked about health organisations creating an “information map” showing how they are collecting and receiving information and the need to notify patients about it.<br /></span></p><p><span style="color: #666666;">"That might be as simple as having signage up at your business that notifies people of how information will be passed on and collected," he said.&nbsp;<br /></span></p><p><span style="color: #666666;">"Underneath that, the full description of what might happen can be found online."<br /></span></p><p><span style="color: #666666;">An exception to Rule 3A is if an organisation has reasonable grounds to believe someone else has already notified the patient but Webster said that belief needs to be backed by evidence, not assumption.<br /></span></p><p><span style="color: #666666;">When asked about AI he said the key concern is ensuring that confidential patient conversations do not end up training the large language models that underpin the tools clinicians rely on.<br /></span></p><p><span style="color: #666666;">Webster recommended organisations do a privacy impact assessment before deploying any significant new AI tool, treating it as standard due diligence to understand what the tool does and how it handles data.<br /></span></p><p><span style="color: #666666;">He noted that a cybersecurity advisory issued recently flagged increasing cyber threats driven by AI and said health organisations should start treating a data breach as an ‘when not if’ event.<br /></span></p><p><span style="color: #666666;">He spoke about four privacy law reform priorities his office is advocating for which are; the right to erasure; financial penalties for serious breaches; stronger accountability provisions requiring organisations to publicly disclose their privacy practices; and oversight requirements for automated decision-making systems</span></p><p><span style="color: #666666;">A fifth priority has come from the Managed My Health inquiry, which involves <a href="https://www.hinz.org.nz/news/news.asp?id=728199" target="_blank">extending liability for security failures</a> to third-party service providers.<br /></span></p><p><span style="color: #666666;">The Office of the Privacy Commissioner has published detailed guidance on Rule 3A, including worked examples, through its <a href="https://www.privacy.org.nz/responsibilities/poupou-matatapu-doing-privacy-well/" target="_blank">Poupou Matatapu</a> resource hub.&nbsp;</span></p><p><span style="color: #666666;"><em><span style="font-size: 12px;">Image: Privacy Commissioner Michael Webster</span></em></span></p><p><span style="color: #666666;">&nbsp;</span><em style="font-size: 12px; color: #666666;"></em></p><p><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor <a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></p><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to </span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Mon, 29 Jun 2026 01:09:00 GMT</pubDate>
</item>
<item>
<title>Third-Party providers should be held liable for data breaches - Privacy Commissioner</title>
<link>https://www.hinz.org.nz/news/news.asp?id=728199</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=728199</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS&nbsp;&nbsp;- eHealthNews editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial4/2021.05.13.privacy-image.jpg" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" /></span></p><p><span style="color: #666666;">The Office of the Privacy Commissioner (OPC) has recommended amendments to the Privacy Act that would hold third-party providers liable for security failures, even when they are collecting or storing data on behalf of another agency.&nbsp;<br /></span></p><p><span style="color: #666666;">The recommendation is part of a Phase 1 inquiry into the December 2025 Manage My Health breach, which resulted in the private health information of more than 99,000 New Zealanders being accessed, stolen and put up for sale.<br /></span></p><p><span style="color: #666666;">"Third parties are increasingly playing a key role in the sharing, processing and storage of personal data," Privacy Commissioner Michael Webster says.&nbsp;<br /></span></p><p><span style="color: #666666;">"As such they are a target for malicious actors. It is critical they too are incentivised to put in place safeguards."<br /></span></p><p><span style="color: #666666;">The report also recommends that the Ministry of Health set up a process for verifying and assuring that patient health portals such as Manage My Health meet health sector security standards.<br /></span></p><p><span style="color: #666666;">“It is not practicable for every user, such as individual GP practices, to do their own separate security testing or assurance. Instead, providers should be checked and approved at a central level,” it says.<br /></span></p><p><span style="color: #666666;">Altersec chief executive Faustin Roman says the OPC recommendation is overdue and the model already exists and works in other countries.<br /></span></p><p><span style="color: #666666;">“Europe's GDPR makes processors directly liable for security alongside the controller, and Australia is moving the same way. New Zealand is now the outlier,”&nbsp; he tells eHealthNews.<br /></span></p><p><span style="color: #666666;">“Processor liability would give OPC a direct enforcement lever it currently lacks and reduce the unrealistic due-diligence burden on small principals like GP practices.”<br /></span></p><p><span style="color: #666666;">However, he says this is not the whole answer and he was pleased to see the report also puts clear obligations on Government, the Ministry of Health and Health NZ.<br /></span></p><p><span style="color: #666666;">“Health NZ is in a unique position here: it is both a respondent in this inquiry and the sector lead through the HISF standard. It is the agency best placed, and most obligated, to drive these reforms across the sector. It should lead from the front,” Roman says.<br /></span></p><p><span style="color: #666666;">GPNZ deputy chair Justin Butcher says the OPC recommendation is a sensible and practical step.<br /></span></p><p><span style="color: #666666;">“Small businesses such as general practices should not be left relying solely on contractual remedies when IT providers fail to meet appropriate standards,” he says.<br /></span></p><p><span style="color: #666666;">An independent technical review of the MMH breach by CyberCX for the Ministry of Health recommends that Health New Zealand “comprehensively review and uplift its third party risk management practices”, saying the attack method was not technically sophisticated.<br /></span></p><p><span style="color: #666666;">The breach happened when a hacker calling themselves Kazu used compromised user credentials to exploit flaws in an application programming interface to access stored data, which included clinical notes, intimate imagery and documents such as passport scans.<br /></span></p><p><span style="color: #666666;">The review found Manage My Health was "unprepared for an incident of this nature", had "significant control failings" in its technology environment and were likely not aligned with the Health Information Security Framework requirements before the breach happened.<br /></span></p><p><span style="color: #666666;">The inquiry also found Health New Zealand failed in its responsibilities and its contract with Manage My Health was "not fit for purpose," as it was generic rather than designed to reflect how information sharing would work and what was necessary to protect it.<br /></span></p><p><span style="color: #666666;">The OPC review found GP practices were not liable for security failings that caused the breach, as they could not have prevented it and were not the source of stolen information.&nbsp;<br /></span></p><p><span style="color: #666666;">However, it sets out security safeguards it expects all GP practices to have in place when using patient portals.<br /></span></p><p><span style="color: #666666;">Damon Campbell, chief operating officer, WellSouth Primary Health Network, says third-party digital health providers such as Manage My Health need to be held to the same standards as the health agencies they serve.<br /></span></p><p><span style="color: #666666;">“The systemic lesson here is one the sector needs to take seriously: digital innovation in health is vital, but it cannot outpace the privacy and security frameworks that protect people,” he says.<br /></span></p><p><span style="color: #666666;">Phase 2 of the inquiry will focus on the impacts of the breach, including whether patients were properly asked for authorisation before accounts were established, whether they received adequate information about the portal, and whether the breach caused disproportionate impact on Northland Māori.<br /></span></p><p><span style="color: #666666;">Budget 2026 has committed more than <a href="https://www.hinz.org.nz/news/728111/Budget-2026-commits-450-million-to-digital-health.htm" target="_blank">$150 million in funding</a> for cybersecurity in health over the next four years.<br /></span></p><p><span style="color: #666666;">In his Budget statement health minister Simeon Brown said that over the next year, Health New Zealand will implement a programme to identify and manage cyber risks posed by third‑party vendors and systems, strengthen accountability for fixing security risks, introduce annual audits of critical systems, and use scalable tools, including AI-enabled assessments, to improve cyber security maturity across primary care.</span></p><p><span style="color: #666666;">&nbsp;</span></p><p><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor <a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></p><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to </span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Fri, 29 May 2026 01:16:00 GMT</pubDate>
</item>
<item>
<title>GPNZ backs stronger national assurance following Phase One MMH inquiry findings</title>
<link>https://www.hinz.org.nz/news/news.asp?id=728004</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=728004</guid>
<description><![CDATA[<p><em><span style="font-size: 12px;"><strong><span style="color: #666666;">SECTOR UPDATE - General Practice New Zealand&nbsp;</span></strong></span></em></p><p><span style="color: #666666;"><strong>General Practice New Zealand (GPNZ) welcomes the shared conclusions of three reports into the Manage My Health (MMH) privacy breach, saying the findings reinforce the need for a coordinated, system-wide approach to privacy and security across the health sector.</strong></span></p><p><span style="color: #666666;"><strong></strong></span><span style="color: #666666;">“With these recommendations in place, we expect to see rapid and meaningful system improvements that will ensure the protection of patient information, with clear standards and accountability,” says GPNZ Deputy Chair Justin Butcher.&nbsp;<br /></span></p><p><span style="color: #666666;">As the Ministry of Health report says, the experience ‘should serve as a call to action for the health sector, and New Zealand organisations more broadly, to improve cyber security controls and governance’.<br /></span></p><p><span style="color: #666666;">GPNZ endorses the Ministry’s recommendation that ‘Health NZ comprehensively review and uplift its third-party risk management practices’.<br /></span></p><p><span style="color: #666666;">“This is a clear theme across the separate reports that needs urgent action. One of the most significant recommendations of the Privacy Commissioner’s report is the call for the Ministry of Health to establish a centralised and ongoing programme to verify that key health sector vendors are meeting appropriate security standards,” says Mr Butcher.&nbsp;<br /></span></p><p><span style="color: #666666;">“A nationally coordinated assurance function will help create greater consistency, clearer accountability and stronger confidence across the system, while reducing duplication and avoiding unrealistic compliance expectations being placed on frontline providers.”<br /></span></p><p><span style="color: #666666;">GPNZ had an opportunity to provide feedback to the Office of the Privacy Commissioner during the inquiry process, and it is positive to see the final report acknowledge the practical limitations general practices face when dealing with complex security and contractual arrangements with vendors – issues the sector has raised for some time.<br /></span></p><p><span style="color: #666666;">The OPC’s recommendation to consider amendments to the Privacy Act to ensure third-party technology vendors have direct obligations for maintaining appropriate privacy and security safeguards is a sensible and practical step.<br /></span></p><p><span style="color: #666666;">“Small businesses such as general practices should not be left relying solely on contractual remedies when IT providers fail to meet appropriate standards,” says Mr Butcher.<br /></span></p><p><span style="color: #666666;">General practices already understand the obligations they have around privacy and information security, with PHOs continuing to work alongside practices to support that work.<br /></span></p><p><span style="color: #666666;">“Today’s findings reinforce the importance of regularly reviewing security settings, processes and governance arrangements, alongside stronger national assurance and better support for general practice.”<br /></span></p><p><span style="color: #666666;">GPNZ has been working alongside Health NZ to develop practical resources for the sector, including a cyber security checklist and guidance for safe information sharing practices.<br /></span></p><p><span style="color: #666666;">While the reports acknowledge the efforts of Health NZ and MMH in responding to the breach, GPNZ said there also needed to be stronger recognition of the extensive response led by PHOs and general practices across the country.<br /></span></p><p><span style="color: #666666;">“Primary care teams carried a significant operational and relationship burden throughout this incident,” says Mr Butcher.<br /></span></p><p><span style="color: #666666;">“Practices and PHOs were heavily relied on to support patients, respond to concerns, provide reassurance, gather information and help resolve issues in real time, at considerable time and cost.”<br /></span></p><p><span style="color: #666666;">“That work was critical to maintaining patient trust and supporting the overall system response, and future breach response planning needs to properly recognise and incorporate the role of primary care.”<br /></span></p><p><span style="color: #666666;">The safe sharing of health information is a vital element of modern healthcare, which, unfortunately, hackers will continue to try to exploit. The MMH breach was a wake-up call for us all, and these inquiries reinforce the additional elements we need to put in place to ensure the protection of that data.<br /></span></p><p><span style="color: #666666;">GPNZ will continue working collaboratively with the Ministry of Health, Health NZ and its members to support ongoing improvements across the sector.<br /></span></p><p><span style="color: #666666;">“This is about building a safer, more resilient and more trusted digital health system for patients and practices alike.”<br /></span></p><div>&nbsp;</div><p><span style="color: #666666;"></span><span style="font-weight: 700; font-family: Garamond; color: #666666;">Source: General Practice New Zealand&nbsp;media release</span></p><p><span style="font-size: 10.5pt; font-family: Garamond; color: #666666;">Sector updates are provided by organisations to eHealthNews.nz and have not necessarily been edited or checked for accuracy. Any queries should be directed to the organisation issuing the release.</span><br /></p><div><hr /></div><p><span style="color: #666666;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;">Do you have an item to add to sector updates?</span></b><br /></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;"><span style="color: #666666;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="color: #666666;"><span style="font-size: 12pt; font-family: Arial, sans-serif;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><span style="color: #666666;"><span style="font-size: 10.5pt; font-family: Arial, sans-serif;">Email your information to us at </span><span style="font-size: 10.5pt; font-family: Arial, sans-serif;"><a href="mailto:updates@hinz.org.nz">updates@hinz.org.nz</a></span></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: red;">Return to </span></b><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif;"><a href="http://www.ehealthnews.nz/" target="_blank">eHealthNews.nz home page</a></span></b></p>]]></description>
<pubDate>Wed, 27 May 2026 03:38:00 GMT</pubDate>
</item>
<item>
<title>Privacy Commissioner’s findings on Manage My Health breach a wake-up call to resource health IT</title>
<link>https://www.hinz.org.nz/news/news.asp?id=728003</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=728003</guid>
<description><![CDATA[<p><em><span style="font-size: 12px;"><strong><span style="color: #666666;">SECTOR UPDATE - PSA</span></strong></span></em></p><p><span style="color: #666666;"><strong>The Privacy Commissioner’s finding that Health NZ and Manage My Health had deficient security safeguards confirms what the PSA warned about in January: the health sector’s IT systems are under-resourced and vulnerable.</strong></span></p><p><span style="color: #666666;"><strong></strong></span><span style="color: #666666;">"This finding should be a wake-up call. Nearly 100,000 New Zealanders, many of them in Northland, had their most sensitive personal information stolen because security was not up to scratch," said Fleur Fitzsimons, National Secretary for the Public Service Association Te Pukenga Here Tikanga Mahi.<br /></span></p><p><span style="color: #666666;">"Tomorrow’s Budget will make scandals like this a feature of public services in New Zealand as the Government moves to dismiss thousands of public servants. We know services are already being damaged, members tell us of the mounting toll cuts have inflicted." <br /></span></p><p><span style="color: #666666;">"In January, the PSA called on the Privacy Commissioner to investigate the impact of cuts to Health NZ’s digital workforce. He declined. Since then, we have seen the Waikato payroll failure affecting 4,000 health workers, and OIA documents showing Health NZ’s own internal reports warned that cutting IT staff would increase risks to patient care and hospital resilience.<br /></span></p><p><span style="color: #666666;">"The pattern is clear. Health NZ’s digital workforce has been cut by nearly 1,000 roles. The systems these workers maintained and protected are ageing and vulnerable. IT problems are taking longer to resolve. The people who understood those old systems and their weaknesses are gone.<br /></span></p><p><span style="color: #666666;">"The Government needs to stop treating health IT as a cost to be cut and start treating it as the critical infrastructure it is. Properly resourcing digital services in the health system is not optional - it is essential to protecting patient safety and privacy.<br /></span></p><p><span style="color: #666666;">"New Zealanders whose personal health information was stolen deserve better than this.<br /></span></p><p><span style="color: #666666;">"We hope tomorrow’s Budget marks a turning point in health funding, and not more of the same - patient care must be a priority," said Fitzsimons.</span></p><div>&nbsp;</div><p><span style="color: #666666;"></span><span style="font-weight: 700; font-family: Garamond; color: #666666;">Source: PSA media release</span></p><p><span style="font-size: 10.5pt; font-family: Garamond; color: #666666;">Sector updates are provided by organisations to eHealthNews.nz and have not necessarily been edited or checked for accuracy. Any queries should be directed to the organisation issuing the release.</span><br /></p><div><hr /></div><p><span style="color: #666666;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;">Do you have an item to add to sector updates?</span></b><br /></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;"><span style="color: #666666;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="color: #666666;"><span style="font-size: 12pt; font-family: Arial, sans-serif;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><span style="color: #666666;"><span style="font-size: 10.5pt; font-family: Arial, sans-serif;">Email your information to us at </span><span style="font-size: 10.5pt; font-family: Arial, sans-serif;"><a href="mailto:updates@hinz.org.nz">updates@hinz.org.nz</a></span></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: red;">Return to </span></b><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif;"><a href="http://www.ehealthnews.nz/" target="_blank">eHealthNews.nz home page</a></span></b></p>]]></description>
<pubDate>Wed, 27 May 2026 03:36:00 GMT</pubDate>
</item>
<item>
<title>WellSouth response to Privacy Commissioner findings for MMH breach</title>
<link>https://www.hinz.org.nz/news/news.asp?id=728002</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=728002</guid>
<description><![CDATA[<p><em><span style="font-size: 12px;"><strong><span style="color: #666666;">SECTOR UPDATE - WellSouth&nbsp;</span></strong></span></em></p><p><span style="color: #666666;"><strong>Today's Privacy Commissioner findings are important. Not only was the Manage My Health breach preventable, but it found that GP practices were not the source of the breach and could not have prevented it. During the crisis response we advocated strongly for this position.</strong></span></p><p><span style="color: #666666;"><strong></strong></span><span style="color: #666666;">Nearly 100,000 New Zealanders had their sensitive health information stolen, including many hundreds of affected patients in Otago and Southland. Yet our general practices largely bore the brunt of this crisis.<br /></span></p><p><span style="color: #666666;">Everyone in the health sector has a responsibility to safeguard patient information, including general practice. However, practices trusted Manage My Health and Health New Zealand to have adequate protections in place, and that trust was misplaced. The Commissioner's recommendation that patient health portal providers be verified and approved centrally is exactly right. Practice teams should be able to focus on their core role: supporting the health and wellbeing of their patients.<br /></span></p><p><span style="color: #666666;">Third-party digital health providers such as Manage My Health need to be held to the same standards as the health agencies they serve, but Health NZ also failed to uphold security obligations under the Health Information Privacy Code.<br /></span></p><p><span style="color: #666666;">We therefore welcome the Commissioner's intention to issue formal compliance notices to both organisations. Described in the report as "the strongest tool currently available," these notices will require both parties to demonstrate that the necessary changes have been made and are working.<br /></span></p><p><span style="color: #666666;">The systemic lesson here is one the sector needs to take seriously: digital innovation in health is vital, but it cannot outpace the privacy and security frameworks that protect people.<br /></span></p><p><span style="color: #666666;">We have been closely watching this inquiry. We note that Health NZ's formal response plan will be published in July, setting out the way forward with regular reporting to the Board and relevant agencies. We will continue to track both the regulatory response and Phase 2 as they unfold.<br /></span></p><p><span style="color: #666666;"><em>Damon Campbell, Chief Operating Officer, WellSouth Primary Health Network.&nbsp;</em><br /></span></p><div>&nbsp;</div><p><span style="color: #666666;"></span><span style="font-weight: 700; font-family: Garamond; color: #666666;">Source: WellSouth media release</span></p><p><span style="font-size: 10.5pt; font-family: Garamond; color: #666666;">Sector updates are provided by organisations to eHealthNews.nz and have not necessarily been edited or checked for accuracy. Any queries should be directed to the organisation issuing the release.</span><br /></p><div><hr /></div><p><span style="color: #666666;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;">Do you have an item to add to sector updates?</span></b><br /></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;"><span style="color: #666666;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="color: #666666;"><span style="font-size: 12pt; font-family: Arial, sans-serif;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><span style="color: #666666;"><span style="font-size: 10.5pt; font-family: Arial, sans-serif;">Email your information to us at </span><span style="font-size: 10.5pt; font-family: Arial, sans-serif;"><a href="mailto:updates@hinz.org.nz">updates@hinz.org.nz</a></span></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: red;">Return to </span></b><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif;"><a href="http://www.ehealthnews.nz/" target="_blank">eHealthNews.nz home page</a></span></b></p>]]></description>
<pubDate>Wed, 27 May 2026 03:34:00 GMT</pubDate>
</item>
<item>
<title>Manage My Health and Health NZ breached Privacy Act</title>
<link>https://www.hinz.org.nz/news/news.asp?id=727999</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=727999</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS&nbsp;&nbsp;- eHealthNews editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="Privacy Commissioner Michael Webster" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/2026.05.27-Privacy_Commissio.png" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" /></span></p><p><span style="color: #666666;">The Ministry of Health and Health New Zealand are strengthening cyber security across the health system following independent reviews into the Manage My Health cyber incident, which resulted in the private health information of 99,000 New Zealanders being accessed, stolen and put up for sale.<br /></span></p><p><span style="color: #666666;">Privacy Commissioner Michael Webster has found both Manage My Health and Health NZ breached the Privacy Act by failing to maintain reasonable security safeguards to protect patient information.&nbsp;<br /></span></p><p><span style="color: #666666;">The breach occurred on 21 December 2025, when a hacker using compromised credentials exploited a vulnerability in Manage My Health's application programming interface to extract more than 400,000 patient documents.&nbsp;<br /></span></p><p><span style="color: #666666;">Webster says the theft of this highly personal information caused significant anxiety and distress for patients.<br /></span></p><p><span style="color: #666666;">More than 90 percent of those affected are in Northland, many of whom are likely to be Māori. This is because of a <a href="https://www.hinz.org.nz/news/news.asp?id=664366" target="_blank">unique arrangement between Health NZ and Manage My Health</a> involving hospital discharge information, which was not happening in other hospitals.<br /></span></p><p><span style="color: #666666;">Ministry of Health chief medical officer Joe Bourne says a Ministry review found the breach was largely preventable and identified weaknesses in technical controls, incident preparedness, and communications.<br /></span></p><p><span style="color: #666666;">"This incident has highlighted clear areas where the system needs to improve, and our focus is now on learning from it and implementing these changes at pace," he says.<br /></span></p><p><span style="color: #666666;">The Privacy Commissioner will issue compliance notices to both Manage My Health and Health NZ, which he says are the strongest tools currently available to respond to serious privacy breaches.&nbsp;<br /></span></p><p><span style="color: #666666;">"Several of Manage My Health's technical security safeguards were inadequate at the time the breach occurred," Webster says.&nbsp;<br /></span></p><p><span style="color: #666666;">"We want to independently check what has been done and that the changes provide effective protection against similar types of attacks in future."<br /></span></p><p><span style="color: #666666;">Phase 1 of the commissioner’s report found the cybersecurity breach was not the result of a single security failure but was due to a combination of problems. Manage My Health had several key gaps in security that allowed the attack to happen and failed to have systems in place that would detect large amounts of information being accessed.<br /></span></p><p><span style="color: #666666;">It says that Health NZ should have taken more steps to ensure it was safe to pass information to patients through the portal. The project team that engaged with Manage My Health did not include specialist privacy and security personnel, which was needed for a project of this type, scale and novelty.<br /></span></p><p><span style="color: #666666;">"There was over-reliance on information from Manage My Health about the security and privacy of the health portal as opposed to doing independent checks," the Privacy Commissioner's report says.<br /></span></p><p><span style="color: #666666;">Ministry of Health chief information officer Quin Carver says the Ministry and Health New Zealand are taking action, including working with Manage My Health to get independent assurance of post-incident security improvements and strengthening expectations for suppliers holding sensitive health information.<br /></span></p><p><span style="color: #666666;">The Ministry is reviewing how the Health Information Security Framework is applied and monitored in practice and establishing clearer roles and processes for patient notification during cyber incidents. A desktop review of other major patient portals is underway, along with developing a system-wide action plan.<br /></span></p><p><span style="color: #666666;">An independent review commissioned by the Ministry makes 26 recommendations, including; stronger third-party cyber risk management and independent assurance, clearer system-wide processes for patient notification, improved visibility of supply chain risks, and enhanced incident preparedness.<br /></span></p><p><span style="color: #666666;">Bourne says the Ministry has accepted all the report's recommendations. Three actions are complete, five have been actioned with the Ministry awaiting external confirmation they are complete, 12 are underway and a further six are being planned.<br /></span></p><p><span style="color: #666666;">Health NZ chief financial officer Bevan McKenzie says the organisation accepts the Privacy Commissioner's overarching finding that more should have been done to protect patient information.<br /></span></p><p><span style="color: #666666;">"People expect their personal health information to be securely stored, and Health NZ and the rest of the health sector must ensure that is done," McKenzie says.&nbsp;<br /></span></p><p><span style="color: #666666;">"On this occasion patients were let down and that is unacceptable."<br /></span></p><p><span style="color: #666666;">Health NZ has stopped the flow of information from Northland district to Manage My Health because of the Privacy Commissioner's findings and measures are being put in place to ensure Northland patients can immediately be provided a paper copy of their discharge summary after a hospital visit, and that patient services are not impacted.<br /></span></p><p><span style="color: #666666;">The Privacy Commissioner recommends the Ministry of Health should establish a process for verifying and assuring that patient health portals meet health sector security standards. The report also recommends amending the Privacy Act to allow third-party providers who do not meet reasonable security safeguards to be held liable.<br /></span></p><p><span style="color: #666666;">"Third parties are increasingly playing a key role in the sharing, processing and storage of personal data," Webster says.&nbsp;<br /></span></p><p><span style="color: #666666;">"As such they are a target for malicious actors. It is critical they too are incentivised to put in place safeguards."<br /></span></p><p><span style="color: #666666;">Bourne says protecting people's health information is fundamental to trust in the health system and that strong governance, clear accountability, and independent assurance are essential to reducing cyber risk.Manage My Health (MMH) says in a statement that it acknowledges the serious nature of the December 2025 cyber security incident and the distress and concern it has caused patients, healthcare providers and the wider community. <br /><br />"We apologise for this occurrence and for the impact it has had on those affected," it says. <br /><br />It says MMH is responding to the Privacy Commissioner’s report, as well as reviews  by the Ministry of Health and Health New Zealand. <br /><br />"Since the incident, MMH has undertaken a comprehensive programme of security and operational improvements. These include mandatory multi-factor authentication for all users, enhanced real-time monitoring and alerting capability, strengthened access controls, and expanded independent security testing across the platform," the statement says. <br /><br />"We are continuing to work constructively with regulators and sector partners to demonstrate that our controls are in place and operating effectively." </span></p><p><span style="color: #666666;"><em><span style="font-size: 12px;">Image:&nbsp;Privacy Commissioner Michael Webster</span></em></span></p><div>&nbsp;&nbsp;</div><div><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor <a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></div><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to </span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Tue, 26 May 2026 23:31:00 GMT</pubDate>
</item>
<item>
<title>My View - Safety is everyone&apos;s responsibility</title>
<link>https://www.hinz.org.nz/news/news.asp?id=726939</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=726939</guid>
<description><![CDATA[<p><b style="font-size: 12px; color: #666666;"><i>VIEW -&nbsp;Brian Yow, clinical informatics director, digital services, Health NZ</i></b></p>
<p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><img alt="Brian Yow, clinical informatics director, digital services, Health NZ" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/View-Brian-Yow.png" style="border: 5px solid #ffffff; width: 250px; float: right; margin: 1px; height: 172px;" /><strong>‘A bad system will beat a good person every time’ -Deming -</strong></span></span>
</p>
<p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">System safety is about empowering everyone through positive leadership, quality guardrails, appropriate training and clinical governance, underpinned by a culture of excellence and continuous improvement. In a digital era, clinical safety extends to electronic systems that consumers, patients and healthcare workers use every day.
</span></span>
</p>
<p><span style="color: #666666;">At Health New Zealand | Te Whatu Ora, we have co-developed a Digital Clinical Safety Framework in partnership with consumers, healthcare professionals, technologists and wider health system stakeholders. These concepts are incorporated into our National Clinical Governance Framework.</span></p>
<p><span style="color: #666666;">Digital clinical safety is two-fold. First, it is about ensuring the quality, safety and resilience of digital systems intrinsically. Second, it enables people using these systems to deliver safer, more effective and efficient care extrinsically. Safety-by-design forms a foundational tri-weave alongside privacy and security-by-design.</span></p><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/2026.05.11-Digital-Safety.png" style="border:5px solid #ffffff;width: 250px; margin: 1px;    height: 250px; float: right;" />
<p><span style="color: #666666;"><span style="font-size: 14px;"><strong>Our Digital Clinical Safety Principles:<br /></strong></span></span>
</p>
<p><span style="color: #666666;"><strong>Culture of Safety</strong> - We empower our people by weaving a korowai, or cloak of protection, via the fabric of quality and safety systems. Digital solutions are interwoven to enhance safety, clinical safety and digital clinical safety as part of a broader organisational safety culture.</span></p>
<p><span style="color: #666666;"><strong>Collaborative Design</strong> - Involve healthcare consumers, workforce, technologists and industry throughout the digital solution lifecycle, so that digital health tools are human-centred, fit for purpose, and deliver maximum value and widespread benefits across the ecosystem.</span></p>
<p><span style="color: #666666;"><strong>Embedding Equity</strong> - Ensure solutions are holistic, inclusive, culturally safe, embrace diversity, and break down barriers through safe use, co-design and evaluation of technology. By embedding equity within our digital health systems, we endeavour to improve equity of access to healthcare services, and ultimately equity of health outcomes for all peoples.</span></p>
<p><span style="color: #666666;"><strong>Balanced Decision-Making</strong> - Clinical, operational and digital teams play to each other's strengths, amplified via multi-lane cost-benefit assessments, allowing us to make robust and data-informed investment and prioritisation decisions through leadership and clinical governance.</span></p>
<p><span style="color: #666666;"><strong>Semantic Interoperability</strong> - Promote interoperability among systems. Ensure digital tools and data exchanges are seamless while promoting data sovereignty, data quality, veracity, integrity, security, and privacy.</span></p>
<p><span style="color: #666666;"><strong>Continuous Quality Improvement</strong> - Build a resilient Safety-II system into our digital health environment by promoting virtuous cycles, striving to make it easier to do the right thing and harder to do the wrong thing. Adapt and improve based on real-world experiences. Review near-misses to bolster resilience, incidents to close gaps, and continuously drive towards “better” by evaluating risks and vulnerabilities.</span></p>
<p><span style="color: #666666;"><strong>Embedding into Practice</strong></span></p>
<p><span style="color: #666666;">These principles represent our values and help shape strategy. Frameworks need to be embedded to drive action and influence outcomes. The overarching goal is to bring teams from different backgrounds with different perspectives, skills and expertise closer together. Implementation into practice includes various actions/objectives across strategic, governance and operational levels:</span></p>
<p><span style="color: #666666;"><strong>Digital Investment</strong> - Digital initiatives, projects and programmes are prioritised using a clinical quality and safety lens.</span></p>
<p><span style="color: #666666;"><strong>Clinical Sponsorship</strong> - Clinically relevant digital initiatives require sponsorship from relevant clinical leaders at the appropriate level, so that there is senior leadership buy-in, ownership, championing and escalation pathways for clinical governance and risk management.</span></p>
<p><span style="color: #666666;"><strong>Clinical Collaboration</strong> - Clinically relevant digital initiatives require input from clinicians and consumers at appropriate phases across the delivery lifecycle (especially multidisciplinary, frontline and junior staff).</span></p>
<p><span style="color: #666666;"><strong>Hazard Logs</strong> - Digital risks can impact clinical care delivery. Hazard logs capture both clinical risks that could arise from digital systems and vice versa. The end of a project is not only the start of business as usual, but also continuous quality improvement. Living hazard logs continue to be co-reviewed at regular intervals by clinical and digital product owners, informing the need for future enhancement via a pragmatic risk-based and cost-benefit approach.</span></p>
<p><span style="color: #666666;"><strong>Training</strong> - Teams at every level require training according to their needs. Digital specialists with a grounding in health can speak the same language as healthcare workers, and vice versa. Groups cross-pollinate to build a truly integrated clinical-digital team. Likewise, leaders also need to be supported in terms of leadership, governance and evidence-based decision-making.</span></p>
<p><span style="color: #666666;"><strong>Standards</strong> - Embed relevant clinical safety, quality, data, digital, architecture and interoperability standards into product delivery lifecycles and roadmaps.</span></p>
<p><span style="color: #666666;"><strong>Metrics</strong> - Clinically relevant digital initiatives should have at least one quality and safety indicator measured as a key success factor, ideally automatically collected as part of monitoring and feedback loops.</span></p>
<p><span style="color: #666666;"><strong>Continuous Learning System</strong> - Implement an integrated system to capture feedback, incidents, near-misses, risks, mitigations and lessons learnt (and implemented), so that there is whole-of-system visibility, monitoring and assurance via continuous feedback loops. This builds upon Safety II resilience towards Safety III, emphasizing the interconnectedness between people, process and technology across complex adaptive systems, which is further enhanced by incorporating predictive analytics and risk modelling to monitor safety thresholds, especially in the era of AI.</span></p>
<p><span style="color: #666666;"><strong>Looking Ahead</strong> - Digital clinical safety is a core tenet of clinical governance in digital health. It is a building block for developing sustainable systems and the 10-year Health Digital Investment Plan (HDIP), led by the Centre for Digital Modernisation of Health.<br /></span>
</p>
<div>&nbsp;</div>

<div>&nbsp;</div>
<div><em style="color: #666666;">If you want to contact eHealthNews.nz regarding this View, please email the editor&nbsp;<a href="mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</em></div>
<p>&nbsp;</p>
<p><span style="color: #666666;"><b>Read more&nbsp;<a href="https://www.hinz.org.nz/page/eHN-views" target="_blank">VIEWS</a></b></span></p>
<div>
    <hr style="color: #333333;" />
</div>
<p><strong><strong style="color: #666666;"><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong style="color: #666666;"><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></strong>
</p>]]></description>
<pubDate>Mon, 11 May 2026 00:42:00 GMT</pubDate>
</item>
<item>
<title>Health Accelerator &amp; PenTest NZ to provide discounted cyber security assessment for general practice</title>
<link>https://www.hinz.org.nz/news/news.asp?id=726937</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=726937</guid>
<description><![CDATA[<p><em><span style="font-size: 12px;"><strong><span style="color: #666666;">SECTOR UPDATE - ProCare</span></strong></span></em></p>
<p><span style="color: #666666;"><strong>Primary care practices across New Zealand can now access a national, discounted cyber security assessment designed specifically for general practice, helping strengthen protection of patient data and digital systems.<br /></strong></span></p>
<p><span style="color: #666666;">The offer is being rolled out by Health Accelerator, a national primary care led innovation group focused on developing and scaling practical solutions for general practice, in partnership with PenTest NZ (a brand of Altersec).</span></p>

<p><span style="color: #666666;">The initiative comes in response to cyber incidents that affected the health sector earlier this year, highlighting the need for reliable data privacy and for practices to better understand and strengthen their current cyber security settings.</span></p>

<p><span style="color: #666666;">Through the partnership, practices can access a 25% discount on PenTest NZ’s standard cyber security assessment for general practice, an average saving of around $1,000 off the base assessment.</span></p>

<p><span style="color: #666666;">The assessment is carried out independently by PenTest NZ and identifies and documents cyber security risks specific to each practice. Practices receive clear findings, tailored recommendations, and evidence demonstrating steps taken to improve cyber security and manage risk.</span></p>
<p><span style="color: #666666;">Paul Roseman, CEO at Health Accelerator, says cyber security is now a fundamental part of delivering safe, trusted care.</span></p>
<p><span style="color: #666666;">“Cyber security is more important than ever, and Health Accelerator’s role is to support practices to ensure their security is sound and reliable. Partnering with PenTest NZ allows us to offer an independent, real world cyber security assessment at a significantly reduced cost.”</span></p>
<p><span style="color: #666666;">“Taking an assessment isn’t just for the sake of ticking boxes. It’s about giving practices confidence that they understand their risks, have the evidence they need to back their decisions, and can take sensible steps to protect systems and information.”</span></p>
<p><span style="color: #666666;">Faustin Roman, CEO of Altersec and the PenTest NZ brand, says collaboration across the sector is key to improving cyber resilience.</span></p>
<p><span style="color: #666666;">“We’re fully behind the innovation of the Health Accelerator initiative and supporting health providers in primary care and beyond to stay safe and healthy online.</span></p>
<p><span style="color: #666666;">“We’ve worked with PHOs for some time, including Tū Ora, and they share our belief that real progress comes from partners working together toward the same goal. System level leadership at PHO organisations enables companies like ours to support primary care, while clinicians focus on keeping people well.”</span></p>
<p><span style="color: #666666;">“This type of exercise is long overdue for many practices, so we welcome organisations that are interested in getting involved. Let’s spread the word, maximise this Health Accelerator partnership, and get New Zealand health services pen tested.”</span></p>
<p><span style="color: #666666;">The partnership reflects the need for practical cyber risk management aligned with Health NZ expectations, while ensuring solutions remain accessible and cost effective for practices. Health Accelerator is encouraging general practices to take up the offer and proactively support continuity of care.</span></p>
<p><span style="color: #666666;">More information about the PenTest NZ offer is available at: https://www.healthaccelerator.co.nz/pen-test-cyber-offer</span></p>
    <div>&nbsp;</div>

<p><span style="font-weight: 700; font-family: Garamond; color: #666666;">Source: ProCare&nbsp;media release</span></p>
<p><span style="font-size: 10.5pt; font-family: Garamond; color: #666666;">Sector updates are provided by organisations to eHealthNews.nz and have not necessarily been edited or checked for accuracy. Any queries should be directed to the organisation issuing the release.</span><br /></p>
<div>
    <hr />
</div>
<p><span style="color: #666666;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;">Do you have an item to add to sector updates?</span></b><br /></span>
</p>
<p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;"><span style="color: #666666;"></span></span></b></p>
<p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="color: #666666;"><span style="font-size: 12pt; font-family: Arial, sans-serif;"></span></span></b></p>
<p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><span style="color: #666666;"><span style="font-size: 10.5pt; font-family: Arial, sans-serif;">Email your information to us at&nbsp;</span><span style="font-size: 10.5pt; font-family: Arial, sans-serif;"><a href="mailto:updates@hinz.org.nz">updates@hinz.org.nz</a></span></span>
</p>
<p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: red;">Return to&nbsp;</span></b><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif;"><a href="http://www.ehealthnews.nz/" target="_blank">eHealthNews.nz home page</a></span></b></p>]]></description>
<pubDate>Sun, 10 May 2026 23:26:00 GMT</pubDate>
</item>
<item>
<title>Three health cyber breaches in three months reveals &apos;feeding frenzy&apos; pattern</title>
<link>https://www.hinz.org.nz/news/news.asp?id=724625</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=724625</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial4/2021.05.13.privacy-image.jpg" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" /></span></p><p><span style="color: #666666;">Three high-profile health data breaches within three months have exposed what a cybersecurity expert describes as a "feeding frenzy" pattern, where attackers target sectors with demonstrated weak defences and minimal consequences.<br /></span></p><p><span style="color: #666666;">The latest incident at IntraCare, an Auckland-based private healthcare provider, comes after breaches at <a href="https://www.hinz.org.nz/news/718553/Ministry-review-to-examine-technical-failures-in-MMH-breach.htm" target="_blank">Manage My Health</a> and <a href="https://www.hinz.org.nz/news/news.asp?id=721334" target="_blank">MediMap</a>, following what Altersec chief executive Faustin Roman says is a predictable pattern rather than coincidence.<br /></span></p><p><span style="color: #666666;">"New Zealand health providers are genuinely under greater attack: one high-profile breach absolutely leads to more," he says.<br /></span></p><p><span style="color: #666666;">In the latest case, IntraCare took its patient management system, Picture Archiving and Communication System (PACS), and finance systems offline after detecting unusual activity within its IT environment on 20 March 2026.<br /></span></p><p><span style="color: #666666;">“We have confirmed the incident involved unauthorised access to parts of our network,” a spokesperson says.&nbsp;<br /></span></p><p><span style="color: #666666;">“We are working to establish exactly how this occurred and are already implementing additional safeguards and monitoring to further strengthen our systems.”<br /></span></p><p><span style="color: #666666;">Roman says healthcare data represents the most valuable commodity on the dark web, with a single health record worth far more than a stolen credit card because it contains identity details, NHI numbers, and clinical history that cannot be cancelled like financial cards.<br /></span></p><p><span style="color: #666666;">“In cybersecurity, we see a clear "feeding frenzy" pattern: once an attacker publicly compromises a sector and demonstrates that defences are weak and consequences are minimal, the broader criminal ecosystem takes notice,'" he says.<br /></span></p><p><span style="color: #666666;">"The MMH breach effectively put a spotlight on New Zealand's health tech sector and potentially signalled 'this is soft.&nbsp;<br /></span></p><p><span style="color: #666666;">"Threat actors share this intelligence. They target the same vertical, in the same country, because the conditions that allowed the first breach - legacy platforms, voluntary security standards, a $10,000 privacy penalty cap – have not changed overnight."<br /></span></p><p><span style="color: #666666;">The interconnected nature of health systems to enable data sharing may also allow attackers to move from one system to another, says Roman.<br /></span></p><p><span style="color: #666666;">The timing of these breaches also aligns with known vulnerability windows, particularly the December-January holiday period when organisations operate with skeleton IT crews and reduced monitoring.<br /></span></p><p><span style="color: #666666;">The ManageMyHealth breach was detected on 30 December, MediMap in February and IntraCare in March.&nbsp;<br /></span></p><p><span style="color: #666666;">“Attackers who gain access during the holiday period may not be discovered until staff return and systems are properly reviewed," he says.<br /></span></p><p><span style="color: #666666;">The National Cyber Security Centre's Q4 2025 Cyber Security Insights report shows the threat landscape was already intensifying before these breaches, with website compromise incidents up 16 per cent, denial of service attacks doubling, and 23 per cent of nationally significant incidents attributed to state-sponsored actors.<br /></span></p><p><span style="color: #666666;">Roman says New Zealand's approach to healthcare cybersecurity remains immature compared to other jurisdictions with no mandatory audit regimes and meaningful penalties.<br /></span></p><p><span style="color: #666666;">He described the Privacy Act's maximum fine of $10,000 as "laughable" compared to Australia's privacy legislation or Europe's GDPR.<br /></span></p><p><span style="color: #666666;">IntraCare, which treats more than 2,000 patients annually, says it activated its incident response plan after detecting the breach and engaged Cyber CX, a leading Australasian cybersecurity organisation, to conduct a forensic investigation.<br /></span></p><p><span style="color: #666666;">The provider maintained patient care by reverting to manual processes, but the breach did impact some scheduled procedures with 28 patients temporarily deferred.<br /></span></p><p><span style="color: #666666;">“We recommenced procedures on Monday 30 March. Our focus has been on ensuring systems are fully tested and resilient before bringing them back online,” the spokesperson says.</span></p><div>&nbsp;&nbsp;</div><div><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor&nbsp;<a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></div><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Wed, 1 Apr 2026 02:05:00 GMT</pubDate>
</item>
<item>
<title>My View - Digital safety is patient safety</title>
<link>https://www.hinz.org.nz/news/news.asp?id=724083</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=724083</guid>
<description><![CDATA[<p><b style="font-size: 12px; color: #666666;"><i>VIEW -&nbsp;Ayesha Verrall, Labour health spokesperson</i></b></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><img alt="Ayesha Verrall" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/View-Ayesha-Verrall.jpg" style="border: 5px solid #ffffff; width: 250px; float: right; margin: 1px; height: 172px;" /><strong>As clinicians, we have long accepted that the tools of our trade are changing. Stethoscopes and scalpels are now joined by portals, platforms and AI. These are good things in skilled hands.&nbsp;&nbsp;<br /></strong></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">However, as we increasingly rely on digital infrastructure to manage patient care, digital services and safety have been hollowed out by the National Government’s cuts, which favour short-term savings over long-term patient safety.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">The cyber-security breach of Manage My Health in January this year was a watershed moment. With over 120,000 New Zealanders' private documents, including discharge summaries and specialist referrals, exposed to malicious actors, the incident was not merely an IT failure; it was a profound breach of the clinician-patient relationship and undermined patient trust in digital platforms.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">As we look at the fallout of that event, we must ask: is our wider health system becoming more resilient or more vulnerable to cyberattack? And how do we rebuild the trust our patients have lost in it?<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>The high costs of cuts</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">National’s cuts have made a drastic reduction in the expertise that keeps our health system running and safe. The data and digital workforce at Health NZ has been slashed by nearly 40 percent, moving from a baseline of 2,400 roles to just 1,460.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">I have been vocal about the $330 million the government cut from data and digital health initiatives in Budget 2024. That funding was for work on cybersecurity capability, and it is gobsmacking to me that he would consider work in this field irrelevant when IT services needed investment.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">By cutting these roles and funding we are not just losing staff; we are going backwards. We are missing the opportunity to get ahead of the curve. When we fail to modernise, we do not just stay still, we fall behind, leaving the doors wide open for external threats.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">The Health Digital Investment Plan will never realise its promise unless the initiatives are funded.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>Patient care is at risk</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Both in Parliament and the media, I have highlighted the backwards approach to security standards under the National Government and how it leaves patients vulnerable and undermined trust. I believe that cutting IT support is effectively jeopardising patient care.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">We saw recently when patient records held in the MediMap medication management system were hacked, replaced with fake names and some patients even recorded as ‘deceased’ that patient care – not just their data - is at risk.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">The Government’s refusal to properly fund the Privacy Commissioner and its failure to share cybersecurity capability with private providers has left us exposed to breaches of this nature, and the public distrustful.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">The cuts made in Budget 24 and 25 are false economies that will be wiped out by the cost of a single major data breach or a prolonged system outage.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">New Zealanders deserve confidence that when they use an app like Manage My Health or management of their care is entrusted to a system such as MediMap, their information is safe and that they can have trust in it.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">The Government has a role in ensuring that. Currently, that confidence and trust is at an all-time low.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>What must be done?</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">To prevent further breaches and systemic failures and keep patients and their data safe, we must shift our perspective away from cuts and reinvest where it matters. Digital security is not a ‘nice to have’; it is a clinical necessity.</span></span></p><ol><li><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Mandatory security standards: We must enforce the high-level security standards Labour introduced in 2022 across all platforms, both in the public system and private providers that handle patient data.</span></span></li><li><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Restore digital expertise: We cannot expect a safe, resilient and secure health system without staff who are experts in their field. We must halt the attrition of our digital workforce and re-invest where it is needed</span></span></li><li><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Stronger rules and penalties: The Privacy Commissioner has called for penalties to drive compliance, but the National Government has instead cut funding to the privacy watchdog. All health providers must be properly regulated and held accountable in terms of how they handle personal information.</span></span></li></ol><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>Where we should be heading</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">My vision for the health system is one that is truly patient-centred. That means New Zealanders get the care they need where and when they need it.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Trusted and secure platforms are essential to this; services that are simple and consistent for patients and their clinicians to use, whether they are getting a vaccination in Kaitaia at a community-led provider, or a hip replacement in Dunedin at the hospital.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">In New Zealand, we are lucky to have innovative, creative local developers to do this work, that can create jobs and improve patients’ health, trust in and experience of the health system. It is not clear to me that Health New Zealand’s present direction will give these developers the opportunities they need.<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>Conclusion</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">You cannot have a modern, safe health system while you are hacking away at its digital foundations.&nbsp;</span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">National’s cuts have created security and care risks. The Manage My Health breach was a warning shot, swiftly followed by MediMap. If we continue to hollow out our digital services, we are gambling with patient care.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">As health professionals and leaders, we must demand that digital infrastructure be treated with the same clinical rigor as any other medical tool. We cannot allow "efficiency" to become a euphemism for "vulnerability." Patients’ privacy, care and their safety depends on it.<br /></span></span></p><div><em style="color: #666666;">&nbsp;</em></div><div><em style="color: #666666;">If you want to contact eHealthNews.nz regarding this View, please email the editor&nbsp;<a href="mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</em></div><p>&nbsp;</p><p><span style="color: #666666;"><b>Read more&nbsp;<a href="https://www.hinz.org.nz/page/eHN-views" target="_blank">VIEWS</a></b></span></p><div><hr style="color: #333333;" /></div><p><strong><strong style="color: #666666;"><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong style="color: #666666;"><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></strong></p>]]></description>
<pubDate>Thu, 26 Mar 2026 03:28:00 GMT</pubDate>
</item>
<item>
<title>GPNZ calls for digital primary care to be treated as critical infrastructure</title>
<link>https://www.hinz.org.nz/news/news.asp?id=721667</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=721667</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/2026.03.06-GPNZ.png" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" /></span></p><p><span style="color: #666666;">General Practice New Zealand has released a position paper calling for digital primary care systems to be treated as critical national infrastructure, with enforceable minimum security standards and independent certification for all vendors handling patient data.<br /></span></p><p><span style="color: #666666;">The <a href="https://gpnz.org.nz/wp-content/uploads/260305-GPNZ-position-paper_Prevention-is-protection_Securing-digital-primary-care.pdf" target="_blank">position paper</a> also says that sustainable investment in digital primary care is crucial as the funding model was not designed to uplift security and sustain ongoing compliance.<br /></span></p><p><span style="color: #666666;">The move follows recent breaches including Manage My Health and MediMap, which GPNZ describes as symptoms of structural weaknesses in standards, governance, assurance and investment settings rather than isolated failures.<br /></span></p><p><span style="color: #666666;">Justin Butcher, GPNZ deputy chair and chief executive of Pinnacle Midlands Health Network, says the health system’s reliance on digital tools has grown, but the governance and standards surrounding those systems has not kept pace.<br /></span></p><p><span style="color: #666666;">“Digital systems are now embedded in everyday care. Patient portals, shared records and electronic referrals are essential to how primary care operates,” he says.<br /></span></p><p><span style="color: #666666;">“Yet the standards and oversight needed to protect those systems remain inconsistent. The health system needs to move from reacting to incidents to deliberately strengthening its digital foundations.”<br /></span></p><p><span style="color: #666666;">Butcher says other sectors already treat digital systems as critical infrastructure, operating with clear standards and independent oversight.<br /></span></p><p><span style="color: #666666;">“Primary care sits at the frontline of the health system. It is where patients turn for reassurance and care, and that trust must not be undermined by preventable system failures,” he says.<br /></span></p><p><span style="color: #666666;">The position statement calls for enforceable minimum digital security standards, independent certification and transparent assurance, oversight stratified by scale and concentration of risk, structured vendor governance with clear accountability, and sustainable investment recognising digital health as core infrastructure.<br /></span></p><p><span style="color: #666666;">It says that current frameworks such as the Health Information Security Framework (HISF) operate primarily as guidance rather than auditable requirements and HISF is not currently enforceable and is not always used as the reference framework by vendors.<br /></span></p><p><span style="color: #666666;">Because vendors engage individual practices as customers, there is limited aggregation of purchasing power and a lack of ability to influence pricing, standards and contractual terms, it adds.<br /></span></p><p><span style="color: #666666;">Digital systems in general practice are funded from operating budgets and treated as overhead, meaning cost often becomes the main determinant of choice rather than security or functionality.<br /></span></p><p><span style="color: #666666;">"Expecting small and medium sized providers to absorb increasing digital obligations within existing operating margins is neither realistic nor sustainable," the position paper says.<br /></span></p><p><span style="color: #666666;">Butcher says primary care providers are committed to strengthening digital security but need consistent national frameworks to do so effectively.<br /></span></p><p><span style="color: #666666;">His comments echo those of Aged Care Association (ACA) chief executive Tracey Martin and Medical IT Advisors chief executive Faustin Roman <a href="https://www.hinz.org.nz/news/721424/Digital-health-systems-should-be-treated-as-critical-infrastructure.htm" target="_blank">who told eHealthNews</a> that healthcare IT should get similar regulatory treatment to other critical infrastructure sectors, with appropriate assurance and enforcement mechanisms.&nbsp;</span></p><div>&nbsp;&nbsp;</div><div><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor&nbsp;<a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></div><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Fri, 6 Mar 2026 00:06:00 GMT</pubDate>
</item>
<item>
<title>My View - Interoperability &amp; consumer access: is it time for regulation?</title>
<link>https://www.hinz.org.nz/news/news.asp?id=721528</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=721528</guid>
<description><![CDATA[<p><b style="font-size: 12px; color: #666666;"><i>VIEW -&nbsp;Peter Jordan, Fellow of HiNZ and Health Information Standards Implementer&nbsp;</i></b></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><img alt="Peter Jordan" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial10/View-Peter-Jordan.png" style="border: 5px solid #ffffff; width: 250px; float: right; margin: 1px; height: 172px;" /><strong>Last night I logged into my health and wellness app - following a GP consultation earlier in the day. It confirmed that the practice has sent an update, but I noted the absence of a reason for prescribing a new medication; therefore, I sent a response message asking for that data to be added to my record. I also created permissions to enable other members of my care team to see the new data prior to an appointment the following day…&nbsp;<br /></strong></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">…and then I woke up and realised that I’d been dreaming. An hallucination based on a related fantasy that interoperability and consumer access to healthcare data can be achieved without regulatory intervention. Instead, the reality is a world where lip-service is paid to various standards unsupported by conformance and compliance requirements; intermittent funding is made to selected software suppliers to exchange their own proprietary data formats; and patient portals with read-only data are tethered to practice management systems.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>The New Zealand context&nbsp;</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">The goal of interoperability is cited in virtually every single health information strategy and investment plan produced in New Zealand in the last 2 decades. The latest being the <a href="https://www.tewhatuora.govt.nz/assets/Uploads/Health-Digital-Investment-Plan-2025.pdf" target="_blank">Health Digital Investment Plan</a> published in November 2025. However, this excellent document does provide pointers to a way forward that takes us beyond the madness of continuing to expect this outcome by continuing to do the same things.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">In particular, the highlighted phrases this excerpt from the Data &amp; Interoperability Section on Page 7:&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><em>“We will enable the secure and seamless flow of health data across the system. We will do this by establishing and <strong>enforcing common data standards</strong> across the sector, creating a national data catalogue, and building a modern, standards-based interoperability platform <strong>using international best practices</strong>”&nbsp;</em><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">and this ‘horizon’ listed on Page 26:&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><em>“Approved health app developers can use national API resources to <strong>create innovative tools for patients that securely connect to the patient's health record</strong>”&nbsp;</em><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Obviously, these entries do not directly call out the need for regulation, but they should encourage us to see if other countries are moving in that direction, and even a cursory glance outside the shores of New Zealand reveals that several countries have established or are actively developing regulations regarding interoperable healthcare data.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>The global context&nbsp;</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Arguably leading the way in 2016, the 21st Century Cures Act in the USA prohibits information blocking and mandates that patients have free, electronic access to their medical records. This has been supported by <a href="https://healthit.gov/regulations/cures-act-final-rule/" target="_blank">government regulations</a> stipulating the use of HL7® FHIR® APIs to provide access to consumers and payers.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">This legislative path has been followed in the EU by the <a href="https://www.european-health-data-space.com/" target="_blank">European Health Data Space</a> which mandates that Electronic Health Record systems must meet specific, standardized interoperability requirements to allow for seamless exchange.&nbsp;&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">In Australia, The Modernising My Health Record (Sharing by Default) Act 2025 establishes requirements for healthcare providers to upload key health information to My Health Record by default. This represents a significant shift from voluntary participation to mandatory upload requirements for certain providers.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Health interoperability in the UK is now primarily driven by the Data (Use and Access) Act 2025, which mandates technical standards for IT suppliers and providers. This legislation enforces compliance with interoperability standards—such as FHIR—to ensure seamless data sharing across the NHS and social care.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Following closely behind are <a href="https://www.canada.ca/en/health-canada/news/2026/02/the-government-of-canada-introduces-legislation-to-build-a-more-connected-health-care-system.html" target="_blank">Canada</a> and <a href="https://www.oireachtas.ie/en/bills/bill/2024/61/" target="_blank">Ireland</a> both with new legislation to support standards-based interoperability and patient access, so is it time for New Zealand to follow suit and adopt similar legal mandates?&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>The case for regulation&nbsp;</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">While I would answer that question with a firm ‘yes’, it’s with the caveat that regulation of itself is not a silver bullet and, critically, needs to be supported by investment.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">It’s easy to look at our current state and see that most health information data is not fit for purposes beyond that for which it was originally collected. Certainly, that is my experience based on decades of working on national interoperability projects such as GP2GP patient notes transfers and the NZ e-Prescription Service.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">That is not to blame the numerous software suppliers engaged in those and other similar projects. Their products are principally designed for the purposes of managing healthcare facilities and running practices and, consequently, scheduling and reimbursement related to patient encounters takes precedence over the creation of interoperable patient records.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Naturally, vendors will prioritise new functional features that enhance their clients’ user experience and generate revenue rather than implementing changes that only appear to have downstream benefits. In NZ at least, it’s a low margin business and interoperability does not provide a competitive edge. As many have noted, it’s not a boat race - we are all effectively paddling in the same vessel.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><strong>The need for investment&nbsp;</strong><br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Therefore, it’s clear that regulation needs to be supported by investment. Suppliers need financial incentives – preferably carrots rather than sticks - to comply with standards, and build APIs, that benefit us all in the long run but might otherwise have an adverse short-term effect on their profit margins.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">Furthermore, without the development of standards-based APIs, it’s difficult to foresee the emergence of a market for apps that enable engaged consumers to manage their own health and wellness data. It’s also highly likely that any project attempting to facilitate the sharing of patient records can produce significant benefits without structured, standards-conformant, data.&nbsp;<br /></span></span></p><p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;">We all know that dreams are free; in reality, experience should be teaching us that interoperability and consumer access both require regulation backed by investment. The time has come to put that into practice.&nbsp;<br /></span></span></p><p><em style="color: #666666;">Disclaimer: The opinions expressed in this article are purely personal and do not represent the views of my former clients, HL7 New Zealand, HL7 International or generative AI.&nbsp;</em></p><p><span style="color: #666666;">&nbsp;</span></p><p><em style="color: #666666;">If you want to contact eHealthNews.nz regarding this View, please email the editor&nbsp;<a href="mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</em></p><p>&nbsp;</p><p><span style="color: #666666;"><b>Read more&nbsp;<a href="https://www.hinz.org.nz/page/eHN-views" target="_blank">VIEWS</a></b></span></p><div><hr style="color: #333333;" /></div><p><strong><strong style="color: #666666;"><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong style="color: #666666;"><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></strong></p>]]></description>
<pubDate>Thu, 5 Mar 2026 02:00:00 GMT</pubDate>
</item>
<item>
<title>Digital health systems should be treated as critical infrastructure</title>
<link>https://www.hinz.org.nz/news/news.asp?id=721424</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=721424</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial4/2021.05.13.privacy-image.jpg" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" /></span></p><p><span style="color: #666666;">Digital health systems should be treated as critical infrastructure as security failures directly impact patient safety, experts say.&nbsp;<br /></span></p><p><span style="color: #666666;">Aged Care Association (ACA) chief executive Tracey Martin says the MediMap incident highlights how dependent modern care delivery has become on digital systems and this means security, redundancy and contingency planning must be treated as core health infrastructure responsibilities.&nbsp;<br /></span></p><p><span style="color: #666666;">Medical IT Advisors chief executive Faustin Roman agrees, saying that healthcare IT should get similar regulatory treatment to other critical infrastructure sectors, with appropriate assurance and enforcement mechanisms.&nbsp;<br /></span></p><p><span style="color: #666666;">Digital platform MediMap is used widely for prescribing, pharmacy dispensing, and medication administration in aged residential care, disability services, hospices, and community health settings.&nbsp;<br /></span></p><p><span style="color: #666666;">It was taken offline after detecting a security breach on 22 February, creating immediate operational impacts on aged care facilities across New Zealand and forcing providers to shift to manual systems to ensure residents continued receiving medications safely.&nbsp;<br /></span></p><p><span style="color: #666666;">Tracey Martin says digital medication systems bring real benefits by reducing transcription errors, supporting coordination between GPs, pharmacies and facilities, and strengthening clinical oversight.&nbsp;&nbsp;<br /></span></p><p><span style="color: #666666;">“But they are now critical infrastructure," she tells eHealthNews.&nbsp;<br /></span></p><p><span style="color: #666666;">"When they fail, whether through cyber breach or system outage, the pressure shifts immediately onto frontline staff."&nbsp;<br /></span></p><p><span style="color: #666666;">Martin says that manual processes are safe when done well, but are more labour-intensive and increase fatigue and workload risk.&nbsp;&nbsp;<br /></span></p><p><span style="color: #666666;">“That is why cybersecurity and system resilience can't be seen as 'IT issues'. They are patient safety issues,” she says.&nbsp;<br /></span></p><p><span style="color: #666666;">Roman, a certified ethical hacker with more than 10 years' experience in health IT security, does not agree with recent chatter on social media and Health NZ’s position on the MediMap incident, which places sole responsibility for security on platform vendors.&nbsp;&nbsp;<br /></span></p><p><span style="color: #666666;">"I do not agree that any organisation should ever be solely responsible: cybersecurity will always be a shared responsibility" he tells eHealthNews.&nbsp;<br /></span></p><p><span style="color: #666666;">“Providers have primary responsibility of certain controls, however other stakeholders need to play their part, e.g. users must be cyber-aware and protect their credentials, government agencies should enforce minimum standards, healthcare organisations should do regular assessments and third-party assurances,” he says.&nbsp;</span></p><p><span style="color: #666666;">Roman argues that healthcare IT should get similar regulatory treatment to other critical infrastructure sectors, with appropriate assurance and enforcement mechanisms.&nbsp;<br /></span></p><p><span style="color: #666666;">“Regular penetration testing and security assurance should become standard practice, particularly as technology ages and threat levels increase.”&nbsp;<br /></span></p><p><span style="color: #666666;">He believes that New Zealand's approach to healthcare cybersecurity is still immature compared to other jurisdictions with a lack of enforcement mechanisms, assurance, incentives or liabilities.&nbsp;<br /></span></p><p><span style="color: #666666;">New Zealand's Privacy Act maximum fine of $10,000 contrasts sharply with penalties under Australia's privacy legislation or Europe's General Data Protection Regulation.&nbsp;<br /></span></p><p><span style="color: #666666;">Despite recent high-profile incidents, Roman there has been surprisingly low inquiry levels from health IT companies seeking security reviews and advice.&nbsp;<br /></span></p><p><span style="color: #666666;">While there was initial uptick in activity following the Manage My Health breach in late 2025, the MediMap incident has generated far less response than expected.&nbsp;<br /></span></p><p><span style="color: #666666;">"There is a time for talking and planning that maybe was about 10 or 15 years ago, and then there is the time to actually act, which is probably yesterday,” he says.&nbsp;<br /></span></p><p><span style="color: #666666;">Martin says the ACA has maintained regular contact with members since the MediMap incident, providing clear practical guidance and ensuring Health NZ understands the operational impact on facilities.&nbsp;<br /></span></p><p><span style="color: #666666;">"Our members showed resilience and professionalism, as they always do, but this event is a reminder that system-wide digital security matters deeply to aged care and needs to be prioritised accordingly,” Martin says.&nbsp;</span></p><div>&nbsp;&nbsp;</div><div><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor&nbsp;<a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></div><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Tue, 3 Mar 2026 23:39:00 GMT</pubDate>
</item>
<item>
<title>MediMap begins phased restoration after security incident</title>
<link>https://www.hinz.org.nz/news/news.asp?id=721334</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=721334</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial7/2023.08.11-1Chart.png" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" /></span></p><p><span style="color: #666666;">MediMap has started a phased restoration of its digital medication management platform after going offline in New Zealand due to unauthorised activity in its system.<br /></span></p><p><span style="color: #666666;">The privately owned platform, used widely across New Zealand for prescribing, pharmacy dispensing, and medication administration in aged residential care, disability services, hospices, and community health settings, was taken offline after detecting the security breach on 22 February.<br /></span></p><p><span style="color: #666666;">The breach involved some resident demographic information being changed including residents’ names, dates of birth, assigned prescriber, allergy or intolerance information and discharge or deceased status.<br /></span></p><p><span style="color: #666666;">MediMap says restoration began on 2 March 2026 and facilities where current resident information has not been modified will be restored first following internal validation.&nbsp;<br /></span></p><p><span style="color: #666666;">Facilities where resident information may have been impacted will be contacted directly by MediMap to confirm current resident details prior to restoration.<br /></span></p><p><span style="color: #666666;">MediMap has secured a court injunction to protect impacted individuals' information, which prohibits any person from accessing, using, copying, sharing or publishing any MediMap data that may have been unlawfully obtained.<br /></span></p><p><span style="color: #666666;">“At this stage, we cannot confirm whether any resident data has been accessed beyond viewing, extracted, or exposed externally. The investigation is ongoing,” an <a href="https://help.medimap.health/hc/en-au/articles/43920241741197-Facility-FAQs" target="_blank">FAQ for providers on MediMap’s website says</a>.<br /></span></p><p><span style="color: #666666;">The company says it has rebuilt a secure production environment and completed forensic review and validation of its data before beginning the restoration process.&nbsp;<br /></span></p><p><span style="color: #666666;">Independent cyber security specialists have supported the strengthening of authentication controls.<br /></span></p><p><span style="color: #666666;">"We acknowledge the patience and professionalism of providers and their staff, who have continued to deliver care for patients and residents with manual processes during this disruption," MediMap says in a system update on 3 March.<br /></span></p><p><span style="color: #666666;">"We are confident in the integrity of the restored environment.”<br /></span></p><p><span style="color: #666666;">Providers will be required to validate specific demographic information identified during the investigation before accessing the platform and all user passwords will be reset as part of the security measures.<br /></span></p><p><span style="color: #666666;">Healthcare providers have had to revert to manual processes while the system has been offline and must clinically review and reconcile any medication changes made during the outage period.&nbsp;<br /></span></p><p><span style="color: #666666;">Electronic prescribing via NZePS will be progressively re-enabled once the core system stabilises.<br /></span></p><p><span style="color: #666666;">Following the initial restoration phase, MediMap will enter a stabilisation and hypercare period with expanded support arrangements to transition back to business-as-usual operations. The phased restoration approach has been shared with Health New Zealand to ensure alignment as services are progressively restored.<br /></span></p><p><span style="color: #666666;">"Our shared objective is a safe, structured return to digital medication management that balances clinical continuity with strengthened security controls," MediMap says.<br /></span></p><p><span style="color: #666666;">Health New Zealand acting chief information technology officer Darren Douglass says the organisation is supporting MediMap's response and has activated its Cyber Incident Management Team to assist.<br /></span></p><p><span style="color: #666666;">“People need and deserve confidence that their private and sensitive health information is secure. Protecting patient data is a priority across the health system,” Douglass says.<br /></span></p><p><span style="color: #666666;">MediMap has also notified the Office of the Privacy Commissioner and New Zealand Police about the incident.&nbsp;<br /></span></p><p><span style="color: #666666;">"We understand how concerning this situation has been for residents, patients, families and healthcare providers. We sincerely apologise for the disruption and distress caused," the company says in a statement.</span></p><div>&nbsp;&nbsp;</div><div><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor&nbsp;<a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></div><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Tue, 3 Mar 2026 00:34:00 GMT</pubDate>
</item>
<item>
<title>My View - From review to reset: what the MMH breach must change for digital health in Aotearoa </title>
<link>https://www.hinz.org.nz/news/news.asp?id=719363</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=719363</guid>
<description><![CDATA[<p><b style="font-size: 12px; color: #666666;"><i>VIEW -&nbsp;Damon Campbell, Chief Operating Officer, WellSouth Primary Health Network&nbsp;</i></b></p>
<p><span style="font-size: 12px; color: #666666;"><span style="font-size: 14px;"><img alt="Damon Campbell" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial9/View-Damon-Campbell.jpg" style="border: 5px solid #ffffff; width: 250px; float: right; margin: 1px; height: 172px;" /><strong>The true significance of the Manage My Health data breach will not be determined by how thoroughly it is investigated, but by whether the health sector uses this moment to fundamentally improve how digital health data and systems are designed, governed and protected in Aotearoa.&nbsp;</strong></span></span>
</p>
<p><span style="color: #666666;">If we do not get that right, we risk undermining the very tools and digital capability that increasingly support patient care when it is needed most.&nbsp;<br /></span></p><p><span style="color: #666666;"><strong>Time to review&nbsp;</strong><br /></span></p><p><span style="color: #666666;">With the Ministry of Health and Privacy Commissioner's reviews now underway, this is an important moment. Reviews, inquiries and reports are familiar tools in the health system, particularly following high-profile incidents. However, experience shows that the value of these processes lies not in the documentation itself, but in whether they lead to clear, practical, and enduring change.&nbsp;<br /></span></p><p><span style="color: #666666;">For digital health, that bar must be set high. Otherwise, we risk regression at a time when trust is already fragile. Even highly digitally capable general practices, including some in our region, are questioning whether the ’system’ can be relied upon to keep data secure.&nbsp;<br /></span></p><p><span style="color: #666666;">Digital systems are no longer peripheral to care delivery. Patient portals, shared care records, analytics platforms and integrations between primary and secondary care are now core infrastructure. They shape how clinicians work, how patients engage with their care, and how information flows across the system. Here in the South, many general practices rely heavily on digital infrastructure to sustain care delivery amid a constrained workforce, particularly in rural areas where on-site daily clinical coverage is not always possible.&nbsp;<br /></span></p><p><span style="color: #666666;">As a result of this reliance, cybersecurity and privacy can no longer be treated as technical considerations or compliance exercises that sit alongside delivery. They are fundamental design principles that must be embedded from the outset and that are essential to rebuilding trust.&nbsp;<br /></span></p><p><span style="color: #666666;"><strong>Looking forward&nbsp;<br /></strong></span></p><p><span style="color: #666666;">What the sector now needs from the Manage My Health reviews is not simply a retrospective analysis of what went wrong, but a forward-looking framework that helps us, as a nation, deliver digital health better and more safely. That framework needs to provide clarity on expectations, roles and accountabilities across the ecosystem, including vendors, health organisations, funders and regulators. More than that, it must work and regain the trust of clinicians and patients.&nbsp;<br /></span></p><p><span style="color: #666666;">Without that shared understanding, responsibility remains fragmented, and risks are pushed downstream to the organisations and clinicians closest to patients.&nbsp;<br /></span></p><p><span style="color: #666666;">One of the most pressing challenges exposed by recent cyber incidents is the inconsistency in security maturity across digital health platforms. Some organisations invest heavily in cyber governance, independent assurance and continuous monitoring, while others operate with minimal oversight and legacy approaches that no longer reflect the threat landscape. A system that relies on voluntary uplift or variable standards is inherently fragile. The reviews must therefore help define what “good” looks like in practice, including baseline security expectations that are proportionate to the sensitivity and scale of the data being held.&nbsp;<br /></span></p><p><span style="color: #666666;">Equally important is transparency. In a digital health environment built on trust, patients and clinicians need confidence that when things go wrong, information will be shared early, clearly and honestly. This is not about blame. It is about enabling informed decision-making, managing risk and maintaining confidence in the system as a whole. Clear expectations around communication and disclosure should be a core outcome of the reviews, not an afterthought.&nbsp;<br /></span></p><p><span style="color: #666666;"><strong>Opportunities for change&nbsp;</strong><br /></span></p><p><span style="color: #666666;">The reviews also present an opportunity to strengthen cyber governance at a system level. Digital health in Aotearoa has grown rapidly, often through a mix of national initiatives, regional solutions, and vendor-led innovation. While this has delivered real benefits, it has also created complexity and uneven oversight. A more coherent approach to assurance, certification, and ongoing monitoring of digital health platforms would reduce duplication, build confidence and trust, and allow organisations to focus on delivery rather than constantly revalidating the same risks in isolation.&nbsp;<br /></span></p><p><span style="color: #666666;">Importantly, any path forward must recognise the operational realities of the health sector. General practices, community providers, and PHOs are not technology companies, yet they are increasingly expected to manage sophisticated digital risk alongside delivering care. A safer digital health system is one that supports these organisations with clear guidance, shared tools and system-level investment, rather than transferring risk without the means to manage it.&nbsp;<br /></span></p><p><span style="color: #666666;">At its core, this is about trust. Health data is among the most sensitive information people hold, and the expectation that it will be protected is both reasonable and non-negotiable. When that trust is undermined, the consequences extend beyond the immediate incident. Confidence in digital services&nbsp;</span><span style="color: #666666;">erodes, adoption slows, and the potential benefits of digital health are harder to realise.&nbsp;</span></p><p><span style="color: #666666;">The Manage My Health reviews are therefore a pivotal moment. They can either reinforce a pattern in which each incident is treated as isolated and exceptional or mark a genuine reset in how we approach digital health safety across the system. The latter requires courage, coordination and a willingness to move beyond minimum compliance towards shared responsibility.&nbsp;<br /></span></p><p><span style="color: #666666;">If we get this right, the outcome will not just be stronger cybersecurity. It will be a digital health environment that is more resilient, more transparent and more worthy of the trust that patients and clinicians place in it every day.&nbsp;</span></p>
<div>&nbsp;</div>
<p><em style="color: #666666;">If you want to contact eHealthNews.nz regarding this View, please email the editor&nbsp;<a href="mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</em></p>
<p>&nbsp;</p>
<p><span style="color: #666666;"><b>Read more&nbsp;<a href="https://www.hinz.org.nz/page/eHN-views" target="_blank">VIEWS</a></b></span></p>
<div>
    <hr style="color: #333333;" />
</div>
<p><strong><strong style="color: #666666;"><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong style="color: #666666;"><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></strong>
</p>]]></description>
<pubDate>Mon, 2 Feb 2026 01:55:00 GMT</pubDate>
</item>
<item>
<title>Cybersecurity funding scrutinised following MMH breach</title>
<link>https://www.hinz.org.nz/news/news.asp?id=719029</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=719029</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="Health Minister Simeon Brown" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial9/2025.01.20-Simeon-Brown.jpg" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" />Health Minister Simeon Brown defended the government’s funding of health cybersecurity in Parliament today (January 28) as Labour questioned whether Budget 2024 cuts to data and digital services left the health system more vulnerable.<br /></span></p><p><span style="color: #666666;">The questions follow a major data breach at private health organisation Manage My Health in December 2025 that compromised the personal information of more than 120,000 New Zealanders.<br /></span></p><p><span style="color: #666666;">Labour health spokesperson Ayesha Verrall challenged Brown on whether cuts to Health New Zealand's data and digital funding in Budget 2024 led to the cancellation of cybersecurity projects.<br /></span></p><p><span style="color: #666666;">More than $330 million earmarked for data and digital health initiatives at Health NZ was returned as part of budget savings in 2024.<br /></span></p><p><span style="color: #666666;">This included $186 million for 'Data and Digital Foundations and Innovation' and $144 million for 'Data and Digital Infrastructure and Capability – Enabling Health System Transformation' through to 2027-28.<br /></span></p><p><span style="color: #666666;">Verrall referenced Health New Zealand's annual review statement, saying that "planned future work on the next stage of cybersecurity capability uplift has been cut," and asked whether this related to the defunding of digital initiatives in Budget 2024.<br /></span></p><p><span style="color: #666666;">Brown said the government has "continued to invest in strengthening Health New Zealand's cybersecurity capability" with an additional $9 million in Budget 2024 and $10 million in Budget 2025.<br /></span></p><p><span style="color: #666666;">"Over the last two years, Health New Zealand has taken a number of important steps including adoption of new data sharing standards, increasing the use of multi factor authentication to access clinical systems and introducing 24/7 monitoring of devices and systems to detect, quarantine and respond to cyber incidents," Brown told Parliament.<br /></span></p><p><span style="color: #666666;">Brown said the government takes the security of health data extremely seriously.<br /></span></p><p><span style="color: #666666;">“That is why Health New Zealand has responded by running an all of government response, activated incident controllers to support Manage My Health, ensured that independent cyber security experts have been engaged to provide assurances of Manage My Health's response and provided support for the primary care as they respond,” he said.</span></p><p><span style="color: #666666;">Public Service Association national secretary Fleur Fitzsimons has also questioned the impact of budget cuts and <a href="https://www.hinz.org.nz/news/news.asp?id=694327" target="_blank">downsizing of the digital services teams</a> at Health NZ.<br /></span></p><p><span style="color: #666666;">"New Zealanders deserve a health system where their private information is protected. That requires proper investment in IT security and the experts who deliver it - not endless cost-cutting that leaves our systems vulnerable," Fitzsimons said.<br /></span></p><p><span style="color: #666666;">Manage My Health has 1.8 million registered users in New Zealand and the breach has prompted a number of investigations.<br /></span></p><p><span style="color: #666666;">The <a href="https://www.hinz.org.nz/news/718553/Ministry-review-to-examine-technical-failures-in-MMH-breach.htm" target="_blank">Ministry of Health will begin a comprehensive review</a> of the incident at the end of January, examining why critical vulnerabilities remained unaddressed before hackers accessed the system.<br /></span></p><p><span style="color: #666666;">Privacy Commissioner Michael Webster has also announced an independent inquiry under the Privacy Act to examine compliance and governance arrangements surrounding the breach.</span></p><p><span style="color: #666666;"><em><span style="font-size: 11px;">Image: Health Minister Simeon Brown</span></em></span></p><p><span style="color: #666666;"><em><span style="font-size: 11px;">&nbsp;</span></em></span></p><div><i style="color: #666666;">If you would like to provide feedback on this news story, please contact the editor&nbsp;<a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></div><p><span style="color: #666666;"><i>&nbsp;</i></span></p><p><span style="color: #666666;"><i>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a member of HiNZ, for just $17 a month.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Wed, 28 Jan 2026 02:57:00 GMT</pubDate>
</item>
<item>
<title>Ministry review to examine technical failures in MMH breach</title>
<link>https://www.hinz.org.nz/news/news.asp?id=718553</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=718553</guid>
<description><![CDATA[<p style="text-align: justify;"><em><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="color: #666666;"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial4/2021.05.13.privacy-image.jpg" style="border: 5px solid #ffffff; width: 250px; height: 167px; float: right; margin: 1px;" />The Ministry of Health will start a review of the Manage My Health cyber security incident and the response at the end of this month, with a final report expected by 30 April.</span></p><p><span style="color: #666666;">Privacy Commissioner Michael Webster has also announced an independent inquiry under the Privacy Act to examine compliance and governance arrangements surrounding the breach.</span></p><p><span style="color: #666666;">The Ministry review will look at why critical vulnerabilities remained unaddressed before hackers accessed the personal health information of more than 120,000 New Zealanders on 30 December 2025.</span></p><p><span style="color: #666666;">It will also determine whether vulnerabilities found in Manage My Health could be present in other patient portals used across the country.</span></p><p><span style="color: #666666;">Health Minister Simeon Brown commissioned the review following the breach involving the patient portal used by which has 1.8 million registered users.</span></p><p><span style="color: #666666;">"Patient data is incredibly personal and whether it is held by a public agency or a private company, it must be protected to the highest of standards," Brown said in his announcement.</span></p><p><span style="color: #666666;">The Ministry has now <a href="https://www.health.govt.nz/strategies-initiatives/programmes-and-initiatives/manage-my-health-data-breach">published detailed Terms of Reference</a>, outlining the scope of work developed in partnership with the Government Chief Digital Officer and the National Cyber Security Centre.</span></p><p><span style="color: #666666;">The technical assurance assessment will focus on the vulnerability in Manage My Health's Health Documents module and examine why it remained unaddressed despite the platform handling sensitive medical information.</span></p><p><span style="color: #666666;">The review will evaluate the portals’ security controls against industry norms and “assess whether the sensitivity of stored information was matched by appropriate protection standards”, the terms of reference say.</span></p><p><span style="color: #666666;">It will look at the company's capability and capacity to manage a critical health records platform securely, examining data lifecycle management and retention practices that left historical data on internet-facing infrastructure.</span></p><p><span style="color: #666666;">The investigation will also “assess the adequacy, timeliness, coordination, and escalation of response actions by MMH and Health NZ”.</span></p><p><span style="color: #666666;">The Privacy Commissioner's inquiry will determine whether appropriate security safeguards were in place and examine steps needed to prevent similar incidents.</span></p><p><span style="color: #666666;">"Given the scale of the incident, the sensitivity of the information and some of the systemic issues being identified, it's clear to me we need to investigate the privacy issues involved," Webster says.</span></p><p><span style="color: #666666;">His inquiry will establish the circumstances of the cyber security breach, examine impacts on affected people, and assess compliance with relevant standards and the Privacy Act.</span></p><p><span style="color: #666666;">This includes reviewing policy, contractual, and governance arrangements between Manage My Health, Health NZ, primary care providers, and other health sector agencies.</span></p><p><span style="color: #666666;">All reviews and investigations into the incident will coordinate to minimise duplication while maintaining independence, the documents say.</span></p><p><span style="color: #666666;">The Ministry review will produce an interim findings report highlighting key issues requiring urgent attention, followed by a comprehensive final report containing full findings, root cause analysis, and actionable recommendations to prevent similar incidents.<br /></span></p><p><span style="color: #666666;"><i>If you would like to provide feedback on this news story, please contact the editor&nbsp;<a href="mailto:mailto:ehealthnewsnz@gmail.com">Rebecca McBeth</a>.</i></span></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Thu, 22 Jan 2026 03:12:00 GMT</pubDate>
</item>
<item>
<title>GP2GP being stabilised then replaced</title>
<link>https://www.hinz.org.nz/news/news.asp?id=700240</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=700240</guid>
<description><![CDATA[<p><em style="text-align: justify;"><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth&nbsp;</em></span></strong></span></em></em></em></p><p><span style="text-align: justify;"><span style="color: #666666;"><a href="https://ebooks.hinz.nz/view/1063973919/" target="_blank"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial9/2025.03.17-nehr_-_image.jpg" style="border:5px solid #ffffff;   width: 250px; float: right; margin: 1px; height: 188px;" /></a>GP2GP is being stabilised and will either be replaced in the next few years or no longer required because health information will be available through shared digital health records, Health New Zealand | Te Whatu Ora says.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">GP2GP enables patient records to be electronically transferred from one practice management system (PMS) to another.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Primary care leaders have expressed concerns about ongoing issues with this vital service, saying these cause delays in care and introduce clinical risk.&nbsp;<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The latest GPNZ data and digital update says general practice is spending an increasing amount of time and resource managing and checking GP2GP transfers and fixing errors.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Interim chief information technology officer Darren Douglass says Health NZ is investing in stabilising the service, “with an operating model that ensures these stabilisation efforts last until another solution for transferring health records is in place.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“GP2GP will either be replaced in the next few years or no longer required because health information will be available through shared digital health records,” Douglass says in an update shared with primary care.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The GPNZ update says the Health NZ GP2GP team has been working closely with GPNZ and general practice managers to scope stabilisation requirements, as well as talking with HealthLink and PMS suppliers.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“The main issues identified relate to the patient file transfer size limit of 20MB, inconsistencies in data mapping, and difficulty identifying diagnostic results,” Douglass says.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“By July we are aiming to have updated GP2GP source code to PMS suppliers to deploy in their PMSs to support the safe and efficient transfer of patient records. By then, HealthLink will be supporting the transfer of files up to 50MB in size.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“We will also test the GP2GP patient file transfer process between PMS applications once the consistent version is in place, to ensure transfers are error free.”<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The Royal New Zealand College of General Practitioners (RNZCGP) president Luke Bradford says GP2GP is a vital service.&nbsp;<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“The GP record is the most complete health record for a patient in New Zealand and so its complete, secure and error free transfer from one practice to another is essential and does carry risk,” he says.&nbsp;<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“The College has for some time been concerned that HNZ has not grasped the significance of this application and has not prioritised solutions to the problems between PMS or led in driving the industry to address them.&nbsp;<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“As it is, records often arrive corrupted, or with missing or duplicated data. We remain clear that addressing this is important for clinical safety.”<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The GPNZ update says a workshop set up in early May will bring together data and digital leads with clinical and practice expertise to scope additional improvements that could be delivered before the end of June.<br /></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Douglass says enhancing and stabilising GP2GP will mean reduced clinical risk from missing, incorrect or incomplete patient data, as well as reduced admin time for general practices as staff will no longer have to spend time checking file transfers and correcting errors.</span></span></p><div>&nbsp;</div><p><span style="text-align: justify;"><span style="color: #666666;"></span></span><em style="color: #666666; text-align: justify;"></em><em style="color: #666666; text-align: justify;">To comment on or discuss this news story, go to the eHealthNews category on the&nbsp;<a href="https://forum.hinz.org.nz/c/general/news/140" target="_blank">HiNZ eHealth Forum</a></em></p><p><b><span style="color: #666666;"><em style="text-align: justify;"></em></span></b></p><p><b><span style="color: #666666;"><em style="text-align: justify;"></em></span></b></p><p><b><span style="color: #666666;"><em style="text-align: justify;"></em></span></b></p><p><b><span style="color: #666666;"><em style="text-align: justify;"></em></span></b></p><br /><p><b><span style="color: #666666;"><em style="text-align: justify;">You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a&nbsp;<a href="https://www.hinz.org.nz/general/register_member_type.asp" target="_blank">member of HiNZ</a>, for just $17 a month</em></span></b></p><p>&nbsp;</p><p><i style="color: #666666;"></i></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Mon, 5 May 2025 05:00:00 GMT</pubDate>
</item>
<item>
<title>‘Malicious actor’ steals health staff data</title>
<link>https://www.hinz.org.nz/news/news.asp?id=697087</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=697087</guid>
<description><![CDATA[<p><em style="text-align: justify;"><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS - eHealthNews.nz editor Rebecca McBeth&nbsp;</em></span></strong></span></em></em></em></p><p><span style="text-align: justify;"><span style="color: #666666;"><a href="https://ebooks.hinz.nz/view/1063973919/" target="_blank"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial2/2020.3.18.scams-image.jpg" style="border:5px solid #ffffff;   width: 250px; float: right; margin: 1px; height: 188px;" /></a>A ‘malicious actor’ accessed and downloaded occupational health and safety information of some Health New Zealand | Te Whatu staff during an IT security breach last October, the organisation has confirmed.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The breach affected employees from the Capital, Coast &amp; Hutt Valley and Wairarapa districts over a four-year period and the perpetrator is likely to face criminal charges.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">New Zealand’s largest trade union says that proposed cuts to Health NZ’s data and digital directorate will further compromise the security of the sensitive information it holds.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;"><a href="https://www.ccdhb.org.nz/news-publications/news-and-media-releases/2025-03-27-privacy-breach-public-notice/" target="_blank">Health NZ says</a> in a statement that as soon as the breach was detected, immediate action was taken to secure its systems and investigate the extent of the impact.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“That investigation has since shown the malicious actor accessed and downloaded occupational health and safety information relating to some current and former staff members across two Central region districts – Capital, Coast &amp; Hutt Valley, and Wairarapa - covering the period from 2020 to 2024,” Health NZ said.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The affected information ranges from general occupational health and safety records to more sensitive personal data, including medical assessments and health-related correspondence.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Health NZ reassured staff that there is currently no evidence the data has been shared publicly.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“We deeply regret that this has happened and sincerely apologise to anyone affected,” the agency said, adding that it continues to monitor the situation.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Health NZ is consulting on <a href="https://www.hinz.org.nz/news/news.asp?id=688136" target="_blank">plans to slash 1120 net roles</a> from the data and digital directorate’s current workforce of 2405 FTE as part of an effort to save $100 million a year from its budget.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Public Service Association (PSA) national secretary Fleur Fitzsimons says data and digital staff warned Health NZ last year about the rising risks if the cuts went ahead.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“This is just more proof that the damaging cuts to data and digital must be reversed, or more sensitive patient and staff information will be put at risk,” Fitzsimons says.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“Enough is enough. The latest breach should be ringing alarm bells in the Beehive. We urge the Minister to stop the cuts and reassure New Zealanders their information will be safe and secure.”</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">eHealthNews <a href="https://www.hinz.org.nz/news/news.asp?id=695821" target="_blank">reported this month</a> that the Minister of Health has asked Health NZ to assure him that proposed changes to its data and digital team will not impact frontline service delivery.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Health NZ says it reported the breach to the Office of the Privacy Commissioner and New Zealand Police, with criminal charges expected against the malicious actor. Meanwhile, it has advised people to remain vigilant against scams.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The national health organisation also pledged to strengthen its cybersecurity measures and learn from the incident.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“We are committed to continually strengthening our protections and will learn from this incident to make improvements to help prevent something similar from happening again,” a statement says.</span></span></p><p>&nbsp;</p><p><em style="color: #666666; text-align: justify;">To comment on or discuss this news story, go to the eHealthNews category on the&nbsp;<a href="https://forum.hinz.org.nz/c/general/news/140" target="_blank">HiNZ eHealth Forum</a></em></p><p><b><span style="color: #666666;"><em style="text-align: justify;"></em></span></b></p><p><b><span style="color: #666666;"><em style="text-align: justify;">&nbsp;</em></span></b></p><p><b><span style="color: #666666;"><em style="text-align: justify;">You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a&nbsp;<a href="https://www.hinz.org.nz/general/register_member_type.asp" target="_blank">member of HiNZ</a>, for just $17 a month</em></span></b></p><p>&nbsp;</p><p><i style="color: #666666;"></i></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Thu, 27 Mar 2025 05:00:00 GMT</pubDate>
</item>
<item>
<title>New NHI Format</title>
<link>https://www.hinz.org.nz/news/news.asp?id=682885</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=682885</guid>
<description><![CDATA[<p><em><span style="font-size: 12px;"><strong><span style="color: #666666;">SECTOR UPDATE - Health NZ<em style="box-sizing: border-box; color: #333333; background-color: #ffffff;"><span style="box-sizing: border-box; font-size: 12px;"><span style="box-sizing: border-box; font-weight: 700;"><span style="box-sizing: border-box; color: #666666;">&nbsp;<em style="box-sizing: border-box; color: #333333;"><span style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span style="box-sizing: border-box; color: #666666;">- Te Whatu Ora</span></span></span></em></span></span></span></em></span></strong></span></em></p><p><span style="color: #666666;"><strong>We are introducing a new format for the National Health Index (NHI) starting 1 July 2026. If you are a health IT service provider or medical device supplier, you will need to update your systems, devices, and processes for both the current and new format before 1 July 2026.<br /></strong></span></p><p><span style="color: #666666;">An NHI is a unique identifier given to every person in New Zealand from birth or their first interaction with health services. It links patient health information and supports the coordination of patient care.<br /></span></p><p><span style="color: #666666;">Read the media release: <a href="https://lnkd.in/gYxkAgQB" target="_blank">https://lnkd.in/gYxkAgQB</a><br /></span></p><p><span style="color: #666666;">Review the HISO Standard Compliance information: <a href="https://lnkd.in/gdnP_Ach" target="_blank">https://lnkd.in/gdnP_Ach</a><br /></span></p><p><span style="color: #666666;">Read the NHI Overview: <a href="https://lnkd.in/g2H2k_dW" target="_blank">https://lnkd.in/g2H2k_dW</a><br /></span></p><p><span style="color: #666666;">Read the NHI Format Change FAQs: <a href="https://lnkd.in/gevMXykm" target="_blank">https://lnkd.in/gevMXykm</a><br /></span></p><p><span style="color: #666666;">Ensure your systems are ready by completing the self-assessment on Health NZ’s Jira Service Management platform to update compliance, request support, and provide feedback: <a href="https://lnkd.in/gfbTVzH6  " target="_blank" id="https://lnkd.in/gfbTVzH6  ">https://lnkd.in/gfbTVzH6<br /></a></span></p><div><a href="https://lnkd.in/gfbTVzH6  " target="_blank" id="https://lnkd.in/gfbTVzH6  "></a><br /></div><div><span style="font-weight: 700; font-family: Garamond; color: #666666;">Source: Health NZ - Te Whatu Ora&nbsp;media release</span></div><p><span style="font-size: 10.5pt; font-family: Garamond; color: #666666;">Sector updates are provided by organisations to eHealthNews.nz and have not necessarily been edited or checked for accuracy. Any queries should be directed to the organisation issuing the release.</span><br /></p><div><hr /></div><p><span style="color: #666666;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;">Do you have an item to add to sector updates?</span></b><br /></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;"><span style="color: #666666;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="color: #666666;"><span style="font-size: 12pt; font-family: Arial, sans-serif;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><span style="color: #666666;"><span style="font-size: 10.5pt; font-family: Arial, sans-serif;">Email your information to us at&nbsp;</span><span style="font-size: 10.5pt; font-family: Arial, sans-serif;"><a href="mailto:updates@hinz.org.nz">updates@hinz.org.nz</a></span></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: red;">Return to&nbsp;</span></b><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif;"><a href="http://www.ehealthnews.nz/" target="_blank">eHealthNews.nz home page</a></span></b></p>]]></description>
<pubDate>Wed, 25 Sep 2024 05:00:00 GMT</pubDate>
</item>
<item>
<title>Cyber uplift slashes attack response times</title>
<link>https://www.hinz.org.nz/news/news.asp?id=680667</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=680667</guid>
<description><![CDATA[<p><em style="text-align: justify;"><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS -&nbsp;eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="text-align: justify;"><span style="color: #666666;"><strong><a href="http:"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial8/ehTALK_tiles_330x227_sonny_t.png" style="border:2px solid #ffffff;   width: 250px; float: right; margin: 1px 1px 5px; height: 172px;" /></a></strong></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">A programme to improve national cybersecurity capability following the Waikato cyberattack has slashed response times to high severity events and meant the system was not significantly impacted by the CrowdStrike outage.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The national Cybersecurity Uplift Programme was launched to address critical security gaps identified in the aftermath of the 2021 Waikato DHB ransomware attack.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The three-year programme finished at the end of June 2024, and a further two years of funding has been provided to maintain the maturity achieved so far.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">"At the end of that incident, the lessons learned were worked through, and we found we had a number of gaps in our security posture and our ability to protect ourselves at the district level," says Health New Zealand - Te Whatu Ora chief information security officer (CISO) Sonny Taite.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">One of the key milestones of this program was the establishment of the National Security Operations Centre (SOC), which became fully operational by the end of 2023. This brings together cybersecurity experts from across the country's 20 former districts.&nbsp;&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Speaking on the <a href="https://www.hinz.org.nz/page/PodcastEpisodes" target="_blank">latest episode of eHealthTalk NZ</a>, Taite says this centralisation of expertise and resources has enabled Health New Zealand to monitor and respond to cyber threats more effectively.&nbsp;&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“Our SOC receives thousands of security events every month," Taite says.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">"We categorise those events into high severity and those events to be noted. Our team targets a 15-minute response time for high-severity alerts and serves as one of our first lines of defence against cybercriminals.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“The speed of attackers nowadays is so fast that we always need to be getting better and better, using all of the tools at our disposal and continuing to innovate.”&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">Health NZ moved to a standardised security product and platform through 2023, reducing the coverage and impact of the CrowdStrike outage in July which crashed millions of Windows systems worldwide.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“If we had not done that work we would have had quite significant impact and disruption on the health system,” Taite explains.</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">The cybersecurity team also delivers an ongoing education and awareness programs aimed at the 90,000-strong workforce in the healthcare sector.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">"We have been spending a lot of time building awareness across our workforce because of the constant load of phishing and scam emails that attempt to trick our staff into clicking on malicious links," Taite says.&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">“We have made a lot of progress since the Waikato incident where we did not have those capabilities: there was no national SOC or many of the services we now have in place.”&nbsp;</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;"><br /><em>Hear more from Sonny Taite in the latest episode of <a href="https://www.hinz.org.nz/page/PodcastEpisodes" target="_blank">eHealth Talk NZ</a>.</em><br /></span></span></p><div>&nbsp;</div><div><em style="text-align: justify; color: #666666;">To comment on or discuss this news story, go to the eHealthNews category on the&nbsp;<a href="https://forum.hinz.org.nz/c/general/news/140" target="_blank">HiNZ eHealth Forum</a></em><br /></div><div><b><span style="color: #666666;"><em style="text-align: justify;"></em></span></b><br /></div><div><b><span style="color: #666666;"><em style="text-align: justify;">You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a&nbsp;<a href="https://www.hinz.org.nz/general/register_member_type.asp" target="_blank">member of HiNZ</a>, for just $17 a month.</em></span></b></div><div><b><span style="color: #666666;"><em style="text-align: justify;">&nbsp;</em></span></b></div><div><b><span style="color: #666666;"><em style="text-align: justify;"></em></span></b><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/default.asp?id=16118">Read more Information Governance news</a></span></b></div><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Tue, 27 Aug 2024 05:00:00 GMT</pubDate>
</item>
<item>
<title>National digital identity modernised for health</title>
<link>https://www.hinz.org.nz/news/news.asp?id=677348</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=677348</guid>
<description><![CDATA[<p><em style="color: #333333;"><strong>eHealthNews.nz editor Rebecca McBeth</strong></em><br /></p><p><em style="color: #333333;"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial3/2020.07.29.digital_identity_.jpg" style="border: 5px solid #ffffff; width: 250px; height: 132px; float: right; margin: 1px;" /></em></p><p><span style="color: #666666;">Health New Zealand Te Whatu Ora is modernising and consolidating its digital identity solutions to create a faster, more consistent process for up to 125,000 staff logging into its systems every day.</span></p><p><span style="color: #666666;">SailPoint has been piloted for corporate users within Health NZ since April, with plans to extend it to clinical systems in the coming months.</span></p><p><span style="color: #666666;">Garry Johnston, data and digital programme lead, national programmes, says the legacy systems that supported the 28 entities that became Health NZ still exist and the organisation needs to integrate these disparate systems into a unified framework.</span></p><p><span style="color: #666666;">This fragmentation means users, who often work across former DHB boundaries, experience inconsistent onboarding and access processes.</span></p><p><span style="color: #666666;">Health NZ has around 125,000 users logging into its systems on a daily basis, including employees, contractors, and external partners.</span></p><p><span style="color: #666666;">"Our users still experience the echo of the former organisations that those systems supported," Johnston said.</span></p><p><span style="color: #666666;">“We are looking at ways of consolidating and standardising the experience for our users.”</span></p><p><span style="color: #666666;">SailPoint is a cloud-based SaaS application and Johnston says the platform is expected to save considerable time and resources.</span></p><p><span style="color: #666666;">Previously, provisioning access could sometimes take several days or longer, but the aim is to reduce this to less than 2 hours. This frees up administrative time, allowing staff to focus on more critical tasks, he says.</span></p><p><span style="color: #666666;">The cloud-based platform has connectors deployed in each legacy environment. This means it can manage user access and entitlements across legacy systems, ensuring that users have the necessary entitlements based on their roles and locations.</span></p><p><span style="color: #666666;">“It makes our users’ experience faster, simpler, and more consistent no matter what legacy environment they connect into. When they start, when they change roles, or when they leave the organisation,” he tells eHealthNews.</span></p><p><span style="color: #666666;">Johnston explains that SailPoint is particularly helpful for new employees and those transitioning between roles, as traditionally staff often retained access to systems from previous roles, creating potential security risks.</span></p><p><span style="color: #666666;">The new platform ensures access is granted based solely on current needs and system owners can regularly certify and review user access.</span></p><p><span style="color: #666666;">“One of the core drivers for this programme of work is freeing staff from the drudgery of provisioning things manually: one of the key challenges for the health system is how we can drive efficiency and reduce the fragmentation that we have today,” he says.</span></p><p><span style="text-align: justify;"><span style="color: #666666;"><em>To comment on or discuss this news story, go to the eHealthNews category on the&nbsp;<a href="https://forum.hinz.org.nz/c/general/news/140" target="_blank">HiNZ eHealth Forum</a><br /></em></span></span></p><p><i style="color: #666666;"></i></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/default.asp?id=16118" target="_blank">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong>&nbsp;<strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Thu, 18 Jul 2024 23:35:00 GMT</pubDate>
</item>
<item>
<title>CISO warns of phishing attack on health system</title>
<link>https://www.hinz.org.nz/news/news.asp?id=674918</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=674918</guid>
<description><![CDATA[<p><em style="text-align: justify;"><em style="color: #666666;"><em><span style="font-size: 12px;"><strong><span style="color: #ff0000;"><em style="color: #333333;">NEWS -&nbsp;eHealthNews.nz editor Rebecca McBeth</em></span></strong></span></em></em></em></p><p><span style="text-align: justify;"><span style="color: #666666;"><strong><a href="http:"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial8/2024.06.13-Sonny.png" style="border:2px solid #ffffff;   width: 250px; float: right; margin: 1px 1px 5px 10px; height: 172px;" /></a></strong></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">A live phishing attack is targeting the New Zealand health system and staff should be cautious of emails that may compromise their organisations, says chief information security officer (CISO) Sonny Taite.<br /><br />Taite spoke at a Health New Zealand Te Whatu Ora stakeholder hui in June where he said the team had become aware of a phishing campaign targeting the collective health system. <br /><br />The malicious campaign is impacting up to 13 small and large organisations across the health sector.<br /><br />“We would like you to be very aware and cautious of emails that are being shared from compromised and impacted health organisations,” he said. <br /><br />“They are relying on the trust that we have with each other to compromise an email account and then use that email account to share phishing scam emails to you all.”&nbsp;<br /></span></span></p><hr /><p><span style="text-align: justify;"><span style="color: #666666;"><em><strong>You’ve read this article for free, but good journalism takes time and resource to produce. Please consider supporting eHealthNews by becoming a&nbsp;<a href="https://www.hinz.org.nz/general/register_member_type.asp" target="_blank">member of HiNZ</a>, for just $17 a month.</strong></em></span></span></p><hr /><p><span style="text-align: justify;"><span style="color: #666666;">He said the emails appear legitimate as they look like a file sharing invitation from Microsoft OneDrive or Microsoft SharePoint, but then ask for the person’s username and password to harvest those credentials.<br /><br />“We are aware of it and the PHOs are working to bring that knowledge and that awareness to you all as well,” he told the hui. <br /><br />He said the New Zealand health system is “fairly constantly under attack”. Another common target is ‘internet facing technology devices’ and there is also a significant increase in attacks on cloud computing environments. <br /><br />Taite said Health NZ has refreshed the <a href="https://www.tewhatuora.govt.nz/publications/health-information-security-framework/" target="_blank">Health Information Security Framework (HISF)</a> to make it easier for organisations to understand where to go for information and use this security framework to plan ahead. <br /><br />Guidance is now provided for four different types of organisations;  hospitals, micro to small organisations; medium to large organisations; and suppliers.<br /><br />Health NZ chief executive Margie Apa said cybersecurity is hugely important for protecting against bad actors, and to ensure public trust in the health system holding their personal data.<br /><br />“We operate on the trust and confidence of our communities and patients and people who gift us the information to help us do our work,” she said. <br /><br />Apa said the HISF will become core to the way that Health NZ commissions and engages with providers and that providers should set expectations with their IT vendors.<br /><br />“The Health Information Security Framework should be a really useful guide when you are negotiating with your vendors and providers of ICT services,” she said. <br /><br />“The onus is on the vendors to demonstrate how they are going to help you ensure that you are able to meet those security, privacy and also cybersecurity resilience issues. <br /><br />“I would encourage colleagues to see the Health Information Security Framework as another helpful checklist when you are assessing your own vendor’s performance and also selection of vendors.”</span></span></p><p><span style="text-align: justify;"><span style="color: #666666;">On June 25 Taite provided an update saying the cybersecurity team is, "seeing reduced incidences of this particular phishing scam reaching our people, however we are encouraging everyone to remain vigilant.  <br /><br />"This latest scam is a timely reminder that phishing emails are increasingly common and that people should always be cautious when receiving and opening emails, and especially before clicking on links or entering personal information," he tells eHealthNews.<br /><br />Some good advice to follow is:<br /></span></span></p><ul><li><span style="text-align: justify;"><span style="color: #666666;">Check the sender - even if it is someone you have dealt with before, are they sending you email content they typically would?<br /></span></span></li><li><span style="text-align: justify;"><span style="color: #666666;">If they are sharing a document, were you expecting them to send you something?  Does the document name sound legitimate?<br /></span></span></li><li><span style="text-align: justify;"><span style="color: #666666;">Scammers can use legitimate services such as Microsoft which may initially give a feeling of legitimacy, check each page that appears the whole way through.<br /></span></span></li><li><span style="text-align: justify;"><span style="color: #666666;">If you are being asked to re-authenticate, check that this is how you would normally do this – check the URL.<br /></span></span></li><li><span style="text-align: justify;"><span style="color: #666666;">If you click a link and are asked to enter your username and password, then stop, and look at the steps above.</span></span></li></ul><p><span style="text-align: justify;"><span style="color: #666666;"><br />If you do think you’ve clicked a link or entered some information you shouldn’t have, you should contact your IT team or supplier, and let <a href="https://www.cert.govt.nz/individuals/report-an-issue/">CERT NZ k</a>now.<br /><br /><br /><br /><em>Picture: CISO Sonny Taite presenting at the June stakeholder hui<br /></em></span></span></p><p><span style="text-align: justify;"><span style="color: #666666;"><br /><em>To comment on or discuss this news story, go to the eHealthNews category on the&nbsp;<a href="https://forum.hinz.org.nz/c/general/news/140" target="_blank">HiNZ eHealth Forum</a><br /></em></span></span></p><p><i style="color: #666666;"></i></p><p><b><span style="color: #666666;"><a href="https://www.hinz.org.nz/news/Default.asp?id=16118" target="_blank">Read more Information Governance news</a></span></b></p><hr style="color: #333333;" /><p style="color: #333333;"><span style="color: #666666;"><strong><span style="font-size: 18px; color: #ff0000;">Return to&nbsp;</span></strong><strong><span style="font-size: 18px;"><a href="http://www.ehealthnews.nz/" target="_self">eHealthNews.nz home page</a></span></strong></span></p>]]></description>
<pubDate>Wed, 12 Jun 2024 05:00:00 GMT</pubDate>
</item>
<item>
<title>Diagnosing the problem with medical device security in Australia</title>
<link>https://www.hinz.org.nz/news/news.asp?id=674700</link>
<guid>https://www.hinz.org.nz/news/news.asp?id=674700</guid>
<description><![CDATA[<p><em><span style="font-size: 12px;"><strong><span style="color: #666666;">SECTOR UPDATE - Claroty</span></strong></span></em></p><p><span style="color: #666666;"><strong><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial8/2024.06.11-Claroty.png" style="border: 2px solid #ffffff; width: 250px; float: right; margin: 1px 1px 5px 10px; height: 172px;" />Over the last few years, Australian hospitals and healthcare providers have been battered by cyber attacks.<br /><br /></strong>In 2021, a Victorian hospital network suffered a huge ransomware attack which left it unable to access patient files for over 2 weeks and delayed many surgeries. The same year, a Queensland hospital network was hit by a ransomware attack which forced them to turn to paper-based operations for over a month, significantly impacting workflows and the delivery of patient care. <br /><br />In 2023, a major cancer treatment centre in Sydney was caught up in a cyber attack, with hackers threatening to release stolen data unless hospital administrators paid a ransom. Meanwhile, the personal details of patients at a major Melbourne hospital were compromised after cybercriminals hacked a staff member’s private email. These are just some of the many stories gracing the front pages of Australian newspapers.<strong><br /><br />The facts call for greater action by Australia’s healthcare industry<br /></strong>The healthcare sector recorded more data breaches than any other Australian industry in 2023, and more than twice the number reported by the financial services sector, according to the most recent <a href="https://www.oaic.gov.au/__data/assets/pdf_file/0021/156531/Notifiable-data-breaches-report-July-to-December-2023.pdf" target="_blank">Notifiable Data Breaches Report</a>.<br /><br />There are several important explanations for this. Firstly, the healthcare sector represents a highly attractive target for adversaries because of the high value of stolen patient records. Secondly, hospitals simply cannot afford to have their operations go down, meaning they are far more likely to pay the ransom to get critical patient systems back online.<br /><br />Another contributing factor is that cybersecurity standards are weaker in healthcare than in other industries. The Australian Cyber Security Centre notes that the Australian healthcare industry in particular suffers from a <a href="https://www.theage.com.au/politics/victoria/auditor-general-hacked-into-hospitals-to-expose-online-security-flaws-20190529-p51sd9.html" target="_blank">lack of cybersecurity training</a>, <a href="https://www.abc.net.au/news/health/2018-08-21/lax-hospital-security-culture-could-undermine-my-health-record/10128274" target="_blank">lax security practices</a> and chronic underinvestment in technology and digital infrastructure.<br /><br />An indication of just how vulnerable healthcare systems are can be gained from recent global research by Claroty, which looked at the cybersecurity levels of critical medical devices, ranging from imaging systems to infusion pumps and more. <br /><br />The research found some alarming trends and statistics: One in four (23%) of medical devices—including imaging devices, clinical IoT devices and surgery devices—have at least one known security vulnerability, which has been previously exploited by adversaries.<br /><br />Furthermore, 14 percent of connected medical devices were found to be running an unsupported or end-of-life operating system, along with seven percent of surgical devices whose failure might endanger patient safety.<br /><br />The <a href="https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/my-health-record/report-a-my-health-record-data-breach" target="_blank">Australian Digital Health Agency (ADHA)</a>—which is responsible for My Health Records data held by state or territory bodies—said in its <a href="https://www.digitalhealth.gov.au/sites/default/files/documents/australian-digital-health-agency-annual-report-2022-23.pdf" target="_blank">2022-2023 annual report</a> it was strengthening its cybersecurity with a new, mandatory suite of security requirements that would harden clinical information systems against cybersecurity attacks, uplift information security and give better protection for consumer information. Every vendor with software products connected to the My Health Record system will need to supply extensive evidence to show conformance.<br /><br />The ADHA has “a clear plan to meaningfully support Australian healthcare providers and health technology partners to protect themselves and the critical health information they hold.” To this end, its website provides <a href="https://www.digitalhealth.gov.au/healthcare-providers/cyber-security" target="_blank">comprehensive advice</a> on cybersecurity covering how to set up a secure environment, how health service providers can protect information, and what can users do to secure information.<strong><br /><br />How we can improve the security levels of medical devices<br /></strong>In the meantime, much can be done to beef up the security of health IT systems and devices with some fairly basic cyber-hygiene measures. Below are some of the best ways to achieve this:</span></p><ol><li><span style="color: #666666;">Avoid connecting any equipment to the internet unless such a connection is strictly essential.</span></li><li><span style="color: #666666;">Isolate your connected medical devices—patient and surgical—from your corporate networks.</span></li><li><span style="color: #666666;">Where remote access is needed by employees, ensure that this is secured with strong credential management and multifactor authentication.</span></li><li><span style="color: #666666;">Furthermore, where remote access to healthcare systems must be extended to third parties such as vendors and contractors, healthcare providers should ensure this is even further controlled. Specifically, healthcare providers should segment these networks and operate under a principle of ‘least privilege’ i.e. only giving users the minimum access level required to fulfill their assigned roles.</span></li><li><span style="color: #666666;">Maintain a comprehensive and up-to-date inventory of all assets throughout your facility and identify those that are internet-connected and most likely to be targeted by attackers.</span></li><li><span style="color: #666666;">Patch internet-connected devices and systems as soon as software updates become available, especially those systems that bridge enterprise and medical networks.</span></li><li><span style="color: #666666;">Prioritise risk management efforts based on the role of the equipment and its vulnerability as measured by the Exploit Prediction Scoring System (EPSS) a data-driven, machine-learning model that estimates the likelihood a software vulnerability will be exploited.<strong><br /></strong></span></li></ol><p><span style="color: #666666;"><strong>The takeaway:<br /></strong>In summary, implementing and maintaining strong cybersecurity for healthcare systems is not rocket science: it is largely good housekeeping. However, the challenge is one of scale: a healthcare environment is a house with many rooms, all full of tempting targets for the bad guys. The good news is there are automated security solutions that can take the legwork out of this process, freeing up your time to focus on what matters most: patient care.<strong><br /><br /><br /></strong></span></p><p><span style="color: #666666;"><strong><a href="https://claroty.com/" target="_blank"><img alt="" src="https://www.hinz.org.nz/resource/resmgr/ehealthnews/editorial8/2024.06.11-Claroty-Logo.png" style="width: 250px;" /></a></strong></span></p><p><strong style="color: #666666;"></strong></p><p><span style="font-weight: 700; font-family: Garamond; color: #666666;"></span></p><p><span style="font-weight: 700; font-family: Garamond; color: #666666;"></span><span style="font-weight: 700; font-family: Garamond; color: #666666;">&nbsp;</span></p><p><span style="font-weight: 700; font-family: Garamond; color: #666666;">Source: Claroty media release</span></p><p><span style="font-size: 10.5pt; font-family: Garamond; color: #666666;">Sector updates are provided by organisations to eHealthNews.nz and have not necessarily been edited or checked for accuracy. Any queries should be directed to the organisation issuing the release.</span><br /></p><div><hr /></div><p><span style="color: #666666;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;">Do you have an item to add to sector updates?</span></b><br /></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 12pt; font-family: Arial, sans-serif;"><span style="color: #666666;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="color: #666666;"><span style="font-size: 12pt; font-family: Arial, sans-serif;"></span></span></b></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><span style="color: #666666;"><span style="font-size: 10.5pt; font-family: Arial, sans-serif;">Email your information to us at&nbsp;</span><span style="font-size: 10.5pt; font-family: Arial, sans-serif;"><a href="mailto:updates@hinz.org.nz">updates@hinz.org.nz</a></span></span></p><p style="background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;"><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: red;">Return to&nbsp;</span></b><b><span style="font-size: 13.5pt; font-family: Arial, sans-serif;"><a href="http://www.ehealthnews.nz/" target="_blank">eHealthNews.nz home page</a></span></b></p>]]></description>
<pubDate>Mon, 10 Jun 2024 05:00:00 GMT</pubDate>
</item>
</channel>
</rss>
