The Privacy Commissioner has issued compliance notices to both Health NZ and Manage My Health (MMH) following the December 2025 cyber incident that resulted in the compromise of health information relating to approximately 99,416 individuals. Health NZ must complete its required actions by 29 January 2027 and provide evidence to the Privacy Commissioner by 12 February 2027. The MMH notice has a separate deadline of 27 March 2027 for the requirements listed by the Commissioner.
The Health NZ notice relates specifically to its obligations under Rule 5(1)(b) of the Health Information Privacy Code and the provision of hospital documentation through the MMH portal.
What did the Privacy Commissioner find?
The main finding from the Privacy Commission inquiry last year was that:
“Health NZ did not meet its obligations to ensure patient information would be protected to the required standards for due diligence, contract drafting, governance, risk management and ongoing assurance. These failures amounted to a breach of rule 5(1)(b) of the Code, as set out in the Inquiry Report.”
Another important finding was:
“Health NZ’s project team appear to have relied too much on assessments about the security and privacy of information provided by MMH, rather than taking a more independent view”
The Commissioner also identified deficiencies around due diligence, privacy risk assessments, understanding how the MMH system would manage Health NZ information, governance, involvement of privacy and security specialists, and the contracts between Health NZ and MMH.
The scale of the incident is significant. The Health NZ notice states that approximately 99,416 individuals were affected, with around 91% being Health NZ patients in Northland. Approximately 403,730 Health NZ documents stored in the affected “My Health Documents” module were compromised.
But what does this actually mean for Health NZ?
I won’t go too much into the details of the required actions, as I did that for the MMH notice. The more interesting question is what the Health NZ notice actually means for Health NZ as a whole.
The required actions start with:
“In order to ensure that everything reasonably within the power of Health NZ is done to prevent unauthorised use or unauthorised disclosure of patient health information when procuring digital services for the distribution of hospital discharge information to patients (services) by or through third-party service providers (providers) (the MMH Replacement Project), Health NZ must implement a project plan that appropriately identifies and manages privacy and security risk from governance, procurement, and implementation perspectives”
This is where things get interesting.
The wording specifically refers to “distribution of hospital discharge information to patients” and then goes even further by defining this as “the MMH Replacement Project.”
On one reading, this makes the scope of the compliance notice considerably narrower than the broader security lessons from the MMH incident might initially suggest.
Health information systems can contain many different categories of highly sensitive information — laboratory results, aged-care information, mental health information, allergies, clinical notes, medical photographs and other patient information, for example. The Privacy Commissioner’s Phase 1 findings themselves noted that health information can include clinical notes, lab results, vaccination records and medical photographs.
So the question becomes:
Does Health NZ only have to implement these particular governance, privacy, security and contracting requirements for systems used to distribute hospital discharge information to patients?
What about other third-party systems holding patient health information?
And what about other internet-accessible Health NZ solutions containing patient data for different purposes?
Do the same requirements apply to systems that aren’t primarily designed for sharing information directly with patients?
The wording in the notice
The Commissioner does appear to recognise that the issue has implications beyond the original MMH incident.
The notice states:
“4.5. However, the breach is not a matter that is solely of historic interest. Health NZ has informed the Commissioner that it is likely to consider other digital solutions for sharing hospital information with patients in the future. The Commissioner has therefore identified the steps that Health NZ must take to ensure it does not repeat the breach of rule 5(1)(b) that was identified by the inquiry, and that it is meeting its security obligations if supplying this patient information to a third-party service provider in the future.”
It also states:
“4.10. The steps that Health NZ has reported it has taken following the cyber security breach should reduce the likelihood of Health NZ’s breach of the Code being repeated. Health NZ is likely to consider other digital solutions for sharing hospital information with patients in the future. It is therefore necessary for Health NZ to take the steps required by this notice to further reduce the likelihood that this breach of the Code could be repeated in future.”
The notice therefore clearly has a future-facing purpose, but the prescribed actions are still framed around the procurement of digital services for distributing hospital information to patients.
Is this a “get out of jail free card” for other PHI systems?
That is perhaps the more interesting question for cyber security and privacy teams.
It would be a mistake to interpret the notice as meaning that other systems holding patient health information somehow fall outside Health NZ’s general privacy and security obligations. Rule 5(1)(b) itself applies where health information is given to a person in connection with the provision of a service to Health NZ, including storing, processing or destruction of that information.
However, the specific compliance notice is clearly targeted.
Its Schedule requires Health NZ to establish governance, privacy risk management, security requirements and contracting processes for the MMH Replacement Project. The requirements include independent privacy assessments, privacy impact assessments, security requirements, independent assessment against the Health Information Safety Framework, security testing aligned with NCSC standards, robust contractual obligations, assurance reporting and audit rights.
That creates an interesting distinction between:
What the Commissioner has specifically ordered Health NZ to do under this notice
and
What Health NZ may need to do more broadly to demonstrate that it is meeting its obligations when using third-party providers to handle health information.
The compliance notice itself should therefore not necessarily be read as establishing a blanket control framework for every Health NZ system containing patient health information.
The bigger cyber security lesson
For Health NZ, the real issue may ultimately be less about MMH and more about how the organisation manages third-party digital services that process patient health information.
The original inquiry identified problems with due diligence, governance, privacy risk assessment, security assurance and contracting. Those are not concepts that are unique to patient discharge documents.
The question for Health NZ — and potentially other organisations handling sensitive health information — is whether these lessons are being treated as controls for one replacement project, or as an opportunity to establish a consistent enterprise-wide approach to third-party systems handling PHI.
The Privacy Commissioner has already stated that Health NZ is a central provider of health services within the New Zealand public health system and that managing privacy and security risk around sensitive health information is important to restoring public trust in digital health services.
That makes the scope question particularly interesting.
Is the compliance notice simply a set of requirements for the MMH replacement, or will it become the template for how Health NZ should procure, assess, contract with, and continuously assure third-party systems handling patient health information more broadly?
That distinction could become just as important as the original breach. This should have been the Commissioners time to put everyone on notice to lift their game.
The Commissioner can bring enforcement proceedings in the Human Rights Review Tribunal if there is reason to believe Health NZ has not remedied the breach as required by the notice or fails to provide the required reporting.
For organisations working with Health NZ, third-party health platforms, or other sensitive patient information, the MMH case is therefore worth watching well beyond the replacement of the MMH portal.
Privacy Commissioner – Compliance Notices for Health NZ and Manage My Health