The New Zealand Privacy Commissioner has issued Compliance Notices to Manage My Health (MMH) and Health New Zealand (Health NZ) following the December 2025 cyber incident that resulted in sensitive patient information being accessed and extracted.
Note: we do not know what Kazu the ransomware group did with the data it stole and threatened to publish. They only requested a small ransom of $60,000 and it disappeared from their leak site. It would be good to know if MMH paid a ransom or more importantly if they know if a ransom was paid (as it may have been paid on their behalf).
The breach affected approximately 99,416 individuals, with around 91% of affected people being Health NZ patients in Northland. The compromised information included 403,730 Health NZ documents and 22,609 documents uploaded by patients.
The Privacy Commissioner found that both organisations had breached requirements under the Health Information Privacy Code 2020.
The Compliance Notice issued to Manage My Health states:
“The Commissioner found that MMH did not meet its obligations under rule 5(1)(a) of the Code to ensure patient information it held in the My Health Documents module of the portal was protected, by such security safeguards as are reasonable in the circumstances to take, against loss, access, use, modification, or disclosure that is not authorised by MMH, and other misuse”
The notice also states:
“At the time of the breach, MMH’s key security safeguards were ineffective and did not meet the requirements of rule 5(1)(a) of the Code”
Seven areas of ineffective security controls
The Privacy Commissioner identified seven areas where security protections were ineffective:
- Multifactor authentication (MFA)
- Identity and access management
- Web security
- Patch and vulnerability management
- System acquisition, development, and maintenance
- Logging and monitoring
- Data leak prevention
The Phase 1 inquiry found that the incident was not caused by a single security failure. Rather, it involved a combination of weaknesses. The investigation also found that valid stolen patient credentials were used to access the portal and subsequently access and copy information belonging to thousands of other patients.
One particularly significant finding was that MMH’s own systems did not detect the attackers’ activity. The company became aware of the incident after being alerted by Health NZ.
Remediation requirements
The Compliance Notice sets out a number of specific remediation requirements for Manage My Health.
Issue A – Patch and vulnerability management
MMH is required to implement effective vulnerability management controls, including:
- Risk-based vulnerability remediation timeframes
- Addressing the underlying causes of vulnerabilities
- Identifying recurring vulnerability themes
- Validating that vulnerabilities have actually been remediated
- Appropriate governance and oversight
- Formal risk acceptance where applicable
The requirement is to be completed by 26 February 2027, with evidence supplied by 26 March 2027.
Importantly, the evidence must include outputs from recent penetration testing or security assessment, together with evidence showing how identified vulnerabilities were managed and resolved. A second penetration test or security assessment report is also required 6 months later to demonstrate continuing effectiveness which is something historically overlooked.
Issue B – System acquisition, development and maintenance
MMH is required to implement a structured secure development lifecycle (SDLC) incorporating security throughout system acquisition, development and maintenance.
This includes security-by-design principles, appropriate controls for access management and API security, protection of health information, and processes for tracking and remediating vulnerabilities identified during development and testing.
This requirement is also due by 26 February 2027, with evidence required by 26 March 2027.
Issue C – Logging and monitoring
MMH must implement effective logging and monitoring controls capable of detecting and responding to suspicious, abnormal or unauthorised activity.
It basically says to ensure appropriate logging and monitoring via a Security information and event management (SIEM). The requirements include:
- Appropriate log retention and accessibility
- Monitoring and analysis of log data
- Security alerts covering relevant threat scenarios
- Active monitoring of security alerts
- Processes for reviewing, triaging and responding to alerts
- Demonstrable capability for timely detection and response
The controls must be implemented by 30 November 2026, with evidence provided to the Commissioner by 22 January 2027.
Interestingly, while the notice requires effective monitoring and response, it does not specifically prescribe a 24×7 SOC. The important requirement is that the organisation can demonstrate that its monitoring and alerting capability can support timely detection and response in practice.
Issue D – Data leak protection
The fourth area is particularly relevant given the scale of the breach.
MMH is required to implement data loss prevention controls capable of detecting and preventing unauthorised access to or extraction of health information.
The controls must also be able to:
- Identify and quantify data access during an incident
- Detect suspected data exfiltration
- Generate alerts for suspected exfiltration
- Detect bulk data access and export activity
- Identify anomalous data access patterns
- Support timely investigation and response
Now as long as MMH completes Issue C, then this step is basically a couple of data leak detections in the SIEM, so not onerous.
Again, the deadline for implementing these controls is 30 November 2026, with evidence required by 22 January 2027.
What about MFA and Identity & Access Management?
One interesting aspect of the Compliance Notice is that although MFA and Identity and Access Management were two of the seven areas where controls were found to be ineffective at the time of the breach, they are not included as separate outstanding remediation issues in the schedule.
The Privacy Commissioner notes that MMH has already implemented MFA, IAM and web security controls following the incident.
The Phase 1 report also states that MMH had made MFA mandatory for all users and had fixed the particular vulnerability used by the attackers, although the Commissioner had not independently validated at that stage whether all the changes were operating effectively.
From a security operations perspective, there is still an important lesson here: implementing MFA and IAM controls is only part of the requirement for a mature security capability.
Organisations should also consider whether their SIEM and detection capability can identify situations such as:
- MFA being disabled or bypassed
- Unusual authentication patterns
- Excessive failed or successful authentication attempts
- Privilege changes
- New or unusual accounts
- Access to sensitive records outside normal patterns
- A legitimate account suddenly accessing large volumes of information
Controls can fail, be misconfigured or be bypassed, so it would have been good to see the notice require evidence of detections to be implemented to prevent slippage in future.
Compliance and enforcement
The Compliance Notice provides the Privacy Commissioner with the ability to take further enforcement action if MMH does not remedy the identified breach.
The notice states that:
“The Commissioner may bring enforcement proceedings in the Human Rights Tribunal if there is reason to believe that MMH has not remedied the breach as required by this notice”
The Commissioner has also stated that independent verification is important because MMH had already reported making changes following the incident, but those changes had not yet been independently validated.
All in all, MMH got away lightly with the Privacy Commissioner requiring them to do the basics of what a company should be doing if they are hosting Patient Identifiable data on the internet.
The wider lesson for healthcare organisations
The Manage My Health incident provides a useful example of why healthcare cybersecurity cannot rely on a single control such as MFA. (I’m sure Zenith Technology is watching closely)
The Privacy Commissioner’s findings cover the complete security lifecycle — from vulnerability management and secure development through to logging, monitoring and data loss prevention.
For organisations handling sensitive health information, the practical takeaway is that security controls need to work together.
A vulnerability management programme should identify and address recurring weaknesses. Secure development should prevent those weaknesses from being introduced or repeated. IAM and MFA should restrict access. Logging and monitoring should identify suspicious behaviour. Finally, data loss prevention and exfiltration detection should provide a last line of defence when an attacker manages to obtain legitimate access.
The incident also highlights the importance of independent assurance. Having policies, controls and security tooling in place is not necessarily enough. Organisations increasingly need to demonstrate that those controls are operating effectively — and that evidence can withstand regulatory scrutiny.
The Privacy Commissioner has published the Compliance Notices and Phase 1 inquiry report as part of the ongoing investigation.