The New Zealand Privacy Commissioner issued Compliance Notices to both Manage My Health (MMH) and Health NZ this morning, finding that neither complied at the time of the December 2025 cyber attack with the security requirements of rule 5 of the Health Information Privacy Code. The notices follow the Commissioner's Phase 1 report in May 2026, which identified seven areas where security protections were ineffective; MMH has since improved three — the effectiveness of multi-factor authentication controls, restricting user access to information, and controlling unauthorised external access — and must complete the remaining requirements by 31 August 2027. Health NZ's notice concerns rule 5(1)(b) and the obligation to do everything reasonably in its power to prevent unauthorised use or disclosure before giving information to a service provider; its deadline is 29 January 2027. Commissioner Michael Webster drew attention to the affected population rather than the volume, noting that 90 per cent of the patients whose data was stolen are Māori in Northland. The significance is procedural: these are the notices the Commissioner signalled in May, and they convert a completed inquiry into enforceable, dated remediation obligations.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-23 |
| Source | NZ Office of the Privacy Commissioner |
| Reliability | Tier 1 |