The Health System Cyberattacks as a Catalyst for Exposure of New Zealand’s Digital Defences

by heidi lin

I Introduction

Cyberattacks are unauthorised attempts by malicious individuals to gain access to computer systems, networks, or digital devices to destroy, alter, or exploit vulnerable data. These breaches can cause immense stress for both the individuals or entities who must respond to a hacked system and the individuals whose information is involved. However, when the topic of privacy rights and data protection comes up, people immediately turn their minds to general information such as login credentials, web history, and addresses. But what about sensitive personal information, such as health information, which is equally, if not more, important? This article will firstly shine a light on the importance of protecting health information. The recent cyberattacks in New Zealand's (NZ) healthcare system and how these events have exposed gaps in NZ privacy laws will then be explored before finally examining the government's response.

II What Makes Health Information Special?

Sensitive personal information is information that has real significance to the individual who may wish for it to be kept private. Such information includes a person's race, religion, gender, sexual orientation, political beliefs, and, especially, health information. If exposed, this can risk the individual being treated in a negative light. A major issue that arises if health data is not protected adequately is the reinforcement of stigma and discrimination against particular conditions, which can contribute to underreporting and delay of support and treatment. These concerns are especially relevant for those suffering from mental and sexual health conditions who already encounter difficulties in seeking help from their community to restore their quality of life. Many have described carrying the stigma itself as more burdensome than the illness. Alongside stigma and discrimination, exposure of sensitive personal information can also lead to the loss of trust in the healthcare system, which is already problematic for Māori populations, who already have a long history of mistrust towards Western medicine due to poor experiences and conflict in beliefs and values. 

III The Recent Cyberattacks in the NZ Healthcare System 

The risks of health data vulnerability became apparent during recent cyberattacks which disrupted NZ's healthcare system. In 2021, what began with a phishing email led to what was considered the worst incident in NZ history, affecting the Waikato District Health Board. The breach led to all computer and phone-line systems shutting down as patient and staff information, such as health records and financial data, was accessed by the cybercriminals, and even published on the dark web

The exposure of poorly-equipped security protocols shifted to the private sector in December 2025 when the patient portal, Manage My Health, was hacked by a group named "Kazu" who threatened to release 428,337 files made up of names, medical records, test results, prescription details and more to the dark web if they were not paid a ransom of $104,000 NZD. This breach wreaked havoc and frustration amongst affected patients and GPs when the agency failed to provide clear and consistent information regarding the breach and was found to have breached the Information Privacy Principle (IPP) 5 of the Privacy Act 2020. Less than two months later, in February 2026, another cyber incident occurred involving the medication-management platform, MediMap, where patient information was altered, including saying they were deceased.  Shortly thereafter, in March 2026, yet again, a private healthcare provider, IntraCare, experienced a cyber breach, leading to all IT systems shutting down and 28 procedures being deferred or relocated. 

IV The Legal Framework

These major cyberattacks have exposed vulnerabilities in our system and gaps in NZ's privacy laws. Currently, NZ's privacy laws are fragmented, with no single piece of legislation mandating enforceable minimum cybersecurity requirements. The Health Information Privacy Code 2020 IPP 5 requires "organisations and agencies to use reasonable security safeguards to protect personal data from loss, unauthorised access, modification, disclosure, or misuse". However, "reasonable" is ambiguous and not a proactive step to ensuring compliance. Instead, it allows agencies to conduct self-assessments of their privacy practices, where the Privacy Commissioner has no power to conduct regular audits, a power many have voiced in the March 2025 privacy survey that the Privacy Commissioner should possess. Compared to other countries, NZ is falling behind on international trends. For example, in Finland, mandatory external security audits were strengthened and broadened, with no further major breaches reported since the Vastaamo incident in 2020. In the United States, the Health Insurance Portability and Accountability Act provides for federal audits of healthcare providers. 

Although liability was found against the involved agencies, such as Manage My Health, for breaching IPP 5, NZ privacy laws lack punitive teeth, with the strongest tool for responding to serious privacy breaches being a compliance notice. For example, following the MediMap incident, action involved Health NZ reminding healthcare providers to comply with minimum cybersecurity and privacy requirements. Mere reminders are insufficient to give people confidence that their sensitive information is safe, thereby pushing people away from the health system.

Besides NZ falling behind international trends in audit processes, many, including the Privacy Commissioner himself, have argued that NZ is also falling behind in penalty regimes. Currently, the Privacy Act 2020 has a fine capped at $10,000 NZD for very narrow administrative breaches, such as a failure to notify the Privacy Commissioner of a privacy breach, rather than a failure to have secure cybersecurity systems. Even then, this sum is merely a minor operational expense compared to a deterrent comparable to that of our neighbour, Australia, which has a maximum fine of $50 million AUD. 

V How is the Government Responding?

The first definitive step towards addressing the vulnerabilities of our systems was the Privacy Amendment Act 2025, which introduced IPP 3A and came into effect on 1 May 2026. IPP 3A imposes a new obligation on any agency that collects personal information indirectly from third parties to notify the individual that their information is being collected. This new obligation forces transparency and accountability on agencies, allowing individuals to exercise their privacy rights, such as accessing (IPP 6) and correcting (IPP 7) their personal information. However, even this step has its limitations, where the Privacy Act 2020 provides that IPP 3A does not apply to information collected before 1 May 2026 (s 25A). Although this boundary reduces significant burdens and is operationally feasible, a large amount of data collection remains hidden from individuals, leaving a transparency gap. 

Furthermore, the government has launched the Cybersecurity Action Plan 2026/2027, which imposes stricter compliance measures to incentivise the protection of personal information. The major proposal as part of the 2026/2027 Action Plan is the introduction of civil penalty and criminal liability regimes that move away from the questionable complaints-based model and impose strict penalties for negligence. On a more targeted framework, Health NZ has also introduced the NZ Health Action Plan in response to the Manage My Health cyber incident. Part of the Action Plan addresses auditing concerns by conducting regular audits and assurance assessments to maintain compliance with health security frameworks, including third-party risk management. Additionally, given the ongoing risk of cyber events, the NZ Health Action Plan requires agencies to conduct regular tabletop incident response exercises with those who hold sensitive health data. This would allow agencies to promptly practise and define their responsibilities in the event of emergencies, a primary issue which caused havoc and confusion in past cyberattacks. 

VI Conclusion

The cyberattacks on the Waikato District Health Board, Manage My Health, MediMap, and Intracare served as a troubling but necessary wake-up call about how NZ's privacy framework is falling short. Although the steps taken by the government are still in the proposal stage, these proposals provide a good starting point for moving away from a purely reactive system of encouraging compliance to a more proactive framework that enforces accountability and protects sensitive personal information, which poses significant risks if handled passively. 

==

The views expressed in the posts and comments of this blog do not necessarily reflect those of the Equal Justice Project. They should be understood as the personal opinions of the author(s). No information on this blog will be understood as official. The Equal Justice Project makes no representations as to the accuracy or completeness of any information on this site or found by following any link on this site. The Equal Justice Project will not be liable for any errors or omissions in this information nor for the availability of this information.