Skip to main content
Click ITTauranga · NZ · Global

Cybersecurity

What New Zealand's 2025-26 Health Data Breaches Mean for Your Business

Click IT Team 2026-10-06 7 min read

What actually happened

The most significant New Zealand cyber incident in years began on 31 December 2025, when the privately owned patient portal Manage My Health was breached. Hundreds of thousands of medical files were taken, including hospital discharge summaries and GP referrals. The National Cyber Security Centre's report for the first quarter of 2026 rated it a C2 incident - a 'highly significant' event likely to affect key sensitive data or disrupt essential services. Before this, New Zealand had not recorded a C2 incident since the Waikato DHB breach in May 2021.

It was not isolated. In February 2026, a second privately owned patient portal, MediMap, identified unauthorised activity. In March 2026, private healthcare provider IntraCare reported a similar breach. Three major incidents in a single quarter, all touching health data, reshaped how seriously New Zealand organisations are now treating data protection.

What the regulator found

The Privacy Commissioner's Phase 1 report, released in May 2026, found that both Manage My Health and Health New Zealand 'failed in their responsibilities' to have reasonable security safeguards in place. In September 2026 the Commissioner went further and issued compliance notices to both organisations, with deadlines extending into 2027.

The significance is hard to overstate. These were not penalties for a mistake in a spreadsheet - they were findings that basic, well-understood security controls were missing from systems holding some of the most sensitive personal information in the country. The Office of the Privacy Commissioner's 2024-25 annual report had already flagged a 43% increase in serious privacy breaches notified to the regulator.

The pattern behind the headlines

Read across the incidents and the same weaknesses keep appearing: identity and access controls that were too weak, third-party and supplier exposure that had not been assessed, monitoring and logging that could not see what was happening, and incident response that was improvised rather than practised. None of these are exotic. They are the same gaps we find in audits of businesses of every size.

A survey of larger New Zealand organisations by Kordia and Aura Information Security found that only about half of boards had discussed cyber security, and that around half of organisations over 50 seats had never practised their incident response plan. A plan that has never been rehearsed is not a plan - it is a document.

What it means for your business

You do not have to be a hospital to be exposed. If you hold personal information - customer records, patient or student data, staff files, financial details - the same obligations under the Privacy Act 2020 apply, and the same controls are what protect you. The practical shortlist: multi-factor authentication on every account that matters, least-privilege access that is reviewed, logging and alerting you actually watch, third-party and cloud suppliers assessed for security, and a written incident response plan that gets rehearsed, not filed.

Where client or tender requirements are involved, certification against ISO/IEC 27001 is increasingly the evidence buyers ask for - a structured ISMS that proves those controls operate, not just exist. See our 2026 ISO/IEC 27001 guide for where the standard stands today.

Where to start

Start with the three controls that stop the most incidents: MFA everywhere, tested and immutable backups, and a rehearsed response plan. Then close the gaps that remain - access, patching, monitoring and supplier risk - using a risk assessment rather than a shopping list. Click IT packages this work as a security review and ISO/IEC 27001 readiness programme, delivered from Tauranga across New Zealand.

Quick answers

Under the Privacy Act 2020, any organisation holding personal information must have reasonable security safeguards, regardless of size or sector. The regulator has shown it will issue compliance notices where those safeguards are missing - and private companies have been on the receiving end.

Need help putting this into practice?

The Click IT team is based in Tauranga and helps businesses across New Zealand act on advice like this.

Last updated: 2026-10-06. This article is general information, not specific advice for your situation - talk to us about your circumstances.