Your leading voice in digital health news
Twitter X Logo

Action Plan aims to strengthen Health NZ digital security

24 July 2026
By Reesh Lyon
Image: iStock

Health New Zealand today released an Action Plan to strengthen digital security across the health system, in response to the reviews into the Manage My Health (MMH) cybersecurity incident. 

Health NZ Chief Financial Officer Bevan McKenzie said following the MMH breach and the release of the reports, Health NZ took immediate steps to safeguard patient information – including stopping the data flow from Northland hospitals to MMH and ending the contract. 

“Health NZ continues to work with the Ministry of Health and primary care partners to strengthen privacy and security settings for how patient information is shared and managed across the system,” Mr McKenzie said.

“We are conducting assurance assessments of the six patient portals, including MMH, and work is progressing on a third‑party risk management framework and an incident response guide.”

PLAN OVERVIEW

The action plan outlines a review of six private patient portals, including Manage My Health, alongside the development of a sector engagement plan aimed at improving third-party security assurance across the health sector.

It says Health NZ will document measures to strengthen compliance with the Health Information Security Framework (HISF) and communicate updated sector compliance levels and thresholds.

Health NZ also plans to introduce a more structured approach to managing supplier risk – including developing criteria to classify suppliers as “high risk,” examining options for regular assurance of their security posture and HISF compliance and creating a register of suppliers that store or process sensitive health information. 

Suppliers will be tiered according to risk factors including the volume and sensitivity of records they hold, while associated contracts and data retention policies will also be documented.

As part of a broader risk management programme, Health NZ will undertake risk assessments across its digital portfolio to prioritise remediation of higher-risk systems, services and data. 

Milestones include establishing a baseline of around 10 per cent of systems assessed, implementing a streamlined risk assessment process, and increasing coverage to around 17.5 per cent of systems by the fourth quarter.

The plan also proposes changes to procurement and project governance, including minimum contractual standards aligned with the new government information sharing standard.

These standards will be incorporated into all new contracts, while existing high-risk contracts will be updated following risk assessments. Health NZ also plans to require formal privacy and security risk assessments before new projects proceed or procurements are undertaken, supported by documented assurance processes and risk decision records.

In regards to privacy, the action plan includes work to standardise patient and whānau notification and consent policies relating to the storage, access and processing of health information, alongside development of a health information storage and access consent framework.

It also calls for the Ministry of Health and Health NZ to jointly define processes, responsibilities and protocols for notifying patients following data breaches involving third-party suppliers.

The cyber incident response workstream includes regular tabletop exercises with critical suppliers that hold sensitive health data to test incident response arrangements and clarify roles and responsibilities. 

Health NZ also plans to develop an incident response capability improvement plan, approve an investment roadmap, and implement and test enhanced cyber incident response capabilities.

The plan also includes several measures specific to the Manage My Health incident, including updating Health NZ’s interoperability strategy and delivering a vendor-agnostic solution in Northland as an alternative means of sharing secondary care records with patients through patient portals. 

Health NZ will also seek an inventory of MMH’s critical third-party suppliers, review those contractual relationships, and assess what patient data is accessible to those suppliers.

Further actions require MMH to undertake penetration testing and purple/red team exercises, commission an external assessment of HISF compliance and provide the resulting reports to Health NZ – which will share them with the Ministry of Health. 

Health NZ will also seek assurances from MMH on data management practices, including user onboarding and offboarding processes, data retention periods, audit methodologies and whether patient data is accessible to suppliers or related parties, before closing out remaining security and privacy remediation items.

RISK-BASED APPROACH

Mr McKenzie said Health NZ was taking a “risk-based approach” to this work, beginning with patient portals and building more consistent assurance processes for higher-risk third-party services across the health system. 

“These initiatives are among the 19 priorities outlined in the Action Plan, many of which are already in progress. The plan brings together our response to the reviews’ findings, addressing gaps and focusing on the highest priority areas,” Mr McKenzie said.

“The plan aims to lift cyber security, privacy, and third‑party risk management across the health system, with strong oversight and measurable risk reduction. 

“Health NZ will work with the Ministry of Health on five actions that require joint oversight and coordinated delivery. Health NZ will monitor progress against the Action Plan through its Digital Transformation Committee. 

“Health NZ remains committed to strengthening digital security and working with partners across the sector to protect the privacy and security of patient information.”

Leave a Reply

Your leading voice in digital health news

Twitter X

Your leading voice in digital health news 

Keep your finger on the pulse with full access to all articles published on 
pulseit.news
Subscribe from only $39
magnifiercrossmenuchevron-down