Insurancebusinessmag New Zealand Privacy Commissioner Issues Compliance Notices After Major Data Breach
Article Content
- •Nearly 100,000 health records were exposed in a cyberattack on Manage My Health.
- •Both Manage My Health and Health NZ were found liable for inadequate security measures.
- •Compliance deadlines set for both organizations to improve data protection measures.
New Zealand's Privacy Commissioner, Michael Webster, issued compliance notices on September 23, 2026, to Manage My Health and Health NZ following a cyberattack in December 2025 that compromised health records of nearly 100,000 individuals. The attack targeted Manage My Health, which operates the largest patient health portal in New Zealand, resulting in the exposure of 403,730 Health NZ documents and 22,609 patient-uploaded documents. The breach primarily affected individuals in Northland, with 90% of those impacted residing there. The Privacy Commissioner found both organizations liable for failing to maintain adequate security controls, including deficiencies in access control and multi-factor authentication. Manage My Health has until August 31, 2027, to comply with the requirements, while Health NZ must meet its obligations by January 29, 2027. No financial penalties were imposed, but the Commissioner emphasized the importance of treating patient data securely.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Health NZ in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical RCE Vulnerability in F5 BIG-IP APM Exploited in the Wild A severe heap-based buffer overflow vulnerability, tracked as CVE-2026-94127, has been identified in F5 BIG-IP Access Policy Manager (APM), allowing unauthenticated remote code execution (RCE) on the Traffic Management Microkernel (TMM) data plane. This vulnerability is triggered when both an APM access policy and an…