New Zealand’s Privacy Commissioner has issued formal compliance notices to both Manage My Health and Health NZ – and the way liability was split between them is the detail that matters most for brokers.
Privacy Commissioner Michael Webster issued the notices on September 23, 2026, following a cyberattack in December 2025 that exposed the health records of nearly 100,000 New Zealanders. Each organisation was found to have breached the Health Information Privacy Code under separate provisions. One operated the portal. The other supplied the data. Both were held liable.
The attack targeted Manage My Health, which operates New Zealand’s largest patient health portal. Hackers compromised 403,730 Health NZ documents and 22,609 documents uploaded by patients, according to RNZ. Around 90% of those affected were based in Northland.
The Office of the Privacy Commissioner’s (OPC) Phase 1 Report, released in May 2026, identified seven areas where security controls were inadequate at the time of the attack – including gaps in access control, insufficient multi-factor authentication (MFA), and deficiencies in data leak prevention and incident detection.
Manage My Health has until August 31, 2027, to complete all requirements. Three of the seven – covering multi-factor authentication, user access restrictions, and controls against unauthorised external access – have already been addressed. Health NZ must comply by January 29, 2027, according to the Office of the Privacy Commissioner.
Read next: Ransomware group claims cyberattack on Dunedin clinical trial company
The dual liability structure is the part brokers should examine carefully. Manage My Health was found to have breached Rule 5(1)(a): the obligation for health agencies to maintain reasonable safeguards against loss, misuse, or disclosure of personal information.
Health NZ was found to have breached Rule 5(1)(b): the obligation to do everything reasonably within its power to prevent unauthorised use or disclosure before passing health information to a service provider.
Health NZ did not run the portal. It handed over the data. The regulator held it liable under a different rule, for a different failure.
Webster said the notices were significant for the communities most affected. “Health information by its nature is sensitive personal information and this breach affected many people, whanau, and communities,” he said.
He added: “These Compliance Notices will ensure, and confirm to me, that Manage My Health and Health NZ are treating patient data securely and it will give New Zealanders assurance that we take these breaches seriously and that strengthening systems is vitally important.”
The notices carry no financial penalty. Under the Privacy Act 2020, monetary penalties of up to NZ$10,000 apply only to a narrow set of procedural offences. There is no civil penalty for breaching the information privacy principles themselves.
The Privacy Commissioner has called for that to change. In a submission to Parliament’s Petitions Committee earlier this year, Webster said the Act “does not provide sufficient incentives for many organisations to understand or meet even the most basic privacy requirements.”
By comparison, serious privacy breaches in Australia can attract fines of up to AU$50 million, according to Consumer NZ. No equivalent penalty regime exists here.
For brokers advising clients on coverage limits, the direction of travel on enforcement is worth factoring into placement conversations now.
The liability structure in this case maps directly onto a coverage problem that is becoming more common across New Zealand’s cyber market. Jack Petts, principal in Marsh Specialty’s cyber practice, has noted that brokers who use current soft-market conditions to sharpen policy language – rather than simply reduce premiums – are better placed when losses arise. “The first is securing strong coverage wording now,” he said, pointing specifically to contingent business interruption protection that reflects real vendor dependency.
Dependent Business Interruption cover responds when an insured suffers loss from a disruption at a third-party vendor, where the insured’s own environment is not the point of failure. Coverage triggers vary between carriers, and some policies require a defined “security failure” to activate that cover at all.
Whether a client’s policy responds when the breach originates with a vendor – rather than the client directly – can turn entirely on specific wording. Most clients never ask that question until a claim is already in motion.
The Manage My Health case sits within a broader pattern of rising cyber risk in New Zealand. The National Cyber Security Centre (NCSC) recorded NZ$5.6 million in direct financial losses in Q1 2026, a 76% increase on the previous quarter. Three incidents during that period were classified at the C2 “highly significant” level – the first time that threshold had been reached since the 2021-22 financial year. Of the 77 incidents requiring specialist technical support that quarter, 17% were assessed as likely linked to state-sponsored actors, according to the NCSC’s Q1 2026 Cyber Security Insights report.
Some New Zealand cyber policies exclude losses attributed to state actors outright. That makes attribution language a practical consideration before any incident, not after.
The NCSC’s Cyber Threat Report 2025 separately identified supply chain vulnerabilities and unpatched systems among the most commonly exploited attack vectors – consistent with the inquiry’s finding that the Manage My Health breach resulted from a combination of control failures rather than a single point of entry.
Read next: What the Gemini and Claude hacking incidents mean for cyber insurers
Health NZ chief financial officer Bevan McKenzie said much of what the compliance notice requires was already underway.
“The specific arrangement under which Northland hospital discharge information was provided through Manage My Health has already ceased. Health NZ continues to work with the Ministry of Health and primary care partners to strengthen privacy and security settings for how patient information is shared and managed across the system,” McKenzie said.
McKenzie said Health NZ was also progressing third-party risk management work and developing an incident response guide.