Privacy Commissioner Michael Webster said the ordeal had caused “serious anxiety and distress” for many affected.
He announced in January an inquiry into the cyber security breach would be undertaken in two phases.
The results of phase one, which focused on the cause of the breach and accountability, were released today, finding the attack was caused by a combination of problems rather than a single security failure.
ManageMyHealth and Health NZ breached Rule 5 of the Health Information Privacy Code related to the storage and security of information.
Webster said several of ManageMyHealth’s technical security safeguards were inadequate at the time.
Key gaps in the organisation’s security allowed the attack, including a lack of systems to detect when large amounts of information were accessed.
The inquiry said such systems could have interrupted the hacker before so much information was stolen.
Questions were also raised about the quality of ManageMyHealth’s overall security design and risk management practices.
As for Health NZ, Webster said it should have done more to ensure information was safe before passing it on to Northland hospital patients through ManageMyHealth.
Of the 99,416 patients affected, 90,850 had data from Health NZ included.
Health NZ and ManageMyHealth had a unique arrangement in the region involving hospital discharge information, which is why most people caught up in the breach were from Northland.
Hospitals outside the region were not affected.
Webster said the project was “a novel digital project involving transfers of large amounts of health information”.
Privacy Commissioner Michael Webster.
According to the inquiry, the project team that engaged with ManageMyHealth did not include specialist privacy and security personnel needed for a project of this type and scale.
Instead of carrying out independent checks of the health portal’s security and privacy, the project team relied too heavily on information from ManageMyHealth.
The inquiry found poor-quality internal privacy risk assessments left project designers and decision-makers insufficiently informed about what was needed to safely share hospital information through the portal.
The contract between Health NZ and ManageMyHealth was not fit for purpose.
“It was generic rather than being designed to reflect how the information sharing would work and what was necessary to protect the information.”
Webster plans to issue compliance notices to ManageMyHealth and Health NZ.
“Compliance notices are the strongest tool I currently have available to me to respond to serious privacy breaches,” he said.
The notices require ManageMyHealth and Health NZ to demonstrate to Webster’s satisfaction that security improvements are effective.
The inquiry found GP practices were not liable as there was nothing they could have done to prevent the breach and were not the source of the stolen information.
ManageMyHealth apologised for the breach, saying it was a deliberate criminal attack that used compromised credentials to exploit a vulnerability.
ManageMyHealth offices in Auckland. Photo / Michael Craig
The organisation has since implemented security and operational improvements, including mandatory multi-factor authentication, enhanced real-time monitoring and alerting, strengthened access controls, and expanded independent security testing across the platform.
“We are continuing to work constructively with regulators and sector partners to demonstrate that our controls are in place and operating effectively.”
ManageMyHealth said it was not aware of any stolen data being publicly released beyond the initial sample shared.
“Ongoing dark web monitoring is in place, supported by High Court injunctions to restrict access to and further distribution of the data.”
Health NZ accepted the Privacy Commissioner’s finding it should have done more.
“On this occasion, patients were let down and that is unacceptable,” Health NZ chief financial officer Bevan McKenzie said.
“The incident revealed weaknesses in the Northland patient portal arrangement, which had been designed to improve patient services.”
McKenzie said Health NZ had stopped the flow of information from the Northland health district to ManageMyHealth, and apologised to any patients surprised to find their health information was stored in the portal.
Health NZ and ManageMyHealth had a unique arrangement in Northland involving hospital discharge information. Photo / NZME
Patient access to ManageMyHealth portals and their GP-related clinical records, appointments and repeat prescription services are unaffected.
McKenzie said measures were being put in place so Northland patients could immediately receive a paper copy of their discharge summary and to avoid impacting patient services.
“While ensuring people have timely access to their own health information is a priority for Health NZ, safeguarding the security of that information must always remain paramount.”
Health NZ commissioned its own independent review into the cyber breach, its relationship with ManageMyHealth and the management of Northland patient records to prevent a repeat.
The review called for sweeping reforms, including stronger national security standards, tighter oversight of third-party providers, and a full review of health data systems across the country.
While the inquiry focused on the ManageMyHealth breach, Webster indicated it was a wake-up call for the health sector.
He said while digital innovation, such as patient portals, could unlock more efficient and effective services, safety was paramount.
“Patients need to be able to trust that their sensitive health information is being protected.”
The Ministry of Health will tighten cyber security across the health system after its own independent review into the breach. It called one of the most serious experienced by the New Zealand health sector.
Measures include independent security checks on suppliers, stronger standards for handling health data, improved patient notification processes, and a wider review of digital health systems, with all recommendations accepted and work already underway.
Ministry of Health chief information officer Quin Carver said protecting people’s health information was fundamental to trust in the health system.
The second phase of the Privacy Commissioner’s inquiry is expected to start soon and will assess the attack’s impact.
Privacy complaints from affected patients could now be considered.
Further compliance action may result if it can be demonstrated breaches of the Privacy Act have occurred.