{"id":223814,"date":"2026-01-08T20:35:25","date_gmt":"2026-01-08T20:35:25","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/223814\/"},"modified":"2026-01-08T20:35:25","modified_gmt":"2026-01-08T20:35:25","slug":"criticism-of-manage-my-health-cyber-attack-response-mounts-as-another-deadline-passes","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/223814\/","title":{"rendered":"Criticism of Manage My Health cyber attack response mounts as another deadline passes"},"content":{"rendered":"<p><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/01\/4JV8FCI_Media_2_jpg.jpeg\" width=\"1050\" height=\"787\" alt=\"ManageMyHealth, Manage My Health generic images\"\/><\/p>\n<p class=\"photo-captioned__information\">\n<p>Photo: RNZ \/ Finn Blackwell\n<\/p>\n<p>New ransom deadline arrives<br \/>\nDeceased patients among those to have data breached<br \/>\nManage My Health response labelled &#8220;shambolic, frustrating and slow&#8221;<br \/>\nPatient told she is caught up in breach after being earlier told she wasn&#8217;t<\/p>\n<p>A new ransom deadline is thought to have arrived as criticism mounts of Manage My Health&#8217;s response to its <a href=\"https:\/\/www.rnz.co.nz\/news\/national\/582969\/managemyhealth-confirms-cyber-breach\" rel=\"nofollow noopener\" target=\"_blank\">hacking and massive data breach<\/a>.<\/p>\n<p>In an interview with RNZ this week, the country&#8217;s largest patient portal believed the new deadline was 5am on Friday.<\/p>\n<p>It would not be drawn on whether it was prepared to pay.<\/p>\n<p>The College of GPs said Manage My Health&#8217;s reaction to the cyber attack had been shambolic, frustrating and slow.<\/p>\n<p>&#8220;<a href=\"https:\/\/www.rnz.co.nz\/news\/political\/583535\/patients-ask-gps-for-info-on-health-records-after-manage-my-health-security-breach\" rel=\"nofollow noopener\" target=\"_blank\">Patients are really frustrated<\/a>, GPs are frustrated, there&#8217;s mixed amounts of information coming out,&#8221; president Luke Bradford said.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/01\/4L6PHXP_Dr_Luke_Bradford_1_png.jpeg\" width=\"1050\" height=\"787\" alt=\"Royal New Zealand College of General Practitioners medical director Dr Luke Bradford.\"\/><\/p>\n<p class=\"photo-captioned__information\">\nCollege of GPs president Luke Bradford.<br \/>\nPhoto: Supplied\n<\/p>\n<p>&#8220;Some practices are being told the number of patients they have affected but not which patients, my practice for instance was told we had 59 patients but not the patients&#8217; names, some practices are being given the patients&#8217; names, Manage My Health has said they&#8217;re going to contact patients but that hasn&#8217;t happened particularly quickly yet.&#8221;<\/p>\n<p>He said his own practice stopped using Manage My Health several years ago and it had no idea records were still being stored after that relationship ended.<\/p>\n<p>Manage My Health needed to up its game and give step-by-step instructions to not only affected patients and practices but everyone it still had records for, he said.<\/p>\n<p>RNZ has also received <a href=\"https:\/\/www.rnz.co.nz\/news\/political\/583535\/patients-ask-gps-for-info-on-health-records-after-manage-my-health-security-breach\" rel=\"nofollow noopener\" target=\"_blank\">multiple reports of the website crashing<\/a> as patients try to find out if they&#8217;ve been affected.<\/p>\n<p>Angus Chambers from the General Practice Owners Association was also unimpressed with how long it was taking to Manage My Health to contact patients.<\/p>\n<p>Those who had not yet been told their data had been breached had been left wondering whether it had, he said.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2025\/10\/4KKINDH_GenPro_jpg\" width=\"1050\" height=\"635\" alt=\"GenPro chair Angus Chambers, a Christchurch GP, says practices are going broke and being forced to hike fees and cut services.\"\/><\/p>\n<p class=\"photo-captioned__information\">\nAngus Chambers from the General Practice Owners Association.<br \/>\nPhoto: Supplied\n<\/p>\n<p>Manage My Health&#8217;s latest update said &#8220;direct notifications to the first 50 percent of patients affected&#8221; had commenced.<\/p>\n<p>It did not answer a request from RNZ to clarify that statement.<\/p>\n<p>Notifications were being sent by email to addresses affected patients used to register their account.<\/p>\n<p>An Auckland patient, Barbara, told RNZ she was disturbed after Manage My Health told her that her data had been breached after telling her two days earlier it had not.<\/p>\n<p>&#8220;I got an e-mail saying that my details hadn&#8217;t been impacted by the hacking, and that was fine, I thought &#8216;oh well, good&#8217;,&#8221; she said.<\/p>\n<p>&#8220;And then I got another email to say well actually, yes I have unfortunately.&#8221;<\/p>\n<p>Barbara said she was directed to go online to immediately change her password.<\/p>\n<p>&#8220;I got part way through and then there was a notification saying the website was down, I presume everybody who&#8217;s just been notified was trying to change their password immediately and it was overloaded,&#8221; she said.<\/p>\n<p>Barbara was now left trying to figure out what her data being breached meant for her, she said.<\/p>\n<p>&#8220;I can see for some people that have come forward, like the people who have suffered from abuse and things like that, you definitely don&#8217;t want that information out there.<\/p>\n<p>&#8220;But what else is there? And that&#8217;s what&#8217;s worrying me.&#8221;<\/p>\n<p>Another patient who RNZ has agreed to not name said Manage My Health should have known that lots of anxious patients would flood its website.<\/p>\n<p>&#8220;They are reporting problems with the platform on the platform that is having problems,&#8221; she said.<\/p>\n<p>Disability advocate Blake Forbes, meanwhile, said it was unacceptable that many people were still in the dark over a week after the cyber attack.<\/p>\n<p>&#8220;For me it&#8217;s causing, from a personal perspective, and I know a lot of friends are like this as well, it&#8217;s causing me a lot of anxiety, their GPs don&#8217;t even know what&#8217;s going on.&#8221;<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/01\/4K9UEFE_250328_Blake_Forbes_Gentle_1_jpg.jpeg\" width=\"1050\" height=\"700\" alt=\"Blake Forbes\"\/><\/p>\n<p class=\"photo-captioned__information\">\nDisability advocate Blake Forbes.<br \/>\nPhoto: RNZ \/ Samuel Rillstone\n<\/p>\n<p>Dead patients among those with records breached<\/p>\n<p>Manage My Health announced it had appointed an honorary clinical advisor in the wake of the breach, Emeritus Professor Murray Tilyard.<\/p>\n<p>He told RNZ the breach was significant, but varied from practice to practice.<\/p>\n<p>&#8220;So I&#8217;m aware of a clinical network who have over 100,000 enrolled patients, and 99.6 percent of those patients&#8217; records have not been breached,&#8221; he said.<\/p>\n<p>&#8220;Now, that doesn&#8217;t mean that other practice networks or practices don&#8217;t have a much higher proportion.&#8221;<\/p>\n<p>Tilyard expanded on what he said were three categories within the breach relating to three years of data between 2017 and 2019.<\/p>\n<p>The first was Northland hospital discharge summaries, he said.<\/p>\n<p>&#8220;So these only affect patients who were resident in that Northland area in those years, 2017 to 2019. We now know that many of them have shifted.&#8221;<\/p>\n<p>The second category was material uploaded by patients themselves.<\/p>\n<p>&#8220;It could be, for instance, I&#8217;ve notified via the portal that I&#8217;ve changed my address. It could be that I&#8217;ve actually uplifted my home blood pressure recording, or my weight.<\/p>\n<p>&#8220;So these are patient-generated documents.&#8221;<\/p>\n<p>The third was referral documents.<\/p>\n<p>&#8220;So I&#8217;m interested, once I&#8217;m briefed, to understand the mix of those,&#8221; he said.<\/p>\n<p>&#8220;Because that&#8217;s actually important to be able to tell the patients whose data has been breached what has actually been taken because some data, I would suggest both you and I would feel is more sensitive than other data.&#8221;<\/p>\n<p>Tilyard said he did not underestimate how patients would be feeling.<\/p>\n<p>&#8220;I mean, I go back to when I was very young and living at home in Wellington and we came back from holiday to find that people had broken the house and lived there for a week. My mother was devastated, she wanted to leave,&#8221; he said.<\/p>\n<p>&#8220;The house was tainted, her privacy was tainted.&#8221;<\/p>\n<p>Tilyard said his role would also include helping practices identify patients who were potentially vulnerable and may need more support.<\/p>\n<p>He said the breaches did not just affect patients.<\/p>\n<p>&#8220;I&#8217;m aware that some of the patients who start have been breached are deceased, so my strong view is that the practices must identify, obviously, those who are deceased.&#8221;<\/p>\n<p>He said next of kin must be identified and contacted because they themselves may be vulnerable.<\/p>\n<p>&#8220;In New Zealand there are 1022 individual general practices, so we&#8217;re mobilising.&#8221;<\/p>\n<p>Tilyard said he knew Manage My Health chief executive Vino Ramayah and offered his help.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/01\/1767781329_31_4JV7VPG_image_png.jpeg\" width=\"1050\" height=\"603\" alt=\"Manage My Health CEO Vino Ramayah\"\/><\/p>\n<p class=\"photo-captioned__information\">\nManage My Health CEO Vino Ramayah.<br \/>\nPhoto: SCREENSHOT \/ RNZ\n<\/p>\n<p>Manage My Health response &#8216;unacceptable&#8217;, site still has flaws<\/p>\n<p>Vimal Kumar, a senior lecturer at Waikato University&#8217;s Cyber Security Lab, said it had taken too long for Manage My Health to contact affected patients.<\/p>\n<p>He described the security breach as &#8220;a pretty major one&#8221;.<\/p>\n<p>&#8220;The company was made aware of this on 30th of December and they are reaching out to their users, people who have been affected now,&#8221; he said.<\/p>\n<p>&#8220;It&#8217;s shocking, and people are worried about the safety of their data and their own well-being.<\/p>\n<p>&#8220;And then to have to wait for nine days to get any information from the organisation is shocking, to be honest.&#8221;<\/p>\n<p>Kumar said other aspects of Manage My Health gave an indication of its security.<\/p>\n<p>&#8220;There&#8217;s something called DMARC (Domain-based Message Authentication, Reporting, and Conformance) which has not been set up properly.&#8221;<\/p>\n<p>He said this was something that was easy to configure.<\/p>\n<p>&#8220;Now, this particular hack is not related to DMARC, but that sort of gives you an idea of the cybersecurity posture of the organisation.<\/p>\n<p>&#8220;If the DMARC which is fairly easy to set up has not been set up, then what other things were not being done properly?&#8221;<\/p>\n<p>The key facts according to Manage My Health<\/p>\n<p>The cyber incident was limited to 6-7 percent of 1.8 million registered users, within the &#8220;My Health Documents&#8221; module only.<\/p>\n<p>The data relates to a range of medical practices, including:<\/p>\n<p>Approximately 45 Northland-based GP practices;<br \/>\nClinical discharge summaries and historical clinical referral records in the Northland region (data that is between six and eight years old)<br \/>\nApproximately 355 &#8220;referral-originating&#8221; GP practices across a number of New Zealand regions<br \/>\nPersonal health information uploaded by patients<\/p>\n<p><a href=\"https:\/\/radionz.us6.list-manage.com\/subscribe?u=211a938dcf3e634ba2427dde9&amp;id=b3d362e693\" rel=\"nofollow noopener\" target=\"_blank\">Sign up for Ng\u0101 Pitopito K\u014drero<\/a>, a daily newsletter curated by our editors and delivered straight to your inbox every weekday.<\/p>\n","protected":false},"excerpt":{"rendered":"Photo: RNZ \/ Finn Blackwell New ransom deadline arrives Deceased patients among those to have data breached Manage&hellip;\n","protected":false},"author":2,"featured_media":223815,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[48,47,111,43,139,69,49,46,44,45],"class_list":{"0":"post-223814","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-new-zealand","8":"tag-audio","9":"tag-current-affairs","10":"tag-new-zealand","11":"tag-news","12":"tag-newzealand","13":"tag-nz","14":"tag-podcasts","15":"tag-public-radio","16":"tag-radio-new-zealand","17":"tag-rnz"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/223814","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=223814"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/223814\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/223815"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=223814"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=223814"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=223814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}