NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • Deloitte Fast 50
    • Generate wealth weekly
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In

Advertisement
Advertise with NZME.
Home / New Zealand

Manage My Health ignored warning about lax security system – cyber-security expert

RNZ
15 Jan, 2026 12:00 AM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save
    Share this article
Manage My Health. Photo / RNZ, Finn Blackwell

Manage My Health. Photo / RNZ, Finn Blackwell

By Ruth Hill of RNZ

IT experts allege Manage My Health ignored warnings about vulnerabilities in its cyber security for years – but the regulatory vacuum meant the company was not required to take action.

About 127,000 New Zealanders have had their information stolen in the ransomware attack after hackers were apparently able to obtain a password giving them access to part of its database containing more than 430,000 documents.

University of Auckland cyber security expert Dr Abhinav Chopra said he discovered the holes in Manage My Health’s system two years ago when he was trying to find out why it was still holding on to his health records after his GP moved to a new provider.

In an email to his GP, Manage My Health and eventually the Privacy Commission, he listed all the problems, including the lack of multi-factor authentication and the fact that multiple administrators had access to unencrypted files.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

“This is the same pattern. They should have invested. They’ve had two years and these are the exact same areas that have caused them the issue.”

The company did not respond to him, he said.

Manage My Health has said it is required to hold on to patients’ data – even if their GP switches provider – unless patients deregister themselves.

Advertisement
Advertise with NZME.

However, Chopra believes Manage My Health could have another reason for holding on to patient records.

Its own website proudly notes its database of “1.8 million Kiwis” and its ability to get its customers’ message to them “when they’re thinking about their health”.

“If this company did not have any commercial gains to make out of this data, then they would not be paying the extra storage costs for this data,” Chopra said.

Terms and conditions gave company an ‘out’

A Wellington IT worker caught up in the Manage My Health data breach – whom RNZ has agreed not to name – also questioned the lack of regulatory checks and balances.

“Health services that have this information and these functions should be subject to the same scrutiny and compliance requirements and auditing as financial institutions.

“If your banking app is down, it’s a huge deal and it gets lots of scrutiny.”

However, Manage My Health’s users could not say they were not warned, she said.

“The irony is that I actually read their terms and conditions, and they haven’t breached them because their entire terms of usage is they can’t guarantee their system is any good or that they’ll fix it, even if it’s foreseeable and they know about it.

“It’s essentially, ‘We can’t guarantee our product doesn’t suck, but here, give it a go’.”

Digital specialist Callum McMenamin (who also alerted Manage My Health to its security vulnerabilities six months ago) said the 300-page Health Information Security Framework contained many good things – but entirely relied on “hand-wavy” self-regulation.

Advertisement
Advertise with NZME.

“It’s all just a high-trust system where the Government sets the standards but then closes its eyes and doesn’t check if the standards are actually being met.”

Industry has opposed regulation - commentator

According to political analyst Bryce Edwards from The Democracy Project, the lack of regulatory oversight was “not an accident”.

The Digital Health Association – the industry body for health software vendors – had lobbied against what it called “overly burdensome privacy laws and regulation”, he said.

“They have time and time again asked government to keep the rules on privacy quite weak and relaxed so the companies that deal with data are not subject to too much of what they call ‘red tape’ or essentially costs on them.”

Successive governments had ignored warnings from three Privacy Commissioners over the last 15 years of the need for stronger penalties, like in Australia, where errant companies faced multimillion-dollar fines, Edwards said.

The Digital Health Association pushed for the repeal of the Therapeutic Product Act, which would’ve regulated software as a medical device with surveillance and penalties for non-compliance, he continued.

Advertisement
Advertise with NZME.

“If you don’t have these rules, if you don’t have penalties for companies not looking after data, it means they can often be quite lax. They don’t have good systems because they don’t have those incentives.”

Industry group advocates for ‘better’ legislation

Digital Health Association chief executive Stella Ward said the organisation did not oppose the Therapeutic Products Act (TPA).

“Across all our submissions and briefings, we repeatedly advocated for better regulation – not less.

“Our concern was that the bill, as drafted, lacked clarity and risked creating broad, impractical definitions that would not achieve best‑practice oversight.”

The association supported “the intent” of the bill: ensuring modern, fit-for-purpose regulation that keeps New Zealanders safe, she said.

Current privacy penalties were low by international standards – but international experience showed “stronger penalties alone do not prevent incidents” and continuous investment was required.

Advertisement
Advertise with NZME.

“What matters most is having a clear, consistent regulatory framework that supports safe, efficient delivery of digital health services while protecting patients’ rights.”

Health NZ mulls independent cyber-security auditing in future

Health NZ said it was Manage My Health’s responsibility to ensure the data it was contracted to manage was “safe”.

The Health Information Security Framework (HISF) – published by Health NZ – was intended to “guide” the health sector in the secure use and management of health and information technology.

“Health NZ expects health sector providers to have safeguards in place to protect health information, including assessing the security of their IT service providers, aligned to the recommendations of the HISF.”

However, a spokesperson indicated oversight could be introduced in future.

“As Health NZ progresses implementation of measures to increase the accessibility and security of health information, we are considering what further assurance of third-party providers against regulations and standards is required.

Advertisement
Advertise with NZME.

“This may include independent testing of third-party services such as patient portals.”

Save
    Share this article

Latest from New Zealand

New Zealand

Why the world’s fattest parrots now feel frisky enough to save their species

15 Jan 01:26 AM
New Zealand

Federated Farmers names new chief executive

15 Jan 01:24 AM
New Zealand

Three dead in 48 hours: Police issue plea after crashes near Rotorua

14 Jan 11:13 PM

Sponsored

Discover Australia with AAT Kings’ easy-going guided holidays 

15 Jan 12:33 AM
Advertisement
Advertise with NZME.

Latest from New Zealand

Why the world’s fattest parrots now feel frisky enough to save their species
New Zealand

Why the world’s fattest parrots now feel frisky enough to save their species

A bumper rimu fruit crop means conservationists expect over 50 chicks.

15 Jan 01:26 AM
Federated Farmers names new chief executive
New Zealand

Federated Farmers names new chief executive

15 Jan 01:24 AM
Three dead in 48 hours: Police issue plea after crashes near Rotorua
New Zealand

Three dead in 48 hours: Police issue plea after crashes near Rotorua

14 Jan 11:13 PM


Discover Australia with AAT Kings’ easy-going guided holidays 
Sponsored

Discover Australia with AAT Kings’ easy-going guided holidays 

15 Jan 12:33 AM
NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2026 NZME Publishing Limited
TOP