Waikato Herald
  • Waikato Herald home
  • Latest news
  • Sport
  • Business
  • Rural
  • Lifestyle
  • Lotto results

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • On The Up
  • Sport
  • Business
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
  • Lifestyle
  • Lotto results

Locations

  • Hamilton
  • Coromandel & Hauraki
  • Matamata & Piako
  • Cambridge
  • Te Awamutu
  • Tokoroa & South Waikato
  • Taupō & Tūrangi

Weather

  • Thames
  • Hamilton
  • Tokoroa
  • Taumarunui
  • Taupō

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Waikato News

Waikato DHB cyberattack: Board prewarned security was severely compromised

Natalie Akoorie
By Natalie Akoorie
Local Democracy Editor·Other·
11 Nov, 2021 08:17 PM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

4200 people were affected by the breach. Photo / 123RF

4200 people were affected by the breach. Photo / 123RF

The Waikato District Health Board was warned its IT security was inadequate and severely compromised just months before a massive ransomware attack that brought Waikato Hospital to its knees.

An internal cyber security document dated December last year also warned that a lack of training meant staff posed an unintentional threat to its systems.

However, Waikato DHB said the strategy was only a draft that was part of a wider digital strategy about to be heard by the DHB's commissioners when hackers struck on May 18.

The draft strategy, seen by Local Democracy Reporting, says the DHB's IT security was compromised by outdated systems, infrastructure and staff resourcing, making it a sitting duck for a major cybersecurity attack.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

In the aftermath of the cyberattack, some cancer patients were transferred and elective surgeries postponed as hackers brought down hundreds of servers and patient and staff information was dumped on the dark web.

The strategy said at the time there was no cyber security incident response plan and noted the urgent incident response option available to staff at Waikato Hospital was to "unplug network equipment".

It appears to be a damning indictment of the state of IT security at the DHB five months before the cyber security breach.

The 32-page report said Waikato DHB:

Advertisement
Advertise with NZME.

* Was still using Windows XP on some systems, a software released in 2001 that has been unsupported for five years;

* Relied on "perimeter security" such as firewalls, blocking, and malware protection that was becoming outdated as the DHB moved to cloud-based services;

* Struggled with multiple IT applications with inconsistent functionality, most very old and with poor support if any;

* Was behind on patching, the installation of critical software updates for security purposes;

* Did not have enough IT staff to manage and co-ordinate IT security with no cyber security specialist, and investments in cyber security were not prioritised;

* Did not have continuously monitored cloud services to detect suspicious behaviour;

* And did not have appropriate policies or training for staff around IT security.

The strategy, authored by two DHB employees, estimated the DHB had at least 800 software applications, many of them known to be duplicating significant functionality.

"Some of the legacy systems do not have security setups that can be modernised to protect against current security threats, and the majority are based on technology that is so old that it can no longer be patched or updated to guard against emerging security threats."

There was no procurement policy designed to monitor and regulate the purchase of medical devices used in patient care.

Advertisement
Advertise with NZME.

This meant they were often bought based on vendor demonstrations without consideration of compatibility.

"As a result, the DHB has many systems and devices that were acquired to perform a clinical role but which have many security holes that are difficult to plug."

The strategy gave an example of clinical devices connectable to the internet that were running Windows XP.

"These old control systems cannot be patched, and when the machines are plugged into the network they pose significant risk to the DHB's network and other devices."

The devices had poorly configured IT security controls that could be compromised by malware, resulting in bad readings, corrupted data, or even being hacked for patient data.

"This creates clinical risk for patients and for the DHB."

Advertisement
Advertise with NZME.

There was also no "follow-you" printing model at the DHB, meaning unauthorised parties could potentially view printed information at the printer.

The document said a skills deficit in the IT unit meant the DHB's IT operations approach was to reduce cyber risk by locking systems down and limiting access.

"DHB clinical staff have responded to this by turning to 'shadow IT' – informal software applications and personal hardware devices – which in turn increases IT risk even more, creating a never-ending risk cycle that gets worse with every turn."

With a limited budget, Waikato DHB was faced with a difficult choice when allocating resources, the report said, and cyber security had not been a priority when the DHB was struggling to meet minimum requirements for IT provision to support the delivery of healthcare.

"This trade-off is a common one at the DHB, even though the consequences of a targeted cyberattack would be catastrophic for patient safety."

Sources told Local Democracy Reporting the draft strategy was abandoned because of cost but Waikato DHB chief executive Dr Kevin Snee said: "This was a working document that was an input into the broader Digital Health Strategy that subsequently came to the executive on May 13."

Advertisement
Advertise with NZME.

"It proposed substantial investment into digital technology, was supported by the executive, and was due to go to the commissioners on May 26 but was interrupted by the cyberattack."

A DHB spokesperson said the work had been initiated by the DHB's new digital leadership to address any areas that required attention, and support the migration to new solutions such as cloud-based applications, which would also introduce new cyber security considerations as it moved systems outside the "perimeter security" setting of firewalls, intrusion and malware protections.

"The document had not yet reached final draft, had not been reviewed or qualified and had not been presented to management or governance."

The broader Digital Health Strategy, which would have involved substantial investment, was presented to the executive and supported on May 13 and was due to go to the Finance Risk and Audit committee on May 26, the spokesperson said.

"The security strategy work would have informed the Digital Health Strategy as one aspect of that wider programme."

It had not been costed and any associated work programmes not confirmed.

Advertisement
Advertise with NZME.

"This work was interrupted by the cyberattack but has now been restarted."

When asked whether the strategy could have prevented the attack if implemented, the spokesman said elements described in the strategy were under way and in some cases accelerated, such as the migration to the Cloud and organisation-wide adoption of Windows 10.

"...There is no current evidence to indicate whether full implementation of the draft long-term strategy would have impacted the May 18 event."

The spokesman said Windows 10 was deployed on all compatible machines at the time of the cyber-event.

"It is noted that it is not possible in all instances to run Windows 10 due to specific peripheral hardware or medical compliance needs. Mitigations were taken to protect those machines."

The DHB has now recovered from the attack and is continuing to investigate what led to it.

Advertisement
Advertise with NZME.

To date, it has not been said what cost has been incurred by the incident but more than 4200 people were affected and at least 22 people have notified the DHB of a privacy breach.

Complaints have also been lodged with the Privacy Commissioner but a spokesperson would not say how many.

Save

    Share this article

Latest from Waikato News

Waikato Herald

Probe into man who abused girl as he read her stories led to another sinister finding

19 Jun 07:00 AM
Waikato Herald

Hate skiing? Try these snow-free winter adventures in NZ instead

19 Jun 06:00 AM
Waikato Herald

Winter fire warning for seniors after Waihī death

19 Jun 06:00 AM

Jono and Ben brew up a tea-fuelled adventure in Sri Lanka

sponsored
Advertisement
Advertise with NZME.

Latest from Waikato News

Probe into man who abused girl as he read her stories led to another sinister finding
Waikato Herald

Probe into man who abused girl as he read her stories led to another sinister finding

19 Jun 07:00 AM

William Seddon had a collection of child abuse images, said to have led to the assaults.

Hate skiing? Try these snow-free winter adventures in NZ instead
Waikato Herald

Hate skiing? Try these snow-free winter adventures in NZ instead

19 Jun 06:00 AM
Winter fire warning for seniors after Waihī death
Waikato Herald

Winter fire warning for seniors after Waihī death

19 Jun 06:00 AM
'I will kill you all': Woman carried child while shoplifting, threatened to stab staff
Waikato Herald

'I will kill you all': Woman carried child while shoplifting, threatened to stab staff

19 Jun 05:52 AM
Help for those helping hardest-hit
sponsored

Help for those helping hardest-hit

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • Waikato Herald e-edition
  • Manage your print subscription
  • Manage your digital subscription
  • Subscribe to Herald Premium
  • Subscribe to the NZ Herald newspaper
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • Waikato Herald
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP