Read The Times Australia

Daily Bulletin

NZ’s health data hack needs a proper diagnosis – and a transparent treatment plan

  • Written by: Dylan A Mordaunt, Research Fellow, Faculty of Education, Health, and Psychological Sciences, Te Herenga Waka — Victoria University of Wellington; Flinders University; The University of Melbourne
NZ’s health data hack needs a proper diagnosis – and a transparent treatment plan

Two cyber hacks have highlighted the vulnerability of New Zealand’s digital health systems – and the vast volumes of patient data we rely on them to protect.

Following the hacking of Manage My Health – compromising the records of about 127,000 patients – and an earlier breach at Canopy Health, a concerned public is asking how this happened and who is to blame.

The most urgent question, however, is whether it can happen again.

What we know so far

Manage My Health (MMH) – a patient portal used by many general practices to share test results, prescriptions and messages – published its first public notice about a cyber security incident on New Year’s Day.

According to the company, it became aware of unauthorised access on December 30, after being alerted by a partner. It says it immediately engaged independent cyber security specialists and that the compromise was limited to its “Health Documents / My Health Documents” module.

The Office of the Privacy Commissioner confirmed it was notified on January 1 and later published guidance for those affected. The National Cyber Security Centre also issued an incident notice.

MMH has since obtained urgent High Court injunctions that restrain the use or publication of data taken. In its decision, the court described activity patterns consistent with automation, including unusually high-frequency behaviour and repeated access attempts.

While this sheds some light on how the hacker operated, it does not establish which specific technical control failed – or where responsibility ultimately lies.

We have now also learned that a second provider, Canopy Health, experienced unauthorised access to parts of its administrative systems six months ago, with some patients only being notified this week.

Why framing matters

When health data is stolen at scale, it might be tempting to frame it as “cyberterrorism”. That term, however, has a specific and contested meaning.

Security scholar Dorothy Denning’s widely-cited definition limits cyberterrorism to attacks intended to coerce or intimidate in pursuit of political goals, and which cause severe harm – not financially motivated intrusions or large-scale data theft alone. By that standard, the MMH incident does not clearly qualify.

Why does the label matter? Because the way breaches are framed shapes the response.

Casting an incident as “cyberterror” can privilege speed over evidence, and dramatic reassurance over careful diagnosis. It can also encourage what critics describe as “security theatre”: visible but poorly targeted measures that look decisive without necessarily reducing risk.

Research on cyber-threat politics shows that threat narratives influence which problems receive funding, which solutions are prioritised and which questions are ultimately sidelined.

So far, the government’s response has centred on commissioning a review. In announcing it, Health Minister Simeon Brown framed MMH as a privately operated portal used by some general practices, and asked the Ministry of Health to review the response by MMH and Health New Zealand.

That approach makes sense from a stewardship perspective. But it also creates an immediate transparency problem.

If government agencies are part of the system response, a ministry-led review can look like “marking our own homework” unless the terms of reference and independence are explicit.

At minimum, the review needs a transparent method, a clear boundary between facts and assumptions and a public explanation of what evidence will be examined.

An obvious starting point is clarifying who holds the data and who is accountable. MMH’s privacy statement and terms of use outline how information is made available through the portal and the responsibilities of users.

But public sources do not fully set out the underlying hosting arrangements, the role of subcontractors, or how responsibility is allocated between different parties. Without a clear “data custody chain”, accountability becomes diffuse.

What real fixes look like

Offering advice to users – such as that around unique passwords, multi-factor authentication and phishing – may be important, but it is only the baseline.

Preventing a repeat of the MMH breach really depends on controls that operate at system level and can be independently audited.

First, portal operators should maintain a credible vulnerability-disclosure programme that publicly sets out how security issues can be reported, responded to and tracked.

Second, independent testing must be anchored to explicit standards, not general assurances that a system has been externally checked.

Third, governance needs teeth. Procurement contracts should require proof that basic controls are in place, along with clear timelines for responding to incidents and preserving evidence.

A national framework can help here – and New Zealand’s health agencies already publish their own security frameworks.

Finally, communication should be treated as part of security. Clear, consistent notifications reduce confusion and with it the opportunity for scammers to impersonate security.

In the fallout of this debacle, what matters most now is seeing evidence of improvements across the system.

That means being able to see what was fixed and how it was verified, what will be tested next and by whom, and what will change across the wider health sector, not just within a single portal.

For people affected, the immediate priority is to follow official guidance and remain cautious about phishing or impersonation attempts. The government’s advice on Own Your Online is a sensible starting point.

Authors: Dylan A Mordaunt, Research Fellow, Faculty of Education, Health, and Psychological Sciences, Te Herenga Waka — Victoria University of Wellington; Flinders University; The University of Melbourne

Read more https://theconversation.com/nzs-health-data-hack-needs-a-proper-diagnosis-and-a-transparent-treatment-plan-273343

Business News

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...