|
Getting your Trinity Audio player ready...
|

Up to 126,000 people using the ManageMyHealth app may have had health documents accessed following a cyber security incident identified late last year.
In an update issued on January 3, ManageMyHealth said independent forensic analysis has confirmed that between 108,000 and 126,000 users, around 6 to 7 percent of its approximately 1.8 million registered users, were potentially affected.
The company said it was notified of the cyber security incident on December 30 and provided an initial update on January 2. Independent cyber security specialists have now confirmed the system environment is secure and operating as intended.
The investigation found that a single module within the app: Health Documents, was compromised, rather than the entire platform.
ManageMyHealth says it is commencing legal action to protect client data and now has a complete list of people whose documents may have been accessed. Further forensic work is under way to confirm exactly which documents were affected.
Once that process is completed, the company expects to begin notifying affected users directly from early next week, working alongside primary health organisations and general practices to ensure people receive accurate information and appropriate support, in line with Privacy Act requirements.
Strengthened security measures
ManageMyHealth says it has already closed the specific security gap that allowed unauthorised access, with the fix independently tested and verified by external cyber security experts.
Additional protections have been put in place, including stronger login checks, limits on repeated access attempts, and enhanced security around stored health documents.
Users are being encouraged to reset their passwords and enable two-factor authentication, including biometric options where available, to add an extra layer of protection.
The platform supports Google Authenticator and Microsoft Authenticator for two-factor authentication.
Users are also being advised to remain vigilant for unusual activity, such as unfamiliar medical bills, insurance claims or correspondence from healthcare providers. Any suspicious activity can be reported to New Zealand Police or to CERT NZ.
Sector-wide coordination and support
ManageMyHealth says it is working closely with General Practice New Zealand leadership and Health New Zealand to ensure consistent and accurate messaging across the health sector.
A dedicated helpline is expected to be established by early next week to support both practices and users, including an online helpdesk and a dedicated 0800 number, with details to be released shortly.
The company is also liaising with independent cyber security specialists, the Office of the Privacy Commissioner, Police and Health New Zealand as the investigation continues.
ManageMyHealth says further updates will be provided as soon as additional verified information becomes available.
Health Minister and Pakuranga MP Simeon Brown says he’s been briefed by health officials over the data breach.

“This is a concerning breach of patient data and Health NZ is working closely with ManageMyHealth to ensure it is being appropriately addressed,” Brown said in a statement on social media.
“At this stage, there’s no evidence any Health NZ systems, including My Health Account, have been compromised as ManageMyHealth has separate systems.
“ManageMyHealth and Government agencies are working closely together to fully understand the scope of the breach and to protect the privacy of patients.”
Brown says Health NZ is co-ordinating with agencies, including the National Cyber Security Centre, to ensure all the right steps are being taken.
“I’ve been advised there’s no clinical impact on patient care as a result of this cyber incident, and health services continue to operate as normal.
“I expect ManageMyHealth will continue to keep the public informed as more verified information becomes available and will put appropriate measures in place to ensure patient safety and privacy are protected and given the highest priority.
“I also expect a co-ordinated and robust response, and Health NZ is keeping me updated.”


