New Zealand

Defending the New Zealand health sector with the MCSS

August 21, 2026
15 min read

Key Insights:

  • New Zealand's health sector has suffered multiple adverse security incidents in the last five years
  • The major 2021 Waikato DHB (WDHB) ransomware attack led to some changes in how health data and systems were secured
  • In the last twelve months new incidents and breaches at MediMap and Manage My Health have led to further concerns
  • The National Cyber Security Centre Minimum Cyber Security Standards (MCSS) are being promoted as a baseline standard
  • A new cybersecurity self-assessment tool will provide a national picture of where cyber security gaps exit in health

In May 2021, the Waikato DHB became the victim of a large-scale criminal ransomware attack that saw front page headlines about delays to treating patients and showed thousands of Kiwis the reality of global ransomware attacks on critical systems.

The Final Post Incident Report highlighted the challenges of securing health sector systems where patching and network segmentation may impact on patient outcomes and investment in adequate security is difficult to prioritise in a financially stretched environment.

New attacks on third party providers

“My inquiry has found that there were several problems with how patient information was managed. This incident released the sensitive health information of nearly 100,000 New Zealanders and has caused serious anxiety and distress for many people"
Privacy Commissioner Michael Webster, March 2026

In late 2025, a major cyber-extortion/ransomware incident occurred on Manage My Health (MMH), a popular patient portal platform. MMH experienced disruption and access issues during the response, but Health NZ's core clinical systems were not compromised.

Attackers obtained unauthorised access to MMH and exfiltrated health documents. The Privacy Commissioner subsequently found that the breach resulted from multiple security weaknesses, including inadequate technical safeguards and inadequate detection of unusually large-scale data access.

Both Manage My Health and Health NZ were found to have failed in their responsibilities to have reasonable security safeguards in place to protect patient information and led to the Prime Minister raising public concerns:

"we need to strengthen our cyber security laws here in NZ and also make sure that we are not laid back"
Prime Minister Luxon, February 2026

In February 2026, a similar cyber attack against medication-management platform MediMap saw unidentified attackers modify patient information and generate further concerns that the health sector was failing to adequately protect Kiwi health data with Privacy Commissioner Michael Webster speaking out on the need for new data protection regulations:

"we need to strengthen our cyber security laws here in NZ... recent events in NZ would suggest that one sector which is well and truly facing some cyber security challenges, is the health sector"
Privacy Commissioner Michael Webster, March 2026

Responding to key security gaps

In light of these foundational cyber security failings, it's hoped that a new cybersecurity self-assessment tool will provide a national view of where cyber security gaps exist across New Zealand's primary care sector for the first time.

Health New Zealand (Te Whatu Ora) has developed an assessment process with General Practice New Zealand and launched an information sharing and security awareness initiative. The goal is to support front line care providers to understand and meet their cyber security obligations under the Health Information Security Framework (HISF).

A simple security checklist can be used by health sector providers to assess their current cyber security capability against the National Cyber Security Centre's Minimum Cyber Security Standards.

The NZ Government proposed Minimum Cyber Security Standards for Government Agencies in June 2025 and has begun to drive wider adoption and compliance with a deadline for reporting in April this year.

Now these ten standards will be used to baseline and drive further improvements across health providers.

Foundational cyber resilience with the MCSS

New Zealand's Minimum Cyber Security Standards (MCSS) provide a structured set of foundational cyber security practices that address common areas of cyber security risk.

The ten standards focus on practical activities that help organisations improve their resilience across people, processes, technology, and governance.

Overcyte provides a structured platform for managing MCSS assessments, maturity evaluations, remediation programmes, and continuous improvement activities. Our platform enables organisations to assess current capabilities, identify gaps, document evidence, assign actions, and monitor progress against the ten standards over time.

Get in touch to learn how you can assess your MCSS maturity and compliance with Overcyte.

External NZ health sector cyber security resources

Health agencies and providers can consult the official resources to improve their data protection practices:

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo