
In May 2021, the Waikato DHB became the victim of a large-scale criminal ransomware attack that saw front page headlines about delays to treating patients and showed thousands of Kiwis the reality of global ransomware attacks on critical systems.
The Final Post Incident Report highlighted the challenges of securing health sector systems where patching and network segmentation may impact on patient outcomes and investment in adequate security is difficult to prioritise in a financially stretched environment.
“My inquiry has found that there were several problems with how patient information was managed. This incident released the sensitive health information of nearly 100,000 New Zealanders and has caused serious anxiety and distress for many people"
Privacy Commissioner Michael Webster, March 2026
In late 2025, a major cyber-extortion/ransomware incident occurred on Manage My Health (MMH), a popular patient portal platform. MMH experienced disruption and access issues during the response, but Health NZ's core clinical systems were not compromised.
Attackers obtained unauthorised access to MMH and exfiltrated health documents. The Privacy Commissioner subsequently found that the breach resulted from multiple security weaknesses, including inadequate technical safeguards and inadequate detection of unusually large-scale data access.
Both Manage My Health and Health NZ were found to have failed in their responsibilities to have reasonable security safeguards in place to protect patient information and led to the Prime Minister raising public concerns:
"we need to strengthen our cyber security laws here in NZ and also make sure that we are not laid back"
Prime Minister Luxon, February 2026
In February 2026, a similar cyber attack against medication-management platform MediMap saw unidentified attackers modify patient information and generate further concerns that the health sector was failing to adequately protect Kiwi health data with Privacy Commissioner Michael Webster speaking out on the need for new data protection regulations:
"we need to strengthen our cyber security laws here in NZ... recent events in NZ would suggest that one sector which is well and truly facing some cyber security challenges, is the health sector"
Privacy Commissioner Michael Webster, March 2026
In light of these foundational cyber security failings, it's hoped that a new cybersecurity self-assessment tool will provide a national view of where cyber security gaps exist across New Zealand's primary care sector for the first time.
Health New Zealand (Te Whatu Ora) has developed an assessment process with General Practice New Zealand and launched an information sharing and security awareness initiative. The goal is to support front line care providers to understand and meet their cyber security obligations under the Health Information Security Framework (HISF).
A simple security checklist can be used by health sector providers to assess their current cyber security capability against the National Cyber Security Centre's Minimum Cyber Security Standards.
The NZ Government proposed Minimum Cyber Security Standards for Government Agencies in June 2025 and has begun to drive wider adoption and compliance with a deadline for reporting in April this year.
Now these ten standards will be used to baseline and drive further improvements across health providers.
New Zealand's Minimum Cyber Security Standards (MCSS) provide a structured set of foundational cyber security practices that address common areas of cyber security risk.
The ten standards focus on practical activities that help organisations improve their resilience across people, processes, technology, and governance.
Overcyte provides a structured platform for managing MCSS assessments, maturity evaluations, remediation programmes, and continuous improvement activities. Our platform enables organisations to assess current capabilities, identify gaps, document evidence, assign actions, and monitor progress against the ten standards over time.
Get in touch to learn how you can assess your MCSS maturity and compliance with Overcyte.
Health agencies and providers can consult the official resources to improve their data protection practices: