Skip to main content

Manage My Health LimitedManage My Health patient portal breach exposed ~126,000 New Zealanders' medical records after stolen-credential attack

Hackers using stolen patient credentials accessed the 'My Health Documents' section of New Zealand's largest patient portal, Manage My Health, copying documents from roughly 126,000-127,000 patient accounts (later revised down from an initial estimate of 126,000+); a group calling itself 'Kazu' claimed 108GB across 428,337 files and demanded a US$60,000 ransom. New Zealand's Privacy Commissioner opened a statutory inquiry under the Privacy Act 2020 and found in its Phase One report that MMH had made multi-factor authentication optional rather than mandatory, had insufficient access controls and breach-detection capability (Health NZ, not MMH, first alerted the company), and had failed to remediate access-control and application-security risks flagged in prior security testing -- concluding MMH breached Rule 5 of the Health Information Privacy Code.

Scoring Impact

TopicDirectionRelevanceContribution
Data Security-againstprimary-1.00
Overall incident score =-0.497

Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.66)× agency (negligent ×0.5)

Evidence (2 signals)

Confirms Legal Action Jun 1, 2026 verified

NZ Privacy Commissioner executive summary: Manage My Health inquiry finds Rule 5 breach

Official Phase One executive summary of the Privacy Commissioner's statutory inquiry into the breach, finding MMH's optional (not mandatory) MFA, insufficient access controls, and failure to remediate known security risks breached Rule 5 of the Health Information Privacy Code.

Confirms Criticism Jan 15, 2026 documented

RNZ: Manage My Health data breach timeline of what happened

RNZ's timeline of the December 2025 ransomware/credential-theft breach, including the 'Kazu' group's ransom demand and scope of compromised patient records.

Related: Same Topics