Manage My Health Limited—Manage My Health patient portal breach exposed ~126,000 New Zealanders' medical records after stolen-credential attack
Hackers using stolen patient credentials accessed the 'My Health Documents' section of New Zealand's largest patient portal, Manage My Health, copying documents from roughly 126,000-127,000 patient accounts (later revised down from an initial estimate of 126,000+); a group calling itself 'Kazu' claimed 108GB across 428,337 files and demanded a US$60,000 ransom. New Zealand's Privacy Commissioner opened a statutory inquiry under the Privacy Act 2020 and found in its Phase One report that MMH had made multi-factor authentication optional rather than mandatory, had insufficient access controls and breach-detection capability (Health NZ, not MMH, first alerted the company), and had failed to remediate access-control and application-security risks flagged in prior security testing -- concluding MMH breached Rule 5 of the Health Information Privacy Code.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Data Security | -against | primary | -1.00 |
| Overall incident score = | -0.497 | ||
Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.66)× agency (negligent ×0.5)
Evidence (2 signals)
NZ Privacy Commissioner executive summary: Manage My Health inquiry finds Rule 5 breach
Official Phase One executive summary of the Privacy Commissioner's statutory inquiry into the breach, finding MMH's optional (not mandatory) MFA, insufficient access controls, and failure to remediate known security risks breached Rule 5 of the Health Information Privacy Code.
RNZ: Manage My Health data breach timeline of what happened
RNZ's timeline of the December 2025 ransomware/credential-theft breach, including the 'Kazu' group's ransom demand and scope of compromised patient records.