{"id":15834,"date":"2026-01-03T15:24:47","date_gmt":"2026-01-03T02:24:47","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=15834"},"modified":"2026-01-03T15:24:47","modified_gmt":"2026-01-03T02:24:47","slug":"managemyhealth-data-breach-what-weve-heard","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=15834","title":{"rendered":"Manage My Health Data Breach &#8211; What We&#8217;ve Heard"},"content":{"rendered":"\n[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<h2 class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>What New Zealand Businesses Need to Learn from 126,000 Compromised Patient Records<\/strong><\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">New Zealand&#8217;s largest patient information portal confirmed a major cyber security breach on New Year&#8217;s Eve, with up to 126,000 users potentially affected. The Manage My Health incident isn&#8217;t just a healthcare story. It is a warning for every New Zealand business handling sensitive customer data.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">While most Kiwis were celebrating the new year, the Kazu ransomware group was exfiltrating 108 gigabytes of medical data from Manage My Health.\u00a0 This included patient records, test results, prescriptions, appointment histories, and personal information for potentially 6-7% of the platform&#8217;s 1.8 million registered users.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The breach highlights three critical cybersecurity failures that New Zealand businesses can&#8217;t afford to ignore.<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><span style=\"color: #222222; font-family: Montserrat, Helvetica, Arial, Lucida, sans-serif; font-size: 26px; font-weight: bold;\">The Breach: What Actually Happened<\/span><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Manage My Health, the online platform connecting patients with GP practices across New Zealand, <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/582969\/managemyhealth-confirms-cyber-breach\">identified &#8220;unauthorised access&#8221; to its systems<\/a> on December 30, 2025. The platform immediately engaged international forensic consultants and notified the Privacy Commissioner, Police, and Health New Zealand.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/dailydarkweb.net\/managemyhealth-data-breach-kazu-group-claims-ransomware-attack\/\">Kazu group claims to have stolen 428,337 files<\/a> totalling 108GB of data. They&#8217;ve set a ransom demand of $60,000 USD with a deadline of January 15, 2026, threatening to release the complete dataset if payment isn&#8217;t received.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">CEO Vino Ramayah stated the incident has been contained and investigations are underway. <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/583030\/managemyhealth-reveals-scope-of-data-breach\">Affected users are being notified directly<\/a>, though the company estimates this represents between 108,000 and 126,000 individuals.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/583047\/managemyhealth-data-breach-concerning-but-no-clinical-impact-health-minister\">Health Minister Simeon Brown described the breach as &#8220;concerning&#8221;<\/a> while confirming Health New Zealand&#8217;s own systems remain unaffected, as Manage My Health operates separate infrastructure.<\/p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Three Critical Failures Every Business Should Note<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>1. Communication Breakdown During Crisis<\/strong><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Perhaps the most damaging aspect wasn&#8217;t the breach itself\u2014it was how stakeholders learned about it.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/582996\/gps-worried-by-lack-of-information-on-managemyhealth-data-breach\">Dr Luke Bradford, president of the College of GPs, told media<\/a>: &#8220;It&#8217;s terribly disappointing. They&#8217;re an absolutely key tool that we use for patients&#8230; if their data&#8217;s not safe, then their very personal information is not safe.&#8221;<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>The problem was that GPs learned about the breach from news articles, not from Manage My Health. D<\/strong>octors\u2014the platform&#8217;s primary professional users\u2014found out from media reports while their practices were closed for the holiday period.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Business lesson:<\/strong> Your incident response plan must identify primary stakeholders and notify them before they read about it in the news. When doctors who rely on your platform daily learn about security breaches from journalists, trust erodes immediately.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>2. The Holiday Timing Vulnerability<\/strong><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The breach occurred during the extended Christmas\/New Year period when most GP practices were closed for four days. This wasn&#8217;t coincidental. Cyber criminals specifically <a href=\"https:\/\/new.kinetics.co.nz\/christmas-is-coming-will-you-get-the-grinchy-hacker\/\">target holiday periods<\/a> when security teams are operating with reduced staff and response capabilities are compromised.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Business lesson:<\/strong> Cybersecurity doesn&#8217;t take holidays. Attackers know this and exploit it systematically. Your monitoring and response capabilities need to maintain effectiveness during holiday periods, not scale back when your business is most vulnerable.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>3. Scale Matters\u2014But So Does Preparation<\/strong><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/582996\/gps-worried-by-lack-of-information-on-managemyhealth-data-breach\">Cybersecurity expert Daniel Ayers noted this breach is &#8220;catastrophic on the New Zealand scale,&#8221;<\/a> potentially affecting 30 times more people than the <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/582996\/gps-worried-by-lack-of-information-on-managemyhealth-data-breach\">2021 Waikato DHB breach<\/a> (4,000 people).<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">With 1.8 million registered users, Manage My Health is New Zealand&#8217;s largest patient information portal. But size didn&#8217;t protect them,\u00a0 and the ransom demand of just $60,000 seems surprisingly low given the data&#8217;s sensitivity and the number of affected users.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Business lesson:<\/strong> Whether you&#8217;re managing 1,800 customer records or 1.8 million, the fundamental security principles remain the same. Systematic protection, with current software patches and tools, consistent monitoring, and verified backup procedures aren&#8217;t optional.<\/p>[\/et_pb_text][et_pb_image src=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2026\/01\/HealthBreach.png&quot; title_text=&quot;HealthBreach&quot; _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; border_radii=&quot;on|10px|10px|10px|10px&quot; box_shadow_style=&quot;preset1&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][\/et_pb_image][et_pb_text _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;]<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\"><span style=\"font-size: 26px;\">What This Means for Your Business<\/span><\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">If your organisation handles sensitive customer data such as financial records, personal information, proprietary business details, or client communications, then Manage My Health breach offers three immediate lessons:<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Your stakeholders deserve direct communication.<\/strong> Don&#8217;t let customers, partners, or professional users learn about security incidents from media reports. Incident response plans must include immediate stakeholder notification protocols.\u00a0 Kinetics can help you prepare these plans, which hopefully will never be needed.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Holiday vulnerabilities are real.<\/strong> December through January represents New Zealand&#8217;s highest-risk period for cyber attacks. Reduced staffing, delayed responses, and slower decision-making create opportunities attackers systematically exploit.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Containment isn&#8217;t resolution.<\/strong> Manage My Health contained the breach quickly and engaged forensic consultants.\u00a0 These are correct immediate responses, but the real test comes in transparency, stakeholder communication, and demonstrable security improvements that restore trust.<\/p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(34,34,34,0.1)&#8221; custom_padding=&#8221;10px|10px|10px|10px|false|false&#8221; border_radii=&#8221;on|10px|10px|10px|10px&#8221; border_width_all=&#8221;1px&#8221; box_shadow_style=&#8221;preset1&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Sunday Update:<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/managemyhealth.co.nz\/mmh-cyber-breach-update-3-january-2026\/\">Manage My Health provided crucial clarification on Friday, January 3<\/a>, significantly narrowing the scope of the breach. Independent forensic specialists confirmed that only one module\u2014&#8221;Health Documents&#8221;\u2014was compromised, not the entire application. Preliminary investigation reveals no evidence that the core patient database was accessed, no data modification or destruction occurred, and user credentials remain secure. The company announced it has the complete list of affected individuals and is commencing legal action to protect client data. However, the situation remains urgent: cybersecurity analysts report that<strong> Kazu issued a 48-hour ultimatum on January 3,<\/strong> effectively accelerating their deadline from January 15 to approximately today, January 5. Manage My Health has confirmed the system environment is now secure and continues working with the Privacy Commissioner, Police, and Health New Zealand to finalize forensic verification before notifying all affected parties.<\/p>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Monday Update: Government Review Ordered, High Court Injunction Granted:<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The Manage My Health breach escalated significantly on Monday, January 5, as <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/top\/583207\/government-orders-review-into-managemyhealth-data-breach\">Health Minister Simeon Brown ordered a Ministry of Health review<\/a> into the incident and the company&#8217;s response. The review, set to commence by January 30, will assess the cause of the breach, evaluate the adequacy of data protections, and recommend improvements to prevent similar incidents. Brown described the breach as &#8220;pretty unacceptable&#8221; and a &#8220;big wake-up call,&#8221; noting that <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.theregister.com\/2026\/01\/05\/nz_managemyhealth_breach_review\/\">New Zealanders have a right to expect their data is held to the highest standards<\/a>, whether by public or private entities.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Manage My Health secured a <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/managemyhealth.co.nz\/mmh-cyber-breach-update-5-january-2026\/\">High Court injunction prohibiting third parties from accessing or sharing any stolen data<\/a>, and established an international monitoring team to issue immediate takedown notices if information appears on data leak websites. The company <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/managemyhealth.co.nz\/mmh-cyber-breach-update-5-january-2026\/\">issued its first direct apology<\/a>, acknowledging &#8220;we could have done a better job at communication&#8221; while defending the priority given to securing data and verifying accuracy before public statements.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The urgency intensified as the Kazu group&#8217;s modified deadline approached\u2014Tuesday, January 6 at 5am\u2014threatening to release all stolen data if the $60,000 ransom wasn&#8217;t paid. Brown stated firmly that <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.1news.co.nz\/2026\/01\/05\/minister-orders-review-into-managemyhealth-cyber-breach\/\">the government recommends against payment<\/a>: &#8220;They are criminals. They are trying to use people&#8217;s most personal information to extort money from this company.&#8221;<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Disturbing details emerged about the stolen data&#8217;s sensitivity. IT consultant Cody Cooper, who <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/583243\/managemyhealth-hack-new-zealand-s-worst-cybersecurity-incidents\">examined samples before they were taken down<\/a>, confirmed the files include passport scans, psychiatric assessments, and nude medical photographs. The breach is now <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/583243\/managemyhealth-hack-new-zealand-s-worst-cybersecurity-incidents\">being described as potentially New Zealand&#8217;s worst cybersecurity incident<\/a>, significantly larger than the 2021 Waikato DHB breach that affected 4,000 people. Manage My Health began contacting affected general practices on Monday, with direct patient notifications expected throughout the week\u2014though the company still cannot specify exactly when all 126,000 affected individuals will be informed.<\/p>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Tuesday Update: Ransom Deadline Passes, Patient Notifications Begin:<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The Kazu group&#8217;s ransom deadline <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/583248\/manage-my-health-data-breach-ransom-deadline-arrives\">passed early Tuesday morning at approximately 5:37am<\/a>, and as of midday Tuesday, <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/livenews.co.nz\/2026\/01\/06\/managemyhealth-breach-a-lot-of-queries-from-patients-as-anxiety-about-stolen-data-grows\/\">the hackers have not released additional data<\/a> beyond the initial samples. However, uncertainty about whether the data will still be leaked continues to fuel patient anxiety.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Manage My Health <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/managemyhealth.co.nz\/mmh-cyber-breach-update-6-january-2026\/\">began the formal notification process on Monday, January 6<\/a>, distributing communications to the first group of affected and unaffected general practices on January 5. The company confirmed that <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.times.co.nz\/lifestyle\/managemyhealth-issues-update-on-cyber-security-incident\/\">features have gone live on the ManageMyHealth app<\/a> allowing practices to view secure lists of enrolled patients affected by the breach. An 0800 helpline is being established where impacted patients can access advice and support, though the number has not yet been publicly released.\u00a0\u00a0GP practices report <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/livenews.co.nz\/2026\/01\/06\/managemyhealth-breach-a-lot-of-queries-from-patients-as-anxiety-about-stolen-data-grows\/\">receiving &#8220;a lot of queries&#8221; from anxious patients<\/a> who still don&#8217;t know whether their data was compromised. General Practice Owners&#8217; Association chairperson Angus Chambers told RNZ that &#8220;there&#8217;s people who have had their privacy breached, and they don&#8217;t know either.&#8221; He emphasized that direct patient notification remains Manage My Health&#8217;s responsibility, though the slow pace of communication continues to frustrate both patients and healthcare providers.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The company is now working through the Privacy Act notification process for each affected individual in conjunction with Health New Zealand and the Office of the Privacy Commissioner. However, <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.times.co.nz\/lifestyle\/managemyhealth-issues-update-on-cyber-security-incident\/\">ManageMyHealth still cannot specify when all 126,000 affected individuals will be informed<\/a>, stating only that notifications will continue &#8220;throughout the course of this week.&#8221;<\/p>\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Wednesday Update: Direct Patient Notifications Begin Today:<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">ManageMyHealth <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/managemyhealth.co.nz\/mmh-cyber-breach-update-7-january-2026\/\">announced yesterday<\/a> that it will begin notifying affected patients directly within the next 24 hours, with notifications sent initially via email to registered account addresses. The company expects to complete the notification process by early next week. In preparation, <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.nzherald.co.nz\/business\/companies\/healthcare\/managemyhealth-turns-off-mobile-app-sets-up-advisory-board-warns-against-communicating-with-hacker\/FADH6L7LEVHPLIKQLJHIXXQQEA\/\">ManageMyHealth temporarily redirected its mobile app to the web application<\/a> to ensure consistent notification information across platforms.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The company also issued a warning that <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/managemyhealth.co.nz\/mmh-cyber-breach-update-7-january-2026\/\">third parties should not engage directly with the criminal hacker groups<\/a>, citing Police advice that doing so &#8220;is not in the best interest of those impacted by this incident and can have un-anticipated consequences.&#8221; ManageMyHealth confirmed it&#8217;s establishing an advisory board to provide additional clinical and technical support in the aftermath of the attack. <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.nzherald.co.nz\/business\/companies\/healthcare\/managemyhealth-turns-off-mobile-app-sets-up-advisory-board-warns-against-communicating-with-hacker\/FADH6L7LEVHPLIKQLJHIXXQQEA\/\">The New Zealand Herald revealed<\/a> that ManageMyHealth doesn&#8217;t have a full board\u2014CEO Vino Ramayah is effectively the sole owner and one of only two directors\u2014raising questions about governance oversight for a platform handling 1.85 million Kiwis&#8217; medical data.<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Immediate Actions for Your Business<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">If you&#8217;re responsible for protecting customer or client data, consider these questions:<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Incident response:<\/strong> Could your team identify, contain, and notify stakeholders of a security breach within 48 hours\u2014including during the holiday period?<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong style=\"font-size: 14px;\">Standards Compliance:\u00a0 <\/strong><span style=\"font-size: 14px;\">What cyber-security frameworks are you following?\u00a0 How can you demonstrate to stakeholders that you are taking a proactive approach to protect data held on your platform?\u00a0 \u00a0This includes authentication, encryption, data segmentation, backup verification, platform and tool updates to minimise known vulnerabilities and so forth?<\/span><\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Communication protocols:<\/strong> Do your incident response plans include immediate notification procedures for key stakeholders before they learn about incidents from external sources?<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Monitoring consistency:<\/strong> Do your cybersecurity monitoring and response capabilities maintain effectiveness during holiday periods and staff absences?<\/p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(34,34,34,0.1)&#8221; custom_padding=&#8221;10px|10px|10px|10px|false|false&#8221; border_radii=&#8221;on|10px|10px|10px|10px&#8221; border_width_all=&#8221;1px&#8221; box_shadow_style=&#8221;preset1&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">The Neighbourly Breach: New Zealand&#8217;s Holiday Vulnerability Window<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The ManageMyHealth incident wasn&#8217;t New Zealand&#8217;s only major data breach over the holiday period.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/583124\/neighbourly-users-private-information-up-for-sale-on-dark-web-after-a-breach\">Neighbourly, the Stuff-owned community social media platform, was also compromised<\/a>, with operators learning of the breach on New Year&#8217;s Day. The platform immediately took the site offline while investigating, <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/help.neighbourly.co.nz\/hc\/en-nz\/articles\/52524561335321-Q-A-regarding-Neighbourly-data-breach-03-01-2025\">confirming on January 3<\/a> that registered users&#8217; names, email addresses, GPS coordinates, public posts and private messages were accessed\u2014though passwords remained secure. Dark web monitoring services report that <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/www.rnz.co.nz\/news\/national\/583124\/neighbourly-users-private-information-up-for-sale-on-dark-web-after-a-breach\">over 213 million lines of Neighbourly data were offered for sale on cybercrime marketplaces over Christmas<\/a>. The platform has since restored service and is seeking a court injunction to prevent use of the compromised data. The timing is significant: two major New Zealand platforms breached within days of each other, both during the extended holiday period when monitoring resources are stretched and response capabilities are reduced. This pattern reinforces that the Christmas-New Year window represents New Zealand&#8217;s highest-risk period for cyber attacks.<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\"><span style=\"font-size: 26px;\">The Kinetics Approach to Data Protection<\/span><\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">At Kinetics, our KARE Foundation service builds systematic cybersecurity protection that doesn&#8217;t depend on perfect human vigilance or convenient timing.\u00a0 KARE Foundation Cyber-protection is built around trusted standards with SMB1001 reporting included in monthly reports and other GRC standards available as required.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Multi-layered protection includes endpoint detection and response (EDR), continuous monitoring for unusual authentication patterns (like the<a href=\"https:\/\/new.kinetics.co.nz\/urgent-advisory-were-seeing-a-significant-increase-in-authentication-attacks-this-christmas\/\"> attacks we detected over Christmas<\/a>), verified backup procedures, and documented incident response protocols that maintain effectiveness regardless of holidays or staffing levels.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The difference isn&#8217;t just technology.\u00a0 It&#8217;s systematic processes that ensure critical security tasks happen consistently, even when other priorities compete for attention or key staff are unavailable.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">For businesses handling sensitive customer data, this systematic approach provides both protection and accountability. You&#8217;re not just protected.\u00a0 You have documented evidence of the protection measures in place.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">What Affected Users Should Do Now<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">If you&#8217;ve used Manage My Health, take these immediate steps:<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Change your password immediately<\/strong>\u2014both on Manage My Health and any other site where you&#8217;ve reused that password. Password reuse is one of the primary ways single breaches cascade into multiple compromised accounts.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Watch for phishing attempts.<\/strong> The attackers have your email address and know you&#8217;re a Manage My Health user. Expect targeted phishing emails claiming to be from Manage My Health, your GP, or Health NZ. Don&#8217;t click links in emails\u2014go directly to websites by typing the URL.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Monitor for identity theft.<\/strong> Medical identity theft is real and expensive. Watch for unfamiliar medical bills, insurance claims, or credit inquiries related to healthcare services you didn&#8217;t receive.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Be skeptical of urgent messages.<\/strong> <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/managemyhealth.co.nz\/faqs-cyber-breach\/\">Manage My Health has warned<\/a> that legitimate communications will never ask for passwords or one-time authentication codes. If you&#8217;re unsure whether communication is genuine, don&#8217;t respond\u2014contact the organization directly through their official website.<\/p>\n<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">The Bigger Picture<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The Manage My Health breach will likely prove to be one of New Zealand&#8217;s largest healthcare data breaches. But its real significance isn&#8217;t the numbers.\u00a0 It is a reminder that cybersecurity failures affect real people with real consequences.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Medical records, test results, and health histories are among the most sensitive personal information anyone possesses. When that data is compromised, it&#8217;s not just statistics.\u00a0 There will be individuals facing potential identity theft, privacy violations, and erosion of trust in digital healthcare tools.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">For businesses across all sectors, the lesson is clear: data protection isn&#8217;t optional, incident response requires preparation not improvisation, and trust, once broken, is extraordinarily difficult to rebuild.<\/p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n","protected":false},"excerpt":{"rendered":"<p>What New Zealand Businesses Need to Learn from 126,000 Compromised Patient Records New Zealand&#8217;s largest patient information portal confirmed a major cyber security breach on New Year&#8217;s Eve, with up to 126,000 users potentially affected. The Manage My Health incident isn&#8217;t just a healthcare story. It is a warning for every New Zealand business handling [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":15837,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-15834","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/15834","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15834"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/15834\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}