Why NZ Healthcare Needs 24/7 Security Monitoring in 2026 | NSP
NSP Marketing
23 September 2026
9 min
ReadNZ Healthcare Had Five Cyber Breaches in Nine Months. Monitoring Is No Longer Optional.
In the nine months between December 2025 and September 2026, five separate organisations with New Zealand healthcare connections confirmed significant cyber incidents.
ManageMyHealth. MediMap, Canopy Health, IntraCare and ZenTech.
Together they affected hundreds of thousands of patients. They triggered Privacy Commissioner inquiries, parliamentary questions, Health Minister briefings, police investigations, and a sector-wide review. IntraCare deferred 28 patient procedures when it shut its IT systems down in response. The Privacy Commissioner found that both ManageMyHealth and Health NZ had breached Rule 5 of the Health Information Privacy Code 2020 - the obligation to maintain reasonable security safeguards for health information.
The CyberCX report commissioned by the Ministry of Health described the ManageMyHealth breach as "neither technically sophisticated, nor particularly uncommon." The Privacy Commissioner's Phase 1 inquiry found ManageMyHealth had been warned about similar security flaws before the breach. The breach was preventable.
Five incidents in nine months. A common thread: detection happened after the access had occurred, not during it. And in several cases, the organisations themselves weren't the first to find out something was wrong.
This is the healthcare monitoring problem in New Zealand. And it applies as directly to a GP practice in Tauranga, a specialist clinic in Christchurch, or an allied health provider in Auckland as it does to the organisations whose names appeared in the headlines.
Why Health Data Creates Specific Monitoring Pressure
Health data is not like other business data. A compromised credit card can be cancelled. A changed password restores access. The information held in a patient record - diagnoses, medications, procedures, genetic markers, mental health history - is permanent. It cannot be changed after a breach. It retains its value to attackers indefinitely.
Dr Abhinav Chopra from the University of Auckland, quoted in coverage of the ZenTech breach, made this explicit: "They have information about their bodies and their allergies, they've got clinical information, which is information that cannot be changed - the dataset is quite static and can be used by a number of buyers on the black market."
This permanence is precisely what makes health data so valuable to ransomware groups and extortion operators. The threat of publishing or selling clinical information creates leverage that doesn't expire. For the patients involved, the exposure is lifelong.
It also creates a specific regulatory dimension. Under the Health Information Privacy Code 2020, healthcare organisations are required to maintain reasonable security safeguards for health information. That obligation applies to GP practices, specialist clinics, allied health providers, and private healthcare operators - not only to large platforms like ManageMyHealth. The Privacy Commissioner's findings this year have made concrete what "reasonable safeguards" is expected to mean, and those expectations are rising.
The Tools vs Monitoring Problem in Healthcare
Most NZ healthcare organisations have some security tools in place. Antivirus. Email filtering. Perhaps Microsoft Defender. These tools do something real and valuable - they detect known threats, block malicious files, and generate alerts.
What they don't do is monitor those alerts continuously, investigate whether a sign-in at an unusual hour represents a genuine compromise, or connect activity across identity, email, and clinical systems to identify a pattern that individually looks ambiguous.
IBM's Cost of a Data Breach Report 2025 found that healthcare breach detection and containment averages more than 270 days. That figure reflects the sector globally, but the NZ pattern is consistent with it. ManageMyHealth's breach was discovered after stolen credentials were used to access patient records - detected not through active monitoring of the access event itself, but through subsequent notification. IntraCare became aware of its breach and immediately shut down its IT systems, but the deferral of 28 procedures was the direct operational consequence of detection occurring after compromise rather than during it.
The distance between "we have security tools" and "we have continuous security monitoring" is where NZ healthcare's breach pattern this year has concentrated.
What Continuous Monitoring Changes for a Healthcare Organisation
When a healthcare organisation has 24/7 security monitoring in place, the detection timeline changes fundamentally.
A sign-in to a patient portal from an unexpected IP address at 3am generates an alert. An analyst reviews it within minutes. They check whether the location is plausible for that user, whether the account has shown previous anomalous behaviour, what the account accessed during the session, and whether there is correlated activity across other systems. They make a decision in real time - contain the account, escalate to the organisation, or clear it as legitimate.
Without continuous monitoring, that same sign-in sits in a queue reviewed the following business day. The ManageMyHealth breach involved stolen patient credentials being used to access and copy documents from thousands of other patients' accounts. Each access event generated a log. Those logs, under continuous monitoring by a security analyst, would have presented a visible pattern. Under periodic review, the pattern wasn't identified until the data appeared on BreachForums.
Mandiant's M-Trends 2026 report found the global median dwell time is 14 days. Organisations with internal detection capability detect in nine days. Those that find out through external notification take 25 days. In the ManageMyHealth case, the organisation was notified by a partner organisation - an external notification scenario. In the ZenTech case, Health NZ became aware after files appeared online.
For a healthcare organisation holding patient health information, 14 days of undetected access is not an acceptable outcome. The Privacy Act's 72-hour notification obligation begins when the organisation first suspects a breach - not when the investigation is complete. An organisation that detects a breach through external notification is already under time pressure before it has begun to understand the scope.
The Regulatory and Compliance Context Is Strengthening
The Privacy Commissioner's response to the 2026 NZ healthcare breach cluster has been explicit about what the sector is expected to change.
The Phase 1 inquiry into ManageMyHealth issued compliance notices - described by the Commissioner as "the strongest tool" currently available. The inquiry found that both ManageMyHealth and Health NZ had breached Rule 5 of the Health Information Privacy Code, which requires reasonable security safeguards for health information.
The Commissioner's findings identified specific governance failures: poor risk assessment, overreliance on vendor assurances, and the absence of privacy and security specialists in decision-making processes. Importantly, the breach was described as preventable. Not the result of a sophisticated attack. A result of inadequate security practice.
Health Informatics New Zealand's reporting on the three-breach cluster earlier in 2026 noted that some general practices had begun reassessing how clinical data is handled and where operational dependencies sit. One Wellington practice reportedly stopped uploading consultation records to an external portal in response to the breach environment - not because it had been affected, but because the sector's trust in digital health infrastructure had been shaken.
That trust is rebuilt through demonstrable security governance, not through reassurance. A healthcare organisation that can point to active security monitoring, documented incident response capability, and evidence of maintained controls is in a fundamentally different position - with regulators, with patients, and with cyber insurers - than one that can only describe what tools it has deployed.
What Healthcare Security Monitoring Should Cover
For a NZ healthcare organisation - whether a GP practice, specialist clinic, allied health provider, or private hospital - security monitoring that is genuinely fit for purpose covers several specific areas.
Identity and access. The ManageMyHealth breach used stolen patient credentials to access records at scale. Continuous monitoring of authentication events - sign-ins at unusual hours, access from unexpected locations, unusual volumes of record access - is the layer that would catch this pattern early rather than after it has run for days.
Email and phishing. The Kordia 2026 NZ Business Cyber Security Report found email phishing featured in 45% of NZ cyber attacks. For healthcare staff using Microsoft 365, the combination of email security controls and active monitoring of email-based threat indicators is the front line of credential protection.
Endpoint behaviour. Clinical workstations and administrative devices are the access points through which patient records are reached. Endpoint detection that monitors for unusual behaviour - unexpected process execution, data staging, lateral movement attempts - is what identifies a compromised device before it becomes a compromised patient database.
Third-party and application access. The Kordia report noted that almost one in five NZ incidents stemmed from weaknesses in internet-facing applications. For healthcare organisations using patient portals, clinical software, and connected health platforms, the access that third-party applications hold to health information is a specific monitoring concern.
After-hours activity. Healthcare operations run around the clock, but security monitoring capacity typically doesn't. The Semperis 2025 research found 52% of ransomware events in surveyed organisations including New Zealand occurred on weekends or holidays. For a healthcare provider whose clinical systems are used 24 hours a day, the monitoring capability needs to match the operational hours - not the administrative ones.
NSP's Managed Detection and Response service covers all of these dimensions continuously, powered by Adlumin's detection platform and backed by a local security operations team. For NZ healthcare organisations managing patient information under the Health Information Privacy Code, it provides the active monitoring capability that the Privacy Commissioner's 2026 findings indicate is now expected as part of reasonable security safeguards.
The Question for Every NZ Healthcare Provider
The ManageMyHealth, MediMap, IntraCare, and ZenTech breaches share a common feature: the organisations involved had security tools and practices in place. None of them set out to be breached. What they shared was a detection gap - a period during which access was occurring and the organisation didn't know.
For every NZ healthcare provider reading about those incidents, the relevant question isn't whether those organisations cared about security. It's whether your own organisation's monitoring capability would produce a different outcome.
If a patient portal login occurred at 2am tonight using credentials that shouldn't be active, who would see it? If clinical records were being accessed at a volume that patterns like credential abuse, would the alert be investigated before the data was copied? If a phishing email compromised a staff member's account on a Friday afternoon, would anyone investigate before Monday?
These aren't questions about whether you have the right tools. They're questions about whether the information those tools produce is being acted on continuously enough to catch what five NZ healthcare organisations found out they missed this year.
Frequently Asked Questions
Does the Health Information Privacy Code apply to small healthcare providers, not just large platforms?
Yes. The Health Information Privacy Code 2020 applies to any healthcare organisation that collects or holds health information about individuals. The obligation in Rule 5 - to maintain reasonable security safeguards - applies to GP practices, specialist clinics, allied health providers, and private healthcare operators, not only to large patient portal operators like ManageMyHealth. The Privacy Commissioner's 2026 findings have set a higher bar for what reasonable safeguards are expected to look like.
What is the Privacy Act's breach notification timeline for healthcare?
Under the Privacy Act 2020, organisations must notify the Privacy Commissioner within 72 hours of becoming aware of a notifiable privacy breach - one likely to cause serious harm to affected individuals. The 72-hour clock starts when the organisation first suspects a breach, not when the investigation is complete. For healthcare organisations, where health information almost always meets the serious harm threshold, this notification obligation is immediate. Early detection through continuous monitoring directly supports meeting this timeline.
What did the ManageMyHealth breach investigation find about security safeguards?
The Privacy Commissioner's Phase 1 inquiry found that both ManageMyHealth and Health NZ had breached Rule 5 of the Health Information Privacy Code by failing to maintain adequate security safeguards. The CyberCX report commissioned by the Ministry of Health described the breach as preventable and "neither technically sophisticated, nor particularly uncommon." ManageMyHealth had been warned about similar security vulnerabilities before the breach occurred. The inquiry issued compliance notices - the Commissioner's strongest available enforcement tool.
What is MDR and why is it specifically relevant for healthcare?
Managed Detection and Response is a security service that combines continuous monitoring of your environment - identity, endpoints, email, cloud activity - with security analysts who investigate alerts and respond when a genuine threat is confirmed. For healthcare organisations, it addresses the specific gap that the 2026 NZ breach pattern exposed: the distance between having security tools and having someone actively watching what those tools find, around the clock.
How does MDR support compliance with the Health Information Privacy Code?
Active security monitoring directly supports Rule 5 compliance by providing documented evidence of reasonable security safeguards. It also supports the Privacy Act's breach notification obligation by detecting incidents earlier - giving organisations more time within the 72-hour window to assess the scope of a breach and make a considered notification rather than a reactive one. NSP can provide the documented monitoring logs and incident reports that demonstrate active security governance to the Privacy Commissioner if required.
What should a NZ healthcare provider do if it doesn't currently have continuous security monitoring?
A cybersecurity assessment is the starting point - it gives you a clear picture of your current security posture, what monitoring capability is in place, and where the highest-priority gaps are. NSP's assessment specifically covers Microsoft 365 identity and access controls, email security configuration, endpoint protection, and the data governance considerations that are specifically relevant under the Health Information Privacy Code.
Is Your Healthcare Organisation Protected?
The five NZ healthcare breaches in 2026 share one feature: detection happened after the access had occurred. A 30-minute consultation with NSP covers what your current monitoring capability looks like, what continuous detection would change, and what the specific implications are for your obligations under the Health Information Privacy Code.
Book your free consultation with NSP
Or call us directly: 0508 010 101
Related Reading
CATEGORY
- Cybersecurity (97)
- Digital transformation (37)
- Managed services (33)
- Awareness and education (23)
- Cloud (23)
- AI (20)
- Breach (17)
- IT Risk (17)
- modern workplace (12)
- Collaboration (11)
- Cyber Smart Week (11)
- Business strategy (9)
- Culture (9)
- Managed Detection & Response (MDR) (9)
- microsoft (9)
- Backup (8)
- Remote Workers (8)
- copilot (7)
- Cyber Insurance (6)
- Future of work (6)
- network performance (6)
- Vulnerability Assessment (5)
- Microsoft Teams (4)
- vCISO (4)
- 0365 (3)
- Governance (3)
- IT budget (3)
- Legal Industry (3)
- Best Practice (2)
- Construction Industry (2)
- Penetration Testing (2)
- Tabletop Exercise (2)
- health IT consultant (2)
- Healthcare (1)
RECENT POST
Let’s stay in touch!
Enter your details below to stay up-to-date with the latest IT solutions and security measures.