09/01/2026
๐ ๐ ๐ ๐ฐ๐๐ฏ๐ฒ๐ฟ ๐ฏ๐ฟ๐ฒ๐ฎ๐ฐ๐ต ๐๐ฝ๐ฑ๐ฎ๐๐ฒ, ๐ต ๐๐ฎ๐ป๐๐ฎ๐ฟ๐ ๐ฎ๐ฌ๐ฎ๐ฒ
Further to our 8 January 2026 statement regarding the cybersecurity crime, Manage My Health (MMH) provides the following update.
Our priority focus remains on direct communications with affected patients and practices. MMH would like to reiterate its sincere apology to those impacted by this criminal cyber breach. We understand it is distressing and appreciate the frustration at the timing of communications. However, this is a complex exercise which unfortunately cannot be simplified due to the separate cohorts of patients affected which have to be dealt with in different ways.
As a result of which, there is unfortunately no scenario in which MMH could issue instant notifications to those impacted by the breach. Direct notifications have required coordination and clearance from relevant authorities and health sector stakeholders such as GP organisations.
Upon ascertainment of the breach, we immediately contacted Health NZ and various other Government agencies for their cooperation and management of this incident. We also duly notified the Privacy Commissioner of the breach. We knew it did not affect the core MMH application and was confined to a documents folder which was outside the main database.
We immediately appointed our cyber security forensic experts to analyse the cause of the breach and the investigations are ongoing. We also had an independent vulnerability application test conducted which confirmed the current system environment is secure, and therefore can offer an assurance that the breach was swiftly contained.
๐๐ฒ๐ด๐ฎ๐น
Injunction orders were secured in the interests of protecting client data and to minimise any abuse of data.
Further, MMH has taken all necessary steps to ensure that direct notification to affected practices and patients has complied with relevant legislation including the Privacy Act 2020 and the Health Information Privacy Code.
๐ฃ๐ฎ๐๐ถ๐ฒ๐ป๐ ๐ป๐ผ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป
Direct notifications to patients affected are ongoing, as we are addressing several categories of people, and we expect to complete contacting all remaining patients that can be notified by early next week. More than half of all impacted patients have now received a notification email.
๐ฌ๐ด๐ฌ๐ฌ ๐ป๐๐บ๐ฏ๐ฒ๐ฟ ๐ณ๐ผ๐ฟ ๐ฎ๐ณ๐ณ๐ฒ๐ฐ๐๐ฒ๐ฑ ๐ถ๐ป๐ฑ๐ถ๐๐ถ๐ฑ๐๐ฎ๐น๐
An 0800 number has been established for impacted individuals to call for support and assistance should they require. This number will not be publicly available and only shared with impacted individuals via direct notification, as the team manning this number is dedicated to supporting impacted individuals only.
๐ง๐ฒ๐ฐ๐ต๐ป๐ถ๐ฐ๐ฎ๐น ๐๐๐ฝ๐ฝ๐ผ๐ฟ๐
We are aware of some reports of users experiencing technical difficulties, such as receiving emails, accessing the patient portal and viewing documents in their account. For these and all other enquiries, the MMH team continues to be available via all usual contact methods including via social media direct message or info@managemyhealth.co.nz
๐ ๐ฒ๐ฑ๐ถ๐ฎ ๐ฒ๐ป๐พ๐๐ถ๐ฟ๐ถ๐ฒ๐
MMH appreciates the significant national interest in this criminal cyber breach, given the platformโs role in storing medical information.
As this criminal cyber breach is subject to a police investigation, a full forensic review, and there are privacy concerns involved, there are valid constraints to what MMH can comment on publicly. MMH values its relationship with all media and aims to be accessible, open, and transparent in its communications.
MMH is endeavouring to respond to all individual enquiries and will provide answers to specific questions where possible within these constraints. Regular statements from MMH are shared with media and placed on the website.
๐๐๐๐๐ ๐ฃ๐ค๐ฉ๐: ๐๐ญ๐ฆ๐ข๐ด๐ฆ ๐ด๐ฆ๐ฆ ๐๐๐๐ด ๐ฃ๐ฆ๐ญ๐ฐ๐ธ ๐ง๐ฐ๐ณ ๐ข๐ฅ๐ฅ๐ช๐ต๐ช๐ฐ๐ฏ๐ข๐ญ ๐ช๐ฏ๐ง๐ฐ๐ณ๐ฎ๐ข๐ต๐ช๐ฐ๐ฏ ๐ธ๐ฉ๐ช๐ค๐ฉ ๐ฎ๐ข๐บ ๐ฃ๐ฆ ๐ถ๐ด๐ฆ๐ง๐ถ๐ญ ๐ฃ๐ข๐ด๐ฆ๐ฅ ๐ฐ๐ฏ ๐ณ๐ฆ๐ค๐ถ๐ณ๐ณ๐ช๐ฏ๐จ ๐ฒ๐ถ๐ฆ๐ด๐ต๐ช๐ฐ๐ฏ ๐ต๐ฉ๐ฆ๐ฎ๐ฆ๐ด.
๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ ๐ฎ๐ป๐ฑ ๐ฟ๐ฎ๐ป๐๐ผ๐บ ๐ฑ๐ฒ๐บ๐ฎ๐ป๐ฑ
A cyber-attack is criminal activity, and this incident is subject to a police investigation. MMH is unable to provide any comment relating to the hacker, or any ransom demand.
Police advice is that third parties should not engage directly with criminal hacker groups, including in this situation. Doing so is not in the best interest of those impacted by this incident and can have un-anticipated consequences.
Police also advise that anyone who has been notified that their data is included in the breach does not need to contact police as this has been covered by the Manage My Health report to police. However, police should be contacted if there is evidence of misuse of personal information.
Government guidance on cyber ransom payments: The New Zealand Government recommends not paying a ransom. Payment does not guarantee that you will get your data back, may breach sanctions, and creates harm to others by providing funding for criminal activities.
๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฝ๐ผ๐๐๐๐ฟ๐ฒ ๐ฎ๐ป๐ฑ ๐ฒ๐ป๐ฐ๐ฟ๐๐ฝ๐๐ถ๐ผ๐ป
MMH employs current security measures such as encryption of health data in its database and user passwords.
MMH is an ISO 9001 and ISO 27001 certified organisation. We have quality assurance processes with regular testing of our systems.
๐ ๐ ๐ ๐ฐ๐ผ๐บ๐บ๐ฒ๐ป๐ ๐ผ๐ป ๐ผ๐๐ต๐ฒ๐ฟ ๐ต๐ฎ๐ฐ๐ธ๐ถ๐ป๐ด ๐ฎ๐๐๐ฒ๐บ๐ฝ๐๐
MMH continuously monitors and upgrades its security and data protection systems. This is a continuing process and criminals find sophisticated new ways of attacking any large system which contains personal data, as has been evidenced in both the health and non-healthcare sectors globally and New Zealand is no exception.
The Office of the Privacy Commissioner confirmed on 7 January that they received an email via their enquiries in-box from an anonymous source about Manage My Health in June 2025 alleging names, email addresses and passwords were exposed in the Manage My Health platform.
In this case we investigated and did not find any breach. However, out of an abundance of caution, we forced password resets on the users concerned. We also reinforced that two factor authentication is available to users of Manage My Health for them to use to enhance the security of their access to the portal.
๐๐๐ค๐
โข ๐ก๐๐บ๐ฏ๐ฒ๐ฟ ๐ผ๐ณ ๐ฎ๐ณ๐ณ๐ฒ๐ฐ๐๐ฒ๐ฑ ๐ฝ๐ฎ๐๐ถ๐ฒ๐ป๐๐
o The number of patients impacted is approximately 125,000.
โข ๐ฃ๐ฎ๐๐ถ๐ฒ๐ป๐ ๐ป๐ผ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐ฝ๐ฟ๐ผ๐ด๐ฟ๐ฒ๐๐ ๐ฎ๐ป๐ฑ ๐ฎ๐ฐ๐ฐ๐๐ฟ๐ฎ๐ฐ๐
o Patient notifications continue. More than half of all impacted patients have now received a notification email. All patients who are not impacted can see that in their MMH app. In a small number of cases, users were notified that they were impacted, but the app showed that they were not impacted โ this was caused by the timing of the emails being sent, and the app being updated. This has been updated and all users see the correct details in the app after they have been notified.
โข ๐๐ผ๐ฐ๐๐บ๐ฒ๐ป๐ ๐ฟ๐ฒ๐บ๐ผ๐๐ฎ๐น
o MMH has not removed or changed any documents in MMH which were affected. No direct reports of this nature have been made to MMH, however if any user believes documents are missing from their account, they are encouraged to contact MMH directly.
โข ๐๐น๐ฎ๐ป๐ธ/๐ฐ๐ผ๐ป๐๐ฟ๐ฎ๐ฑ๐ถ๐ฐ๐๐ผ๐ฟ๐ ๐ฒ๐บ๐ฎ๐ถ๐น๐ ๐ฏ๐ฒ๐ถ๐ป๐ด ๐๐ฒ๐ป๐ ๐๐ผ ๐ฝ๐ฎ๐๐ถ๐ฒ๐ป๐๐
o Some email clients may not have displayed the email correctly, and we have corrected this are sending follow up emails where necessary.
โข ๐ก๐ผ๐ฟ๐๐ต๐น๐ฎ๐ป๐ฑ ๐ถ๐บ๐ฝ๐ฎ๐ฐ๐
o MMH provides a service for Northland patients to receive hospital discharge summaries through MMH. This solution was a benefit to Northlanders who did not have to wait in hospital to receive paper records and was of particular benefit to Northlanders who are not enrolled with a GP. This arrangement was not in place in other regions.
โข ๐ข๐๐ฒ๐ฟ๐๐ฒ๐ฎ๐ ๐ฝ๐ฎ๐๐ถ๐ฒ๐ป๐๐ ๐ฏ๐น๐ผ๐ฐ๐ธ๐ฒ๐ฑ ๐ณ๐ฟ๐ผ๐บ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐๐ถ๐ป๐ด ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐
o Out of an abundance of caution, we limited the countries that can access MMH to UK, USA, Aus and NZ during the incident and will gradually restore access internationally.
โข ๐ช๐ฒ๐ฏ๐๐ถ๐๐ฒ ๐๐ฟ๐ฎ๐ณ๐ณ๐ถ๐ฐ ๐๐ผ๐น๐๐บ๐ฒ
o The website has been standing up well, despite the large increase in traffic. We increased capacity as much as possible at short notice to accommodate expected volumes. While some users have experienced some slowness, the application has been operational, and most users are getting the information they need. We ask people to have patience please and to not access the website unless they need to until this notification process is complete.
โข ๐ ๐ ๐ ๐ฑ๐ฎ๐๐ฎ๐ฏ๐ฎ๐๐ฒ ๐น๐ผ๐ฐ๐ฎ๐๐ถ๐ผ๐ป
o The MMH database has always been located in NZ, via NZ data centres.
โข ๐๐ป๐๐๐ฟ๐๐ฐ๐๐ถ๐ผ๐ป๐ ๐ด๐ถ๐๐ฒ๐ป ๐๐ผ ๐๐ฃ๐ ๐ฎ๐ฏ๐ผ๐๐ ๐ถ๐ป๐ณ๐ผ๐ฟ๐บ๐ถ๐ป๐ด ๐ฝ๐ฎ๐๐ถ๐ฒ๐ป๐๐
o MMH is responsible for notifying patients. MMH has shared information with GPs about their impacted patients, but GPs are not expected to notify patients. However, we have prepared an information pack to assist practices, both with affected patients and not, which is being shared this week to support practices with communications to their patients.
โข ๐ฃ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ถ๐ผ๐ป ๐บ๐ฒ๐ฎ๐๐๐ฟ๐ฒ๐ ๐ณ๐ผ๐ฟ ๐ณ๐๐๐๐ฟ๐ฒ ๐ฐ๐๐ฏ๐ฒ๐ฟ ๐ถ๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐๐
o MMH has taken a number of prevention measures. In the first event, we have secured our systems and contracted separate external organisations to run VAPT testing processes to validate our system testing. We are currently carrying out forensic investigations which are still ongoing.
For any further information, please refer to our frequently asked questions here: https://managemyhealth.co.nz/faqs-cyber-breach/
๐ก๐ฒ๐
๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ
MMH will issue its next update on Monday 12 January 2026 once the company has made further progress with direct communications with GP practices, patients and stakeholders.
Our regular updates can be found here: www.managemyhealth.co.nz
As always, if any patients or practices have any concerns or questions, please contact us directly via info@managemyhealth.co.nz
Find the answers to the most frequently asked questions related to the recent Cyber Breach.