Up to 126,000 people may have had their information exposed after a cyberattack on Manage My Health, a widely used patient portal in New Zealand, which detected unauthorized access to its application on Dec. 30, 2025, two days before the New Year.

Up to 126,000 people may have had their information exposed after a cyberattack on Manage My Health, a widely used patient portal in New Zealand, which detected unauthorized access to its application on Dec. 30, 2025, two days before the New Year.
Manage My Health, a privately operated digital health platform used by general practices and patients nationwide, confirmed the incident publicly on New Year’s Day. The company said it was alerted to unauthorized access affecting its system and immediately began an investigation with independent forensic specialists.
In an update issued on Jan. 3, the company said forensic analysis determined that a single module within the application, known as Health Documents, was compromised, while the remainder of the platform was secure and operating as intended. Manage My Health said it has identified and closed the specific security gaps that enabled the intrusion, with remediation measures independently tested and verified by external cybersecurity experts.
The company estimated that between 6% and 7% of its approximately 1.8 million registered users were affected by the breach. It said it has a complete list of individuals whose documents may have been accessed and expects to begin notifying affected users directly from early next week, following confirmation of forensic findings and coordination with primary health organizations and general practices.
Manage My Health said it is continuing to analyze which specific documents were involved. It is also establishing an online helpdesk and a dedicated toll-free support number, both expected to be operational early next week, to assist patients and medical practices.
As part of its response, the company has implemented additional login checks, restricted the number of access attempts within short timeframes, and re-secured all health documents with strengthened storage protections. Users have been encouraged to reset their passwords, enable two-factor authentication, and remain alert for unusual activity such as unrecognized medical bills, insurance claims, or correspondence from healthcare providers.
The breach prompted notifications to the Office of the Privacy Commissioner and New Zealand Police. Te Whatu Ora Health New Zealand confirmed that the incident had no impact on Health NZ systems and said its incident management team had been deployed. Te Whatu Ora Health and General Practice New Zealand are coordinating with Manage My Health as part of the response.
The Ministry of Health has commissioned a review of the Manage My Health breach and the handling of the incident. Health Minister Simeon Brown said patient data must be protected to the highest standards, regardless of whether it is held by public agencies or private companies.
The incident follows several significant healthcare-related cyber events in New Zealand in recent years, including a 2024 breach affecting Te Whatu Ora Central Region staff information and earlier attacks involving healthcare service providers and networks.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543