The Assurance You Didn't Verify

  • Hook type: Accountability pivot (from incident to formal finding)
  • Strategic intent: Deploy the Vendor-Decides Pattern as a named concept (pending author confirmation before publication); advance the Audit of Intent and Hamberger's Law frameworks with empirical Phase 1 evidence
  • NTP claim scan: All e-type claims sourced to OPC Phase 1 report (27 May 2026), cross-confirmed against five NZ media outlets; n-type governance claims defensible as universal board principles with book foundation; no unsourced existence assertions
  • Defence angle paragraph (Section 27): present, 144 words, opposition test passed, reasonable observer test passed. Series defence angle cut: vendor security as an independently verified supply chain control; Kaseya (2021) and MOVEit (2023) supply chain compromise precedents and the sovereign cloud (data residency, jurisdiction, lawful access) architectural dimension as institutional anchors. Per-series calibration applied: NATURAL FIT (written straight, no visible bridging)

[Navigation links: Cyber Sunday Cyber News #5 | Cyber Sunday Cyber News #7 (upcoming)]


There were 99,416 of them.

That is the confirmed number: not an estimate, not a range, not a preliminary figure. On 27 May 2026, the Office of the Privacy Commissioner published Part 1 of its formal inquiry into the ManageMyHealth data breach of December 2025. The revised figure is 99,416 confirmed affected individuals. Ninety-one per cent were patients of Northland's hospital system. The data compromised included hospital discharge summaries, clinical correspondence, and referral letters spanning 2017 to 2019.

The inquiry found that both Manage My Health and Health New Zealand breached Rule 5 of the Health Information Privacy Code 2020, which requires organisations to take reasonable steps to protect health information against loss, unauthorised access, use, modification, or disclosure. The Commissioner intends to issue compliance notices to both parties, describing this as the strongest enforcement tool currently available under the legislation.

Read that again carefully. Not a finding that something might have gone wrong. A formal determination that reasonable security safeguards were absent. Two named organisations. Two confirmed breaches. Compliance notices pending.

For boards, the question is no longer what happened. The question is why the governance architecture that was supposed to prevent this was not fit for purpose, and whether your own organisation has the same gap.

From Incident to Accountability

When the MMH breach was first reported in December 2025, it entered the public record as an incident. A platform was breached, patient data was exposed, a ransom demand of approximately NZ$105,000 was made. These are the facts of the incident.

What the Phase 1 report adds is something different: cause and accountability placed on the record under the Commissioner's authority. This is not a media characterisation or an expert opinion. It is a regulatory determination.

The distinction matters for boards. Incidents are events that organisations manage. Regulatory findings are records that follow organisations. A finding that an organisation breached Rule 5 of the Health Information Privacy Code is a fact that sits in the public domain permanently.

The five-month gap between incident and finding is not unusual; formal inquiry processes take time. What the gap has produced is a report that moves the conversation from "what happened" to "what was structurally missing." For board-level readers, the structural findings are where the learning is.

What the Phase 1 Report Actually Found

The Phase 1 report does not say the breach happened because of a sophisticated attack. It says the breach happened because the governance architecture was not fit for purpose.

Four structural findings stand out.

First: the project team that deployed the My Health Documents module carried no specialist privacy or security personnel, despite the scale and sensitivity of the data involved. Hospital discharge summaries and clinical correspondence for tens of thousands of patients were placed on a platform without the people on the project team who would have known to ask the right questions.

Second: the contractual framework between Health New Zealand and Manage My Health was not fit for purpose. The contract did not establish adequate security requirements, did not create adequate mechanisms for monitoring compliance, and did not assign accountability for security outcomes in a way that could be operationalised.

Third: the internal privacy risk assessments that were conducted were of poor quality. This is an Audit of Intent failure in the precise sense the Cyber Guide framework defines it: the governance machinery existed, but it was not genuinely designed to catch failures. It was designed to document that a process had occurred.

Fourth: and this is the one that matters most for boards, Health New Zealand relied on Manage My Health's own assurances rather than independent checks. The vendor decided what constituted adequate security. The agency accepted that determination without verification.

That fourth finding is the one that travels. It is not unique to health. It is not unique to New Zealand. It is the pattern that appears every time a significant vendor-managed data breach reaches a formal inquiry: the contracting organisation accepted the vendor's self-assessment as evidence of security without independently confirming it.

Hamberger's Law, Demonstrated

The Cyber Guide for New Zealand Boards introduced Hamberger's Law as the organising principle of the series: cybersecurity failures are governance failures before they are technical ones. The Phase 1 report is a direct, formal demonstration.

The breach did not happen because someone lacked the technical knowledge to configure a firewall. It happened because the governance architecture did not require independent confirmation of security, did not staff the project with people who would ask for it, and did not build contractual mechanisms to enforce it.

The Fiduciary Risk Exposure framework from the Cyber Guide holds that the duty of care does not transfer with the contract. Health New Zealand remained the accountable entity for the security of patient data regardless of the role Manage My Health played as a processor. The Phase 1 finding confirms this: both parties are named, both parties breached Rule 5, and compliance notices are directed at both.

For boards in any sector: the contract with your technology vendor does not transfer your organisation's accountability for the data. It may transfer the technical obligation. It does not transfer the board's governance responsibility to confirm that obligation is being met.

The Pattern That Travels

The research community has a name for this: processor self-attestation. The practice of contracting for security and accepting the contractor's own confirmation that the requirements are being met. It is widespread. It is structurally incentivised. Contractors have every reason to confirm their own compliance, and contracting organisations rarely have the technical capacity or the contractual mandate to check.

What the Phase 1 findings add to this picture is the naming of the pattern. The Commissioner found over-reliance on vendor assurances rather than independent checks or verification. Every director reading this should hear that as a description of their own organisation until proven otherwise.

This is what the Cyber Guide refers to as the Vendor-Decides Pattern: when the vendor determines what constitutes adequate security performance and the contracting agency accepts that determination without independent verification. The MMH Phase 1 report is the clearest NZ case study to date of what this pattern produces when it reaches a regulatory finding.

Note to directors: ask your team today whether any of your critical data platforms are governed under contracts where the vendor's own self-certification is the primary evidence of security compliance. If the answer is yes, that gap is now formally documented in a regulatory finding as a cause of breach.

What Changes from Here: The Regulatory Landscape

The Phase 1 report does not only look backward. Two of its recommendations point forward and will affect every NZ organisation that uses vendor-managed data platforms.

Third-party processor direct liability: The Commissioner recommended that the Privacy Act 2020 be amended to hold third-party processors directly liable for security failures when processing data on behalf of another agency. Currently, the legislation places primary accountability on the data controller. The reform would extend liability to the processor. This recommendation is now formally on the record and enters the active Privacy Act review pipeline.

What this means for boards: the current framework allows processors to carry less formal legal exposure than controllers even when the failure originates in the processor's systems. The Phase 1 recommendation would close that gap. Organisations that currently rely on contract terms to manage processor liability should be watching this reform process.

Central verification process for health portals: The Commissioner also recommended establishing a central process for verifying the security of health portals before they are authorised to handle patient data. This would shift the current model, where organisations self-certify security arrangements, toward an independent pre-authorisation step.

Neither recommendation is yet operative. Both are formally on the record. The regulatory ground has shifted even before the recommendations are implemented: the Phase 1 report establishes that the current governance model was inadequate.

The proposed critical infrastructure resilience regime being developed by the Department of the Prime Minister and Cabinet is also relevant context. The MMH Phase 1 findings and the OPC's third-party reform recommendation are material inputs to that consultation. Health data systems are a likely focus of any critical infrastructure framework. Organisations with health data responsibilities should be tracking that consultation.

The New Zealand Lens

The 91 per cent Northland concentration in the affected population is not incidental. It reflects a specific arrangement between the former Northland District Health Board and Manage My Health to surface hospital discharge information through the portal. Other District Health Boards did not replicate that arrangement, which is why the geographic distribution of affected individuals is so heavily concentrated.

Phase 2 of the inquiry will address real-world impacts on affected individuals. It will include face-to-face engagement with Northland providers, including Māori health providers. The Cultural Security Envelope argument developed in the Cyber Guide holds that security governance must reflect the specific populations whose data is held. The concentration of affected individuals in a region with significant Māori health data is exactly the context in which that principle applies.

The Phase 2 findings will add a further layer to the public record. Boards with health data responsibilities, or with data relationships involving Māori communities, should anticipate that Phase 2 will raise governance expectations further.

What Directors Should Do

Three actions follow directly from the Phase 1 findings.

Review your processor contracts. The finding that the contractual framework was not fit for purpose should prompt every board to ask whether its critical data vendor contracts establish security requirements with specificity, create monitoring mechanisms, and assign accountability in ways that can be operationalised. A contract that says "the vendor will maintain appropriate security" is not fit for purpose.

Require independent verification. Self-attestation by a vendor is not evidence of security compliance. Under the NZ Information Security Manual version 3.9, independent security assessment requirements apply across agencies managing sensitive data. If your organisation is relying on vendor confirmation of compliance without independent testing or audit, the MMH Phase 1 findings have identified your gap.

Staff governance with the right people. The finding that the project team carried no specialist privacy or security personnel is a board-level accountability signal. Boards should confirm that any project involving significant data assets has privacy and security expertise on the team, not added as a downstream review.

The international picture confirms the direction. Under NIS2, the EU's critical sector security framework, organisations are required to assess and manage security risks in their supply chain and contractual relationships. The ISO 27001:2022 information security standard, specifically Annex A, clause 5.19 through 5.22 on information security in supplier relationships, requires documented security requirements in contracts and regular assessment of supplier compliance. The Phase 1 finding that the contract was not fit for purpose and that no independent checks were performed is a textbook gap against both international standards.

The SolarWinds consent decree in the United States, the UK Information Commissioner's Office post-breach enforcement against processors, and the NIS2 supply chain audit requirements all converge on the same accountability principle: the contracting organisation remains liable for what the vendor does with its data, and demonstrating due diligence requires evidence of independent verification, not contractual clauses.

Defence and Sovereignty Implications

There is a supply chain dimension to this that critical sector boards should sit with. The vendor assurance failure the Phase 1 report describes is the same structural weakness behind the largest supply chain compromises on record. The 2021 Kaseya incident and the 2023 MOVEit breach both turned a single processor failure into a cascade across thousands of downstream organisations that had each contracted for security and assumed it was present. The defence and critical infrastructure sectors absorbed that lesson first: vendor security is treated as a supply chain control to be independently verified, not a contractual assurance to be accepted. The architectural question underneath it is sovereign cloud, where patient data is processed, under whose jurisdiction it sits, and who holds lawful access to it. For boards holding sensitive data on vendor-managed platforms, the contract answers none of those questions on its own.

The Question for Your Board

The Phase 1 findings are now on the public record. Two organisations, two confirmed breaches, compliance notices pending, and a legislative reform recommendation formally entered into the reform pipeline.

For directors, the question is not whether this could happen to your organisation. The question is whether your governance architecture would catch the same gaps that the Phase 1 report identified: a project team without security expertise, a contract without independent verification mechanisms, risk assessments that document process rather than confirm protection.

The duty of care does not transfer with the contract. It never has.

What does your board's evidence of independent verification actually look like?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is an enterprise architect and technology strategist with more than 30 years of experience across cloud, AI, cybersecurity, and transformation programmes in government, banking, transport, and aviation. He holds TOGAF, IAPP, and AMInstD credentials, and is an Associate Member of the Institute of Directors NZ. He is the founder of Te Pono Limited and the creator of the V.E.R.A. (Verified Existence and Reasoning Architecture) logic engine. The Hamberger Report: Cyber Guide for New Zealand Boards is the definitive board-level cybersecurity governance guide.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] Office of the Privacy Commissioner. "Part 1 Inquiry: ManageMyHealth and Health New Zealand." 27 May 2026. https://www.privacy.org.nz/

[2] RNZ. "Privacy Commissioner finds ManageMyHealth and Health NZ breached privacy code." 27 May 2026. https://www.rnz.co.nz/

[3] NZ Doctor. "MMH breach: Privacy Commissioner findings." 27 May 2026. https://www.nzdoctor.co.nz/

[4] The Spinoff. "Privacy Commissioner report on ManageMyHealth breach." 27 May 2026. https://thespinoff.co.nz/

[5] LiveNews. "OPC Phase 1 findings: ManageMyHealth." 27 May 2026. https://livenews.co.nz/

[6] International Organization for Standardization. "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection." 2022. https://www.iso.org/

[7] National Cyber Security Centre New Zealand. "New Zealand Information Security Manual v3.9." May 2025. https://www.nzism.gcsb.govt.nz/

[8] European Union. "Directive (EU) 2022/2555 (NIS2 Directive)." December 2022. https://eur-lex.europa.eu/

[9] Department of the Prime Minister and Cabinet. "Proposed Critical Infrastructure Resilience Regime: Consultation." 2026. https://www.dpmc.govt.nz/

[10] Cybersecurity and Infrastructure Security Agency. "Supply Chain Compromise Advisories: Kaseya VSA (2021) and MOVEit Transfer (2023)." 2023. https://www.cisa.gov/

Previous
Previous

The Assurance You Could Not See

Next
Next

Cybersecurity Governance: The Week AI Found the 18-Year-Old Hole