Vendor Assurance: Contracted, Not Confirmed
Seven security areas were found ineffective. Three have since been fixed. Four have not. The two that would have caught the theft while it was still happening carry the earliest deadline of the lot: 30 November 2026.
That is the scorecard buried in a compliance notice issued on 23 September 2026 by the Privacy Commissioner, under section 123 of the Privacy Act 2020, to Manage My Health Limited. A second notice went the same day to Health New Zealand, Te Whatu Ora. Both agencies had already been found in breach of rule 5 of the Health Information Privacy Code 2020 over the cyber security breach of 31 December 2025. Both notices put dates, deadlines and named controls against findings that until now existed only as findings. Approximately 99,416 individuals were affected. Approximately 91 per cent of them were Health New Zealand patients in Northland. That is the consequence of what both notices describe as a "unique arrangement", under which Health New Zealand supplied Northland hospital discharge documentation into Manage My Health's patient portal. The compromised material ran to 403,730 Health New Zealand documents and 22,609 documents patients had uploaded themselves, confined to a single module of the portal.
Those are the regulator's figures. They are not the figures most people carry in their heads about this breach. The earliest reporting, in the first fortnight of January 2026, put it at around 127,000 people, with more than 80,000 in Northland, and dated detection to 30 December. I used those numbers myself: the Cyber Guide's own chapter on this incident carries 127,000, "more than 60 percent" in Northland, and a 30 December detection date. Those were the best available figures when I wrote it. They have been superseded by the Commissioner's own confirmed count, inside the same calendar year, on the same incident. Anything written about this breach before the inquiry finished, including that chapter, should be checked against the notices rather than repeated.
The two notices do different jobs
These look like one enforcement action landing on two parties. They are not. They are built differently, and they point in opposite directions in time.
The Manage My Health notice, dated 28 August 2026 and issued under rule 5(1)(a) of the Code, is a scorecard on a breach that already happened. Phase 1 of the inquiry identified seven ineffective security areas. They were multi-factor authentication, identity and access management, web security, patch and vulnerability management, system acquisition and development and maintenance, logging and monitoring, and data leak prevention. The notice records that the first three were already remediated before it issued. The remaining four sit in its Schedule as Issues A to D, each with its own deadline. Logging and monitoring, and data leak protection, require action by 30 November 2026 with evidence to the Commissioner by 22 January 2027. Patch and vulnerability management, and system acquisition and development, run to 26 February 2027 with evidence by 26 March 2027. A second penetration-testing report is due by 31 August 2027, at least six months after the first.
Look at the ordering. The two controls that carry the earliest deadline are the two that detect rather than prevent. The drafting is deliberate. Multi-factor authentication and web security make the intrusion harder; logging and monitoring and data leak protection are what turn a successful intrusion into a short one. The notice requires alerting configured to identify relevant threat scenarios and monitoring able to "identify suspicious, abnormal, or unauthorised activity". It also requires data-loss controls that can quantify what left during an incident and raise alerts on "bulk data access, export activity, and anomalous data access patterns".
In the Cyber Guide I set out a control I called the Audit of Intent: a behavioural detection layer. Its question is not "is this user authenticated" but "does this access pattern match what this user normally does". Its job is to freeze an account after the twentieth anomalous download rather than allow a mass export to complete. The regulator did not adopt that name and has never heard of it. What the notice requires, in its own regulatory language, lands on the same control: alerting on abnormal activity, and detection of bulk access and export patterns, as a dated legal obligation. The notice does not validate the concept. It simply shows that a governance framework and an enforcement instrument, written independently, converged on the same missing capability, and the enforcement instrument gave it the shortest deadline in the document.
The other notice is not about the breach at all
The Health New Zealand notice, HNZ-CN-02-2026a, is issued under rule 5(1)(b). That rule covers the safeguards that must exist before health information is given to a service provider. It does not require Health New Zealand to fix what went wrong. It writes down, in enforceable form, what due diligence on a provider is supposed to mean before the next contract is signed.
Its Schedule runs to four issue groups, all due for completion by 29 January 2027, with the project plan itself due to the Commissioner by 12 February 2027. Project governance: a steering group led by a senior staff member, carrying privacy and technical security expertise, with privacy and security as standing agenda items. Privacy risk management: independent initial assessments of providers, a privacy impact assessment at design stage, reviewed before implementation, before any scope expansion, and annually after that. Information security requirements: documented cyber security requirements, evidence that each potential provider was independently assessed against the Health Information Safety Framework and met a suitable standard before any contract exists. They also require a live demonstration of compliance before contracting, and an attestation of security testing aligned to National Cyber Security Centre standards. Contracting: enforceable privacy and security obligations reaching providers and their subcontractors, incident-notification duties, regular assurance reporting, and audit powers the buyer can actually exercise.
Read that list as a board member rather than as a lawyer, and one word does all the work: evidence. Not "consider", not "seek assurance", but evidence that an independent party assessed the provider against a named framework before the contract. That means a demonstration you watched, an audit right you hold, and a report that arrives on a schedule.
That is the shift. Phase 1 found that the project team relied too much on assessments the provider supplied about its own security and privacy, "rather than taking a more independent view". The compliance notice does not instruct anyone to trust less. Trust is not an auditable quantity, and no regulator can order a change in it. What it does instead is require the buyer to hold proof, which is an auditable quantity, and to hold it before the information moves rather than after something goes wrong. The question moves from "did we ask the vendor" to "what do we hold, and who checked it".
The notice is also specific about what else went missing, and the findings are the buyer's, not the provider's. The notice records that Health New Zealand "did not conduct sufficient due diligence before it decided to engage MMH". It records that there were serious problems with the quality of the privacy risk assessments, improving somewhat in the later stages. It records that the 2023 project steering group "did not include direct privacy or security representation" of the kind a project of that novelty, complexity and scale would be expected to carry. And it records that the contracts between the two organisations "were not fit for purpose and did not contain appropriate protections" for patient information. There is one further line in the notice worth putting in front of a board: Health New Zealand "was unable to contact many former staff" to establish whether internal privacy or security specialists had advised the project early enough. That is a limit on the inquiry's own evidence, stated by the regulator about itself. It is also a preview of what an organisation's institutional memory looks like three years after a decision, when the people who made it have moved on and the only surviving record is the one somebody thought to write down at the time.
Why Northland is not incidental
Both notices carry a finding that deserves to be reported precisely. It is easy to repeat in a form the Commissioner did not make. They record that almost 40 per cent of people in Northland are Māori, and that the Commissioner therefore found the breach "likely to have had a disproportionate effect on Māori".
That is an inference drawn from population data. It is not a count of Māori patients among the 99,416 affected, and no such count appears in either notice or in the release. Phase 2 of the inquiry, which the notices describe as covering real-world impacts, has not reported, and neither document states when it will. So the honest statement is narrow: the regulator has found a likely disproportionate effect on the basis of where the affected patients live, and the question of actual impact remains open.
In the Cyber Guide I argue that Māori data sovereignty is a security principle rather than a cultural add-on. The Kaitiakitanga Checklist asks a board three things it usually cannot answer. Has it identified which of its datasets contain Māori data? Is it partnering with Data Iwi Leaders Groups on oversight? And are its controls "sufficient to prevent bulk exports of community health information"? Kaitiakitanga, the principle of guardianship and stewardship, is the reason those questions sit together. This finding is the sharpest real-world instance of that argument I have had to work with.
It also shows where an enforcement instrument stops. Health New Zealand's Schedule requires independent assessment, privacy impact assessments, contractual protections and audit rights. It does not require iwi partnership, and it does not require a Māori-data-specific control of the kind the Cultural Security Envelope describes. That is a fact about the reach of this instrument, not a shortfall in how the Commissioner used the powers available to him. The practical consequence for a board is simple enough. If the demographic composition of a dataset is going to be part of how harm is assessed afterwards, it needs to be part of how risk is assessed beforehand. No compliance notice is going to put it there for you.
What a board should actually hold
The notices are addressed to two organisations. The standard inside them is now visible to every board in the country, and it is not a health-sector standard.
The climate makes the point on its own. The National Cyber Security Centre's SME Cyber Security Behaviour Tracker, released on 21 September 2026, found that 76 per cent of businesses with 20 to 49 employees had experienced a threat or attack in the previous six months. That is against 53 per cent of small and medium businesses overall. Note the size band. The 76 per cent figure describes a specific size band, not New Zealand businesses generally, and a great many specialist providers sit inside that band.
So, four questions, all answerable from documents you either have or do not have. First: for your most recent provider engagement that touches customer or patient data, what independent assessment do you hold, who performed it, and against which named framework? A completed security questionnaire returned by the vendor is the thing that question exists to replace, not an answer to it. Second: did anyone watch the control work? A live demonstration before contracting is now an explicit requirement in a New Zealand compliance notice, and it is the cheapest thing on this list to arrange. Third: does your contract give you audit rights you have actually used, and do those rights reach the provider's subcontractors? An audit clause nobody has exercised is a clause whose limits are undiscovered. Fourth: does your provider's detection capability match the way your data would leave? Manage My Health's earliest deadline is for logging, monitoring and data leak protection, because those are the controls that would have shortened this breach.
If those four are answerable, the fifth question follows on its own: who on your board owns the answer, and when did they last read it?
The open-source world solved a narrower version of this problem by making the evidence public rather than private. OpenSSF Scorecard, a project of the Open Source Security Foundation, runs eighteen automated checks against any open-source repository and returns a score out of ten on each. Those checks cover whether releases are signed, whether dependencies are pinned, whether code review is required before a change lands, whether a security policy exists, and whether known vulnerabilities are outstanding. What matters is not the number. A prospective user can run the check without asking the maintainer for anything, and can run it again next quarter. The assurance is a measurement anyone can repeat, not a claim the supplier makes about itself. That makes it a different kind of object entirely, the same kind of object a live demonstration produces.
Allied procurement settled this question years ago, and the mechanism is instructive. The United States Federal Risk and Authorization Management Program, known as FedRAMP, publishes both the cloud services authorised for federal use and the independent assessors it recognises. That way the assessor answers to the programme rather than to the vendor who engaged it. Australia does the equivalent work through the Infosec Registered Assessors Program, IRAP, whose assessors are endorsed by the Australian Signals Directorate and measure a system against that country's own Information Security Manual. Neither regime asks a supplier whether it is secure. Both require a named independent party to say so, against a published standard, before the system carries government information. New Zealand firms selling into either market already meet that bar. What changed in September is that a domestic buyer has been told, in writing and with a date, to require something recognisably similar.
None of this makes the next breach less likely on its own. A compliance notice is not a control, and a project plan filed with a regulator in February 2027 does not detect anything. What the notice does is change what a board is expected to be able to produce. That expectation now has dates attached to it: 30 November 2026, 29 January 2027, 26 February 2027, 31 August 2027. The instrument has teeth of a defined shape, too. A recipient may appeal to the Human Rights Review Tribunal within fifteen working days. If it fails to remedy the breach or fails to report on its remedial steps, the Commissioner may bring enforcement proceedings, and may publish the details of the notice, which is exactly what happened here.
Every board reading this has signed at least one contract on the strength of a supplier's own description of its security. When your organisation last onboarded a provider that would hold your customers' data, what did you end up holding afterwards? A completed questionnaire, or something an independent party had checked and put its name to?
If your board wants an independent AI and cyber risk briefing, or a review of what your vendor's assurance actually verified, message me and I will send the scope and the fixed fee.
• • •
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. I write as director of Te Pono Limited; the views are personal and do not represent the position of any client, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance, and it is politically neutral.
• • •
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance. Through Te Pono he provides independent AI and cyber risk briefings and vendor assurance reviews to boards; contact andreas@thehambergerreport.com for the scope and fixed fee.
This article was produced with AI assistance under my direction. Research, drafting and images pass through a pipeline I built and govern: automated gates for source verification, forbidden language and political neutrality, and my own review before anything is published. The tools include Claude, Gemini and Openart. The frameworks, arguments and editorial judgements are mine and are the same discipline I apply to the AI systems I audit for clients. AI accelerated the work; the thinking, and the responsibility for it, are mine.
[1] Office of the Privacy Commissioner. "Compliance Notice to Manage My Health Limited, CN 01/2026." 28 August 2026. https://www.privacy.org.nz/assets/DOCUMENTS/Manage-My-Health/20260923-ManageMyHealth-Compliance-Notice-MMH-A1216487.pdf
[2] Office of the Privacy Commissioner. "Compliance Notice to Health New Zealand Te Whatu Ora, HNZ-CN-02-2026a." 22 September 2026. https://www.privacy.org.nz/assets/DOCUMENTS/Manage-My-Health/20260923-HealthNZ-Compliance-Notice-HNZ-CN-02-2026a-A1220605.pdf
[3] RNZ. "Privacy Commissioner Puts Manage My Health, Health NZ on Notice After Data Breach." 23 September 2026. https://www.rnz.co.nz/news/health/1530878/privacy-commissioner-puts-manage-my-health-health-nz-on-notice-after-data-breach
[4] New Zealand Legislation. "Privacy Act 2020, Section 123: Compliance Notices." 2020. https://www.legislation.govt.nz/act/public/2020/0031/latest/LMS23511.html
[5] National Cyber Security Centre (New Zealand). "SME Cyber Vulnerability Jumps as Attacks Hit Medium-Sized Businesses Hardest." 21 September 2026. https://www.ncsc.govt.nz/news/sme-cyber-vulnerability-jumps-as-attacks-hit-medium-sized-businesses-hardest/
[6] Open Source Security Foundation. "OpenSSF Scorecard." 2026. https://scorecard.dev/
[7] General Services Administration. "FedRAMP Marketplace: Authorized Cloud Services and Recognized Assessors." 2026. https://www.fedramp.gov/
[8] Australian Signals Directorate. "Infosec Registered Assessors Program (IRAP)." 2026. https://www.cyber.gov.au/business-government/protecting-devices-systems/assessment-evaluation-programs/irap

