Key Takeaways
- Manage My Health is contacting affected patients through email notifications to inform them of a data breach
- The notifications include an 0800 number for support and help
- The company is working with Health New Zealand, the Office of the Privacy Commissioner, and other organizations to ensure clear and consistent information is received by patients
- The data breach included clinical discharge summaries, referrals, and related files, as well as patient-uploaded information
- Manage My Health has been granted a High Court injunction to prevent access or sharing of the stolen data
Introduction to the Data Breach
Manage My Health, a patient portal, has announced that it will be contacting affected patients through email notifications to inform them of a data breach. The company stated that it hopes to complete the process of notifying all affected patients by early next week. The notifications will include an 0800 number that patients can call to seek support or help if needed. This is a crucial step in ensuring that patients are informed and supported throughout the process.
Redirecting the Mobile App
The Manage My Health mobile app has been redirected to the Manage My Health web application to ensure that notifications are consistent across platforms. Visitors to the mobile app will see a pop-up notification alerting them to the redirection. The company has stated that this is an intentional move and that the mobile app will be restored in time, with users being notified of this. This redirection is likely an effort to streamline the notification process and prevent any confusion or discrepancies between the mobile app and the web application.
Collaboration with Other Organizations
Manage My Health is working closely with Health New Zealand, the Office of the Privacy Commissioner, General Practice New Zealand, and GP clinics to ensure that clear and consistent information is received by patients. This collaboration is essential in ensuring that patients receive accurate and timely information about the data breach and the support available to them. The company is also working around the clock to respond to the unprecedented criminal cyber attack, which has caused significant disruption and concern for patients and providers.
Criticisms and Concerns
Until recently, some Northland GPs had criticized Manage My Health for a lack of communication regarding the data breach. Kensington Health practice manager Darren Rowbotham expressed concerns that he had received no official information about the number of patients impacted, nor how they would be contacted, what information would be disclosed, and what support would be offered. Manage My Health had created a data breach report within the portal, but the number of affected patients kept changing, and Rowbotham did not know which number was correct. These criticisms highlight the importance of clear and consistent communication in situations like this.
Government Response
Health Minister Simeon Brown has acknowledged the data breach as concerning and has ordered an urgent review into the incident. Brown has stated that patient data is incredibly personal and must be protected to the highest standards, whether it is held by a public agency or a private company. He has expressed pleasure that Manage My Health is starting to contact affected patients and has emphasized the importance of the company working quickly to ensure all impacted patients are contacted as soon as possible. The government’s response to the data breach is crucial in ensuring that patients receive the support and protection they need.
Stolen Data and High Court Injunction
The information taken in the data breach included clinical discharge summaries, referrals, and related files, as well as information uploaded to the system by patients. Some of this information covered historical clinical referral records dating from between 2017 and 2019. Manage My Health was granted a High Court injunction on Tuesday night, preventing anyone from accessing or sharing the stolen data. By the next morning, all posts referring to the Manage My Health hack had been removed from an account purporting to be used by the hacker Kazu. Anyone in possession of the information is required to delete it, highlighting the seriousness of the situation and the importance of protecting patient data.
Conclusion and Next Steps
In conclusion, the data breach at Manage My Health is a serious incident that has caused significant concern and disruption for patients and providers. The company is working to contact affected patients and provide support, and the government has ordered an urgent review into the incident. The importance of clear and consistent communication, as well as the protection of patient data, cannot be overstated. As the situation continues to unfold, it is essential that patients and providers remain informed and vigilant, and that the company and government take all necessary steps to prevent such incidents in the future.


