By Webfit News Desk
The ransom deadline linked to New Zealand’s largest patient data breach has passed, with no further medical information released so far. But the silence has done little to calm concerns.
The cyber attack on Manage My Health continues to raise serious questions about data security, transparency, and accountability across the health sector.
What Happened and Where Things Stand
A hacker using the name “Kazu” demanded US$60,000 after gaining access to hundreds of thousands of medical records belonging to more than 120,000 users.
The ransom deadline was believed to expire at 5.37 am New Zealand time, following an online threat to leak all stolen data if payment was not made.
As of now:
- No additional data has been released
- Manage My Health has not confirmed whether any ransom was paid
- Police and government agencies remain involved
- A formal review has been launched by the Health Minister
Government Position on Ransoms
Health Minister Simeon Brown reiterated the government’s long-standing stance that ransoms should not be paid.
He confirmed he had spoken directly with the platform’s leadership and made clear expectations around public communication and cooperation with authorities.
He described the disappearance of sensitive health data as “unacceptable” and announced an urgent review into how the breach occurred and how it was handled.
Criticism Over Communication and Preparedness
While Manage My Health has apologised for the anxiety caused, it acknowledged shortcomings in how it communicated with patients and health providers in the days following the breach.
The platform said its priority was securing systems and verifying information before issuing updates. It has committed to publishing daily updates going forward.
That explanation has not satisfied everyone.
Cyber security professionals have been blunt in their assessment. One senior technical manager described the breach as deeply damaging, questioning whether the platform could recover trust.
Health data, experts say, is among the most sensitive information any organisation can hold, on par with financial data. Failures in this space carry long-term consequences.
Intelligence and Privacy Experts Weigh In
Former intelligence officer Antony Grasso, who is also a Manage My Health user, said paying a ransom is rarely advisable.
He warned that criminals often release data anyway, even after payment, and that paying only signals vulnerability.
Grasso also criticised what he described as a lack of visible action and transparency from the platform in the immediate aftermath of the breach.
Deputy Privacy Commissioner Liz MacPherson added that concerns around the platform’s security had surfaced previously.
She said the broader issue extends beyond one company. In her view, New Zealand continues to suffer from widespread complacency around cyber security.
A Regulatory Gap in New Zealand
MacPherson pointed to a key difference between New Zealand and other countries.
Unlike Australia, New Zealand currently has no civil penalty regime for serious privacy breaches.
In Australia:
- Major breaches can attract fines exceeding AUD $50 million
- Penalties can reach 30 percent of company turnover
- Fines are designed to outweigh any financial gain from a breach
New Zealand lacks comparable penalties, a gap critics say reduces incentives for companies to invest adequately in cyber protection.
What Manage My Health Is Doing Now
In its latest statement, Manage My Health said:
- It is working with a cross-sector response group
- International teams are monitoring known data leak sites
- Takedown notices will be issued if stolen data appears online
- A High Court injunction has been obtained to prevent access to leaked data
- It will fully cooperate with the ministerial review
The High Court in Wellington has confirmed it received an application for the injunction.
Why This Case Matters
This breach is not just about one platform.
It highlights:
- The growing threat to health data
- Weaknesses in cyber preparedness
- Gaps in enforcement and penalties
- The emotional toll on patients whose most personal information may be exposed
For many users, the concern is not only whether their data has leaked, but whether systems meant to protect them were ever strong enough.
The Bigger Question
As the immediate ransom threat fades, a larger issue remains.
Can public trust in digital health platforms be rebuilt without stronger oversight, clearer accountability, and real consequences for failure?
For now, that question remains unanswered.







