03/01/2026
To all our patients
Many of you will be aware that the Manage My Health patient portal has experienced a major data breach. We understand this has taken the form of a cyber attack on their platform.
Manage My Health is a New Zealand owned and managed independent health-data management platform used by many practices throughout New Zealand to enable patients to access much of their health record through an app or online portal. All of our patients have the option of a Manage My Health account, but many of you will not.
We are awaiting further information about the scale and nature of this attack. At this stage information is limited. All appropriate actions are being taken at local and national level to ensure the breach is contained. No practices as yet have been informed if any of their patients have been affected, us included.
If you have never requested a Manage My Health account then you can be assured you are not affected.
If you do have a Manage My Health account then all we know so far is that you could be affected. However, Fiordland Medical Practice made the decision some time ago to NOT incorporate patient notes (the notes we write) into the Manage My Health system, so you can be assured none of our notes are involved in the breach.
What information could be included?
This could be laboratory results and also communication / letters or notes from specialists or other services. Prescriptions are also visible on the platform. In addition, if you have every used the platform to pay for services, then there is the potential for credit card or bank details to be involved. Please see below for a statement from Manage My Health.
Personal details such as phone numbers, email addresses are possibly involved.
At this stage, we would strongly urge you to NOT OPEN any links contained within communication from Manage My Health* and to certainly be extra vigilant about suspicious communications (phone calls, text-messages, e-mails, etc) in the coming days – at least until we have confirmed whose data has been breached.
Manage My Health, the Privacy Commission, New Zealand Police and Te Whatu Ora are all working to resolve this as fast as possible.
We will be in touch with more updates as they become available
Communication directly from Manage My Heath states :
“Preliminary investigation reveals no evidence at this stage that the core patient database was accessed, nor any evidence of data modification or destruction within our system, nor any access to user credentials.” And that ‘a specific group of documents’ were accessed.
What you can do?
Manage My Health recommends that it is best practice to regularly update your password.
To ensure your online security, we strongly advise you read the guidelines provided by the Own Your Online at https://www.ownyouronline.govt.nz/personal/get-protected/
Manage My Health users can enable Mutli-Factor Authentication (MFA) using a supported authenticator app, providing an additional layer of account security.
Supported Authenticator Apps:
Google AuthenticatorMicrosoft Authenticator
Here is the link to instructions to enable the two-factor authentication (you need to be logged in to access the link) – https://app.managemyhealth.co.nz/myaccount/two-step-verification
* Fiordland Medical Practice has confirmed both of these links are genuine and safe.
Find guidance, tips and advice to help you understand how to protect yourself against common online security threats, and learn how to respond if something happens.