Cybersecurity Alert: Manage My Health Data Breach
As you may be aware, the patient portal Manage My Health has experienced a significant cybersecurity breach involving the theft of sensitive data.
A large amount of personal information and health information was obtained by an organised hacking group for financial benefit. The hackers threatened to release and sell the stolen patient information on the dark web if the company did not pay a ransom. Affected patients and consumers of Manage My Health have been notified directly.
Further advice and information on the breach can be found here: FAQs related to Cyber Breach(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link).
Advice for personnel:
Fire and Emergency and our suppliers do not use the Manage My Health platform. However, this breach is a reminder to follow essential cybersecurity practices to protect information in Fire and Emergency systems and personal accounts:
- Use unique passwords for Fire and Emergency accounts, never reuse personal passwords. How to reset your password.
- Use Multi-Factor Authentication to further protect Fire and Emergency systems and personal accounts. Review the MFA setup guidance.
- Stay alert for phishing attempts via email or phone; avoid clicking suspicious links or attachments. How to manage phishing emails.
- Use only approved ICT systems which have been reviewed against our internal security standards. See the approved software list(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link)(external link).
- Use Information Security Classifications on all official documents. Review the classification guidelines.
- Report any suspicious activity immediately to ICT Support.
- Review our Cyber Security Portal for guidance and best practices.
If you have any general cyber security queries, please contact cyber.security@fireandemergency.nz