Industries

Healthcare & allied health

The most trusted sector, and the one with the most to lose.

Patients trust health providers more than they trust almost anyone, and hand over more sensitive information than they give almost anyone. That's a lot of goodwill sitting on top of a lot of risk. This page is about the obligations that come with it — including the ones somebody has probably told you don't apply to a practice your size.

Health privacy law, accreditation and practice software are all different across the Tasman. Pick yours.

The numbers, from the regulator

Most breached. Most trusted. Most to lose.

225

breach notifications from health service providers in 2025 — more than any other sector

19%

of all notifications in Australia, out of 1,205 across every industry

+8%

on 2024's 1,112 notifications — the highest total since the scheme began in 2018

74%

of Australians say they trust health providers with their personal information

Sources: OAIC Notifiable Data Breaches Report, published 06/07/2026, and the OAIC Australian Community Attitudes to Privacy Survey 2026.

The case every NZ practice should read

Manage My Health, Health NZ, and about 100,000 patients.

In December 2025 the Manage My Health patient portal was breached. Sensitive health information was taken and then offered for sale. On 27/05/2026 the Privacy Commissioner released Phase 1 findings.

100k

New Zealanders affected, or close to it

91%

Of those affected were Northland patients, many of them likely to be Māori

Rule 5

Of the Health Information Privacy Code, breached by both Manage My Health and Health NZ

Both

Parties the Commissioner intends to issue compliance notices to

Source: Office of the Privacy Commissioner statement, 27/05/2026. These are Phase 1 findings — a later phase may still be running, so read them as where the inquiry had got to rather than where it ends. New Zealand does not publish breach notification figures split by sector, so we are not going to give you a health-sector percentage. Nobody has one.

The thing most practices have wrong

The $3 million turnover exemption does not apply to you.

Most small Australian businesses are exempt from the Privacy Act if they turn over less than $3 million a year. It's a well-known rule and it's perfectly real.

It does not apply to health service providers. If you provide a health service and hold health information, you're covered by the Australian Privacy Principles regardless of your size. A three-doctor clinic turning over $800,000 has the same obligations as a hospital group. So does a solo physiotherapist, a psychology practice, a dental surgery and an allied health group running out of a shopfront.

We raise this early because it's the single most common misunderstanding we come across, and it's usually delivered to the practice owner with great confidence by someone who has read the general rule and not the exception.

The thing most practices have wrong

There is no turnover test in New Zealand, for anyone.

Australian practices spend a lot of energy working out whether the $3 million small business exemption catches them. New Zealand practices do not have to, because the Privacy Act 2020 has no size exemption at all. Every agency is covered.

Health goes further again. The Health Information Privacy Code 2020 replaces the information privacy principles for the health sector rather than sitting on top of them, so your obligations are the Code's rules, not the IPPs. The one that does the work is Rule 5 — storage and security. That is the rule the Commissioner found breached in the Manage My Health case, by both the software vendor and the health agency that engaged it.

HIPC Amendment No. 2, made in March 2026, brought IPP 3A into the Code with effect from 01/05/2026 — what you have to tell a patient when you collect their information from someone other than them. Referrals, insurers, other providers. Worth a look at your privacy statement.

Read this one if you have a booking page

On 24/06/2026 the Privacy Commissioner made tracking pixels a health privacy problem.

The Commissioner made findings against Medmate Australia and Monash IVF. The short version: putting a third-party tracking pixel on a health website, and then using it to retarget those visitors on social media, amounts to collecting sensitive information. Sensitive information requires consent.

Here's why that should make you go and check something. Nearly every practice website built in the past decade has a Meta pixel or a Google tag on it, put there by a marketing agency to measure whether the ads were working. If it's sitting on your online booking page, it is watching people who are booking appointments for specific conditions.

Almost nobody knows it's there. The person who installed it has usually moved on, and the practice owner has never seen the inside of the site's code. It doesn't show up on the page.

Worth doing this week

How to find out in ten minutes

  1. Ask whoever manages your website for a list of every third-party script and tag on it, including anything loaded through Google Tag Manager.
  2. Ask specifically whether any of them run on the booking page, the enquiry form, or pages describing particular conditions or services.
  3. Ask your practice management or booking vendor whether their embedded widget loads anything of its own.
  4. If the answer to any of these is "I'm not sure", treat that as a yes until proven otherwise.

We'll do this audit for you if it's easier. It's not a big job, and it's a much better conversation to have now than after a complaint.

Read this one if you use an outside vendor

The Commissioner named three things Health NZ failed to do. All three are governance, not code.

In the Phase 1 findings of 27/05/2026, the vendor was found to have failed on technical security safeguards, on detecting large-scale unauthorised access, and on risk management. Fair enough — that is the vendor's job.

The findings against Health NZ are the ones every practice should read twice, because Health NZ was the customer. It failed to include privacy and security specialists in the project team. It failed to obtain independent security verification. And it failed to develop appropriate contractual protections with the vendor.

None of those three are hard. None of them are expensive, relative to what happened. They are simply things that nobody owns in a practice unless somebody is made to own them — and they are exactly the things an IT provider is for. That is the whole pitch, and it is built on a New Zealand finding rather than an Australian one.

Ask before you sign

Four questions for your next software vendor

  1. Who on our side is responsible for reviewing the privacy and security design before this goes live, and are they in the room now?
  2. Has this product had independent security verification, by someone other than the vendor, and can we see it?
  3. What does the contract actually say about security obligations, breach notification to us, and who pays when it goes wrong?
  4. How would anyone here find out if a large volume of patient records were being pulled out of this system over a weekend?

We will sit in that meeting with you and ask them ourselves if it helps. The questions are more useful before the contract than after the breach.

Practice management systems

Your clinical software decides most of your IT, whether you like it or not.

This is where generic IT advice falls apart. "Just move everything to the cloud" is a fine sentence right up until it meets a vendor-mandated SQL configuration on a server in the storeroom.

System Where it usually lives What that means for you
Best Practice On-premises SQL server, often the oldest machine in the building Backups have to follow the vendor's documented procedure or the restore won't work. Server health and disk space are clinical risks, not IT housekeeping
Medical Director On-premises, with cloud options depending on version Version and database configuration drive what's possible. Upgrades need planning around a clinic day, not a weekend assumption
Genie On-premises server, common in specialist practices Specific supported configurations. Moving it is a project with a rehearsal, not an evening
Zedmed On-premises or hosted Migration paths exist but are detailed. The data conversion is the part that needs the testing
Cliniko Cloud, common in allied health The server problem goes away. Access control, offboarding and device security become the whole job
Halaxy Cloud, common in allied health Same shape as above. Who can see what, and what happens when a practitioner leaves the practice
System Where it usually lives What that means for you
Medtech Evolution On-premises, or on Medtech Cloud Integration runs through the ALEX API platform, which is an integration layer rather than a practice system in its own right. Whether you are on-premises or on Medtech Cloud changes the backup conversation completely, so that is the first thing we establish
indici Cloud, by Valentia Technologies 250-plus practices and over two million active patient records. The server problem goes away and access control, offboarding and device security become the entire job. The myindici patient portal is a second front door worth reviewing separately
Gensolve Allied health, over 1,000 NZ practices Native ACC electronic billing, plus ACC45s and conditions claiming. Which means an outage is not an inconvenience, it is a billing stoppage. Uptime and internet redundancy get treated accordingly
Nookal Allied health, cloud Operates in New Zealand across physio, psychology, OT, podiatry and more. Check what it does and doesn't do for your ACC workflow before you commit — we will not tell you it handles something we have not seen it handle
Toniq Pharmacy, around 85% of NZ pharmacies Over 850 pharmacies run Toniq Dispensary. Toniq Vault covers online backup, which does not remove your obligation to know it restores. Dispensary downtime is a clinical problem within the hour

If you're moving to cloud

Not a single patient record is the only acceptable loss figure. So we do it the slow way: a test migration first, a reconciliation of record counts and attachments, a clinician checking real patient files in the new system before anyone commits, and the old system kept intact and readable until you're certain. Cutover happens when the checks pass, not when the weekend was booked.

Secure messaging and identifiers

Argus, Medical Objects and HealthLink are how referrals, discharge summaries and results actually move between providers. They're also the things that quietly stop working after a server move, a mail change or a certificate expiry — and nobody notices until a specialist rings asking where the referral went.

We treat secure messaging and the Healthcare Identifiers service as part of the clinical system, not as an email add-on. That means checking them after every change and monitoring them between changes.

ACC, secure messaging and identifiers

ACC electronic billing and ACC45 claiming have no Australian equivalent at all, which is precisely why they get overlooked by anyone working from an Australian playbook. If your practice bills ACC, the integration between your practice system and ACC is revenue infrastructure. It gets monitored, and it gets checked after every change, the same as the clinical database.

HealthLink runs the secure messaging, eReferrals and SmartForms side in New Zealand. Like all secure messaging it fails quietly after a server move, a mail change or a certificate expiry, and nobody notices until a specialist rings asking where the referral went. We treat it, and the National Health Index, as part of the clinical system rather than an email add-on.

My Health Record and accreditation

Two sets of obligations that land on the practice manager's desk.

Australia's My Health Record

If your practice is a registered provider organisation, you have ongoing participation obligations under the My Health Records Rule 2016. The one that catches people out is the security and access policy — it isn't optional, and it has to be a real document covering how staff are trained and authorised to access records.

  • It covers reception and admin too. Not just clinicians. Anyone who can get to the system needs to be named in the policy and trained.
  • Reasonable user account management. Individual accounts, removed promptly when someone leaves. Shared logins make this impossible to evidence.
  • Separate breach notification. There are notification obligations to the System Operator that sit alongside the notifiable data breach scheme, not instead of it.
  • It has to be current. A policy written in 2019 by a practice manager who has since left is not a policy, it's a PDF.

Accreditation

For general practices, the RACGP Standards for General Practices (5th edition) require documented information security, backup and business continuity arrangements. The surveyor will ask. Allied health accreditation schemes vary, but they all ask a version of the same questions.

What they're really asking is whether you can show evidence rather than describe intentions. So that's what we produce.

  • An evidence pack, assembled before the visit. Backup reports, restore test results, access lists, policies and training records in one folder.
  • Restore tests with dates on them. A backup nobody has restored from is a hope, not a control, and surveyors have got much better at asking.
  • A business continuity plan that fits a clinic. What happens to today's appointments if the server is down at 8am. Written before you need it.

Hira and the Foundation Standard

Two sets of obligations that land on the practice manager's desk.

New Zealand's Hira programme

New Zealand has no equivalent of Australia's My Health Record, and anyone who tells you otherwise has confused the two. What New Zealand has is Hira, the national health information platform programme run by Health NZ / Te Whatu Ora. It is an interoperability programme — APIs and standards so information can move between providers — rather than one central store of records.

Confusingly, Health NZ calls the consumer-facing part of Hira "My Health Record" as well. So when a vendor or a colleague says My Health Record, ask which country they mean. We always say either "Australia's My Health Record" or "New Zealand's Hira programme", because the two are not the same thing and the difference changes what your practice has to do.

We are not going to tell you what is live in Hira today. The programme has been moving, the published status pages have not kept pace, and a confident answer from an Australian IT provider would be exactly the sort of thing you should distrust. We will find out with you before anything gets planned around it.

The RNZCGP Foundation Standard

The Foundation Standard is compulsory for general practice in Aotearoa and is tied to government funding eligibility. It runs on a three-year cycle: the practice self-assesses, then a College-endorsed assessor does an online review plus an on-site visit of roughly four hours. Fifteen indicators across five domains.

Two of those indicators land squarely on IT. Indicator 2.1 covers the Privacy Act and the Health Information Privacy Code. Indicator 14.2 covers emergency and business planning. Our view — and we will flag it as our view rather than a quote from the Standard — is that a practice cannot demonstrate either one without having addressed data security, backup and recovery.

  • An evidence pack, assembled before the assessor asks. Backup reports, restore test results, access lists, policies and training records in one folder.
  • Restore tests with dates on them. A backup nobody has restored from is a hope, not a control.
  • A continuity plan that fits a clinic. What happens to today's appointments if the practice system is down at 8am.

Cornerstone is a separate thing — the College's voluntary quality accreditation programme, which sits beyond the compulsory Foundation Standard.

The fear nobody says out loud

A staff member looking up a record they had no business looking at.

Not a hacker. Someone on the team, curious about a neighbour, an ex, a colleague, or a name they saw in the news. It happens, practice owners know it happens, and it rarely gets discussed with an IT provider because it feels like an accusation about the staff.

Treat it as a design problem instead. It's a question of access control and audit logging, and both are things we can set up without implying anything about anyone.

  1. Individual accounts, always

    A shared reception login makes every question after the fact unanswerable. This is the one change that makes everything else possible, and it's usually free.

  2. Access scoped to the role

    Reception needs appointments and billing. It does not usually need the full clinical record. Most practice management systems can express that distinction, and most practices have never configured it.

  3. Audit logging turned on and actually retained

    Many systems log record access by default and then keep the logs for a short window, or overwrite them. If a question arises three months later, the answer needs to still exist.

  4. Staff know the log exists

    Not as a threat. As part of induction, in the same tone as hand hygiene. Knowing that access is recorded prevents far more than any after-the-fact investigation ever will.

  5. Offboarding on the day, not the month

    Clinical system, Microsoft 365, secure messaging, the building alarm code and the shared drive. One checklist, run the day someone finishes.

When practices usually ring

"We're up for accreditation."

And the surveyor will ask about information security, backups and business continuity, and nobody has the evidence in one place.

"The practice management server is ancient."

We want it in the cloud, or at least off that machine, without losing a single patient record.

"We read about the tracking pixel finding."

Or: someone accessed a record they shouldn't have, and we can't work out who or when.

"We read what happened to Manage My Health."

And we have no idea what our own software vendor's contract says about security, or who would notice if records started leaving.

Book a review before the surveyor does one.

A free IT review for a practice covers where patient data actually lives, whether the backups restore, who can see what, and what's loading on your website. You get the findings in writing, whether or not you use us.