Digital panel illustrating cybersecurity and data protection

Te Whatu Ora must demonstrate that its action plan is making patient data safer, rather than simply completing documents and frameworks.

The response by Health New Zealand Te Whatu Ora to the Manage My Health cyber incident addresses many of the fundamentals. The next test is whether the action plan produces measurable improvements in the protection of patient data.

Cybersecurity programmes need more than policies, registers and completed milestones. They must show that controls are working in practice: risks are identified early, sensitive information is protected, suppliers are held to clear expectations and incidents are detected and contained quickly.

For health organisations, this means connecting governance activity to outcomes. Progress should be demonstrated through evidence such as improved visibility of critical systems and data, tested incident response arrangements, security assurance across third parties, and a reduction in the gaps that expose patient information.

Completed documentation can establish accountability, but it is not a substitute for operational resilience. Patients and the public need confidence that lessons from the incident are being translated into stronger, measurable safeguards.


Read the original opinion

This IISRI® summary links to Michal Everis' opinion published by New Zealand Doctor Rata Aotearoa.

Read on New Zealand Doctor
This website uses cookies. You can find our Privacy Policy here. If you don‘t agree with it, please leave this website.
I agree