Desk live·
ForensicPost
Breaches/Healthcare/File 25-1228b

ManageMyHealth Breach Exfiltrated Medical Documents for 120,000 Patients

A breach of the ManageMyHealth patient portal, disclosed in late December 2025, involved the exfiltration of medical documents relating to more than 120,000 patients.

Constructed geometry · not a chart of case data
JurisdictionNew Zealandthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetManageMyHealth
ActorUnattributed
D. Kennedy12 min readConfidence: medium2 sources reviewed

A breach of the ManageMyHealth online patient portal, disclosed in late December 2025, involved the exfiltration of hundreds of thousands of sensitive medical documents relating to more than 120,000 patients.

Documents Rather Than Records

The distinction matters. A record in a database is a structured row — a diagnosis code, a date, an identifier. A document is a letter from a specialist, a test result, a referral, a discharge summary.

Documents contain narrative. They are written by clinicians for other clinicians, in plain language, and they describe a person’s condition in terms anybody can read. It is the most directly interpretable form medical data takes.

The corpus filed at 25-1010 that there is no equivalent of a credit freeze for a leaked diagnosis, and at 25-1018 that health payment records published to a public channel are read by neighbours and employers. Clinical correspondence is worse than either.

A Patient Portal Is The Concentration Point By Design

Portals exist so patients can see their own records in one place. That requires assembling correspondence from multiple providers into a single accessible store.

It is a genuine improvement in care and it manufactures exactly the structure this corpus keeps recording — the rule at 25-1219b that the organisation holding the largest population is the one with no relationship to any of them. A patient chooses a doctor; the portal was chosen for them.

And New Zealand Is Otherwise Absent From This Database

The corpus documented at 25-0502 the filters shaping which incidents anywhere become public, and at 25-1225 that this database is overwhelmingly American and British.

This is its first New Zealand file. Graded medium: the incident is reported consistently, and the mechanism, the actor and the notification status are not established in the material we reviewed.

How we reported this

Compiled from published reporting, listed below. The intrusion route and actor are not established. We have not accessed any published material. Corrections: corrections@forensicpost.com.

Sources
  1. ManageMyHealth data breachWikipedia
  2. Data breach, cyber security and privacy law updateStephens Lawyers & Consultants
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary