Blog

You Outsourced Your Customer Data. Did You Outsource the Responsibility?

Oct 8, 2026

When a business puts customer records into a hosted portal, it usually expects the provider to look after security. I would want to know what that includes before relying on it. The New Zealand enforcement action shows why.

On 23 September, New Zealand's Privacy Commissioner announced formal compliance notices for Manage My Health and Health New Zealand following the December 2025 patient-portal breach. The regulator found that both had failed relevant responsibilities under Rule 5 of the Health Information Privacy Code 2020, which concerns information storage and security.

The Manage My Health notice records approximately 99,416 affected patients, with 403,730 Health NZ documents and 22,609 patient-uploaded documents compromised. The affected module was “My Health Documents”.

What Health NZ was expected to check

The Commissioner did not find identical failures at the two organisations.

Manage My Health's notice concerns Rule 5(1)(a), covering reasonable safeguards for the information it held. Its remediation includes vulnerability management, with evidence that fixes work in practice. The September announcement acknowledges improvements already made to MFA, user access restrictions and protection against unauthorised external access.

Health NZ's notice concerns Rule 5(1)(b): doing everything reasonably within its power to prevent unauthorised use or disclosure when information is given to a service provider. For its replacement portal project, it must improve governance, privacy-risk management, information security and contracting/procurement arrangements. The requirements include privacy and security expertise in project oversight and independent provider assessment before contracts are signed.

The Health NZ findings deserve attention from anyone buying hosted software. You may have no control over the provider's servers, but you can examine the arrangement before sending customer records there. You also remain the business those customers deal with. Legal responsibilities can sit with both organisations, depending on the law and their arrangement; outsourcing does not automatically make you liable for everything, and a supplier breach alone does not prove negligence.

New Zealand's health-sector rule is not Australian law. The OAIC's small-business guidance explains that most businesses with annual turnover of $3 million or less are outside the Privacy Act, but exceptions apply. Health service providers and businesses undertaking certain other activities can be covered regardless of turnover.

For organisations covered by the Australian Privacy Principles, APP 11 requires reasonable steps to protect personal information they hold. The OAIC explains that an organisation can still hold information when a third party stores it, if it retains the right to deal with it, including accessing and amending it.

Even if your business falls outside those provisions, the information still needs protecting.

Look at what goes into the portal

Consider an accounting practice asking a client to upload a tax return and a scan of their driver's licence. The client follows a link from the practice and sees its name on the login page. Behind that page, another company stores the files, and its support staff may have access. The accountant may download copies as well. The client has little visibility of any of this.

I would want the practice to be able to explain where those files end up and who can open them. That means checking the provider's access as well as the practice's staff accounts, including any subcontractors working on support. The same concern applies to private clients whose advisers hold sensitive financial or identity documents.

Follow one record through the service. Include the copies in exports and backups, and establish where they are stored. It is easier to have a useful security conversation about an actual tax return than about “data” in general.

For that portal, I would check that MFA is enforced for administrator and supplier support accounts, and establish how encryption protects files in transit and storage. The provider should explain its backup arrangements and who checks that files can be restored. Some protections may depend on settings the practice has to enable itself.

This is a familiar difficulty with outsourced IT: the owner assumes something is included while the supplier expects the customer to configure it. Get those expectations clear before people start uploading documents.

A security claim needs something behind it

The Commissioner's Phase 1 report found that Health NZ's project team relied too much on information provided by Manage My Health rather than taking a sufficiently independent view. The replacement project's assessment requirements address that weakness directly.

I would put little weight on a sales page calling a service secure. A completed security questionnaire gives you more to work with, although the supplier is still describing its own controls.

Certification can be useful if it is current and covers the service you are buying. It does not guarantee security. An independent assessment may examine the controls more closely; its scope and any unresolved findings deserve attention too. The contract then needs to record what the provider has agreed to do.

For a small business, commissioning an audit of every subscription would be excessive. I would spend more effort on a portal full of medical or financial records, especially where supplier staff have broad access. The volume of information and the disruption a failure could cause also affect how much assurance is sensible.

Ask for a current assessment summary and evidence that significant findings were addressed. If you cannot make sense of the response for a service holding sensitive records, get help interpreting it before committing.

Agree what happens when something goes wrong

The agreement should make clear whether suspected incidents trigger notification, how quickly the provider must contact you and what information it must supply. Waiting for a completed investigation may leave you unable to protect accounts or answer customers in the meantime.

Name an emergency contact and someone to cover their absence. You will need to learn which records were affected, obtain relevant logs and receive updates as the investigation proceeds. Agree who will coordinate messages to customers and regulators. Each organisation still needs to meet its own legal obligations, whatever tasks the contract allocates.

Have that conversation before signing, with legal help on the terms where needed. For the accounting practice, an early warning could mean disabling portal access and contacting affected clients while the provider investigates. Waiting until clients ring about suspicious messages leaves the practice with much less room to act.

Deal with the copies left behind

The end of an arrangement needs some attention too. A former website developer may still have hosting or DNS access, while the old host retains a database of enquiries and its backups.

Those accounts and copies belong in a website migration plan, alongside deciding which records need to move. Rebuilding as a static site may remove the website database, but a connected form service or CRM can still hold the same customer information.

There is no reason to carry every old enquiry into a new system by default. Review how long customer data is retained and remove what is no longer needed, subject to any retention requirements.

Before ending a supplier relationship, agree how to export what you need, confirm usable copies and arrange deletion. Ask when backup copies expire and what happens if an old backup is restored. Closing the subscription is not evidence that all the data has gone.

You can make a start without reviewing every supplier at once. As with other small-business cybersecurity work, choose something you can follow through. I would begin with the portal holding the most sensitive records and ask the provider to walk through its access settings and incident process with you. Write down anything neither of you can answer, agree who will check it, and arrange to follow up. Then decide whether you are comfortable leaving customer information there.

Share on LinkedIn