Commentary

Manage My Health: some important lessons for PIAs

The after-effects of the Manage My Health privacy breach continue to resonate, not just for the individuals affected, but also for organisations looking to improve their privacy practices by learning from what went wrong.

What were the OPC’s findings on PIAs?

One area the Office of the Privacy Commissioner (OPC) identified in its Inquiry  Phase 1 report as being of particular concern was Privacy Impact Assessments (PIAs).  Both Manage My Health (MMH) and Health NZ had undertaken PIAs, but the OPC identified significant problems with their quality.

A common problem was that the PIAs did not adequately describe and assess the actual information flows and processes involved. The OPC described MMH’s relevant PIA as “largely generic rather than specific to the project”. Health NZ’s PIA had similar problems, including insufficient detail about the risks and mitigation controls, some incorrect application of the Information Privacy Principles, and reliance on content from MMH’s own “weak” PIA rather than taking an independent view.

There were also particular problems with Health NZ’s process. It had not undertaken a PIA at the proof-of-concept or pilot stage of the project to use the MMH platform, which the OPC considered both a significant oversight and a lost opportunity given the large volumes of health information involved.

A PIA was eventually completed by Health NZ as part of the wider rollout, but it was largely carried out by a project team member who had access to a PIA template but did not have existing privacy knowledge. The OPC described the resulting PIA as “extremely weak”.

It was also completed only a month before the relevant contract with MMH was signed, which the OPC considered “too late to be useful”. The timing, it said, “gives the impression that Health NZ simply considered a PIA as a tick on the checklist for signoff, rather than being a tool that would be used throughout the project to help Health NZ to design the processes and safeguards appropriately”.

The OPC concluded that the weak PIA meant Health NZ’s project steering group and senior leaders did not receive the level of risk advice needed to properly protect patient information processed by MMH.

What does this tell us about PIAs?

There is a fairly simple lesson from these findings: having completed a PIA is not the same thing as having done a good PIA.

Templates are useful, but they don’t replace privacy knowledge and experience. A good PIA requires an understanding of what is actually happening to personal information: what is being collected, where it comes from, where it goes, who can access it, how it will be used and disclosed and what safeguards apply.

It also requires the ability to apply privacy law correctly, identify risks that may not be obvious from the project documentation, test assumptions, and work out whether proposed controls actually address those risks.

The Health NZ related findings illustrate this particularly well. The project team had access to a PIA template. What it didn’t have was sufficient privacy expertise. Important issues were consequently missed and decision-makers did not get the privacy risk advice they needed.

This is one reason it can be worth involving a privacy professional in a PIA, particularly where a project involves sensitive information, new technology, complex information flows or multiple organisations. Their role isn’t simply to complete the document. It is to ask the right questions, understand what is really happening with the information and identify privacy issues that the project team or supplier may not have recognised.

Independence matters too. A supplier’s PIA can be a useful input, but an organisation still needs to understand and assess its own collection, use, disclosure and management of personal information rather than simply relying on the supplier’s assessment.

And timing is important. A PIA completed shortly before a contract is signed or a system goes live may identify risks, but by then there may be limited scope to change the design, negotiate different protections or introduce better controls. As the OPC puts it: “Privacy needs to be built in from the start and be part of system design – not an afterthought or a check-box exercise.”

A security assessment isn’t a PIA

The report also provides a useful reminder that a security assessment and a PIA are not interchangeable.

Security is an important part of privacy and a good PIA will often need input from security specialists. But a PIA asks wider questions about whether and how personal information should be collected, used, shared and retained and whether those activities comply with privacy law.

Security assessments and PIAs need to be seen as complementary. Security expertise doesn’t replace privacy expertise, just as privacy expertise doesn’t replace specialist security expertise.

Conclusion

The wider lesson from the MMH Phase One report extends well beyond the health sector. A PIA isn’t simply a compliance document to complete before a project gets signed off. Done properly and early enough, it should help an organisation understand what it is actually doing with personal information, identify problems before they become embedded, and give decision-makers the information they need to manage the privacy risks.

If you want some tips on how to implement an effective PIA process then you can check out a previous article of ours here, or if you’d rather do some more active learning Simply Privacy is running a two hour online workshop on developing a good PIA process on 6 October 2026 – more details here.

We’ve also developed some handy guidance on Privacy By design methodology, and how to put it in practice, which you can access here.