Health NZ is placing greater emphasis on cyber-security readiness across the healthcare sector, introducing a new security checklist to help organisations assess their ability to securely share health information.
While the checklist may sound daunting, it’s not about deploying complex security systems or building a large cyber-security team. Instead, it focuses on ensuring healthcare providers have the right foundations in place to protect sensitive patient information and understand how their current controls align with recognised cyber-security practices.
Based on guidance from Health NZ and the National Cyber Security Centre (NCSC), organisations sharing information with Health NZ are expected to meet a Baseline level of cyber-security maturity, known as CS-CMM Level 2.
Health NZ’s security checklist is designed to help organisations assess their current cyber-security capability and identify areas for improvement.
For many organisations, this means reviewing controls that may already be familiar, including:
Many healthcare providers will already have some or all of these measures in place. The focus is increasingly on understanding how effectively they’re being managed and being able to demonstrate that they are working as intended.
Recent updates to the Shared Digital Health Record programme have highlighted the importance of security assurance and due diligence before health information is shared more broadly.
For healthcare providers, this serves as a timely reminder to review existing cyber-security controls and ensure they remain aligned with current expectations. Health NZ’s security checklist provides a practical starting point for understanding where your organisation stands, identifying any gaps, and building confidence that appropriate safeguards are in place.
We’ll be reaching out to clients who may be impacted to discuss what these expectations mean and help assess their current position and next steps.
Not sure how these expectations apply to your organisation? Get in touch to discuss where your organisation stands.