In late February, MediMap confirmed a cyber incident involving unauthorised access to its platform that resulted in the modification of some patient records. The platform, which is widely used across aged care, disability, hospice, and community health services, was taken offline while investigations continue.
As a precaution, MediMap placed the system into maintenance mode and engaged external cyber security specialists. Relevant authorities, including the Office of the Privacy Commissioner and NZ Police, were notified, and healthcare providers using MediMap have temporarily reverted to manual processes to maintain continuity of care.
Public reporting indicates the incident likely involved the compromise of a legitimate user account, rather than a technical vulnerability. This allowed an unauthorised party to access the system using valid credentials and make changes from within. Investigations into the scope and impact of the incident are ongoing.
This incident highlights the importance of strong account security. Even secure platforms can be put at risk when protections such as strong passwords and multi‑factor authentication (MFA) are not consistently in place.
MFA adds an extra layer of protection beyond a password. Even if credentials are compromised, MFA can prevent unauthorised access. If your systems support MFA, we highly recommend it be enabled for email, Microsoft 365, and any web‑based platforms used by your team.
Storing passwords in notebooks, sticky notes, or unsecured files increase risk and often leads to password reuse. A password manager allows users to securely store strong, unique passwords without needing to remember or write them down, significantly reducing the likelihood of credential compromise.
Together, these controls significantly reduce the risk of unauthorised access, even when credentials are exposed. Reviewing your MFA coverage and discussing the use of password managers can be a practical first step toward stronger account security.
Reach out if you would like to review your business’s security posture.