Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Angela Antunovic boosted
Alistair K
Alistair K
@libroraptor@mastodon.nz  ·  activity timestamp 10 hours ago

A Wellington law firm is looking to do something about the Manage My Health data breach. Any thoughts on whether it's a good or bad idea to join them?

#managemyhealth

https://dalzellwollerman.co.nz/mmh-data-breach

Dalzell Wollerman

MMH Data Breach — Dalzell Wollerman

  • Copy link
  • Flag this post
  • Block
Alistair K
Alistair K
@libroraptor@mastodon.nz  ·  activity timestamp 10 hours ago

A Wellington law firm is looking to do something about the Manage My Health data breach. Any thoughts on whether it's a good or bad idea to join them?

#managemyhealth

https://dalzellwollerman.co.nz/mmh-data-breach

Dalzell Wollerman

MMH Data Breach — Dalzell Wollerman

  • Copy link
  • Flag this post
  • Block
Angela Antunovic boosted
cameraobscura
cameraobscura
@cameraobscura@mastodon.scot  ·  activity timestamp 5 days ago

#NZ #Privacy Petition, following on from #ManageMyHealth breach

There's a new petition on the NZ Parliament site, to 'Strengthen enforcement powers and penalties under the Privacy Act 2020' - https://petitions.parliament.nz/88fd4852-1539-419c-af36-08de4ca872ae?lang=en.

It was initiated by Katja Feldtmann, who spoke to RNZ about it -https://www.rnz.co.nz/news/political/584086/cyber-security-expert-launches-petition-to-parliament-calling-for-harsher-penalties-for-privacy-breaches.

RNZ

Cyber-security expert launches petition to Parliament calling for harsher penalties for privacy breaches

It comes in the wake of the major Manage My Health data breach.
https://petitions.parliament.nz/88fd4852-1539-419c-af36-08de4ca872ae?lang=en
Petitions are addressed to the House of Representatives and ask that the House do something about a policy or law, or put right a local or private concern.
  • Copy link
  • Flag this post
  • Block
cameraobscura
cameraobscura
@cameraobscura@mastodon.scot  ·  activity timestamp 5 days ago

#NZ #Privacy Petition, following on from #ManageMyHealth breach

There's a new petition on the NZ Parliament site, to 'Strengthen enforcement powers and penalties under the Privacy Act 2020' - https://petitions.parliament.nz/88fd4852-1539-419c-af36-08de4ca872ae?lang=en.

It was initiated by Katja Feldtmann, who spoke to RNZ about it -https://www.rnz.co.nz/news/political/584086/cyber-security-expert-launches-petition-to-parliament-calling-for-harsher-penalties-for-privacy-breaches.

RNZ

Cyber-security expert launches petition to Parliament calling for harsher penalties for privacy breaches

It comes in the wake of the major Manage My Health data breach.
https://petitions.parliament.nz/88fd4852-1539-419c-af36-08de4ca872ae?lang=en
Petitions are addressed to the House of Representatives and ask that the House do something about a policy or law, or put right a local or private concern.
  • Copy link
  • Flag this post
  • Block
Angela Antunovic boosted
Bob LeFridge  :tinoflag:
Bob LeFridge :tinoflag:
@BobLefridge@mastodon.nz  ·  activity timestamp 2 weeks ago

Keith Ng at the Herald has a good summary of what's known and where we're at.

"MMH has confirmed that only a single stolen user account was used in the attack. Posing as a normal user, the hackers were able to trick the application interface into providing the files for 127,000 other users. The control mechanisms meant to stop one user from accessing other users’ files had failed, or did not exist."

It sounds like they accessed one person's files, then trimmed the URL to move up a directory or two where they found paydirt.

So less of a hack, more of a problem with poor or non-existent security.

https://archive.md/EXu2y#selection-4127.0-4127.331

#ManageMyHealth

  • Copy link
  • Flag this post
  • Block
Bob LeFridge  :tinoflag:
Bob LeFridge :tinoflag:
@BobLefridge@mastodon.nz  ·  activity timestamp 2 weeks ago

Keith Ng at the Herald has a good summary of what's known and where we're at.

"MMH has confirmed that only a single stolen user account was used in the attack. Posing as a normal user, the hackers were able to trick the application interface into providing the files for 127,000 other users. The control mechanisms meant to stop one user from accessing other users’ files had failed, or did not exist."

It sounds like they accessed one person's files, then trimmed the URL to move up a directory or two where they found paydirt.

So less of a hack, more of a problem with poor or non-existent security.

https://archive.md/EXu2y#selection-4127.0-4127.331

#ManageMyHealth

  • Copy link
  • Flag this post
  • Block
Bill Bennett
Bill Bennett
@billbennett@mastodon.nz  ·  activity timestamp 2 weeks ago

Despite nagging from my local surgery, I've never signed up for Manage My Health. But in the last two weeks I've had six emails like this. Clearly I'm in the database without my permission. Can anyone shed light on this?

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Bob LeFridge  :tinoflag:
Bob LeFridge :tinoflag:
@BobLefridge@mastodon.nz replied  ·  activity timestamp 2 weeks ago

If your GP practice uses MMH or has used it in the past, you're on their system, whether or not you enrol for their service.

@RedRobyn declined the service, but may have documents at risk because the GPs use it.

@oseiler reports despite their GP practice switching from MMH to another provider, MMH kept all their records. They also received a message to say their data wasn't stolen, followed by another saying it had been.

MMH confirms that unless each individual customer closes their account, it remains active in the background, forever. I wonder how many of their claimed 1.8m users are actually zombie accounts?

In terms of breach management, MMH has ballsed-up their response spectacularly.

@billbennett

#ManageMyHealth

  • Copy link
  • Flag this comment
  • Block
Angela Antunovic boosted
Bob LeFridge  :tinoflag:
Bob LeFridge :tinoflag:
@BobLefridge@mastodon.nz  ·  activity timestamp 2 weeks ago

Given the lack of transparency around the ManageMyHealth breach, Auckland software developer Marcus Crane has put together a damn good summary of what is known so far.

He's even swapped messages with the hacker/s.

https://utf9k.net/blog/managemyhealth-data-breach-recap/

#ManageMyHealth

  • Copy link
  • Flag this post
  • Block
Bob LeFridge  :tinoflag:
Bob LeFridge :tinoflag:
@BobLefridge@mastodon.nz  ·  activity timestamp 2 weeks ago

Given the lack of transparency around the ManageMyHealth breach, Auckland software developer Marcus Crane has put together a damn good summary of what is known so far.

He's even swapped messages with the hacker/s.

https://utf9k.net/blog/managemyhealth-data-breach-recap/

#ManageMyHealth

  • Copy link
  • Flag this post
  • Block
Angela Antunovic boosted
Kay :heart_bi:  :tinoflag:
Kay :heart_bi: :tinoflag:
@Kay@mastodon.nz  ·  activity timestamp 3 weeks ago

Cybersecurity analysis of #ManageMyHealth finds serious deficiences. Looks like a #DataBreach was inevitable. Better #infosec needed. Similar question for many large organisations NZers trust with their data and privacy.
https://blackveil.co.nz/blog/managemyhealth-breach-analysis-2025

  • Copy link
  • Flag this post
  • Block
Kay :heart_bi:  :tinoflag:
Kay :heart_bi: :tinoflag:
@Kay@mastodon.nz  ·  activity timestamp 3 weeks ago

Cybersecurity analysis of #ManageMyHealth finds serious deficiences. Looks like a #DataBreach was inevitable. Better #infosec needed. Similar question for many large organisations NZers trust with their data and privacy.
https://blackveil.co.nz/blog/managemyhealth-breach-analysis-2025

  • Copy link
  • Flag this post
  • Block
Angela Antunovic boosted
Sam Stephens
Sam Stephens
@chopsstephens@mastodon.nzoss.nz  ·  activity timestamp 3 weeks ago

One wrinkle with this whole Manage My Health thing is how they retain data for customers they no longer have. I know this because my local practice switched from Manage My Health to MyIndici, but our Manage My Health accounts were kept open, with no indication the accounts would ever be closed or data deleted.

I complained to my local practice earlier in the year, and eventually got the answer that Manage My Health were the ones who made the call to retain the data.

#manageMyHealth

  • Copy link
  • Flag this post
  • Block
Sam Stephens
Sam Stephens
@chopsstephens@mastodon.nzoss.nz  ·  activity timestamp 3 weeks ago

One wrinkle with this whole Manage My Health thing is how they retain data for customers they no longer have. I know this because my local practice switched from Manage My Health to MyIndici, but our Manage My Health accounts were kept open, with no indication the accounts would ever be closed or data deleted.

I complained to my local practice earlier in the year, and eventually got the answer that Manage My Health were the ones who made the call to retain the data.

#manageMyHealth

  • Copy link
  • Flag this post
  • Block
Angela Antunovic boosted
Kay :heart_bi:  :tinoflag:
Kay :heart_bi: :tinoflag:
@Kay@mastodon.nz  ·  activity timestamp 3 weeks ago

Active thread with an update on Kazu hack of #ManageMyHealth
https://bsky.app/profile/utf9k.net/post/3mbd43ipkzc2f

https://bsky.app
View
  • Copy link
  • Flag this post
  • Block
Angela Antunovic boosted
Kay :heart_bi:  :tinoflag:
Kay :heart_bi: :tinoflag:
@Kay@mastodon.nz  ·  activity timestamp 3 weeks ago

#ManageMyHealth will start notifying users of #DataBreach and next actions soon. Company now working with NZ #Privacy Commissioner.
#AoNZ #InfoSec
https://www.rnz.co.nz/news/national/583030/managemyhealth-reveals-scope-of-data-breach

RNZ

ManageMyHealth reveals scope of data breach

Between 6 and 7 percent of the approximately 1.8 million registered users may have been affected.
  • Copy link
  • Flag this post
  • Block
Kay :heart_bi:  :tinoflag:
Kay :heart_bi: :tinoflag:
@Kay@mastodon.nz  ·  activity timestamp 3 weeks ago

#ManageMyHealth will start notifying users of #DataBreach and next actions soon. Company now working with NZ #Privacy Commissioner.
#AoNZ #InfoSec
https://www.rnz.co.nz/news/national/583030/managemyhealth-reveals-scope-of-data-breach

RNZ

ManageMyHealth reveals scope of data breach

Between 6 and 7 percent of the approximately 1.8 million registered users may have been affected.
  • Copy link
  • Flag this post
  • Block
Kay :heart_bi:  :tinoflag:
Kay :heart_bi: :tinoflag:
@Kay@mastodon.nz  ·  activity timestamp 3 weeks ago

Active thread with an update on Kazu hack of #ManageMyHealth
https://bsky.app/profile/utf9k.net/post/3mbd43ipkzc2f

https://bsky.app
View
  • Copy link
  • Flag this post
  • Block
Carmen-Lisandrette
Carmen-Lisandrette
@carmenlisandrette@mastodon.social  ·  activity timestamp 3 weeks ago

Whelp, it was lovely having private medical records. Shame it didn't last.

#newzealand #managemyhealth #nz

  • Copy link
  • Flag this post
  • Block
Strypey
Strypey
@strypey@mastodon.nzoss.nz  ·  activity timestamp 4 months ago

Here's a policy I'd like to see included in a comprehensive digital-age privacy protection bill;

If a company stores people's personal information, they must supply;

* a single-click way to delete an account and all its data

* a phone number those people can call and get immediate assistance, or failing that, an automated callback

* an address those people can email and get a response within 48 hours. In case they want to have a written record of their interaction with the company

#PolicyNZ

Strypey
Strypey
@strypey@mastodon.nzoss.nz replied  ·  activity timestamp 4 months ago

A couple of months back, I evaluated the privacy policy of ManageMyHealth.co.nz (MMH);

https://mastodon.nzoss.nz/@strypey/114862089185059650

TL;DR Nuke it from orbit, it's the only way to be sure.

Since then, I've been getting nagmails from MMH trying to get me to use their platform. Today I tried figure out how to get this spam to stop.

(1/?)

#privacy#HealthIT#ManageMyHealth

  • Copy link
  • Flag this comment
  • Block
Strypey
Strypey
@strypey@mastodon.nzoss.nz  ·  activity timestamp 6 months ago

Well, I finally got around to evaluating the #ManageMyHealth portal;

https://managemyhealth.co.nz/about-us/

When my GP suggested I sign up with it, I presumed it was a public service offered by Te Whatu Ora, like My Health Record;

https://www.tewhatuora.govt.nz/health-services-and-programmes/digital-health/my-health-record

So what do I think of Manage My Health? Not impressed. This is a privately-owned, for-profit digital platform, that I can't be certain isn't #DataFarming patients who sign up with it.

(1/?)

#privacy #PublicService #PublicHealth #HealthPortals

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct