Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing
Podcast Image

The Detail

Digital health and privacy breaches

03 May 2026

Transcription

Chapter 1: What changes are being made to blood donor screening in New Zealand?

4.655 - 14.753 Unknown

There are big changes coming to the way we screen potential blood donors. No longer will gay and bisexual men be subject to specific questions about their sexual activity.

0

14.794 - 22.748 Amanda Gillies

Instead, everyone will be asked the same questions and those questions are incredibly personal.

0

22.728 - 37.699 Unknown

What we're asking is, have you had any new sexual partners in the last three months? Or have you had multiple sexual partners? And if someone answers yes to those, then the next question is, have you had anal sex with those partners?

0

37.747 - 48.979 Amanda Gillies

So from today, these questions will be put to both men and women, straight and gay. And it's hoped as a result, more people will be able to donate blood.

0

Chapter 2: What personal information is collected from blood donors?

49.459 - 57.448 Amanda Gillies

But what actually happens to this very personal information? Just how protected is it? Because remember this?

0

57.928 - 62.353 Unknown

Did you know that the Manage My Health software in New Zealand has been hacked?

0

Chapter 3: How secure is the Manage My Health software after the recent hack?

65.168 - 83.11 Unknown

GPs say they want more communication about the investigation into a major health privacy breach. Private information doesn't get much more intimate than this. The health history of 126,000 New Zealanders ready to be displayed on the dark web. Deeply, deeply personal stuff in there that

0

83.444 - 92.48 Amanda Gillies

a lot of people wouldn't want to get out. This is a developing story, but here's what we know so far about a major data breach at digital medication platform Medimap.

0

92.5 - 100.153 Unknown

The hack saw some patients who were still alive declared dead. Others had their names changed to Charlie Kirk.

0

100.437 - 117.459 Amanda Gillies

Hi, I'm Amanda Gillies, and today on The Detail, protecting our intimate medical information. The review into the Manage My Health breach has just wrapped up, and it coincides with all Kiwis being asked more personal questions when giving blood.

0

Chapter 4: What are the implications of the data breach at Medimap?

118.019 - 129.634 Amanda Gillies

Add to this, more and more doctors are using AI for note-taking during appointments. So, in 2026, is our personal medical information safe from hackers everywhere?

0

129.614 - 151.066 Jan Thornborough

Short answer, very, very vulnerable, unfortunately. And it's not necessarily the fault of the health sector. It is just the way cybercrime is increasing year by year. With the introduction of artificial intelligence, all the geopolitical problems that we're seeing around the world, cybercrime is big business.

0

151.267 - 156.094 Jan Thornborough

In fact, if it was a country, it would actually be the third richest country in the world.

0

156.074 - 172.8 Amanda Gillies

That's Jan Thornborough, a cyber security specialist and founder of Outfox Limited, which helps keep businesses cyber safe. Today I also talked to a colleague who had her medical information hacked a year after she survived a fatal car crash.

0

173.36 - 197.516 Shalise Tansey

When you put so much trust in an organisation to take care of the most like sacred information that you have, which is your own personal information, You expect them to have these security measures in place. And now that this has happened and these random people somewhere in the world just have my data, I'm just like, how am I meant to trust my health providers?

197.696 - 200.36 Shalise Tansey

That is such a personal trust that you put in them.

200.761 - 211.917 Amanda Gillies

More from Shalise Tansey in a moment. But first, back to Jan, who says hackers and scammers are still making a lot of money from stolen digital health records.

212.15 - 213.432 Jan Thornborough

Oh, absolutely.

Chapter 5: How vulnerable is personal medical information to cybercrime?

213.472 - 236.453 Jan Thornborough

There's really two types of attackers. The main ones are state-sponsored, which are exactly what they sound like. They're government-sponsored attackers. And then you have the cyber criminals. And usually, but not always, the cyber criminals that do the ransomware attacks, such as the one we saw with Manage My Health, and the ones that are trying to extort money

0

236.433 - 255.482 Jan Thornborough

So, you know, they take your health records and then they might, they'll try and sell them on the dark web, but they also might use them to blackmail you or cause, you know, difficulties for you later on. And even try and send fake emails saying that you've got an appointment or something and getting you to click on a link so they can steal your credentials.

0

255.882 - 264.415 Amanda Gillies

Wow. And is it health apps because that is something that is deeply personal to people? That is why it's so attractive to these hackers and scammers?

0

264.732 - 284.459 Jan Thornborough

Oh, absolutely. I mean, at the end of the day, what they want to do is they want to make you scared. They want to put fear into you so that you'll do something urgently. So if you see an email coming in saying, you know, you've got an urgent appointment for something, click here. Or, you know, we're going to tell all your family and friends about your embarrassing health issue.

0

285.04 - 290.267 Jan Thornborough

Those are the sorts of things that they know will make people respond and potentially get the money.

290.534 - 302.914 Amanda Gillies

For Shalice, the Detail's associate producer, her personal medical information, which she thought was safely stored in her Manage My Health app, was hacked at the end of last year.

Chapter 6: What security measures are health organizations implementing?

302.954 - 320.639 Shalise Tansey

So my data was stolen, essentially. The hackers, whoever got in, they took all my health records that were on file. So all the health documents in terms of like ED discharge notes, orthopedic notes, post-op check notes, all of those were taken.

0

321.34 - 335.678 Amanda Gillies

And I want to get personal with you, if that's OK. Go for it. This came after you'd had a terrible, tragic car accident. So it was deeply personal for you and that information. Are you able to talk us through that and what they kind of had access to as a result?

0

335.658 - 356.719 Shalise Tansey

Oh, absolutely. So I was in a car crash at the end of 2024, like the very end of it. I had a laceration across the top of my head. My spine, the top vertebrae in my spine was broken. Both my wrists were fractured and dislocated. And I had injuries on both hands.

0

356.779 - 364.267 Shalise Tansey

My left hand was the worst with the bottom row of what's called your metacarpal bones, essentially, as the surgeon described it, exploded.

0

364.707 - 364.787

Wow.

364.767 - 390.773 Shalise Tansey

Ouch. Yeah, a bit painful. And then also a concussion on top of that. So all of that was included in the notes that were taken. And in there was also just like my date of birth, my full name, NHI number, where I lived, my phone number, like the list goes on, a brief summary of the car crash itself. So yeah, there was some personal notes in there that I was like, oh, well, that's nice.

390.813 - 392.074 Shalise Tansey

Now someone else has that.

392.054 - 402.672 Amanda Gillies

And as I say, when you realise someone else had that, a hacker, a scammer, someone you didn't know and you didn't know what they were going to do with it, how did that feel? What was your reaction?

403.175 - 414.367 Shalise Tansey

At the start, I was nervous only because of all the personal data that they had in terms of like my date of birth, my phone number, like that could all be used to like go in and get other information.

Chapter 7: What role does AI play in healthcare data management?

433.076 - 437.164 Amanda Gillies

But from the breach until you finding out, how long was that?

0

437.885 - 461.97 Shalise Tansey

So that I think was about a week and a half. So we first found out on the 31st through news and stuff that there had been a breach. And then later it came out that it was primarily health organizations within Northland. And that's when I realized, oh, I could be part of this. And then on the 9th of January, I got an email from Manage My Health to say that my data had been stolen.

0

462.322 - 469.412 Amanda Gillies

And what have they done to appease you, to make you feel protected and, you know, where that information now is?

0

469.472 - 482.41 Shalise Tansey

So they advised me to change my password and set up two-factor authentication, which I don't think they had before the breach happened. But besides that, nothing else.

0

482.891 - 496.53 Shalise Tansey

That annoys me because I feel like when you sign up to something like Manage My Health, you kind of go in with the sense that like, I know my privacy is going to be protected because some of my most vulnerable information is on there.

497.331 - 516.973 Shalise Tansey

Like if I'm being honest, I've had all this data stolen and I, besides them notifying me that it had happened and steps to take to ensure that it wouldn't happen again, I haven't heard anything else. And so I'm kind of just like, I've had all this personal information stolen about a traumatic event that I've been through, and I have heard nothing else.

517.574 - 529.25 Amanda Gillies

A review of the Manage My Health breach finally wrapped up last week and will be released publicly shortly. Here's Health Minister Simeon Brown in January after he ordered the review.

529.651 - 537.081 Unknown

This error was on them. They should apologise to all impacted patients. What's happened here is unacceptable.

537.128 - 543.531 Simeon Brown

I absolutely apologise to the New Zealand public for what has happened as a result of criminal activity.

Chapter 8: How can individuals protect their health data from cyber threats?

589.171 - 597.491 Amanda Gillies

New Zealand Blood Now is going to be asking all people who donate blood to answer very, very personal questions about their sex life.

0

597.511 - 611.021 Unknown

Including whether they've had anal sex with new or multiple partners, or if they've had any sexually transmitted infections. If the answer to either is yes, they'll need to wait three months before donating.

0

611.422 - 620.079 Amanda Gillies

Having what happened to you, does that make you question whether you'll donate blood because you think, actually, I don't know how safe my answers are going to be?

0

620.48 - 623.346 Shalise Tansey

It does make me question because that...

0

623.326 - 649.452 Shalise Tansey

medical notes are one thing but like sexual history notes is a whole nother can of worms that you don't even want to tell your like friends and family about this so telling a complete stranger who you're about to give like part of your body to essentially because you're giving blood that just opens a whole nother can of worms that makes you not want to trust them especially with all the data breaches in terms of health companies that have happened so I would

649.432 - 650.835 Shalise Tansey

I would definitely question it.

651.316 - 655.966 Amanda Gillies

So I asked Jan Thornborough, how protected are blood donors today?

656.006 - 675.62 Jan Thornborough

Well, NZ Blood is covered by the Privacy Code, so they should be adhering to the health information security framework and protecting the information accordingly. I looked at their website. I couldn't actually see what kind of standards or security frameworks they are adhering to.

675.68 - 696.06 Jan Thornborough

They made a mention of the fact that they send information overseas because it's saved in Microsoft Azure in Australia. We'd hoped that they were up to standard, but you really have to ask them directly what security standard are they adhering to to actually get the full confidence that everything is robust and in places we need.

Comments

There are no comments yet.

Please log in to write the first comment.