← SecureAZ Blog

Compliance · 6 min read · Published 24 April 2026 · Reviewed 17 August 2026

NZ Health Information Security Framework: What Healthcare Organisations Must Do

The NZ Health Information Security Framework (HISF) requires all healthcare staff to be trained in information security. Here's what the requirement covers and how to meet it.

Healthcare organisations in New Zealand sit at the intersection of two of the most targeted sectors for cybercriminals: critical infrastructure and personal data repositories. A GP clinic, DHB, aged care provider, or health insurer holds highly sensitive information — and the NZ Health Information Security Framework (HISF) exists precisely because the consequences of a breach in this sector are more severe than almost anywhere else.

The HISF training requirement isn't optional. Here's what it covers and what compliance looks like in practice.

What the HISF Requires

The NZ Health Information Security Framework requires all healthcare staff and stakeholders to be trained and aware of their roles in maintaining information security. This isn't limited to IT staff — it applies to clinicians, administrators, reception, contractors, and anyone with access to health information systems.

The framework promotes regular training and a culture of security, not a once-a-year tick-box exercise. Key requirements include:

  • Induction training for all new staff before or immediately upon system access
  • Ongoing refresher training at regular intervals
  • Role-specific training for staff with elevated access or handling of sensitive clinical data
  • Incident awareness — staff must know how to identify and report a security incident

The HISF aligns with the broader NCSC minimum cyber security standards that apply across the NZ public sector, including publicly funded health organisations.

Why Healthcare Is a Prime Target

The healthcare sector accounts for a disproportionate share of reported breaches in New Zealand. CERT NZ's threat reports consistently show health as one of the top targeted sectors. The reasons are straightforward:

  • High-value data — health records command a premium on dark web markets
  • Legacy systems — many clinical environments run outdated software with limited patching
  • Urgency pressure — clinical staff are under time pressure and less likely to pause and verify a suspicious request
  • Supply chain exposure — health organisations deal with hundreds of vendors, each a potential entry point

The most common attack vector remains phishing — a staff member receives a convincing email and clicks a link. Technical controls reduce the damage, but they don't stop the click. Training does.

What Good HISF-Aligned Training Looks Like

A HISF-compliant training programme covers:

Phishing and social engineering — including healthcare-specific lures like fake supplier invoices, fake clinical software update prompts, and impersonation of Te Whatu Ora or ACC.

Data handling — what constitutes health information under the Health Information Privacy Code, how it must be stored and transmitted, and what happens when it's mishandled.

Access control — password policies, MFA requirements, not sharing login credentials (common in clinical environments where staff share terminals).

Incident reporting — the specific steps to follow when a breach is suspected, including who to contact and the 72-hour notification window under the Privacy Act 2020.

Remote work security — many clinical staff now access systems from home or community settings, creating additional exposure.

The Overlap with Privacy Act 2020

The Privacy Act 2020 and the Health Information Privacy Code sit alongside the HISF as complementary obligations. Staff training is the "reasonable steps" defence under the Privacy Act — and health information is subject to the most stringent protections within that framework.

A breach of health information that the Commissioner determines was preventable through training carries significant reputational and financial consequences. The documented training programme is your primary defence.

Practical Implementation for Health Sector Organisations

For smaller healthcare organisations — GP practices, dental clinics, physio groups — the HISF can feel like it was written for DHBs. In practice, the requirements scale:

  1. Enrol all staff on a platform that tracks completion — every role, not just IT
  2. Run induction training before system access is granted to new staff
  3. Set annual (minimum) refreshers — quarterly is better given the threat environment
  4. Run phishing simulations to test whether training is working
  5. Export compliance reports for your cyber insurer and any Te Whatu Ora audit

The documentation matters as much as the training itself. A training programme that runs but produces no records provides no protection when you need it.

SecureAZ includes NZ healthcare-relevant training modules, phishing simulations using NZ-localised templates, and compliance reports designed for exactly this audit context. 45-day free trial, no credit card required.

External references: