Health NZ's New Cyber Security Expectations: What Practices Need to Know
- Geordie McPherson
- Aug 12
- 2 min read
Cyber security has always been important in healthcare...
What's changed is that it's now becoming a much more visible part of how organisations connect and share information across New Zealand's health system.
Health NZ has introduced a security checklist aligned to the National Cyber Security Centre's Cyber Security Capability Maturity Model (CS-CMM). For organisations sharing information with Health NZ, the target is CS-CMM Level 2, known as the Baseline level.
Recent announcements have reinforced just how seriously this is being taken.
In June, Health NZ confirmed delays to parts of the Shared Digital Health Record rollout while additional security and due diligence checks are completed before patient information is shared more broadly.
The good news is that Level 2 is not about building a large security team or buying every cyber security product on the market.
It's about demonstrating that the fundamentals are in place and working.
That includes things like:
Multi-factor authentication (MFA)
Patch management
Security awareness training
Asset and device management
Backup and recovery processes
Monitoring and detection
Incident response planning
These are all practical controls that help reduce risk and protect sensitive patient information.
For many practices, the real challenge is not the technology itself...
It's understanding where you currently stand, identifying any gaps, and being able to provide evidence that controls are operating as expected.
That's where many organisations find the process becomes time-consuming.
Policies live in one location, evidence sits in another, reports are spread across different systems, and maintaining it all becomes an ongoing administrative burden.
Rather than viewing the Health NZ checklist as a once-a-year exercise, we encourage organisations to think about cyber security as an ongoing operational process.
The goal isn't simply to achieve a rating.
It's to build confidence that the right protections are in place and can be demonstrated when required.
At Cloudland, we're helping healthcare organisations understand their current position, assess readiness against CS-CMM Level 2, and establish a practical roadmap for continuous improvement through our CyberSure service.
Whether you're already confident in your cyber security posture or just beginning to understand what the new expectations mean for your organisation, now is a good time to review where you stand.
The requirements are becoming increasingly important across the health sector, and taking a proactive approach today is much easier than scrambling to respond tomorrow - get in touch to learn more!



Comments