Health NZ Level 2 Cyber Security: What Healthcare Providers Need to Know
Cyber security is becoming an increasingly important part of delivering healthcare in New Zealand, and Health NZ has now made its expectations much clearer.
Health New Zealand has introduced a new security checklist to help healthcare organisations assess their cyber-security capability against the National Cyber Security Centre's Minimum Cyber Security Standards.
For organisations accessing or sharing information with Health NZ, the important benchmark is Cyber Security Capability Maturity Model Level 2 - also known as “Baseline”.
What is Level 2?
Level 2 is designed to establish a practical minimum standard of cyber security across the health sector.
It doesn't mean having an enterprise sized security team or implementing every cyber-security technology available. It means being able to demonstrate that the fundamental controls needed to protect sensitive health information are in place and being actively managed.
Health NZ's assessment covers 10 areas:
Cyber risk management
Identifying your organisation's cyber-security risks and having clear responsibility for managing them.Security awareness
Making sure staff understand common cyber threats, know how to work securely and know how to report something suspicious.Knowing what's important
Understanding the systems, devices and information your organisation relies on — particularly those containing sensitive health information.Secure configuration
Making sure computers, applications, cloud services and other technology are securely configured rather than simply relying on default settings.Patching and updates
Keeping operating systems, applications and devices up to date so known security vulnerabilities are addressed.Multi-factor authentication
Using MFA to add another layer of protection to remote access and cloud services, rather than relying on passwords alone.Detecting unusual activity
Having the ability to identify suspicious or unexpected activity that could indicate an account or system has been compromised.Least-privilege access
Making sure people only have access to the systems and information they genuinely need to do their jobs.Data recovery
Maintaining backups and having a reliable way to restore important information and systems following an incident.Incident response
Having a documented plan, so your organisation knows what to do, who to contact and how to respond when a cyber-security incident occurs.
Why does this matter now?
Healthcare organisations hold some of New Zealand's most sensitive information.
Increased cyber-security incidents have demonstrated that significant breaches don't always require highly sophisticated attacks. Missing fundamental controls, including strong authentication, secure access management and effective monitoring, can be enough to expose sensitive information.
Health NZ is consequently putting greater structure around how organisations demonstrate that these basics are being managed.
Organisations sharing information with Health NZ are expected to meet at least CS-CMM Level 2 (Baseline). The security checklist is also becoming part of the assurance process associated with initiatives such as the Shared Digital Health Record.
For practices and healthcare providers, cyber security is therefore increasingly more than an internal IT consideration. It's part of being able to safely participate in New Zealand's increasingly connected health system.
Level 2 doesn't replace HISO
The new Level 2 assessment should also be understood alongside the existing HISO 10029 Health Information Security Framework (HISF).
HISF remains the health-sector framework for protecting New Zealanders' health information. Health NZ recommends organisations use it when implementing security controls appropriate to their size, technology environment and risk.
A useful way to think about the two is:
Level 2 helps establish the minimum cyber-security capability you should be able to demonstrate.
HISF provides the wider health-specific framework for protecting health information.
What should healthcare organisations do?
If your organisation hasn't assessed its cyber-security maturity recently, now is a good time to do so.
Start with the fundamentals:
confirm MFA is enabled wherever required
review who has administrative and privileged access
make sure devices and applications are patched
understand where sensitive information is stored
verify backups and recovery processes
review staff security training
ensure suspicious activity can be detected
document your cyber incident response process
make cyber risk someone’s explicit responsibility.
Most importantly, don't treat the Health NZ checklist as a once-a-year compliance exercise.
Good cyber security comes from making these controls part of normal operations and being able to demonstrate that they're working.
Where Frankie fits
Health NZ’s Level 2 requirements are a reminder that cyber risk is now a real operational and financial risk for healthcare providers.
While strong IT and security controls are the first line of defence, cyber insurance can provide an important financial safety net if something still goes wrong, helping respond to events such as data breaches, cyber-attacks, business interruption and recovery costs.
At Frankie, we can help healthcare providers put appropriate cyber insurance cover in place.
And if you need support assessing or improving your IT and cyber security controls, we can connect you with Cloudland, our recommended medical technology partner.
Need cyber insurance? Get a quote and bind cover online.
