Health NZ Level 2 Cyber Security: What Healthcare Providers Need to Know 

Cyber security is becoming an increasingly important part of delivering healthcare in New Zealand, and Health NZ has now made its expectations much clearer. 

Health New Zealand has introduced a new security checklist to help healthcare organisations assess their cyber-security capability against the National Cyber Security Centre's Minimum Cyber Security Standards. 

For organisations accessing or sharing information with Health NZ, the important benchmark is Cyber Security Capability Maturity Model Level 2 - also known as “Baseline”. 

What is Level 2? 

Level 2 is designed to establish a practical minimum standard of cyber security across the health sector. 

It doesn't mean having an enterprise sized security team or implementing every cyber-security technology available. It means being able to demonstrate that the fundamental controls needed to protect sensitive health information are in place and being actively managed. 

Health NZ's assessment covers 10 areas: 

  1. Cyber risk management 
    Identifying your organisation's cyber-security risks and having clear responsibility for managing them. 

  2. Security awareness 
    Making sure staff understand common cyber threats, know how to work securely and know how to report something suspicious. 

  3. Knowing what's important 
    Understanding the systems, devices and information your organisation relies on — particularly those containing sensitive health information. 

  4. Secure configuration 
    Making sure computers, applications, cloud services and other technology are securely configured rather than simply relying on default settings. 

  5. Patching and updates 
    Keeping operating systems, applications and devices up to date so known security vulnerabilities are addressed. 

  6. Multi-factor authentication 
    Using MFA to add another layer of protection to remote access and cloud services, rather than relying on passwords alone. 

  7. Detecting unusual activity 
    Having the ability to identify suspicious or unexpected activity that could indicate an account or system has been compromised. 

  8. Least-privilege access 
    Making sure people only have access to the systems and information they genuinely need to do their jobs. 

  9. Data recovery 
    Maintaining backups and having a reliable way to restore important information and systems following an incident. 

  10. Incident response 
    Having a documented plan, so your organisation knows what to do, who to contact and how to respond when a cyber-security incident occurs. 

Why does this matter now? 

Healthcare organisations hold some of New Zealand's most sensitive information. 

Increased cyber-security incidents have demonstrated that significant breaches don't always require highly sophisticated attacks. Missing fundamental controls, including strong authentication, secure access management and effective monitoring, can be enough to expose sensitive information. 

Health NZ is consequently putting greater structure around how organisations demonstrate that these basics are being managed. 

Organisations sharing information with Health NZ are expected to meet at least CS-CMM Level 2 (Baseline). The security checklist is also becoming part of the assurance process associated with initiatives such as the Shared Digital Health Record. 

For practices and healthcare providers, cyber security is therefore increasingly more than an internal IT consideration. It's part of being able to safely participate in New Zealand's increasingly connected health system. 

Level 2 doesn't replace HISO 

The new Level 2 assessment should also be understood alongside the existing HISO 10029 Health Information Security Framework (HISF)

HISF remains the health-sector framework for protecting New Zealanders' health information. Health NZ recommends organisations use it when implementing security controls appropriate to their size, technology environment and risk. 

A useful way to think about the two is: 

  • Level 2 helps establish the minimum cyber-security capability you should be able to demonstrate. 

  • HISF provides the wider health-specific framework for protecting health information. 

What should healthcare organisations do? 

If your organisation hasn't assessed its cyber-security maturity recently, now is a good time to do so. 

Start with the fundamentals: 

  • confirm MFA is enabled wherever required 

  • review who has administrative and privileged access 

  • make sure devices and applications are patched 

  • understand where sensitive information is stored 

  • verify backups and recovery processes 

  • review staff security training 

  • ensure suspicious activity can be detected 

  • document your cyber incident response process 

  • make cyber risk someone’s explicit responsibility. 

Most importantly, don't treat the Health NZ checklist as a once-a-year compliance exercise. 

Good cyber security comes from making these controls part of normal operations and being able to demonstrate that they're working. 

Where Frankie fits 

Health NZ’s Level 2 requirements are a reminder that cyber risk is now a real operational and financial risk for healthcare providers. 

While strong IT and security controls are the first line of defence, cyber insurance can provide an important financial safety net if something still goes wrong, helping respond to events such as data breaches, cyber-attacks, business interruption and recovery costs. 

At Frankie, we can help healthcare providers put appropriate cyber insurance cover in place

And if you need support assessing or improving your IT and cyber security controls, we can connect you with Cloudland, our recommended medical technology partner. 

Need cyber insurance? Get a quote and bind cover online.