New Zealand's health sector organisations — DHBs (now Te Whatu Ora districts), health NGOs, primary health providers, and their suppliers — face a compliance landscape that combines NZISM obligations (for government-funded health bodies) with the specific privacy requirements of the Health Information Privacy Code 2020 (HIPC).
Understanding how these frameworks interact — and where they require different things — is essential for health sector information security and privacy teams.
What the HIPC Is
The Health Information Privacy Code is a code of practice issued by the Privacy Commissioner under the Privacy Act 2020. It modifies the Act's Information Privacy Principles (IPPs) as they apply to health information — sometimes making requirements stricter, sometimes adapting them to the specific health context.
Key HIPC requirements include:
Rule 1: Purpose of collection — health information may only be collected for lawful purposes directly connected to the agency's health service functions.
Rule 2: Source of information — health information must generally be collected directly from the individual. Indirect collection requires specific justification.
Rule 3: Collection of information from individual — individuals must be informed about collection, including who is collecting, why, and who it may be shared with.
Rule 5: Limits on storage and security — health agencies must protect health information against unauthorised access, disclosure, alteration, or destruction. This is where NZISM and HIPC directly overlap.
Rule 7: Limits on use — health information must only be used for the purpose for which it was collected or a directly related purpose.
Rule 11: Disclosure — health information can only be disclosed in specific circumstances. The rule includes important provisions around disclosure for research, public health, and law enforcement.
Rule 12: Unique identifiers — governs the use of NHI numbers and other health identifiers.
Rule 10: Limits on disclosure — health information may be disclosed for purposes including treatment, funding, quality improvement, and compliance with legal obligations.
Where HIPC and NZISM Overlap
HIPC Rule 5 (security of health information) directly aligns with NZISM's technical security controls. For health agencies that are also subject to NZISM, meeting NZISM's security requirements generally satisfies HIPC's security obligations — but not automatically.
The key overlap areas:
- Access control — both NZISM and HIPC require that access to health information is limited to those with a need to access it. Role-based access control, least privilege, and regular access reviews satisfy both.
- Encryption — NZISM's cryptography requirements cover the encryption standards HIPC implicitly requires for health information in transit and at rest.
- Incident response — both frameworks require breach detection and response capabilities. HIPC adds specific obligations around notification when health information is breached (under the Privacy Act's mandatory breach notification regime).
- Audit logging — NZISM requires logging; HIPC's accountability requirements benefit from comprehensive audit logs showing who accessed what health information when.
Where HIPC Goes Further
HIPC includes several requirements that NZISM does not directly address:
Patient access rights — individuals have the right to access their own health information and request corrections. Health agencies need processes for handling these requests, including response timeframes.
Secondary use restrictions — using health information for research, teaching, or quality improvement is regulated under the HIPC and may require ethics approval under the National Health and Disability Ethics Committees (HDEC) process.
Disclosure to family and caregivers — the HIPC includes specific rules about disclosing patient information to family members and caregivers, which require judgement calls that NZISM's technical controls don't address.
Breach Notification Under Both Frameworks
A health information breach triggering HIPC obligations also triggers Privacy Act 2020 mandatory breach notification requirements. For health agencies that are also government agencies, NCSC reporting may additionally be required.
The notification chain for a serious health information breach may include:
- NCSC (if the breach involves a cyber incident)
- Privacy Commissioner (mandatory if serious harm is likely)
- Affected individuals (mandatory if serious harm is likely)
- Ministry of Health / Te Whatu Ora (depending on the organisation)
- Board or governance body
Health agencies should map out this notification chain before an incident occurs and assign clear responsibilities for each notification step.
Managing HIPC and NZISM Together
For health agencies subject to both frameworks, an integrated compliance approach is most effective:
- Build your NZISM control library with HIPC rule mapping included
- Ensure your privacy impact assessment (PIA) process covers HIPC requirements for new systems and data uses
- Include HIPC-specific elements (patient access, secondary use, disclosure rules) in staff training alongside NZISM obligations
- Use your NZISM risk register to capture health information-specific risks
AccreditAZ supports HIPC alongside NZISM, ISO 27001, PSR, and Essential Eight — so health sector organisations can manage their full compliance landscape in one place. Start a free trial.