AccreditAZ

← All articles

Frameworks · 6 min read · Published 29 March 2026 · Reviewed 17 August 2026

Health Information Privacy Code (HIPC) and NZISM: What Health Sector Agencies Need to Know

New Zealand's health sector operates under both the Privacy Act 2020 and the Health Information Privacy Code. Here's how HIPC obligations relate to NZISM and what health agencies need to do to meet both.

New Zealand's health sector organisations — DHBs (now Te Whatu Ora districts), health NGOs, primary health providers, and their suppliers — face a compliance landscape that combines NZISM obligations (for government-funded health bodies) with the specific privacy requirements of the Health Information Privacy Code 2020 (HIPC).

Understanding how these frameworks interact — and where they require different things — is essential for health sector information security and privacy teams.

What the HIPC Is

The Health Information Privacy Code is a code of practice issued by the Privacy Commissioner under the Privacy Act 2020. It modifies the Act's Information Privacy Principles (IPPs) as they apply to health information — sometimes making requirements stricter, sometimes adapting them to the specific health context.

Key HIPC requirements include:

Rule 1: Purpose of collection — health information may only be collected for lawful purposes directly connected to the agency's health service functions.

Rule 2: Source of information — health information must generally be collected directly from the individual. Indirect collection requires specific justification.

Rule 3: Collection of information from individual — individuals must be informed about collection, including who is collecting, why, and who it may be shared with.

Rule 5: Limits on storage and security — health agencies must protect health information against unauthorised access, disclosure, alteration, or destruction. This is where NZISM and HIPC directly overlap.

Rule 7: Limits on use — health information must only be used for the purpose for which it was collected or a directly related purpose.

Rule 11: Disclosure — health information can only be disclosed in specific circumstances. The rule includes important provisions around disclosure for research, public health, and law enforcement.

Rule 12: Unique identifiers — governs the use of NHI numbers and other health identifiers.

Rule 10: Limits on disclosure — health information may be disclosed for purposes including treatment, funding, quality improvement, and compliance with legal obligations.

Where HIPC and NZISM Overlap

HIPC Rule 5 (security of health information) directly aligns with NZISM's technical security controls. For health agencies that are also subject to NZISM, meeting NZISM's security requirements generally satisfies HIPC's security obligations — but not automatically.

The key overlap areas:

Where HIPC Goes Further

HIPC includes several requirements that NZISM does not directly address:

Patient access rights — individuals have the right to access their own health information and request corrections. Health agencies need processes for handling these requests, including response timeframes.

Secondary use restrictions — using health information for research, teaching, or quality improvement is regulated under the HIPC and may require ethics approval under the National Health and Disability Ethics Committees (HDEC) process.

Disclosure to family and caregivers — the HIPC includes specific rules about disclosing patient information to family members and caregivers, which require judgement calls that NZISM's technical controls don't address.

Breach Notification Under Both Frameworks

A health information breach triggering HIPC obligations also triggers Privacy Act 2020 mandatory breach notification requirements. For health agencies that are also government agencies, NCSC reporting may additionally be required.

The notification chain for a serious health information breach may include:

  1. NCSC (if the breach involves a cyber incident)
  2. Privacy Commissioner (mandatory if serious harm is likely)
  3. Affected individuals (mandatory if serious harm is likely)
  4. Ministry of Health / Te Whatu Ora (depending on the organisation)
  5. Board or governance body

Health agencies should map out this notification chain before an incident occurs and assign clear responsibilities for each notification step.

Managing HIPC and NZISM Together

For health agencies subject to both frameworks, an integrated compliance approach is most effective:

AccreditAZ supports HIPC alongside NZISM, ISO 27001, PSR, and Essential Eight — so health sector organisations can manage their full compliance landscape in one place. Start a free trial.

Manage your NZISM, ISO 27001, Essential Eight and PSR compliance in one place.

Start free trial →