Canopy Healthcare: Patients notified months after Canopy Healthcare cyber incident

Canopy Healthcare: Patients notified months after Canopy Healthcare cyber incident

Canopy Healthcare Discloses Delayed Data Breach Impacting Patients and Staff

On 12 January 2026, Canopy Healthcare, a major private oncology provider in New Zealand, revealed a cyber incident that compromised patient and staff data six months after the breach occurred. The unauthorized access took place on 18 July 2025, with attackers copying a limited set of administrative data, potentially including patient records, passport details, and bank account numbers.

The company stated that the full scope of affected individuals and stolen data remains unclear, and no evidence has surfaced of the information being leaked or published online. Patient notifications began in December 2025, drawing criticism for the delayed disclosure. One impacted individual expressed frustration over learning of the breach months after the fact.

Canopy Healthcare reported the incident to New Zealand police and the Privacy Commissioner at the time, secured a High Court injunction to prevent data misuse, and confirmed that its medical services remained unaffected. The investigation into the breach is ongoing.

Source: https://dig.watch/updates/canopy-healthcare-data-breach

Canopy Cancer Care cybersecurity rating report: https://www.rankiteo.com/company/canopy-cancer-care

"id": "CAN1768223930",
"linkid": "canopy-cancer-care",
"type": "Breach",
"date": "7/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients and staff',
                        'industry': 'Healthcare',
                        'location': 'New Zealand',
                        'name': 'Canopy Healthcare',
                        'size': 'Large',
                        'type': 'Healthcare Provider'}],
 'customer_advisories': 'Patients notified in December 2025',
 'data_breach': {'data_exfiltration': 'Yes (copied data)',
                 'number_of_records_exposed': 'Small amount',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Patient records',
                                              'Passport details',
                                              'Bank account numbers']},
 'date_detected': '2025-07-18',
 'date_publicly_disclosed': '2025-12',
 'description': 'Canopy Healthcare, one of New Zealand’s largest private '
                'medical oncology providers, disclosed a data breach affecting '
                'patient and staff information six months after the incident '
                'occurred. An unauthorised party accessed part of its '
                'administration systems and copied a ‘small’ amount of data, '
                'which may include patient records, passport details, and some '
                'bank account numbers.',
 'impact': {'customer_complaints': 'Criticism over delay in notification',
            'data_compromised': 'Patient records, passport details, bank '
                                'account numbers',
            'identity_theft_risk': 'High',
            'operational_impact': 'Medical services continued to operate '
                                  'normally',
            'payment_information_risk': 'High',
            'systems_affected': 'Administration systems'},
 'investigation_status': 'Ongoing (unclear which individuals were impacted and '
                         'what data was taken)',
 'references': [{'date_accessed': '2026-01-12', 'source': 'News Article'}],
 'regulatory_compliance': {'legal_actions': 'High Court injunction to prevent '
                                            'misuse of data',
                           'regulatory_notifications': 'Privacy Commissioner '
                                                       'notified'},
 'response': {'communication_strategy': 'Patients notified in December 2025',
              'law_enforcement_notified': 'Yes (Police notified)'},
 'title': 'Canopy Healthcare Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.