If your organisation stores, processes, or transmits health information in New Zealand, HISO 10029:2022, the Health Information Security Framework, sets out what “reasonable security” actually looks like. It’s increasingly showing up as a requirement in funder RFPs and PHO agreements, and it’s worth understanding even if nobody’s asked you for it yet.
The framework covers five functional areas: Plan, Identify, Protect, Detect, and Respond, with segment specific guidance for hospitals, micro to small organisations, medium to large organisations, and suppliers. Most general practices and small healthcare providers fall under the micro to small organisation guidance, which sets out 21 individual requirements.
Working across a range of healthcare clients, we’ve noticed the same handful of gaps come up again and again. Here are the five worth checking for.
1. No documented incident response plan
Most practices have an informal idea of what happens if something goes wrong: restore from backup, reset passwords, call the IT provider. Very few have this written down. HISO 10029:2022 expects a documented, tested response plan with clear steps and a defined path for notifying the relevant authorities if patient data is affected. If you can’t point to a document, this is usually the first gap worth closing.
2. No staff phishing simulation or cyber security training
Technical controls only go so far when the entry point for most breaches is a staff member clicking a link. The framework expects ongoing security awareness training, not a one off induction session years ago. Regular phishing simulations paired with short, recurring training modules give you both the education and the evidence trail auditors and funders want to see.
3. Spam and malware filtering that hasn’t kept pace
Built in email protection has improved a lot, but for organisations handling health information, a dedicated, business grade filtering and endpoint protection package is generally expected rather than optional. It’s also one of the more straightforward gaps to close, often as an upgrade path from whatever antivirus is already in place rather than a rip and replace.
4. No independent Microsoft 365 backup
This is the one that catches people out. Microsoft’s own retention policies and recycle bin are not a backup. They’re designed to protect Microsoft’s infrastructure, not to give you a tested, restorable copy of your mailbox, files, and Teams data if something is deleted, encrypted, or corrupted. HISO 10029:2022 expects backups that are encrypted and periodically tested for restoration, which means a proper third party backup solution sitting across Exchange Online, SharePoint, OneDrive, and Teams.
5. Written internal policies
Technical controls (Conditional Access, endpoint management, patch compliance) are usually the IT provider’s job. Written security and privacy policies, the documents that say what your organisation does and why, are usually the organisation’s own responsibility to hold and maintain, even if your IT provider helps draft them. It’s a distinction that trips a lot of practices up when a funder asks to see policy documents rather than just a description of technical setup.
A related change worth flagging: Microsoft is retiring SMS and voice authentication
Separately from HISO, Microsoft announced in mid-2026 that it’s phasing out SMS and voice call as multi-factor authentication methods in Entra ID. From September 2026, passkeys became the default method for new sign-ins, and from February 2027, Microsoft-provided SMS and voice authentication will be retired entirely. Any user without another registered method will be locked out until they set one up. If your organisation still relies on text message codes for MFA, it’s worth getting ahead of this rather than dealing with it as a lockout emergency next year.
Where to start:
None of these gaps are hard to close individually, and most practices we work with are only missing two or three of the five. The starting point is usually a straightforward gap assessment against the HISO requirements relevant to your organisation’s size, followed by a prioritised plan to close what’s missing.
If you’d like a HISO 10029:2022 gap assessment for your practice, get in touch with the Pure Logic team.






