New Zealand · Health Information Privacy Code 2020

Thirteen rules for health information, run as a working system

For health agencies across New Zealand — AccessPoint runs rule 6 access and rule 7 correction on the Privacy Act clock, Part 6 notifiable privacy breaches, Privacy Commissioner complaints, and health privacy impact assessments.

New Zealand — Health Information Privacy Code at a glance

Access deadline
As soon as reasonably practicable, and no later than 20 working days
Correction
Correction, or a statement of correction sought attached to the record where declined
Breach duty
Notify the Commissioner and affected individuals where serious harm is caused or likely
Structure
Thirteen rules modifying the Privacy Act principles for health agencies
Enforcement
Compliance notices and binding access directions
Languages
English

Built for New Zealand — Health Information Privacy Code

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

Rule 6 access on the clock

Run a patient's access request on the 20-working-day maximum, with the Privacy Act's withholding grounds applied and cited, and the decision recorded rather than communicated informally.

Rule 7 correction

Where correction is declined, the individual may require a statement of the correction sought to be attached to the record. Track that as an outcome, not a loose end — it travels with the health record afterwards.

Part 6 notifiable breaches

Assess whether a breach has caused or is likely to cause serious harm, notify the Commissioner and affected individuals where it has, and record the assessment either way.

Health privacy impact assessments

Run PIAs for new health information systems and data-sharing arrangements as full cases, with risks, mitigations, owners, and a dated sign-off.

Built for binding directions

The Commissioner can now direct an agency to provide access. A timestamped record of what was requested, decided, and withheld is what an investigation of that kind runs on.

In your own tenant

Health information stays inside your own Microsoft 365 and Azure tenant — no third-party cloud, no vendor access, and no cross-border transfers.

The Privacy Act 2020 changed the stakes

Access decisions in New Zealand used to end in a recommendation. Now they can end in a direction.

The Privacy Act 2020 gave the Privacy Commissioner powers the previous Act did not: compliance notices requiring an agency to do or stop doing something, and binding directions requiring that access be given to information the agency declined to release. For health agencies — where access requests are frequent, records are shared between clinicians, and withholding decisions often turn on clinical judgement about harm — that raises the value of a decision that was properly made and properly recorded. An agency asked to justify a rule 6 refusal needs to show what was withheld, on which ground, and on whose clinical assessment. AccessPoint keeps that as structured case data instead of a note in a patient management system, and it holds correction outcomes and breach assessments on the same ledger.

20 working days The Privacy Act maximum, computed and tracked.
Clinical input recorded Who assessed harm, and what they concluded.
Direction-ready The record an access direction is decided against.

Configured out of the box

Installing the nz-hipc jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • The Health Information Privacy Code 2020 as the legal-authority spine, with its thirteen rules
  • Rule 6 access on the 20-working-day maximum with New Zealand public holidays
  • The Privacy Act withholding grounds, colour-coded for redaction and citable line by line
  • Rule 7 correction with statement-of-correction-sought handling where declined
  • Clinical review as a tracked stage where withholding turns on harm
  • Part 6 notifiable privacy breach assessment and notification to the Commissioner and individuals
  • Health privacy impact assessment templates with risks, mitigations, and sign-off
  • Privacy Commissioner complaint, compliance notice, and access direction tracking

New Zealand — Health Information Privacy Code Questions

Who does the HIPC apply to?

Health agencies as the Code defines them — a broad category covering health service providers and others handling health information in New Zealand. The Code modifies the Privacy Act's information privacy principles for that sector, expressing them as thirteen rules tailored to health information.

How long do we have to answer an access request?

As soon as reasonably practicable, and no later than 20 working days after receipt. AccessPoint computes the date over the New Zealand public-holiday calendar and tracks any extension with its ground and the notice given to the individual.

What happens if we decline a correction request?

The individual may require that a statement of the correction sought be attached to the information. AccessPoint records that as an outcome linked to the record, so the statement travels with the health information rather than being filed and forgotten.

Where does health information reside?

Entirely within your own Microsoft 365 and Azure tenant, in the region you choose. Requests, records, assessments, and audit history never leave your control — no third-party cloud, no vendor access, and no cross-border data transfers.

Run the Health Information Privacy Code in Your Own Tenant

Try AccessPoint free for 30 days, configured for New Zealand health agencies. No credit card required.

Start Free Trial