Education Toolkits

Introduction to My Health Record in general practice - Chapter 10

Security

Last revised: 12 Jul 2024

Only healthcare providers who have been authorised by their organisation to access My Health Record can access health information within a patient’s record. All access and use of the My Health Record system is captured in an audit trail.

All databases, including general practice records, can be subject to data safety and privacy issues, such as:

  • identification issues and duplicate records
  • unauthorised access to records and data breaches
  • missing data
  • software and system issues.

There are three types of safeguards to protect the security and privacy of My Health Record data - practice safeguards, system safeguards, and regulatory safeguards.

Practice safeguards:

  • implementing policies and procedures which govern the use of My Health Record at the individual general practice level
  • providing education for all practice staff involved in the use of My Health Record (initial and ongoing training) 
  • promoting a culture of security among practice staff (for example, a culture of keeping devices and passwords secure and ensuring that screens are turned away from view or located in areas under appropriate surveillance) 
  • taking reasonable steps to prevent misuse of/unauthorised access to Healthcare Identifiers with account management measures 
  • taking care to ensure information is accurate to the best of your knowledge before uploading to My Health Record
  • having personal medical indemnity coverage. 

System safeguards:

  • design principles which restrict access to authorised healthcare providers operating within a registered healthcare organisation 
  • data storage being in Australia, on government servers 
  • security vigilance with encryption and digital authentication, access monitoring and penetration testing. 

Regulatory safeguards: 

  • various Acts, Regulations and Rules protecting My Health Record data and ensuring it is used safely  
  • oversight by government agencies and departments such as the Office of the Australian Information Commissioner (OAIC). 
This event attracts CPD points and can be self recorded

Did you know you can now log your CPD with a click of a button?

Create Quick log

Advertising