If your practice is using My Health Record, it must operate in accordance with relevant legislation and comply with a number of obligations that all relevant members of your team need to be aware of.
Prior to registering with My Health Record, your organisation will need to establish a security and access policy to ensure My Health Record is used safely and responsibly. The security and access policy is a requirement under Rule 21 of the My Health Records Rules 2026.
The purpose of the security and access policy is to support compliance with the My Health Records Act 2012 and the My Health Records Rules 2026, and to protect sensitive patient information while ensuring the appropriate use of My Health Record.
It will also support your practice to identify and respond to security risks related to My Health Record and to manage enquiries when they arise.
What needs to be included in the security and access policy?
Rule 21 of the My Health Records Rules 2026 sets out the specific topics that must be covered in your practice’s security and access policy. The topics include:
-
Procedures your practice will use to authorise user access, or use information in the My Health Record system, including procedures for creating and modifying user accounts, and how a user’s account will be suspended or deactivated under specific circumstances.
-
Training for users before they are authorised to access the system, annually, and following any significant changes to the My Health Record system or the governing legislation.
-
Processes for identifying individuals who access a person’s record, and an outline of how your practice will meet its obligations under section 74 of the My Health Records Act 2012.
-
Processes for ensuring compliance with My Health Record data breach obligations under section 75 of the My Health Records Act 2012.
-
Physical security, information security, cybersecurity, and technical and organisational measures, including user account management processes.
-
Strategies for identifying, responding to, and reporting system-related security risks
The Australian Digital Health Agency’s webpage, ‘My Health Record participation obligations’ provides detailed information on the above requirements to help you develop and maintain your security and access policy.
Maintaining your security and access policy
Your My Health Record security and access policy must be reviewed annually, at a minimum, and when any material, new or changed risks are identified, or when requested by the System Operator (Australian Digital Health Agency).
The policy must have a unique version number and date off effect, and a copy of each version of the policy must be retained for five years in accordance with Rule 43 of the My Health Records Rules 2026.
Record-keeping
Your practice must keep a record of how the various elements of your security and access policy are implemented in the practice. This is a requirement under Rule 45 of the My Health Records Rules 2026.
Failure to maintain a security and access policy
Registered practices that fail to comply with the policy requirements of the My Health Records Rules 2026 may be deemed ineligible to participate in the My Health Record system and may have their registration revoked.
The Office of the Australian Information Commissioner (OAIC) is the privacy regulator for My Health Record and the OAIC may take action if an organisation does not maintain a compliant security and access policy. The Commissioner’s enforcement approach is set out in the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026.
Merely having a Security and Access policy is not sufficient to ensure the security and integrity of the My Health Record system and the information it contains. Healthcare provider organisations must actively communicate and enforce their Security and Access policy in relation to all employees and any healthcare providers to whom the organisation supplies services under contract.
Further information on implementing and maintaining your security and access policy is available on the Australian Digital Health Agency’s webpage, ‘My Health Record participation obligations’.
Updated legislation
The My Health Records Rule 2016 has been replaced by the My Health Records Rules 2026, effective 1 April 2026.
A six-month transition period applies to existing participants (registered before 1 April 2026), with full compliance required by 1 October 2026. During this time, general practices may continue to apply the 2016 Rule.
New participants (registered on or after 1 April 2026) must comply with the 2026 Rules.