Getting started – a guide for general practice staff


Getting started – a guide for general practice staff

Overview

To begin using My Health Record in your general practice, you must:

  1. Develop a security and access policy for using My Health Record
  2. Register your practice as an organisation with the Healthcare Identifiers Service
  3. Obtain HPI-Is for all clinical staff who will be using My Health Record
  4. Set up access to My Health Record
  5. Train staff prior to use
  6. Comply with ongoing participation obligations

For full step-by-step instructions and support for connecting your practice to My Health Record, visit the Australian Digital Health Agency’s webpage, ‘Implementing My Health Record in your healthcare organisation’.

If your practice is using My Health Record, it must operate in accordance with relevant legislation and comply with a number of obligations that all relevant members of your team need to be aware of.

Prior to registering with My Health Record, your organisation will need to establish a security and access policy to ensure My Health Record is used safely and responsibly. The security and access policy is a requirement under Rule 21 of the My Health Records Rules 2026.

The purpose of the security and access policy is to support compliance with the My Health Records Act 2012 and the My Health Records Rules 2026, and to protect sensitive patient information while ensuring the appropriate use of My Health Record.

It will also support your practice to identify and respond to security risks related to My Health Record and to manage enquiries when they arise.

What needs to be included in the security and access policy?

Rule 21 of the My Health Records Rules 2026 sets out the specific topics that must be covered in your practice’s security and access policy. The topics include:

  • Procedures your practice will use to authorise user access, or use information in the My Health Record system, including procedures for creating and modifying user accounts, and how a user’s account will be suspended or deactivated under specific circumstances.

  • Training for users before they are authorised to access the system, annually, and following any significant changes to the My Health Record system or the governing legislation.

  • Processes for identifying individuals who access a person’s record, and an outline of how your practice will meet its obligations under section 74 of the My Health Records Act 2012.

  • Processes for ensuring compliance with My Health Record data breach obligations under section 75 of the My Health Records Act 2012.

  • Physical security, information security, cybersecurity, and technical and organisational measures, including user account management processes.

  • Strategies for identifying, responding to, and reporting system-related security risks

The Australian Digital Health Agency’s webpage, ‘My Health Record participation obligations’ provides detailed information on the above requirements to help you develop and maintain your security and access policy.

Maintaining your security and access policy

Your My Health Record security and access policy must be reviewed annually, at a minimum, and when any material, new or changed risks are identified, or when requested by the System Operator (Australian Digital Health Agency).

The policy must have a unique version number and date off effect, and a copy of each version of the policy must be retained for five years in accordance with Rule 43 of the My Health Records Rules 2026.

Record-keeping

Your practice must keep a record of how the various elements of your security and access policy are implemented in the practice. This is a requirement under Rule 45 of the My Health Records Rules 2026.

Failure to maintain a security and access policy

Registered practices that fail to comply with the policy requirements of the My Health Records Rules 2026 may be deemed ineligible to participate in the My Health Record system and may have their registration revoked.

The Office of the Australian Information Commissioner (OAIC) is the privacy regulator for My Health Record and the OAIC may take action if an organisation does not maintain a compliant security and access policy. The Commissioner’s enforcement approach is set out in the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026.

Merely having a Security and Access policy is not sufficient to ensure the security and integrity of the My Health Record system and the information it contains. Healthcare provider organisations must actively communicate and enforce their Security and Access policy in relation to all employees and any healthcare providers to whom the organisation supplies services under contract.

Further information on implementing and maintaining your security and access policy is available on the Australian Digital Health Agency’s webpage, ‘My Health Record participation obligations’.

Updated legislation

The My Health Records Rule 2016 has been replaced by the My Health Records Rules 2026, effective 1 April 2026.

A six-month transition period applies to existing participants (registered before 1 April 2026), with full compliance required by 1 October 2026. During this time, general practices may continue to apply the 2016 Rule.

New participants (registered on or after 1 April 2026) must comply with the 2026 Rules.

To participate in My Health Record, all healthcare organisations must first register with the Healthcare Identifiers Service (HI Service). The HI Service is a national system for identifying healthcare providers, healthcare organisations and individuals receiving healthcare.

Healthcare organisations will either apply to register as a Seed Organisation (a standalone organisation, such as an independent general practice) or a Network Organisation (a subordinate department/division within a large organisation, such as a general practice with multiple sites). Most general practices would be registered as a Seed Organisation.

To register with the HI Service, your practice will need to nominate:

  • Responsible Officer (RO) who holds authority to act on behalf of your practice in its dealings with the System Operator of My Health Record. A person listed on the Australian Business Register for the business is typically nominated for this role. An organisation can only have one RO nominated in the HI service at a time.
  • an Organisation Maintenance Officer (OMO) who holds authority to act on behalf of your practice in its day-to-day administrative dealings with the HI Service and My Health Record. Your practice manager or a senior staff member who is familiar with your practice’s clinical and administrative systems are appropriate fits for this role. Your organisation can nominate multiple OMOs in the HI Service system for the practice.

Steps on how to Register an Organisation with the HI Service (obtain HPI-O) can be found on the Australian Digital Health Agency’s website.

Once you have registered with the HI Service, your practice will receive a unique 16-digit number called a Healthcare Provider Identifier for Organisations (HPI-O).

For more information on managing the responsible officer (RO) and organisation maintenance officers (OMO) details in the Healthcare Identifiers (HI) Service, visit the Services Australia website.

All healthcare providers who wish to use My Health Record require a Healthcare Provider Identifier for Individuals (HPI-I) from the HI Service to do so. As a GP, you will already have a HPI-I as all providers registered with the Australian Health Practitioner Regulation Agency (AHPRA) are automatically registered with the HI Service.

If you do not know your HPI-I, you can obtain these details by logging in to your AHPRA account online, or by calling the HI Service enquiry line on 1300 361 457. Your practice’s OMO can also retrieve an HPI-I via Health Professional Online Services (HPOS), so long as the relevant provider has consented to having their details published in the Healthcare Provider Directory.

Those who are employed in a healthcare profession that is not regulated by AHPRA may still be able to obtain an HPI-I if they are a member of a professional association that has certain characteristics outlined by Services Australia. Non-AHPRA registered healthcare providers can register for a HPI-I via Health Professional Online Services (HPOS).

For more information on how to obtain providers HPI-Is, visit the Australian Digital Health Agency’s website.

Access via a Clinical Information System

You can access, view and upload information to a patient's My Health Record through your practice’s clinical information system (CIS) if it conforms to the requirements of the Australian Digital Health Agency, as the System Operator for My Health Record. A full list of conformant software products is available on the Agency website. 

CISs are linked to the My Health Record system either via a National Authentication Service for Health (NASH) certificate or a Contracted Service Provider (CSP) number. Find out how to connect to My Health Record through your practice’s CIS by contacting your software provider.

NASH certificates can be requested via HPOS. For more information, visit the Australian Digital Health Agency’s National Authentication Service for Health webpage

CSP numbers are provided by your CIS vendor and linked via HPOS. Follow the steps in the Agency’s guide for Contracted Service Provider Linking in HPOS.

Once you have completed either the NASH or CSP linking process, contact your software provider to access support to appropriately configure your healthcare identifiers and certificates.

Access via the National Provider Portal

Alternatively, clinicians are able to view a My Health Record without a clinical information system through the National Provider Portal (NPP). You cannot upload documents to a My Health Record using the National Provider Portal. 

Where possible, it is recommended that My Health Record is accessed via your conformant clinical software, as it does not require an additional log in and is a better user experience.  For further information on how to set up access to My Health Record using either a CIS or NPP, visit the Agency’s website

All members of your practice team who use My Health Record must receive initial and ongoing training on the appropriate collection, use and disclosure of My Health Record information. General practices are legally obligated to provide staff members with My Health Record training before they are authorised to access My Health Record. Each user must be aware of both organisational and individual legislative obligations specific to the My Health Record system.

*Note, it is not appropriate to use a staff member or a patient's My Health Record for training purposes. The Australian Digital Health Agency has training simulators which provide self-paced learning and demonstrations of each of the software systems.

Once registered with My Health Record, your practice must comply with several ongoing participation obligations in accordance with the My Health Records Act 2012 and the My Health Records Rules 2026, including:

  • Deliver healthcare services appropriately regardless of an individual’s My Health Record status

  • Protect the privacy, security and maintain quality of My Health Record information

  • Ensure only authorised users, and where applicable registered healthcare providers (with a valid HPI‑I), access and upload information to My Health Record

  • Maintain accurate organisational details (including RO and OMO contact details) via PRODA and Health Professional Online Services (HPOS)

  • Comply with conditions of registration as a My Health Record system participant and directions given by the System Operator

  • Notify the System Operator of breaches, errors and relevant changes within required timeframes

  • Train staff on the appropriate use of My Health Record, along with privacy and legislative obligations

  • Respect and document healthcare recipient instructions regarding viewing or uploading of health information to their My Health Record.

Further information about the ongoing My Health Record participation obligations can be found on the Australian Digital Health Agency’s webpage, ‘My Health Record participation obligations’.
 

This event attracts CPD points and can be self recorded

Did you know you can now log your CPD with a click of a button?

Create Quick log

Advertising