Security and privacy

Responsible Officer (RO) and the Organisation Maintenance Officer (OMO)


Last revised: 18 Apr 2023

Responsible Officer (RO) and the Organisation Maintenance Officer (OMO)

Two key roles required under the Healthcare Identifiers Act 2010 for the effective operation of the My Health Record in general practice are the Responsible Officer (RO) and the Organisation Maintenance Officer (OMO).

The RO is typically the general practice owner or senior manager and holds the primary, legal responsibility for the organisation’s compliance with My Health Record legislation, policies, and participation requirements.

The RO is responsible for registering the organisation with the Healthcare Identifiers (HI) Service and must ensure general practice staff, GPs offering services at the practice and third party/external contractors adhere to the relevant rules, policies, and legislation governing the use of the My Health Record system.

The OMO is usually the practice manager or a senior staff member who handles the day-to-day administrative tasks ensuring the organisation’s details are up-to-date and managing user access to the My Health Record.

In small general practices, the RO often also acts as the OMO and in larger, more complex general practices, these roles are often separated to divide compliance and administrative tasks.

The RO is the legally responsible authority, while the OMO is the crucial administrator. A general practice can have multiple OMOs but only one primary RO.

This event attracts CPD points and can be self recorded

Did you know you can now log your CPD with a click of a button?

Create Quick log

Updated legislation

The My Health Records Rule 2016 has been replaced by the My Health Records Rules 2026, effective 1 April 2026.

A six-month transition period applies to existing participants (registered before 1 April 2026), with full compliance required by 1 October 2026. During this time, general practices may continue to apply the 2016 Rule.

New participants (registered on or after 1 April 2026) must comply with the 2026 Rules.

Requirements for a Security and Access Policy, formerly Rule 42 in the 2016 Rule, have been updated and renumbered in the 2026 Rules to Rule 43.

Advertising