All general practices participating in My Health Record have specific obligations under both the My Health Records Act 2012 (Cth) and My Health Records Rules 2026.
Rule 43 of the My Health Records Rules 2026 (formerly Rule 42 in the My Health Records Rule 2016) requires healthcare provider organisations to have, communicate and enforce a written Security and Access policy in order to register, and remain registered, to use the My Health Record system.
To ensure the My Health Record system is used responsibly and securely, practice owners must communicate and enforce the Security and Access policy to all individuals using the practice systems to access the My Health Records, including staff, contractors, and healthcare providers using the practices services.
The Security and Access Policy must cover:
- How GPs and practice staff are approved to access My Health Record and who can perform certain actions (viewing, uploading, editing).
- Processes for verifying patients before accessing or uploading to their My Health Record.
- User account management including unique logins, password protections, and prompt removal of access for staff who leave.
- Technical and physical security measures such as screen privacy, secure storage, and encrypted systems.
- Mandatory privacy, security, and My Health Record training for all staff, with regular refreshers.
- Clear internal procedures for identifying, reporting, and escalating suspected breaches.
- Regular updates to keep the policy current with legislative and system changes.
The OAIC has a Security and Access Policy template which provides guidance for healthcare provider organisations on meeting the requirements set out in Rule 43. Further information, including the Security and Access Policy template, can be found on the OAIC website.
Updated legislation
The My Health Records Rule 2016 has been replaced by the My Health Records Rules 2026, effective 1 April 2026.
A six-month transition period applies to existing participants (registered before 1 April 2026), with full compliance required by 1 October 2026. During this time, general practices may continue to apply the 2016 Rule.
New participants (registered on or after 1 April 2026) must comply with the 2026 Rules.
Requirements for a Security and Access Policy, formerly Rule 42 in the 2016 Rule, have been updated and renumbered in the 2026 Rules to Rule 43.