Any healthcare organisation using My Health Record – including solo practitioners – must be compliant with new security policy rules by 1 October.
The grace period to comply with updated My Health Record security and access policy requirements is fast running out, with just days left on the clock for all healthcare organisations using the program to get their paperwork in order.
A new set of rules has technically been in place since April of this year, but compliance will only be enforced from 1 October.
Organisations which registered with My Health Record for the first time after April 2026 would already have had to be compliant with these new rules; the organisations which will be affected are all those which registered before 1 April 2026, under the original ruleset.
Here’s what GPs need to know.
Does this apply to me?
All healthcare organisations which use My Health Record have ongoing participation obligations when it comes to how the service is accessed and who accesses it.
The relevant legislation – in this case, the Healthcare Identifiers Act 2010 – defines a “healthcare provider organisation” simply as an entity that provides healthcare or a support services.
The Australian Digital Health Agency website also clarifies that, even if the organisation only employs one staff member, it still needs to cover all of the My Health Record participation obligations.
Starting this year, pathology and diagnostic imaging providers have been legally obligated to upload reports to My Health Record by default.
Technically, GPs do not face the same obligations… but there’s writing on that particular wall.
The government has been clear in its intentions for sharing by default to become the norm. Early signs show a massive uptick in the number of clinicians viewing reports on the system.
What’s actually changing?
It’s quite technical.
As of April, two of the rules from the original 2016 My Health Records rulebook – specifically rules 42 and 44 – were superseded by new rules, numbered 21 and 43.
Rule 42 dealt with the types of policies that healthcare provider organisations had to have in place, while rule 44 governed user account management within healthcare provider organisations.
Both replacement rules covered security and access policy.
An ADHA fact sheet noted that the “core obligations” of the original rules “remain largely unchanged”, and that the new rules introduce additional requirements rather than change existing requirements.
There’s also an entirely new rule, number 45, which introduces new record-keeping obligations.
Go on then. What do I have to do?
The new requirements added by replacement rule 21 include:
- A policy outlining the procedures to create and modify user accounts
- A policy outlining the procedures for suspending or deactivating user accounts where the user is an individual health practitioner who leaves the organisation
- Annual refresher training for all authorised users, as well as training whenever there are significant changes to the system
- A policy outlining the processes to ensure the organisation complies with data breach obligations
- A policy detailing what cybersecurity, technical and organisational measures (i.e. data protection, encryption and back-up arrangements) are in place
Related
The new requirements that ADHA recommended organisations consider adding to comply with replacement rule 43 include:
- A written statement outlining that the organisation’s My Health Record policy is communicated and made readily accessible to any individual healthcare provider linked to the organisation
- A written statement committing to review the organisation’s My Health Record policy at the request of the system operator
- A written statement confirming that the organisation will ensure that records of each iteration of the My Health Record policy are retained for five years, to be measured starting on the day they commence
The new record keeping requirements under rule 45 include:
- Retaining procedures for authorising users and managing user accounts for five years
- Retaining training documents for five years
- Retaining the process for identifying the individual who accesses a person’s record for two years
- Retaining the process for ensuring compliance with My Health Record data breach obligations for two years
- Retaining documents pertaining to security measures for two years
ADHA has produced a security and access policy template conforming to the new rules.
What happens if we don’t update it in time?
Registered organisations that do not comply with the rules “are not eligible to participate in My Health Record and may have their registration revoked”.
In other words, if you get caught you might be booted from My Health Record.
The Office of the Australian Information Commissioner, which regulates the privacy aspects of My Health Record, may also consider regulatory action.



