My Health Record
My Health Record is a secure online summary of key patient health information. Healthcare providers can access the system to view and add information.
Changes are being made to make it a requirement for public and private pathology and diagnostic imaging providers to share reports to My Health Record by default which will make it easier for healthcare providers to coordinate care and make clinical decisions.
Healthcare provider benefits
- Provides immediate access to key health information.
- Facilitates the validation and verification of clinical information.
- Avoids adverse medication events, provides access to allergy information.
- Avoids duplication of tests and diagnostic imaging.
- Provides immunisation details.
- Provides continuity of care, informs end of life care.
Patient benefits
Prompt access to key health information in an emergency.
- Secure, convenient access to health information.
- Safer, faster more efficient care.
- Less need to remember key aspects of their medical history and medications.
- Improved management of health information.
- Informed self-management of health conditions.
Register and set up access
Discover how to establish policies, register your organisation, and access the system via conformant clinical software, the National Provider Portal (NPP) or hospital applications.
Implementing My Health Record in your healthcare organisation
Education and training
Find resources to help you feel confident using the system. Detailed information, software summary sheets, training and support are all available here.
My Health Record Security and Access Policy Requirements in accordance with the My Health Record Act 2012 and My Health Records Rule 2026.
Organisations that were registered with the My Health Record system before 1 April 2026 must review and update their Security and Access Policy by 1 October 2026 to ensure compliance with the 2026 My Health Record Rules. Organisations registering with My Health Record on or after 1 April 2026 are required to develop and maintain a Security and Access Policy that aligns with the 2026 Rules from the outset.
All Australian healthcare providers have professional, ethical, and legal responsibilities to safeguard the privacy and security of their patients’ health information. Implementing and maintaining robust information security practices is therefore an essential requirement for the delivery of quality healthcare services and compliance with legislative obligations.
My Health Record security and access policy
Healthcare provider organisations that wish to participate in the system, must develop, communicate, keep records of, and enforce a written My Health Record security and access policy that addresses a number of areas, including:
- the manner of authorising people to access the My Health Record system, and deactivating or suspending access
- training that will be provided to employees before they access the My Health Record system, annually and following significant changes to the My Health Record legislation or My Health Record system
- the process outlining how the organisation will meet its obligations under section 74 of the My Health Records Act 2012 in regard to identifying the individual who accessed a person’s My Health Record and communicating the person’s identity to the Australian Digital Health Agency (System Operator)
- the process for ensuring the organisation complies with its data breach obligations under section 75 of the My Health Records Act 2012
- physical security, information security, cybersecurity, technical and organisational measures (including using account management practices) that will be established and adhered to by the healthcare provider organisation and people accessing the My Health Record system on behalf of the organisation
- strategies for identifying, responding to, and reporting of My Health Record system-related security risks.
This policy is required under My Health Records Rules 2026. Once the security and access policy has been established, the healthcare provider organisation is legally required to review it at least annually as well as when new or changed risks are identified, and it must be kept up to date. Each iteration of the policy must be retained. The organisation must also keep records relating to the application of its policy in relation authorising staff access, training, identifying staff, data breach processes and security measures.
(source: Australian Digital Health Agency)
More information
For more information, please visit:
Download template
Here is a link to a policy template developed by the Australian Digital Health Agency – your organisation can use this template to develop your own security and access policy.