Compliance glossary
Privacy & Data Protection

My Health Record(MHR)

Also known as: MHR, My Health Record system, PCEHR, personally controlled electronic health record, My Health Record security and access policy, My Health Records Act, national digital health record

Definition

My Health Record is the national online summary of a patient's health information, operated by the Australian Digital Health Agency as System Operator under the My Health Records Act 2012. A practice joins it as a registered healthcare provider organisation, which requires an HPI-O, a Responsible Officer and an Organisation Maintenance Officer, conformant software, and a written security and access policy made under section 21 of the My Health Records Rules 2026.

Why this matters for your practice

From 1 October 2026, every healthcare provider organisation registered with My Health Record must have a security and access policy that complies with the My Health Records Rules 2026, including organisations that already wrote one under the My Health Records Section 2016. The Rules were made on 27 March 2026 and commenced on 1 April 2026, and section 72 keeps the old requirements alive only until immediately before 1 October 2026. The Agency states the consequence plainly on its participation obligations page: organisations that do not comply are not eligible to participate and may have their registration revoked. The Office of the Australian Information Commissioner may also consider regulatory action.

What is My Health Record?

My Health Record is a national online system holding a summary of a patient's health information, not their complete medical history. The System Operator, the participant responsible for establishing and operating the system, is the Australian Digital Health Agency. It was previously called the personally controlled electronic health record, or PCEHR.

The legal foundation is the My Health Records Act 2012, which commenced on 29 June 2012 and establishes the System Operator role, a registration framework, a privacy and security framework and penalty provisions. The operational detail sits in the My Health Records Rules 2026, alongside the Healthcare Identifiers Act 2010, the My Health Records Regulations 2026 and the Healthcare Identifiers Regulations 2020.

A practice joins as a registered healthcare provider organisation, which the Agency defines as an organisation, or a part of an organisation, that has conducted, conducts, or will conduct, healthcare. A sole practitioner registers the same way. What it uploads includes a shared health summary, which also feeds the eHealth Practice Incentive. For a practice, this is a registration with obligations attached, not a feature of the clinical software.

What does a practice need before it can connect to My Health Record?

The policy comes before the registration: the organisation must develop it first, then attest at the time of registering that it is in place. It also needs two named people, because section 18 requires the Responsible Officer and the Organisation Maintenance Officer to be authorised to act for the organisation in its dealings with the System Operator. The rest of the registration sequence runs through PRODA and Health Professional Online Services.

Four steps a practice must complete before it can connect to My Health Record: appoint a Responsible Officer and Organisation Maintenance Officer who hold a PRODA account linked to HPOS, register the seed organisation with the Healthcare Identifiers Service to obtain a 16 digit HPI-O, write the security and access policy required by section 21 of the My Health Records Rules 2026 and attest to it at registration, then set up conformant clinical software or the read only National Provider Portal with a NASH PKI certificate or a CSP number and an HPI-I for each clinician.

What you needWhat it isWho arranges it
Responsible Officer and Organisation Maintenance OfficerThe two named contacts accountable for compliance with ongoing participation obligationsThe practice appoints them, and the RO registers the organisation
HPI-OA unique 16 digit number identifying the organisation, issued by the Healthcare Identifiers ServiceThe RO registers the seed organisation through PRODA and HPOS
Security and access policyThe written policy required by section 21, in place before registration and attested to at registrationThe practice writes it
Conformant clinical software or the National Provider PortalHow staff reach the system, the National Provider Portal being read onlyThe practice's software vendor, or the Agency
NASH PKI certificate or CSP numberWhat authenticates the organisation when conformant software is usedRequested and downloaded through HPOS by the RO or OMO
HPI-I for each clinicianA unique 16 digit number identifying an individual healthcare providerAhpra registered providers already have one

What must the security and access policy cover?

Section 21(1) requires a written security and access policy that addresses the matters in section 21(2) and is drafted so the organisation's performance can be audited against it. The five matters in section 21(2), formerly rule 42 of the 2016 Rule, are:

Authorising users. The procedures used to authorise a user and to create and modify accounts, and how an account is suspended or deactivated if the user leaves, their security is compromised, their duties no longer require access, or they are an individual healthcare provider that ceases to be linked to the organisation.

Training. The training given before a user is authorised, annually, and after any significant change to the Act, the regulations, the Rules or the system. Section 21(3) says it must cover using the system accurately and responsibly, the legal obligations of organisations and users, and the consequences of breaching them.

Section 74 and 75 processes. How the organisation will avoid contravening section 74, which requires it to identify the individual who asked for access, or section 75, the data breach duty.

Security measures. The physical security, information security, cybersecurity and technical and organisational measures implemented, including user account management, regular system maintenance, data protection with encryption and regular back-up, and monitoring and review.

Risk management. How security risks will be promptly identified, acted upon and reported to management.

Section 21(4) then lists seven user account management practices: restrict access to users who need it for their duties; uniquely identify each user and protect that identity with a password or equivalent; keep those mechanisms sufficiently secure and robust given the risks; deactivate accounts of users no longer authorised; suspend access as soon as practicable after an account or password is compromised; review the practices at least annually; and train users in them. An authorised user register usually covers the first two.

Sections 43 to 45 keep the policy alive. It must stay readily accessible to employees, contracted healthcare providers and linked individual healthcare providers. Each iteration carries a unique version number and date of effect, is reviewed at least annually, on any material new or changed risk and on request by the System Operator, and is kept for 5 years. Section 44 gives you 7 days to hand over a copy on request. Section 45 adds records of the policy being applied: 5 years for the user authorisation procedures and the training, 2 years for the section 74 and 75 processes and the security measures.

When can a practice look at a patient's record?

Section 61 authorises collection, use and disclosure of health information in a patient's My Health Record where it is for the purpose of providing healthcare to that patient and in accordance with the access controls they set, or the default controls if they set none. By default, every health service provider involved in the patient's care can see the record and its documents.

A patient can tighten that. A Record Access Code locks the whole record until the patient hands the code over, after which the organisation sits on a provider access list and does not need the code again. A Limited Document Access Code works the same way but also opens documents marked restricted. As the OAIC's access controls guidance puts it, a patient can stop a particular organisation, but cannot stop a particular individual inside it. The practice must not refuse care over the controls a patient sets, must do as they ask if they ask that a document not be uploaded, and must not download more than is necessary to treat them. Once information is on the local system, the Privacy Act 1988 and its Australian Privacy Principles take over.

Emergency access under section 64 overrides the controls where the provider reasonably believes it is necessary to lessen or prevent a serious threat to life, health or safety and it is unreasonable or impracticable to obtain consent. The System Operator must be advised, and the access must occur not later than 5 days after that advice. Every access is logged in the record's access history.

Which breach rules apply, the My Health Records Act or the Notifiable Data Breaches scheme?

Section 75 covers unauthorised collection, use or disclosure of health information in a My Health Record, and events or circumstances compromising the security or integrity of the system. A registered healthcare provider organisation must, as soon as practicable after becoming aware, notify both the System Operator and the Information Commissioner. Suspicion is enough, and the Agency says you must notify even where the breach has been resolved.

QuestionMy Health Records Act section 75Notifiable Data Breaches scheme
What triggers itUnauthorised collection, use or disclosure of information in a My Health Record, or an event or circumstances compromising the security or integrity of the systemA data breach likely to result in serious harm to an individual
Is suspicion enoughYes, a breach that may have occurred must be notifiedThe scheme turns on likely serious harm
Who you notifyThe System Operator and the Information Commissioner, or the System Operator alone for a State or Territory bodyThe OAIC
Who tells the patientsYou must ask the Agency to notify affected healthcare recipientsSee notifiable data breach
Penalty for not notifying1,500 penalty units under section 75(2)See the same page

The request to the Agency must cover the general public too where a significant number of people are affected, and stands even if the practice has already contacted patients itself. The Agency's four steps are contain, assess, manage notifications, continue investigation, the same order as our data breach response guide and the breach notification procedure. Separately, from 1 July 2026 pathology and diagnostic imaging providers are subject to a sharing by default upload requirement.

What the regulator or assessor expects

The OAIC is the privacy regulator for My Health Record. It may consider regulatory action where a policy is not compliant, and it regularly carries out privacy assessments that may involve reviewing those policies. Its powers, set out in the My Health Records (Information Commissioner Enforcement Powers) Guidelines 2026, include accepting an enforceable undertaking, making a determination, and applying to a court for an injunction or a civil penalty order.

The penalties sit in the Act. Section 59 makes it an offence, punishable by imprisonment for 5 years or 300 penalty units, or both, to collect health information from the system, or use or disclose information obtained through it, without authorisation where the person knows or is reckless as to that fact. The civil penalty is 1,500 penalty units. At the penalty unit amount of $364 set by the Crimes (Amount of a Penalty Unit) Instrument 2026 for offences committed on or after 1 July 2026, 300 penalty units is $109,200, a figure calculated from the penalty unit amount rather than stated in the Act. Section 74(1) carries 100 penalty units where an individual requesting access on the organisation's behalf cannot be identified to the System Operator without asking someone else.

The Agency also expects accurate RO and OMO contact details in PRODA and HPOS, and the System Operator told within 14 days if the practice ceases to be eligible for registration. None of this displaces the practice's wider privacy and cyber security obligations.

Common mistakes

Treating the 2016 policy as still good after 1 October 2026. A policy written under the My Health Records Section 2016 does not satisfy section 21 of the 2026 Rules once that date passes.

Assuming a small or inactive practice is exempt. The Agency's answer to practices with few or no staff is that every organisation must address every specified topic regardless of size, scale or technical capability, whether or not it actively uses the system.

Keeping no record of the policy being applied. Section 45 is a separate duty, with 5 years for the user authorisation and training records and 2 years for the rest. Training that happened but was never recorded cannot be evidenced.

Notifying one regulator, or waiting for certainty. Section 75(2) requires both the System Operator and the Information Commissioner to be told as soon as practicable, even where the breach only may have occurred. The quarterly shared health summary target is the other My Health Record deadline practices miss.

Frequently asked questions

What is My Health Record?

My Health Record is a national online system holding a summary of a patient's health information, not their complete medical history. The System Operator is the Australian Digital Health Agency. It is governed by the My Health Records Act 2012, which commenced on 29 June 2012, with the operational detail in the My Health Records Rules 2026. It was previously called the PCEHR.

Does my practice need a My Health Record security and access policy?

Yes. Every organisation registered with My Health Record must have a written policy addressing the matters in section 21 of the My Health Records Rules 2026, regardless of size, scale or technical capability, and regardless of how often the system is used. It must be in place before registration and attested to at registration.

What is the 1 October 2026 My Health Record deadline?

It is the date from which every registered healthcare provider organisation must have a security and access policy complying with the My Health Records Rules 2026, including organisations whose policy was written under the 2016 Rule. For organisations registered before 1 April 2026, the old requirements apply only until immediately before that date.

Can a patient stop one of our GPs from seeing their record?

No. Access controls operate at organisation level. A patient can stop a particular healthcare provider organisation from reaching their record, or particular documents, using a Record Access Code or a Limited Document Access Code, but cannot stop a particular individual inside that organisation.

Do we have to notify both the Agency and the OAIC about a My Health Record breach?

Yes. Under section 75(2) a registered healthcare provider organisation must notify both the System Operator and the Information Commissioner as soon as practicable after becoming aware of an actual or potential breach, even if it has been resolved. You must also ask the Agency to notify affected healthcare recipients.

What are the penalties for looking at a My Health Record without authorisation?

Section 59 carries imprisonment for 5 years or 300 penalty units, or both, where the person knows or is reckless as to the lack of authorisation, plus a civil penalty of 1,500 penalty units. At the $364 penalty unit amount, 300 penalty units is $109,200, a figure calculated from the penalty unit amount rather than stated in the Act.

How long do we have to keep My Health Record training records?

Five years. Section 45 requires records of the section 21(2)(b) training, and of the user authorisation procedures, to be retained for 5 years starting on the day the record was created. Records of the section 74 and 75 processes and of the security measures are retained for 2 years.

Last reviewed

30-day free trial, no credit card

Be the practice the assessor compliments.

Set up your frameworks this weekend. Walk into your next visit with your evidence linked and current, and nothing left to chase.

No credit card required
Australian data residency (Sydney)
Cancel anytime