What's in this template?
This free policy template gives every registered My Health Record provider organisation the policy they are legally required to hold under section 21 of the My Health Records Rules 2026, the requirement formerly known as Rule 42. It is built from the structure of the OAIC's published guidance (still titled "Rule 42 guidance") and the Australian Digital Health Agency's current participation obligations, then tailored for use in an Australian medical practice or allied health service.
The template covers 14 sections plus a sign-off block:
- Purpose: links the policy to section 21 of the My Health Records Rules 2026 (formerly Rule 42) and the registration requirements in the My Health Records Act 2012
- Scope: every worker, every system, every access pathway (clinical software, NASH PKI, mobile, remote)
- Legislative and regulatory framework: table of every Act, Rule and scheme that applies
- Roles and responsibilities: Responsible Officer, authorised users, all workers
- Authorising, reviewing and removing access: same-day removal when workers leave
- Identification, authentication and access controls: passwords, MFA, screen lock, NASH certificate handling
- Physical and technical security: server, workstation, paper, backup, audit logging
- Mobile devices and remote access: BYOD rules, lost device reporting
- Training and awareness: links to the Staff Training and Awareness Procedure
- Detecting, reporting and managing breaches: 1-hour reporting, System Operator and OAIC notification
- Audit, monitoring and oversight: quarterly audit log review and annual policy review under section 43
- Related documents: cross-references to your other compliance documents
- Definitions: HPI-O, HPI-I, IHI, NASH, Responsible Officer, System Operator
- Approval and review: formal sign-off table
Editable placeholder fields
- Practice name{{practice_name}}, ABN{{abn}}, Hpi o{{hpi_o}}, Practice address{{practice_address}}, Phone{{phone}}, Email{{email}}
- Responsible officer{{responsible_officer}}: the person named to the Australian Digital Health Agency
- Clinical software{{clinical_software}}: your conformant clinical system (Best Practice, Medical Director, etc.)
- Access review frequency{{access_review_frequency}}: e.g., quarterly, every 6 months
- It support contact{{it_support_contact}}, Training records owner{{training_records_owner}}
- Review date{{review_date}}, Next review date{{next_review_date}}
Who needs a security and access policy? (formerly Rule 42)
A documented Security and Access Policy is mandatory for every organisation registered to the My Health Record system, regardless of size. That includes:
- General practices of any size, including solo GPs
- Specialist medical practices registered to the system
- Allied health practices (physiotherapy, podiatry, psychology, etc.) connected via conformant software
- Pharmacies dispensing prescriptions through My Health Record
- Aboriginal Community Controlled Health Organisations
- Private hospitals and day surgeries registered to the system
- Pathology and diagnostic imaging providers uploading results
If you have a Healthcare Provider Identifier-Organisation (HPI-O) and a NASH PKI certificate, this policy applies to you.
Section 21 at a glance
Section 21 of the My Health Records Rules 2026 (the provision that replaced Rule 42) requires every registered provider organisation to hold a written policy, drafted so performance against it can be audited, addressing:
- (a) Authorisation and removal: procedures for authorising a user, and for suspending or deactivating their account when they leave, are compromised, no longer need access, or stop being linked to the practice
- (b) Training: the training given before a user is authorised, refreshed annually, and repeated after any significant change to the Act or the system
- (c) Sections 74 and 75: the processes that keep the practice from contravening the Act's rules on unauthorised collection, use and disclosure, and its data breach notification duty
- (d) Security measures: the physical, information, cyber, technical and organisational measures in place, including user account management, regular maintenance, encryption and back-up, and monitoring
- (e) Risk response: strategies to ensure security risks are promptly identified, acted on and reported to management
Section 21(4) then sets seven specific user account management practices every policy must commit to: restrict access to users who need it, uniquely identify each user with their identity protected by a password or equivalent (this is the provision a shared login breaches), require sufficiently robust passwords, deactivate accounts that are no longer authorised, suspend compromised accounts as soon as practicable, review these practices at least annually, and make sure users are aware of and trained in them.
This template covers each of those requirements in the order an auditor will look for them, with editable placeholders so the policy reflects your specific practice rather than a generic stock document.
Registered before April 2026? The clock runs out on 1 October 2026
Section 72 of the My Health Records Rules 2026 keeps the old Rule 42 requirements running for organisations that were registered before 1 April 2026, but only until immediately before 1 October 2026. From that date, the section 21 content list applies to every registered organisation, no matter when it registered. Organisations that registered on or after 1 April 2026 have been on the 2026 Rules from day one.
If your practice registered before April 2026 and you are reviewing an old Rule 42 policy now, do not simply renew it in its old shape. Rebuild it against section 21: the authorisation and removal procedures, the training limb, the sections 74 and 75 processes, the security measures, and the risk response strategies, plus the seven section 21(4) account practices. From 1 October 2026 this is the only version of the policy an auditor will accept, and there is no benefit in waiting.
Legal force behind the policy
Section 21 is not a stand-alone rule. It is an eligibility requirement for registration under paragraphs 43(b) and 109(3)(a) of the My Health Records Act 2012, and sections 43 to 46 of the My Health Records Rules 2026 (the policy's life cycle, production and record-keeping duties) are conditions on registration under paragraph 109(3)(c). Failure to hold a compliant policy puts registration itself at risk, and can result in:
- Suspension or cancellation of My Health Record system registration
- Regulatory action by the OAIC, which regulates privacy on the My Health Record system
- Reputational damage if a breach occurs without an adequate policy in place
The Australian Digital Health Agency, as System Operator, may request a copy of your policy at any time, and section 44 gives you only 7 days to produce it once that request is in writing. Section 43 also requires the policy to carry a unique version number and effective date on every iteration, and to be reviewed at least annually, whenever a material new or changed risk arises, or whenever the System Operator asks. Practices that complete RACGP accreditation are also typically asked to evidence this policy under criterion C6.4 (Information security).
How to customise this template
- Download the Word document and replace every Placeholder{{placeholder}} with your details
- Nominate your Responsible Officer: typically the practice principal, practice manager, or a senior clinician
- Confirm your HPI-O and NASH PKI certificate location with your practice manager or IT contact
- Tailor section 6 (Identification and authentication) to match how your conformant software actually works
- Set your access review cadence in section 5: quarterly is good practice for most practices
- Have it approved by the Responsible Officer and signed in the approval table at the back
- Communicate it to all authorised users and require them to sign the Staff Training and Awareness Procedure acknowledgement
- Schedule the next review: at least annually under section 43, or sooner if your software, processes or the legislation change
Related templates and tools
This policy is the foundation document. Pair it with the procedures that bring it to life:
- My Health Record Staff Training and Awareness Procedure: the section 21(2)(b) training procedure with a built-in training register
- My Health Record Emergency Access Procedure: when and how clinicians may access a record under section 64 without consent
- My Health Record Authorised User Access Register: the fillable log of everyone this policy's section 5 authorises, reviews and removes
- My Health Record Data Breach Notification Procedure: the section 75 dual-notification steps behind this policy's section 10
For broader information security obligations, see the Computer and Information Security Policy and the Privacy Policy in the RACGP library.
Frequently asked questions
Is a My Health Record Security and Access Policy mandatory?
Yes. Section 21 of the My Health Records Rules 2026 (the provision that replaced Rule 42 of the 2016 Rules) requires every registered healthcare provider organisation participating in the My Health Record system to have a documented security and access policy. The Rules are made under section 109 of the My Health Records Act 2012, and holding this policy is an eligibility requirement for registration. This applies to solo practitioners as well as larger organisations. The Australian Digital Health Agency, as System Operator, may request a copy at any time, and section 44 gives you 7 days to produce it.
What is Rule 42?
Rule 42 was the provision in the My Health Records Rule 2016 that prescribed the minimum content of every registered provider's security and access policy. The 2016 Rules were repealed and replaced by the My Health Records Rules 2026 (commenced 1 April 2026), and the old Rule 42 content is now spread across several provisions: authorisation, training and security measures sit in section 21; the policy's life cycle, communication, versioning and annual review sit in section 43; the 7 day production duty sits in section 44; and record keeping sits in section 45. The OAIC's published guidance is still titled "Rule 42 guidance," which is why the term is still in use, but the current legal requirement is section 21.
Who is the Responsible Officer?
The Responsible Officer is the person nominated by the organisation to be the contact point for the Australian Digital Health Agency on My Health Record matters. They are accountable for approving the security and access policy, authorising users, ensuring training is delivered, and managing breaches. In a small general practice this is usually the practice principal or practice manager. The Responsible Officer is named at registration and updated through the Healthcare Identifiers Service.
What are the penalties for not having this policy?
The most common consequence is suspension or cancellation of My Health Record system registration, because holding this policy is an eligibility requirement for registration under the My Health Records Act 2012. The OAIC, as the My Health Record system's privacy regulator, may also take regulatory action. Separately, unauthorised access by a worker, which is more likely without a clear policy and trained staff, can attract criminal penalties of up to 2 years' imprisonment under sections 59 to 62 of the Act. Practices undergoing accreditation may also fail evidence requirements under RACGP criterion C6.4.
How often does the policy need to be reviewed?
Section 43 of the My Health Records Rules 2026 requires the policy to be reviewed at least annually, and immediately whenever there is a material new or changed risk: a new clinical software system, a change to the legislation, a breach, or a change of Responsible Officer, or whenever the System Operator asks. Each iteration needs its own unique version number and effective date, and must be kept for 5 years from its effective date. The template includes a built-in review schedule.
Does this policy replace our broader privacy policy?
No. The section 21 policy (formerly the Rule 42 policy) is specific to the My Health Record system. You still need a general Privacy Policy covering the Australian Privacy Principles (APPs) and a Computer and Information Security Policy. The three documents reference each other and form your overall information governance set. ClinicComply provides templates for all three.
Is this policy enough on its own to comply with section 21?
The policy is the cornerstone, but section 21(2)(b) also requires a training procedure for authorised users. Most practices pair this Security and Access Policy with the Staff Training and Awareness Procedure (downloadable separately) so the training, knowledge check and refresher cadence are documented as well.
Can a sole-trader GP use this template?
Yes. The Australian Digital Health Agency's own sole-trader guidance is built on the same framework that now sits in section 21, only the scale of the safeguards changes. A solo practitioner is both the Responsible Officer and the only authorised user, so several sections collapse to single-person responsibilities, but every section 21 topic still has to be covered. This template is structured so you can simply remove sections that do not apply (e.g., reviews of multiple users) and keep the rest.