Skip to main content
Compliance Guide — Updated August 2026

My Health Records Security Requirements

Complete guide to My Health Records Act obligations, ADHA security standards, and best practices for participant healthcare organisations in Australia.

What is My Health Record?

My Health Record (MHR) is a secure online summary of a patient's health information, accessible by authorised healthcare providers across Australia. Managed by the Australian Digital Health Agency (ADHA), the system holds information including medical histories, medications, allergies, diagnostic imaging, and discharge summaries.

Participation in My Health Record is voluntary for patients, but all registered healthcare providers who participate must comply with strict security and privacy obligations under the My Health Records Act 2012 (Cth) and the Privacy Act 1988 (Cth).

As of 2026, over 24 million Australians have a My Health Record. GP practices, hospitals, allied health providers, and pharmacies participating in the system carry significant security obligations — and significant liability if those obligations are not met.

Governing Legislation

My Health Records Act 2012 (Cth)

Primary legislation. Establishes the My Health Record system, defines participant obligations, sets security and access requirements, and specifies breach reporting timelines.

Privacy Act 1988 (Cth) — APP 11

Australian Privacy Principles apply concurrently. APP 11 requires "reasonable" security for all personal health information — including data accessed via My Health Record.

ADHA Security Policy Framework

ADHA publishes mandatory security requirements for system operators and healthcare provider organisations. Non-compliance can result in suspension from the system.

Participant Security Obligations

Healthcare providers registered in My Health Record are "participant healthcare provider organisations" under the Act. The following obligations apply from the moment your organisation connects to the system:

Authenticate All Users

Only authorised clinical and administrative staff with a legitimate clinical need may access patient My Health Records. Authentication must be verifiable — shared passwords are explicitly prohibited. Individual user accounts with unique credentials and MFA are required for any system with direct access to the MHR portal.

Maintain Comprehensive Audit Logs

All access to My Health Records must be logged: which user, which patient record, what action (view, download, upload), and timestamp. Logs must be retained and available for audit by ADHA or OAIC. Audit logs are your primary evidence of compliance in an investigation.

Report Unauthorised Access Within 24 Hours

If you become aware of (or suspect) unauthorised access to any My Health Record data, you must notify the ADHA System Operator within 24 hours. This is separate from and in addition to the OAIC 30-day NDB notification timeline — the ADHA clock is shorter.

Conduct Annual Security Assessments

Healthcare provider organisations must conduct (or commission) an annual security assessment of systems used to access My Health Record. The assessment must identify risks and document remedial actions. This assessment should be retained for at least 5 years.

Staff Training and Awareness

All staff with access to My Health Records must receive training on: privacy obligations under the Act, how to access records appropriately, how to identify and report suspected breaches, and the consequences of unauthorised access (including criminal penalties under the Act).

ADHA Technical Security Requirements

The ADHA publishes specific technical security requirements for My Health Record participant systems. These include:

Encryption in Transit

TLS 1.2 or higher required for all data transmitted to/from the My Health Record system. Older SSL and TLS 1.0/1.1 protocols are prohibited.

Encryption at Rest

Patient data downloaded or cached locally must be encrypted using AES-256. Clinical workstations with cached MHR data must have full-disk encryption enabled.

Access Control (RBAC)

Role-based access control limiting MHR access to staff with a current treatment relationship with the patient. Receptionist-level staff should not have access to clinical record contents.

Session Management

Automatic session timeouts after 15 minutes of inactivity on workstations used to access MHR. Screens must lock when unattended in clinical areas.

Network Security

Separate clinical and administrative network segments. Firewall protection between clinical systems and public internet. Intrusion detection on networks accessing MHR.

Incident Response

Documented procedures for detecting, investigating, containing, and reporting security incidents involving MHR data — with specific timelines aligned to the 24-hour ADHA notification requirement.

Consequences of Non-Compliance

Security failures in My Health Record carry severe consequences beyond standard Privacy Act breaches:

Criminal Penalties

The My Health Records Act includes criminal offence provisions. Knowingly providing false or misleading information about a security breach carries imprisonment penalties.

Suspension from the System

ADHA can suspend or terminate a healthcare provider's access to My Health Record pending investigation. This directly impacts clinical operations and patient continuity of care.

OAIC Investigation

Breaches of MHR data also trigger Privacy Act obligations. Dual investigations — by both ADHA and OAIC — are common for significant incidents.

Reputational Damage

ADHA publishes summary reports of significant security incidents. Media coverage of patient data breaches causes lasting reputational damage and patient attrition for the practice.

Best Practice: MFA for All MHR Access

While MFA is strongly recommended rather than explicitly mandated by the Act, ADHA has signalled it will become mandatory for all healthcare provider systems connecting to My Health Record. Implementing MFA now positions your organisation ahead of compliance requirements and dramatically reduces credential-based breach risk.

Recommended: Microsoft Authenticator or Google Authenticator (TOTP) for all clinical staff accounts.

Related Compliance Resources

Is Your Practice MHR-Compliant?

ShieldForce helps healthcare providers implement ADHA-compliant security controls, audit procedures, and incident response plans for My Health Record participation.

Book Your Free Compliance Assessment

References

Authors: ShieldForce Editorial Team, led by Obi Ibeto, Founder & CEO, ShieldForce Australia

Published: August 2026 | Last Updated: August 2026

See our full author credentials