Doctor with patient

Key changes in My Health Record Rules and updates required to your Organisation’s Security & Access Policy

Doctor with patient

Healthcare Provider Organisations accessing the My Health Record system are required to maintain a written Security and Access Policy. This policy outlines how the organisation protects My Health Record information, manages user access, provides training, and maintains privacy and security safeguards.

From 1 April 2026, updated My Health Record Rules 2026 came into effect, replacing the previous 2016 Rules. The updated Rules introduce a revised set of Security and Access Policy requirements which are outlined in Rule 21 and 43, which replace Rule 42 and 44 from the 2016 rules.  

For organisations that already have a Security and Access Policy in place, the 2026 Rules do not replace the requirement for an existing policy, they build on and strengthen existing requirements. While many privacy and security obligations remain unchanged, there are several important updates.

Key changes include:

  • Organisations must have clear processes for managing user accounts, providing staff training, maintaining security measures, and responding to any My Health Record data breaches.
  • Organisations are required to keep records that show how they are meeting these requirements and applying their security and access policies. Depending on the type of record, these records need to be kept for between 2 and 5 years

What does this mean for organisations already using My Health Record before 1 April 2026?

  • Existing registered organisations may continue to operate under previous requirements during the transition period.
  • Organisations have until 1 October 2026 to review and update their Security and Access Policy to align with the My Health Records Rules 2026.

What does this mean for organisations registering for my Health Record from 1 April 2026?

  • New organisations registering for My Health Record from 1 April 2026 must meet the new requirements when they register.
  • A written Security and Access Policy that complies with the 2026 Rules must be in place before participation in My Health Record.

Next steps for your organisation:

The Australian Government, Office of the Australian Information Commissioner (OAIC), have developed a template Security and Access Policy to support healthcare provider organisations in meeting the new requirements. Further information and the template can be found on the OAIC website here

Additionally, the following resources may assist organisations to review and update their policies:

For any further questions or queries, please don't hesitate to reach out to the Adelaide PHN Digital Health Team on digitalhealth@adelaidephn.com.au

Our Digital Health Team offers training on how to use My Health Record and can support your organisation's registration.

Information current as of 15 September 2026.

13 August 2026