Back to Frameworks

Australia My Health Records Act 2012

Australia
v2012 (amended 2018)
5 domains
22 controls

The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator.

Verified

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit legislation.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Breach and Enforcement

4 controls

Mandatory data breach notification, offences, civil penalties and enforcement (Parts 5-6).

Controls in the Breach and Enforcement domain of Australia My Health Records Act 20124 controls
CodeTitle
MYHR-ENF-1Mandatory data breach notification
MYHR-ENF-2Civil penalty compliance
MYHR-ENF-3Criminal offences and sanctions
MYHR-ENF-4Enforceable undertakings and injunctions

Collection, Use and Disclosure

5 controls

Authorised and prohibited collection, use and disclosure of health information (Part 4).

Controls in the Collection, Use and Disclosure domain of Australia My Health Records Act 20125 controls
CodeTitle
MYHR-CUD-1Authorised collection, use and disclosure only
MYHR-CUD-2Prohibition on unauthorised collection, use and disclosure
MYHR-CUD-3Use limited to My Health Record purposes
MYHR-CUD-4Records not held or taken outside Australia
MYHR-CUD-5Interaction with the Privacy Act 1988

Governance

2 controls

System Operator and Data Governance Board oversight (Parts 2 and 7).

Controls in the Governance domain of Australia My Health Records Act 20122 controls
CodeTitle
MYHR-GOV-1System Operator functions and oversight
MYHR-GOV-2Data Governance Board

Registration and Participation

4 controls

Registration of participants and healthcare recipients and conditions of participation (Part 3).

Controls in the Registration and Participation domain of Australia My Health Records Act 20124 controls
CodeTitle
MYHR-REG-1Registration as a participant
MYHR-REG-2Healthcare recipient registration and identity verification
MYHR-REG-3Conditions of registration and participation
MYHR-REG-4Contracted service provider oversight

Security and Access

7 controls

Security and access obligations of registered participants (Act + My Health Records Rule).

Controls in the Security and Access domain of Australia My Health Records Act 20127 controls
CodeTitle
MYHR-SEC-1Written security and access policy
MYHR-SEC-2Access controls and user account management
MYHR-SEC-3Audit logging and access monitoring
MYHR-SEC-4Training of authorised employees
MYHR-SEC-5Security risk assessment
MYHR-SEC-6Emergency access controls
MYHR-SEC-7Consumer access controls and consent

Your Compliance Coverage

If you comply with Australia My Health Records Act 2012, you already cover:

Maps to 7 other frameworks

22 total controls
Australian Privacy Principles (APPs)
8 source controls mapped|5 target controls covered
36%
HIPAA Security Rule
6 source controls mapped|6 target controls covered
27%
NIST SP 800-66 Rev 2
5 source controls mapped|5 target controls covered
23%
NIST SP 800-53 Rev 5
5 source controls mapped|5 target controls covered
23%
GDPR
2 source controls mapped|2 target controls covered
9%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|2 target controls covered
5%
ISO 27701:2019
1 source controls mapped|1 target controls covered
5%

Frequently Asked Questions

What is Australia My Health Records Act 2012?

Australia My Health Records Act 2012 is a compliance framework from Australia with 5 domains and 22 controls. The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Australia My Health Records Act 2012 have?

Australia My Health Records Act 2012 has 22 controls organised across 5 domains. The largest domains are Security and Access (7 controls), Collection, Use and Disclosure (5 controls), Breach and Enforcement (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Australia My Health Records Act 2012 map to?

Australia My Health Records Act 2012 maps to 7 other compliance frameworks. The top mapping partners are Australian Privacy Principles (APPs) (36% coverage), HIPAA Security Rule (27% coverage), NIST SP 800-66 Rev 2 (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Australia My Health Records Act 2012 compliance?

Start your Australia My Health Records Act 2012 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia My Health Records Act 2012 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required