Australia My Health Records Act 2012
The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator.
Australia My Health Records Act 2012 is a compliance framework from Australia with 6 domains and 40 controls that map to 24 other frameworks. The largest domains are Registration and Participation (12 controls), Security and Access (7 controls), Collection, Use and Disclosure (6 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit legislation.gov.auFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Breach and Enforcement
Mandatory data breach notification, offences, civil penalties and enforcement (Parts 5-6).
| Code | Title |
|---|---|
| MYHR-ENF-1 | Mandatory data breach notification |
| MYHR-ENF-2 | Civil penalty compliance |
| MYHR-ENF-3 | Criminal offences and sanctions |
| MYHR-ENF-4 | Enforceable undertakings and injunctions |
| MYHR-ENF-5 | Infringement notices |
Collection, Use and Disclosure
Authorised and prohibited collection, use and disclosure of health information (Part 4).
| Code | Title |
|---|---|
| MYHR-CUD-1 | Authorised collection, use and disclosure only |
| MYHR-CUD-2 | Prohibition on unauthorised collection, use and disclosure |
| MYHR-CUD-3 | Use limited to My Health Record purposes |
| MYHR-CUD-4 | Records not held or taken outside Australia |
| MYHR-CUD-5 | Interaction with the Privacy Act 1988 |
| MYHR-CUD-6 | Prohibition on use for a prohibited purpose |
Governance
System Operator and Data Governance Board oversight (Parts 2 and 7).
| Code | Title |
|---|---|
| MYHR-GOV-1 | System Operator functions and oversight |
| MYHR-GOV-2 | Data Governance Board |
| MYHR-GOV-3 | Annual reporting on the My Health Record system |
| MYHR-GOV-4 | Review of decisions |
| MYHR-GOV-5 | Retention, destruction and correction obligations of the System Operator |
| MYHR-GOV-6 | The Register of participants |
Registration and Participation
Registration of participants and healthcare recipients and conditions of participation (Part 3).
| Code | Title |
|---|---|
| MYHR-REG-1 | Registration as a participant |
| MYHR-REG-10 | Notification when eligibility or registration conditions can no longer be met |
| MYHR-REG-11 | Ensuring required information is given to the System Operator |
| MYHR-REG-12 | Cancellation, suspension and variation of registration |
| MYHR-REG-2 | Healthcare recipient registration and identity verification |
| MYHR-REG-3 | Conditions of registration and participation |
| MYHR-REG-4 | Contracted service provider oversight |
| MYHR-REG-5 | Mandatory registration of prescribed healthcare provider organisations |
| MYHR-REG-6 | Condition of registration relating to uploading records |
| MYHR-REG-7 | Copyright conditions on handling old records for provider organisations |
| MYHR-REG-8 | Copyright conditions on handling old records for operators and service providers |
| MYHR-REG-9 | Non-discrimination in providing healthcare |
Security and Access
Security and access obligations of registered participants (Act + My Health Records Rule).
| Code | Title |
|---|---|
| MYHR-SEC-1 | Written security and access policy |
| MYHR-SEC-2 | Access controls and user account management |
| MYHR-SEC-3 | Audit logging and access monitoring |
| MYHR-SEC-4 | Training of authorised employees |
| MYHR-SEC-5 | Security risk assessment |
| MYHR-SEC-6 | Emergency access controls |
| MYHR-SEC-7 | Consumer access controls and consent |
Sharing by Default
| Code | Title |
|---|---|
| MYHR-SBD-1 | Share by default for prescribed key health information |
| MYHR-SBD-2 | Approved periods where sharing or registration is not required |
| MYHR-SBD-3 | Record keeping for sharing with the My Health Record system |
| MYHR-SBD-4 | Notice where information is not being shared |
Your Compliance Coverage
If you comply with Australia My Health Records Act 2012, you already cover:
Maps to 24 other frameworks
What is Australia My Health Records Act 2012 and who does it apply to?
Australia My Health Records Act 2012 is a compliance framework from Australia with 6 domains and 40 controls. The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Australia My Health Records Act 2012 actually require?
Australia My Health Records Act 2012 has 40 controls organised across 6 domains. The largest domains are Registration and Participation (12 controls), Security and Access (7 controls), Collection, Use and Disclosure (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Australia My Health Records Act 2012 do I already cover?
Australia My Health Records Act 2012 maps to 24 other compliance frameworks. The top mapping partners are GDPR (68% coverage), NIST SP 800-53 Rev 5 (68% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (68% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Australia My Health Records Act 2012?
Start your Australia My Health Records Act 2012 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia My Health Records Act 2012 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required