Back to Frameworks

Australia My Health Records Act 2012

Australia
vMy Health Records Act 2012, Compilation No. 18, compilation date 2026-07-01, incorporating the sharing by default regime; read with the My Health Records Rule 2016, Compilation No. 1
6 domains
40 controls

The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator.

Verified

Australia My Health Records Act 2012 is a compliance framework from Australia with 6 domains and 40 controls that map to 24 other frameworks. The largest domains are Registration and Participation (12 controls), Security and Access (7 controls), Collection, Use and Disclosure (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit legislation.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Breach and Enforcement

5 controls

Mandatory data breach notification, offences, civil penalties and enforcement (Parts 5-6).

Controls in the Breach and Enforcement domain of Australia My Health Records Act 20125 controls
CodeTitle
MYHR-ENF-1Mandatory data breach notification
MYHR-ENF-2Civil penalty compliance
MYHR-ENF-3Criminal offences and sanctions
MYHR-ENF-4Enforceable undertakings and injunctions
MYHR-ENF-5Infringement notices

Collection, Use and Disclosure

6 controls

Authorised and prohibited collection, use and disclosure of health information (Part 4).

Controls in the Collection, Use and Disclosure domain of Australia My Health Records Act 20126 controls
CodeTitle
MYHR-CUD-1Authorised collection, use and disclosure only
MYHR-CUD-2Prohibition on unauthorised collection, use and disclosure
MYHR-CUD-3Use limited to My Health Record purposes
MYHR-CUD-4Records not held or taken outside Australia
MYHR-CUD-5Interaction with the Privacy Act 1988
MYHR-CUD-6Prohibition on use for a prohibited purpose

Governance

6 controls

System Operator and Data Governance Board oversight (Parts 2 and 7).

Controls in the Governance domain of Australia My Health Records Act 20126 controls
CodeTitle
MYHR-GOV-1System Operator functions and oversight
MYHR-GOV-2Data Governance Board
MYHR-GOV-3Annual reporting on the My Health Record system
MYHR-GOV-4Review of decisions
MYHR-GOV-5Retention, destruction and correction obligations of the System Operator
MYHR-GOV-6The Register of participants

Registration and Participation

12 controls

Registration of participants and healthcare recipients and conditions of participation (Part 3).

Controls in the Registration and Participation domain of Australia My Health Records Act 201212 controls
CodeTitle
MYHR-REG-1Registration as a participant
MYHR-REG-10Notification when eligibility or registration conditions can no longer be met
MYHR-REG-11Ensuring required information is given to the System Operator
MYHR-REG-12Cancellation, suspension and variation of registration
MYHR-REG-2Healthcare recipient registration and identity verification
MYHR-REG-3Conditions of registration and participation
MYHR-REG-4Contracted service provider oversight
MYHR-REG-5Mandatory registration of prescribed healthcare provider organisations
MYHR-REG-6Condition of registration relating to uploading records
MYHR-REG-7Copyright conditions on handling old records for provider organisations
MYHR-REG-8Copyright conditions on handling old records for operators and service providers
MYHR-REG-9Non-discrimination in providing healthcare

Security and Access

7 controls

Security and access obligations of registered participants (Act + My Health Records Rule).

Controls in the Security and Access domain of Australia My Health Records Act 20127 controls
CodeTitle
MYHR-SEC-1Written security and access policy
MYHR-SEC-2Access controls and user account management
MYHR-SEC-3Audit logging and access monitoring
MYHR-SEC-4Training of authorised employees
MYHR-SEC-5Security risk assessment
MYHR-SEC-6Emergency access controls
MYHR-SEC-7Consumer access controls and consent

Sharing by Default

4 controls
Controls in the Sharing by Default domain of Australia My Health Records Act 20124 controls
CodeTitle
MYHR-SBD-1Share by default for prescribed key health information
MYHR-SBD-2Approved periods where sharing or registration is not required
MYHR-SBD-3Record keeping for sharing with the My Health Record system
MYHR-SBD-4Notice where information is not being shared

Your Compliance Coverage

If you comply with Australia My Health Records Act 2012, you already cover:

Maps to 24 other frameworks

40 total controls
GDPR
27 source controls mapped|26 target controls covered
68%
NIST SP 800-53 Rev 5
27 source controls mapped|49 target controls covered
68%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
27 source controls mapped|55 target controls covered
68%
SOC 2
27 source controls mapped|32 target controls covered
68%
ISO 27002:2022
21 source controls mapped|32 target controls covered
53%
ISO 27001:2022
21 source controls mapped|32 target controls covered
53%
NIST Cybersecurity Framework 2.0
20 source controls mapped|37 target controls covered
50%
FedRAMP High
18 source controls mapped|52 target controls covered
45%
FedRAMP Moderate
18 source controls mapped|52 target controls covered
45%
NIST SP 800-53 Revision 5.1 HIGH
18 source controls mapped|48 target controls covered
45%
NIST SP 800-53 Rev 5 MODERATE
18 source controls mapped|48 target controls covered
45%
APEC Cross-Border Privacy Rules (CBPR) System
17 source controls mapped|29 target controls covered
43%
APPI
17 source controls mapped|16 target controls covered
43%
NIST SP 800-53 Rev 5 LOW
16 source controls mapped|40 target controls covered
40%
CIS Controls v8
16 source controls mapped|34 target controls covered
40%
HIPAA Security Rule
16 source controls mapped|34 target controls covered
40%
Australian Privacy Principles (APPs)
16 source controls mapped|9 target controls covered
40%
NIST SP 800-66 Rev 2
15 source controls mapped|28 target controls covered
38%
C5 (Germany)
13 source controls mapped|31 target controls covered
33%
NIST SP 800-161 Rev 1
10 source controls mapped|25 target controls covered
25%
APRA CPS 234
8 source controls mapped|12 target controls covered
20%
Azure Security Benchmark
7 source controls mapped|17 target controls covered
18%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|2 target controls covered
3%
ISO 27701:2019
1 source controls mapped|1 target controls covered
3%

What is Australia My Health Records Act 2012 and who does it apply to?

Australia My Health Records Act 2012 is a compliance framework from Australia with 6 domains and 40 controls. The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Australia My Health Records Act 2012 actually require?

Australia My Health Records Act 2012 has 40 controls organised across 6 domains. The largest domains are Registration and Participation (12 controls), Security and Access (7 controls), Collection, Use and Disclosure (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Australia My Health Records Act 2012 do I already cover?

Australia My Health Records Act 2012 maps to 24 other compliance frameworks. The top mapping partners are GDPR (68% coverage), NIST SP 800-53 Rev 5 (68% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (68% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Australia My Health Records Act 2012?

Start your Australia My Health Records Act 2012 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia My Health Records Act 2012 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required