Australia My Health Records Act 2012
The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Assurance
| Code | Title |
|---|---|
| MHR-18 | Periodic Compliance Self Assessment |
Availability
| Code | Title |
|---|---|
| MHR-17 | System Availability and Resilience |
Breach
| Code | Title |
|---|---|
| MHR-11 | Mandatory Data Breach Notification |
Clinical Systems
| Code | Title |
|---|---|
| MHR-04 | Conformant Clinical Software |
Consent
| Code | Title |
|---|---|
| MHR-07 | Consent and Access Controls by Consumer |
Data Quality
| Code | Title |
|---|---|
| MHR-09 | Document Upload Quality and Suppression |
Discipline
| Code | Title |
|---|---|
| MHR-12 | Sanctions for Unauthorised Access |
Emergency
| Code | Title |
|---|---|
| MHR-08 | Emergency Access Use |
Governance
| Code | Title |
|---|---|
| MHR-01 | Registration and Participation Agreement |
Identifiers
| Code | Title |
|---|---|
| MHR-03 | Healthcare Identifiers Service Integration |
Identity
| Code | Title |
|---|---|
| MHR-06 | Identity Verification of Patients |
Part 1 — Preliminary
| Code | Title |
|---|---|
| MHR-1 | Objects and Definitions |
| MHR-2 | Application and Scope |
| OSA-1 | Objects and Definitions |
| OSA-2 | Scope of Application |
| POFMA-1.1 | Definitions and Interpretation (Sections 2-3) |
| POFMA-1.2 | Application and Scope (Section 4) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 6 | Establishment of the Commission |
Part 3 — Registration and Access
| Code | Title |
|---|---|
| MHR-3 | Healthcare Recipient Registration |
| MHR-4 | Access Controls |
Part 4 — Collection, Use and Disclosure
| Code | Title |
|---|---|
| MHR-5 | Collection of Health Information |
| MHR-6 | Use and Disclosure Framework |
| MHR-7 | Unauthorized Access Prohibition |
Part 6 — Enforcement
| Code | Title |
|---|---|
| MHR-8 | Civil Penalties (Division 1) |
| MHR-9 | Criminal Offenses |
Part 7 — Data Governance Board
| Code | Title |
|---|---|
| MHR-10 | Privacy Notice and Patient Information |
| MHR-11 | Mandatory Data Breach Notification |
Part 8 — Other Matters
| Code | Title |
|---|---|
| MHR-12 | Sanctions for Unauthorised Access |
| MHR-13 | Training for Authorised Employees |
| MHR-14 | Security Risk Assessment |
Privacy
| Code | Title |
|---|---|
| MHR-10 | Privacy Notice and Patient Information |
Retention
| Code | Title |
|---|---|
| MHR-16 | Data Retention and Archive |
Risk
| Code | Title |
|---|---|
| MHR-14 | Security Risk Assessment |
Security
| Code | Title |
|---|---|
| MHR-05 | Access Controls and Audit Logging |
Third Party
| Code | Title |
|---|---|
| MHR-15 | Contracted Service Provider Oversight |
Training
| Code | Title |
|---|---|
| MHR-13 | Training for Authorised Employees |
Use
| Code | Title |
|---|---|
| MHR-02 | Authorised Use and Collection Limits |
Your Compliance Coverage
If you comply with Australia My Health Records Act 2012, you already cover:
ILO Nursing Personnel Convention C149 (1977)
26%
9 controls mapped
Compare →6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673)
26%
9 controls mapped
Compare →ISO 8000 — Data Quality
26%
9 controls mapped
Compare →+ 611 more: FATF Recommendation 16 — Virtual Asset Travel Rule (26%), Privacy by Design (PbD) — Seven Foundational Principles (26%)
See all 614 mapped frameworks ↓Maps to 614 other frameworks
Frequently Asked Questions
What is Australia My Health Records Act 2012?
Australia My Health Records Act 2012 is a compliance framework from Australia with 24 domains and 40 controls. The My Health Records Act 2012 establishes the legal framework for Australia's national digital health record system (My Health Record). Managed by the Australian Digital Health Agency, it enables individuals and healthcare providers to access a summary of health information online. The system operates on an opt-out basis (since 2018). The Act establishes strict access controls, penalties for misuse, and governance by the System Operator. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Australia My Health Records Act 2012 have?
Australia My Health Records Act 2012 has 40 controls organised across 24 domains. The largest domains are Part 1 — Preliminary (10 controls), Part 4 — Collection, Use and Disclosure (3 controls), Part 8 — Other Matters (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Australia My Health Records Act 2012 map to?
Australia My Health Records Act 2012 maps to 614 other compliance frameworks. The top mapping partners are ILO Nursing Personnel Convention C149 (1977) (26% coverage), 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) (26% coverage), ISO 8000 — Data Quality (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Australia My Health Records Act 2012 compliance?
Start your Australia My Health Records Act 2012 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australia My Health Records Act 2012 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required