Skip to content

Evidence request lists

Australia My Health Records Act 2012

Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Breach and Enforcement

MYHR-ENF-1
Mandatory data breach notification

Notify the System Operator and the OAIC (and affected individuals where required) of unauthorised access to, or loss of, information in the My Health Record system, as soon as practicable.

Artefacts an auditor will ask for
  • Data breach response procedure
  • Records of notifications to System Operator/OAIC
  • Notification to affected individuals where required
Where this commonly fails
  • Breaches not notified
  • Notification delayed beyond as-soon-as-practicable
  • No breach response procedure
MYHR-ENF-2
Civil penalty compliance

Comply with the civil penalty provisions of the Act and the My Health Records Rules (Part 6 Div 1).

Artefacts an auditor will ask for
  • Compliance monitoring against civil penalty provisions
  • Remediation of identified contraventions
Where this commonly fails
  • Repeated contraventions
  • No monitoring of civil penalty obligations
MYHR-ENF-3
Criminal offences and sanctions

Prevent conduct constituting criminal offences under the Act (e.g. unauthorised use/disclosure) and apply sanctions for breaches by personnel (Part 5).

Artefacts an auditor will ask for
  • Sanction/disciplinary policy for breaches
  • Controls preventing offence conduct
Where this commonly fails
  • No sanction policy
  • Offence conduct not prevented or addressed
MYHR-ENF-4
Enforceable undertakings and injunctions

Cooperate with regulator enforcement mechanisms including enforceable undertakings and injunctions (Part 6 Div 2-3).

Artefacts an auditor will ask for
  • Records of any enforceable undertakings and compliance
  • Response to regulator action
Where this commonly fails
  • Non-compliance with undertakings
  • No process to respond to enforcement
MYHR-ENF-5
Infringement notices

Infringement notices may be issued for contraventions of specified provisions, and the recipient must understand the response options and time limits.

Artefacts an auditor will ask for
  • Procedure for receiving and escalating an infringement notice
  • Register of any notices received and how they were handled
  • Evidence of legal review within the response period
  • Root cause analysis following a notice
Where this commonly fails
  • No owner for regulator correspondence so notices sit unactioned
  • Penalty paid with no root cause analysis

Collection, Use and Disclosure

MYHR-CUD-1
Authorised collection, use and disclosure only

Collect, use and disclose health information in a My Health Record only as authorised by the Act (Part 4 Div 2).

Artefacts an auditor will ask for
  • Authorisation basis recorded for use/disclosure
  • Access tied to provision of healthcare
Where this commonly fails
  • Use/disclosure without authorisation
  • Access not tied to a permitted purpose
MYHR-CUD-2
Prohibition on unauthorised collection, use and disclosure

Do not collect, use or disclose health information except as authorised; unauthorised dealing is an offence (Part 4 Div 1).

Artefacts an auditor will ask for
  • Controls preventing unauthorised dealing
  • Access reviews
Where this commonly fails
  • Unauthorised access/dealing occurs
  • No preventive controls
MYHR-CUD-3
Use limited to My Health Record purposes

Do not use My Health Record information for prohibited purposes (e.g. employment, insurance underwriting); use is limited to permitted purposes (Part 4 Div 3, 3A).

Artefacts an auditor will ask for
  • Purpose controls preventing prohibited use
  • Staff guidance on prohibited purposes
Where this commonly fails
  • Information used for a prohibited purpose
  • No purpose limitation controls
MYHR-CUD-4
Records not held or taken outside Australia

Do not hold, take, process or handle records (or information from them) outside Australia except as permitted.

Artefacts an auditor will ask for
  • Evidence records are held only in Australia
  • Data location controls for any CSPs/cloud
Where this commonly fails
  • Records or backups held offshore
  • Processing occurs outside Australia
MYHR-CUD-5
Interaction with the Privacy Act 1988

Treat a contravention of the Act as an interference with privacy under the Privacy Act 1988 and comply with the combined regime (Part 4 Div 4).

Artefacts an auditor will ask for
  • Privacy handling aligned with the Privacy Act
  • Complaint/interference handling
Where this commonly fails
  • Privacy Act interaction ignored
  • No alignment with APP obligations
MYHR-CUD-6
Prohibition on use for a prohibited purpose

Do not use information included in a My Health Record, or information derived from it, for a prohibited purpose such as employment or insurance underwriting decisions.

Artefacts an auditor will ask for
  • Policy naming the prohibited purposes and the penalties
  • Access control design preventing employment or insurance functions reaching the data
  • Attestations from staff with access
  • Audit of access by role against legitimate healthcare purpose
Where this commonly fails
  • Policy covers privacy generally but never names prohibited purposes
  • Human resources or insurance related roles hold system access

Governance

MYHR-GOV-1
System Operator functions and oversight

Operate within, and support the oversight functions of, the System Operator who administers the My Health Record system (Part 2).

Artefacts an auditor will ask for
  • Alignment with System Operator requirements
  • Responses to System Operator directions
Where this commonly fails
  • Operating outside System Operator requirements
  • Directions not actioned
MYHR-GOV-2
Data Governance Board

Have regard to the Data Governance Board's role in governing secondary use and data governance of My Health Record data (Part 7).

Artefacts an auditor will ask for
  • Compliance with secondary-use data governance
  • Evidence of Data Governance Board framework awareness
Where this commonly fails
  • Secondary use without governance
  • No regard to the Data Governance Board framework
MYHR-GOV-3
Annual reporting on the My Health Record system

Annual reporting obligations of the Information Commissioner, the System Operator and the Data Governance Board.

Artefacts an auditor will ask for
  • Published annual reports for the relevant years
  • Evidence of the data compiled to support the reports
  • Records of matters escalated into the annual report
  • Board records approving its annual report
Where this commonly fails
  • Reporting data assembled at year end with no ongoing capture
  • Board annual report not separately evidenced
MYHR-GOV-4
Review of decisions

Decisions made under the Act are subject to review, and participants affected by a reviewable decision may seek review.

Artefacts an auditor will ask for
  • Register of reviewable decisions received
  • Evidence that notices of decision explained review rights
  • Records of any review sought and its outcome
  • Procedure for responding to an adverse decision within time
Where this commonly fails
  • Review rights and time limits not tracked
  • No owner for responding to a reviewable decision
MYHR-GOV-5
Retention, destruction and correction obligations of the System Operator

System Operator obligations to retain and destroy records uploaded to the National Repositories Service and to act on correction of information.

Artefacts an auditor will ask for
  • Retention and destruction schedule for the National Repositories Service
  • Evidence of destruction events and their authorisation
  • Correction request register and outcomes
  • Evidence of action taken following Information Commissioner findings
Where this commonly fails
  • Retention rules documented but destruction never evidenced
  • Corrections applied in one repository but not propagated
MYHR-GOV-6
The Register of participants

Maintenance of the Register and the entries that must be made in it.

Artefacts an auditor will ask for
  • Evidence the Register is maintained and current
  • Reconciliation of Register entries against registration decisions
  • Records of Register updates on cancellation, suspension or variation
  • Access and integrity controls over the Register
Where this commonly fails
  • Register updates lag registration decisions
  • No integrity control over Register amendments

Registration and Participation

MYHR-REG-1
Registration as a participant

Healthcare provider organisations, repository operators, portal operators and contracted service providers register with the System Operator and meet the conditions of registration (Part 3).

Artefacts an auditor will ask for
  • Registration with the System Operator
  • Evidence conditions of registration are met
  • Participation agreement
Where this commonly fails
  • Operating without valid registration
  • Conditions of registration not met
MYHR-REG-10
Notification when eligibility or registration conditions can no longer be met

Notify the System Operator where the participant ceases to be eligible for registration or a provider organisation ceases to be able to meet the conditions on its registration.

Artefacts an auditor will ask for
  • Procedure defining the triggers for notification and who owns it
  • Copies of notifications sent and their dates
  • Periodic self assessment against eligibility and conditions
  • Evidence of timeliness against the required period
Where this commonly fails
  • No periodic self assessment so a loss of eligibility goes unnoticed
  • Notification obligation not assigned to any role
MYHR-REG-11
Ensuring required information is given to the System Operator

Registered healthcare provider organisations must ensure that the required information about people accessing the system is given to the System Operator.

Artefacts an auditor will ask for
  • Process linking user provisioning to the information given to the System Operator
  • Records of information supplied and when
  • Reconciliation between local user lists and what was reported
  • Evidence of updates when users join or leave
Where this commonly fails
  • Information supplied at onboarding only and never updated
  • Local user list and reported list not reconciled
MYHR-REG-12
Cancellation, suspension and variation of registration

Understand and respond to cancellation, suspension or variation of registration, including any requirements that apply after registration is cancelled or suspended.

Artefacts an auditor will ask for
  • Procedure for responding to a notice of cancellation, suspension or variation
  • Evidence of compliance with post cancellation requirements
  • Continuity plan for clinical operations during suspension
  • Records of any past suspension and the actions taken
Where this commonly fails
  • No plan for operating during a suspension
  • Post cancellation data handling requirements not understood
MYHR-REG-2
Healthcare recipient registration and identity verification

Healthcare recipients are registered and their identity verified before access to their My Health Record is provided (Part 3 Div 1).

Artefacts an auditor will ask for
  • Identity verification process for recipients
  • Records of verification
Where this commonly fails
  • Access granted without identity verification
  • Weak identity proofing
MYHR-REG-3
Conditions of registration and participation

Registered participants comply with ongoing conditions of registration; registration may be cancelled, suspended or varied for non-compliance (Part 3 Div 4).

Artefacts an auditor will ask for
  • Evidence of ongoing compliance with conditions
  • Remediation of any conditions breaches
Where this commonly fails
  • Conditions breached
  • No monitoring of compliance with conditions
MYHR-REG-4
Contracted service provider oversight

Where a registered participant uses contracted service providers, it ensures they are registered/authorised and meet the system's obligations (Part 3 Div 3).

Artefacts an auditor will ask for
  • CSP registration/authorisation
  • Contractual obligations binding CSPs to the Act and Rule
  • Oversight of CSPs
Where this commonly fails
  • CSPs not bound to obligations
  • No oversight of contracted providers
MYHR-REG-5
Mandatory registration of prescribed healthcare provider organisations

Prescribed healthcare provider organisations must be registered in the My Health Record system.

Artefacts an auditor will ask for
  • Documented assessment of whether the organisation is a prescribed kind
  • Current registration certificate or record
  • Evidence registration was obtained before the required date
  • Governance record of accountability for maintaining registration
Where this commonly fails
  • No documented assessment of prescribed status
  • Registration lapsed and not noticed
MYHR-REG-6
Condition of registration relating to uploading records

Comply with the registration condition governing the uploading of records to the My Health Record system.

Artefacts an auditor will ask for
  • Upload procedures aligned to the registration condition
  • Audit of uploaded record types against what is permitted
  • Evidence of consent or authority where required before upload
  • Records of upload errors and corrections
Where this commonly fails
  • Uploading treated as a technical function with no compliance oversight
  • No audit of what has actually been uploaded
MYHR-REG-7
Copyright conditions on handling old records for provider organisations

Comply with the registration conditions governing the handling of old records, sound recordings and films that are subject to copyright.

Artefacts an auditor will ask for
  • Procedure for identifying old records subject to copyright before upload
  • Records of copyright assessments made
  • Training for staff who digitise or upload historical records
  • Incident records where a work was uploaded in breach and the response
Where this commonly fails
  • Bulk digitisation of historical files with no copyright screening
  • No awareness that liability attaches to breach uploads
MYHR-REG-8
Copyright conditions on handling old records for operators and service providers

Repository operators, portal operators and contracted service providers must comply with the registration conditions on handling old copyright records, recordings and films.

Artefacts an auditor will ask for
  • Contractual flow down of the copyright conditions to operators and service providers
  • Evidence of operator level screening procedures
  • Assurance reports or attestations from service providers
  • Incident records and responses
Where this commonly fails
  • Conditions not flowed down in the service contract
  • No assurance obtained over the operator's own screening
MYHR-REG-9
Non-discrimination in providing healthcare

Do not discriminate in providing healthcare to a healthcare recipient because the recipient does not have a My Health Record.

Artefacts an auditor will ask for
  • Policy prohibiting differential treatment based on My Health Record status
  • Staff training records covering the condition
  • Complaints records tested for discrimination themes
  • Evidence that access controls set by a recipient do not change service provision
Where this commonly fails
  • Policy silent on the condition
  • Staff unaware that restricted access must not change how care is delivered

Security and Access

MYHR-SEC-1
Written security and access policy

Maintain a written policy addressing how the organisation manages security and access to the My Health Record system, covering the matters required by the My Health Records Rule.

Artefacts an auditor will ask for
  • Documented security and access policy
  • Coverage of required Rule matters
  • Policy review records
Where this commonly fails
  • No written security and access policy
  • Policy missing required matters
MYHR-SEC-2
Access controls and user account management

Implement access controls so only authorised employees access the system, with user accounts created, suspended and deactivated appropriately.

Artefacts an auditor will ask for
  • User access provisioning/deprovisioning records
  • Role-based access to the system
  • Account suspension on role change/termination
Where this commonly fails
  • Shared or orphaned accounts
  • No timely deactivation of access
MYHR-SEC-3
Audit logging and access monitoring

Log and monitor access to and activity in the My Health Record system to detect and investigate unauthorised access.

Artefacts an auditor will ask for
  • Access/activity audit logs
  • Monitoring and review of logs
  • Investigation of anomalies
Where this commonly fails
  • No access logging
  • Logs not reviewed
  • Unauthorised access undetected
MYHR-SEC-4
Training of authorised employees

Train authorised employees on their obligations and the secure use of the My Health Record system before access and on an ongoing basis.

Artefacts an auditor will ask for
  • Training records before access is granted
  • Refresher training
  • Coverage of obligations under the Act and Rule
Where this commonly fails
  • Access before training
  • No ongoing training
MYHR-SEC-5
Security risk assessment

Identify and manage security risks to the My Health Record system through periodic risk assessment.

Artefacts an auditor will ask for
  • Security risk assessment of the system
  • Risk treatment/mitigation records
  • Periodic reassessment
Where this commonly fails
  • No risk assessment
  • Risks not treated or reviewed
MYHR-SEC-6
Emergency access controls

Control and record emergency ('break glass') access to a healthcare recipient's My Health Record, used only where permitted and subject to audit.

Artefacts an auditor will ask for
  • Emergency access procedure and authorisation
  • Logging and post-hoc review of emergency access
Where this commonly fails
  • Emergency access uncontrolled or unlogged
  • Routine use of emergency access
MYHR-SEC-7
Consumer access controls and consent

Respect healthcare recipients' access controls and consent settings, including restricting access to documents where the consumer has set controls.

Artefacts an auditor will ask for
  • Honouring consumer-set access controls
  • Consent settings applied to documents
Where this commonly fails
  • Consumer access controls bypassed
  • Documents accessed against consumer settings

Sharing by Default

MYHR-SBD-1
Share by default for prescribed key health information

Prescribed healthcare provider organisations must share prescribed health information with the My Health Record system unless an upload exception applies.

Artefacts an auditor will ask for
  • Register of information types the organisation is required to share
  • System configuration or integration evidence showing automatic upload
  • Upload success and failure logs with remediation records
  • Documented assessment of each upload exception relied on
  • Clinical governance sign off on sharing scope
Where this commonly fails
  • Organisation assumes it is not prescribed without documenting the assessment
  • Upload failures logged but never remediated
  • Exceptions applied as a blanket setting rather than per record
MYHR-SBD-2
Approved periods where sharing or registration is not required

Where the System Operator approves a period during which sharing with the system or registration is not required, the organisation must operate within the terms of that approval.

Artefacts an auditor will ask for
  • Copy of the System Operator approval and its expiry date
  • Evidence of the application and the grounds relied on
  • Diary or control ensuring behaviour reverts when the approval lapses
  • Records showing conduct during the approved period matched the approval
Where this commonly fails
  • Approval expired but non sharing continued
  • No internal owner tracking the approval expiry
MYHR-SBD-3
Record keeping for sharing with the My Health Record system

Keep the records required in relation to sharing information with the My Health Record system, including where an exception was relied on.

Artefacts an auditor will ask for
  • Retained records of information shared and dates
  • Records of each occasion an exception was relied on and the reason
  • Retention schedule covering these records
  • Evidence records can be produced to the regulator on request
Where this commonly fails
  • Upload logs held only in a vendor system with no retention guarantee
  • Exception reasons not recorded at the time
MYHR-SBD-4
Notice where information is not being shared

Prescribed healthcare provider organisations must display the required notice when they are not sharing information with the My Health Record system.

Artefacts an auditor will ask for
  • Photographs or copies of the displayed notice and its locations
  • Procedure triggering display when sharing stops
  • Dated records of when the notice went up and came down
  • Staff awareness records
Where this commonly fails
  • Sharing suspended without the notice being displayed
  • Notice displayed in a back office rather than where individuals can see it
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia My Health Records Act 2012 framework page.