Australia My Health Records Act 2012
Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Breach and Enforcement
Notify the System Operator and the OAIC (and affected individuals where required) of unauthorised access to, or loss of, information in the My Health Record system, as soon as practicable.
- Data breach response procedure
- Records of notifications to System Operator/OAIC
- Notification to affected individuals where required
- Breaches not notified
- Notification delayed beyond as-soon-as-practicable
- No breach response procedure
Comply with the civil penalty provisions of the Act and the My Health Records Rules (Part 6 Div 1).
- Compliance monitoring against civil penalty provisions
- Remediation of identified contraventions
- Repeated contraventions
- No monitoring of civil penalty obligations
Prevent conduct constituting criminal offences under the Act (e.g. unauthorised use/disclosure) and apply sanctions for breaches by personnel (Part 5).
- Sanction/disciplinary policy for breaches
- Controls preventing offence conduct
- No sanction policy
- Offence conduct not prevented or addressed
Cooperate with regulator enforcement mechanisms including enforceable undertakings and injunctions (Part 6 Div 2-3).
- Records of any enforceable undertakings and compliance
- Response to regulator action
- Non-compliance with undertakings
- No process to respond to enforcement
Infringement notices may be issued for contraventions of specified provisions, and the recipient must understand the response options and time limits.
- Procedure for receiving and escalating an infringement notice
- Register of any notices received and how they were handled
- Evidence of legal review within the response period
- Root cause analysis following a notice
- No owner for regulator correspondence so notices sit unactioned
- Penalty paid with no root cause analysis
Collection, Use and Disclosure
Collect, use and disclose health information in a My Health Record only as authorised by the Act (Part 4 Div 2).
- Authorisation basis recorded for use/disclosure
- Access tied to provision of healthcare
- Use/disclosure without authorisation
- Access not tied to a permitted purpose
Do not collect, use or disclose health information except as authorised; unauthorised dealing is an offence (Part 4 Div 1).
- Controls preventing unauthorised dealing
- Access reviews
- Unauthorised access/dealing occurs
- No preventive controls
Do not use My Health Record information for prohibited purposes (e.g. employment, insurance underwriting); use is limited to permitted purposes (Part 4 Div 3, 3A).
- Purpose controls preventing prohibited use
- Staff guidance on prohibited purposes
- Information used for a prohibited purpose
- No purpose limitation controls
Do not hold, take, process or handle records (or information from them) outside Australia except as permitted.
- Evidence records are held only in Australia
- Data location controls for any CSPs/cloud
- Records or backups held offshore
- Processing occurs outside Australia
Treat a contravention of the Act as an interference with privacy under the Privacy Act 1988 and comply with the combined regime (Part 4 Div 4).
- Privacy handling aligned with the Privacy Act
- Complaint/interference handling
- Privacy Act interaction ignored
- No alignment with APP obligations
Do not use information included in a My Health Record, or information derived from it, for a prohibited purpose such as employment or insurance underwriting decisions.
- Policy naming the prohibited purposes and the penalties
- Access control design preventing employment or insurance functions reaching the data
- Attestations from staff with access
- Audit of access by role against legitimate healthcare purpose
- Policy covers privacy generally but never names prohibited purposes
- Human resources or insurance related roles hold system access
Governance
Operate within, and support the oversight functions of, the System Operator who administers the My Health Record system (Part 2).
- Alignment with System Operator requirements
- Responses to System Operator directions
- Operating outside System Operator requirements
- Directions not actioned
Have regard to the Data Governance Board's role in governing secondary use and data governance of My Health Record data (Part 7).
- Compliance with secondary-use data governance
- Evidence of Data Governance Board framework awareness
- Secondary use without governance
- No regard to the Data Governance Board framework
Annual reporting obligations of the Information Commissioner, the System Operator and the Data Governance Board.
- Published annual reports for the relevant years
- Evidence of the data compiled to support the reports
- Records of matters escalated into the annual report
- Board records approving its annual report
- Reporting data assembled at year end with no ongoing capture
- Board annual report not separately evidenced
Decisions made under the Act are subject to review, and participants affected by a reviewable decision may seek review.
- Register of reviewable decisions received
- Evidence that notices of decision explained review rights
- Records of any review sought and its outcome
- Procedure for responding to an adverse decision within time
- Review rights and time limits not tracked
- No owner for responding to a reviewable decision
System Operator obligations to retain and destroy records uploaded to the National Repositories Service and to act on correction of information.
- Retention and destruction schedule for the National Repositories Service
- Evidence of destruction events and their authorisation
- Correction request register and outcomes
- Evidence of action taken following Information Commissioner findings
- Retention rules documented but destruction never evidenced
- Corrections applied in one repository but not propagated
Maintenance of the Register and the entries that must be made in it.
- Evidence the Register is maintained and current
- Reconciliation of Register entries against registration decisions
- Records of Register updates on cancellation, suspension or variation
- Access and integrity controls over the Register
- Register updates lag registration decisions
- No integrity control over Register amendments
Registration and Participation
Healthcare provider organisations, repository operators, portal operators and contracted service providers register with the System Operator and meet the conditions of registration (Part 3).
- Registration with the System Operator
- Evidence conditions of registration are met
- Participation agreement
- Operating without valid registration
- Conditions of registration not met
Notify the System Operator where the participant ceases to be eligible for registration or a provider organisation ceases to be able to meet the conditions on its registration.
- Procedure defining the triggers for notification and who owns it
- Copies of notifications sent and their dates
- Periodic self assessment against eligibility and conditions
- Evidence of timeliness against the required period
- No periodic self assessment so a loss of eligibility goes unnoticed
- Notification obligation not assigned to any role
Registered healthcare provider organisations must ensure that the required information about people accessing the system is given to the System Operator.
- Process linking user provisioning to the information given to the System Operator
- Records of information supplied and when
- Reconciliation between local user lists and what was reported
- Evidence of updates when users join or leave
- Information supplied at onboarding only and never updated
- Local user list and reported list not reconciled
Understand and respond to cancellation, suspension or variation of registration, including any requirements that apply after registration is cancelled or suspended.
- Procedure for responding to a notice of cancellation, suspension or variation
- Evidence of compliance with post cancellation requirements
- Continuity plan for clinical operations during suspension
- Records of any past suspension and the actions taken
- No plan for operating during a suspension
- Post cancellation data handling requirements not understood
Healthcare recipients are registered and their identity verified before access to their My Health Record is provided (Part 3 Div 1).
- Identity verification process for recipients
- Records of verification
- Access granted without identity verification
- Weak identity proofing
Registered participants comply with ongoing conditions of registration; registration may be cancelled, suspended or varied for non-compliance (Part 3 Div 4).
- Evidence of ongoing compliance with conditions
- Remediation of any conditions breaches
- Conditions breached
- No monitoring of compliance with conditions
Where a registered participant uses contracted service providers, it ensures they are registered/authorised and meet the system's obligations (Part 3 Div 3).
- CSP registration/authorisation
- Contractual obligations binding CSPs to the Act and Rule
- Oversight of CSPs
- CSPs not bound to obligations
- No oversight of contracted providers
Prescribed healthcare provider organisations must be registered in the My Health Record system.
- Documented assessment of whether the organisation is a prescribed kind
- Current registration certificate or record
- Evidence registration was obtained before the required date
- Governance record of accountability for maintaining registration
- No documented assessment of prescribed status
- Registration lapsed and not noticed
Comply with the registration condition governing the uploading of records to the My Health Record system.
- Upload procedures aligned to the registration condition
- Audit of uploaded record types against what is permitted
- Evidence of consent or authority where required before upload
- Records of upload errors and corrections
- Uploading treated as a technical function with no compliance oversight
- No audit of what has actually been uploaded
Comply with the registration conditions governing the handling of old records, sound recordings and films that are subject to copyright.
- Procedure for identifying old records subject to copyright before upload
- Records of copyright assessments made
- Training for staff who digitise or upload historical records
- Incident records where a work was uploaded in breach and the response
- Bulk digitisation of historical files with no copyright screening
- No awareness that liability attaches to breach uploads
Repository operators, portal operators and contracted service providers must comply with the registration conditions on handling old copyright records, recordings and films.
- Contractual flow down of the copyright conditions to operators and service providers
- Evidence of operator level screening procedures
- Assurance reports or attestations from service providers
- Incident records and responses
- Conditions not flowed down in the service contract
- No assurance obtained over the operator's own screening
Do not discriminate in providing healthcare to a healthcare recipient because the recipient does not have a My Health Record.
- Policy prohibiting differential treatment based on My Health Record status
- Staff training records covering the condition
- Complaints records tested for discrimination themes
- Evidence that access controls set by a recipient do not change service provision
- Policy silent on the condition
- Staff unaware that restricted access must not change how care is delivered
Security and Access
Maintain a written policy addressing how the organisation manages security and access to the My Health Record system, covering the matters required by the My Health Records Rule.
- Documented security and access policy
- Coverage of required Rule matters
- Policy review records
- No written security and access policy
- Policy missing required matters
Implement access controls so only authorised employees access the system, with user accounts created, suspended and deactivated appropriately.
- User access provisioning/deprovisioning records
- Role-based access to the system
- Account suspension on role change/termination
- Shared or orphaned accounts
- No timely deactivation of access
Log and monitor access to and activity in the My Health Record system to detect and investigate unauthorised access.
- Access/activity audit logs
- Monitoring and review of logs
- Investigation of anomalies
- No access logging
- Logs not reviewed
- Unauthorised access undetected
Train authorised employees on their obligations and the secure use of the My Health Record system before access and on an ongoing basis.
- Training records before access is granted
- Refresher training
- Coverage of obligations under the Act and Rule
- Access before training
- No ongoing training
Identify and manage security risks to the My Health Record system through periodic risk assessment.
- Security risk assessment of the system
- Risk treatment/mitigation records
- Periodic reassessment
- No risk assessment
- Risks not treated or reviewed
Control and record emergency ('break glass') access to a healthcare recipient's My Health Record, used only where permitted and subject to audit.
- Emergency access procedure and authorisation
- Logging and post-hoc review of emergency access
- Emergency access uncontrolled or unlogged
- Routine use of emergency access
Respect healthcare recipients' access controls and consent settings, including restricting access to documents where the consumer has set controls.
- Honouring consumer-set access controls
- Consent settings applied to documents
- Consumer access controls bypassed
- Documents accessed against consumer settings
Sharing by Default
Prescribed healthcare provider organisations must share prescribed health information with the My Health Record system unless an upload exception applies.
- Register of information types the organisation is required to share
- System configuration or integration evidence showing automatic upload
- Upload success and failure logs with remediation records
- Documented assessment of each upload exception relied on
- Clinical governance sign off on sharing scope
- Organisation assumes it is not prescribed without documenting the assessment
- Upload failures logged but never remediated
- Exceptions applied as a blanket setting rather than per record
Where the System Operator approves a period during which sharing with the system or registration is not required, the organisation must operate within the terms of that approval.
- Copy of the System Operator approval and its expiry date
- Evidence of the application and the grounds relied on
- Diary or control ensuring behaviour reverts when the approval lapses
- Records showing conduct during the approved period matched the approval
- Approval expired but non sharing continued
- No internal owner tracking the approval expiry
Keep the records required in relation to sharing information with the My Health Record system, including where an exception was relied on.
- Retained records of information shared and dates
- Records of each occasion an exception was relied on and the reason
- Retention schedule covering these records
- Evidence records can be produced to the regulator on request
- Upload logs held only in a vendor system with no retention guarantee
- Exception reasons not recorded at the time
Prescribed healthcare provider organisations must display the required notice when they are not sharing information with the My Health Record system.
- Photographs or copies of the displayed notice and its locations
- Procedure triggering display when sharing stops
- Dated records of when the notice went up and came down
- Staff awareness records
- Sharing suspended without the notice being displayed
- Notice displayed in a back office rather than where individuals can see it
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia My Health Records Act 2012 framework page.