The Office of the Australian Information Commissioner (OAIC), in collaboration with the Australian Digital Health Agency (the Agency), has developed an updated My Health Record Security and Access Policy Template to help healthcare provider organisations meet their obligations under the new My Health Records Rules 2026 (the Rules).
From 1 October 2026, all healthcare provider organisations registered with My Health Record must comply with the security and access policy requirements set out in rules 21 and 43 of the Rules. These requirements replace security and access policy requirements previously set out in rule 42 of the My Health Records Rule 2016.
The updated template and supporting guidance material are designed to help organisations:
- understand the updated security and access policy requirements
- review and update existing security and access policies
- meet their ongoing My Health Record participation obligations.
To support implementation, the Agency has also developed a fact sheet outlining the key changes organisations should consider when reviewing their existing security and access policies. The fact sheet provides a practical summary of the updates required to align with the 2026 Rules.
Click on the button below for further information on updated My Health Record participation obligations available on the Australian Digital Health Agency website.