29 September 2026

From 1 October 2026, all healthcare provider organisations registered with My Health Record must ensure their My Health Record security and access policy complies with the My Health Record Rules 2026.

This includes organisations who had previously developed a policy under the My Health Records Rule 2016.

While the core requirements remain largely consistent, several key changes have been introduced. This includes changes to requirements concerning user account management, training and security measures, and a new requirement to include processes for responding to My Health Record data breaches.

In addition to the policy itself, organisations must keep records showing how the policy has been applied.

All organisations which use My Health Record should review their security and access policy now, ensuring it complies with the requirements of the 2026 Rules.

  • Organisations registered with the My Health Record system before 1 April 2026, must update their security and access policy by 1 October 2026, in line with the 2026 Rules.
  • Organisations registering for My Health Record from 1 April 2026, must develop a security and access policy in accordance with the 2026 Rules.

The updates follow recent legislative changes aimed at ensuring the system continues to support safe, secure and effective healthcare delivery.

Resources and support:

If you need support, contact our Digital Health team at DigitalHealth@swsphn.com.au

 


This article appeared in Practice Pulse on Wednesday, 30 September 2026. If you are a GP, practice nurse or practice manager in South Western Sydney and do not get the weekly Practice Pulse email, speak to your Practice Support Officer.