Skip to main
Help and resources
Register
for My Account
Sign in
to My Account
Search
Australian Government
Federal Register of Legislation
Site navigation
Constitution
Acts
Legislative instruments
Notifiable instruments
Gazettes
Administrative Arrangements
Prerogative instruments
Norfolk Island
Home
Legislative instruments
In force
Text
Details
Authorises
Downloads
All versions
Interactions
My Health Records Rules 2026
In force
Administered by
Department of Health, Disability and Ageing
This item is authorised by the following title:
My Health Records Act 2012
Latest version
Order print copy
Save this title to My Account
Set up an alert
F2026L00392
31 March 2026
Legislation text
View document
Select value
Legislative instrument
Explanatory statement
Filter active
Table of contents
Enter text to search the table of contents
Collapse
Part 1—Preliminary
1 Name
2 Commencement
3 Authority
4 Schedules
5 Definitions
6 Definition of authorised representative of a healthcare recipient—persons to which healthcare identifier not required to have been assigned
7 Definition of nominated representative of a healthcare recipient—persons to which healthcare identifier not required to have been assigned
Collapse
Part 2—The System Operator and the functions of the Chief Executive Medicare
Collapse
Division 1—Functions of the System Operator—requirements for access control mechanisms
8 Access controls set by registered healthcare recipients for access by healthcare provider organisations and nominated representatives
9 Default access controls
10 Circumstances for automatic suspension of access to a healthcare recipient’s My Health Record
11 Circumstances for automatic cancellation of access to a healthcare recipient’s My Health Record
Collapse
Division 2—Functions of the System Operator—other functions conferred by this instrument
12 Purpose of this Division
13 Deleting information or a record in the My Health Record system in certain circumstances
14 Suspending access to the My Health Record system if security, integrity or operations are or may be compromised
15 Providing a mechanism to access My Health Record system
Collapse
Part 3—Registration
Collapse
Division 1—Registering healthcare recipients
16 Matters System Operator to have regard to
Collapse
Division 2—Registering healthcare provider organisations
Collapse
Subdivision A—When organisations are eligible for registration—requirements organisations must comply with
17 Purpose of this Subdivision
18 Organisation officers must have authority to act on behalf of organisation
19 Organisation must give System Operator and service operator certain information
20 Organisations that are network organisations—seed organisation for network must be a registered healthcare provider organisation
21 Organisation must have security and access policy
22 Organisation must give System Operator security and access policy on request
Collapse
Subdivision B—Condition of registration—uploading of records, etc
23 Kinds of records
24 Prescribed circumstances
Collapse
Division 3—Registering repository operators and portal operators
25 Purpose of this Division
26 Person must have an operator officer
27 Person must have security and access policy
28 Person must give security and access policy to System Operator with application for registration
29 Person must have technical and after-hours contacts
Collapse
Division 4—Registering contracted service providers
30 Purpose of this Division
31 Person must have a contracted service provider officer
32 Person must have security and access policy
33 Person must give security and access policy to System Operator with application for registration
Collapse
Division 5—Cancellation, suspension and variation of registration
34 Requirements after registration is cancelled or suspended—retention, transfer or disposal of records
Collapse
Part 4—Other matters—conditions on the registration of participants in the My Health Record system
Collapse
Division 1—Preliminary
35 Purpose of this Part
Collapse
Division 2—Registered healthcare provider organisations
36 Complying with directions to delete information or a record
37 Uploading records
38 Notifying System Operator of certain matters
39 Compliance with interoperability requirements
40 Providing assistance to the System Operator on request
41 Uploading advance care planning information
42 Organisations that are network organisations—seed organisation for network must be a registered healthcare provider organisation
43 Security and access policy—general
44 Security and access policy—giving to System Operator on request
45 Security and access policy—application record-keeping
46 Security and access policy—giving application records to System Operator on request
Collapse
Division 3—Registered repository operators and portal operators
47 Application
48 Complying with directions to delete information or a record
49 Ensuring operator officer carries out duties
50 Notifying System Operator of certain matters
51 Compliance with interoperability requirements
52 Providing assistance to the System Operator on request
53 Security and access policy—general
54 Security and access policy—giving to System Operator on request
55 Security and access policy—application record-keeping
56 Security and access policy—giving application records to System Operator on request
Collapse
Division 4—Registered contracted service providers
57 Application
58 Complying with directions to delete information or a record
59 Ensuring contracted service provider officer carries out duties
60 Notifying System Operator of certain matters
61 Compliance with interoperability requirements
62 Providing assistance to the System Operator on request
63 Security and access policy—general
64 Security and access policy—giving to System Operator on request
65 Security and access policy—application record-keeping
66 Security and access policy—giving application records to System Operator on request
67 Accessing the My Health Record system or using health information included in a healthcare recipient’s My Health Record
Collapse
Part 5—Other requirements relating to the My Health Record system
68 Purpose of this Part
69 Requirements for System Operator—system availability
Collapse
Part 6—Other matters—authorised representatives and nominated representatives
70 Requirement for System Operator—identity verification for healthcare recipients on ceasing to have an authorised representative
Collapse
Part 7—Opt-out model for the participation of healthcare recipients in the My Health Record system
71 Opt-out model applies to all healthcare recipients in Australia
Collapse
Part 8—Application, transitional and saving provisions
Collapse
Division 1—Provisions for this instrument as originally made
Collapse
72 Security and access policy requirements for certain registered entities existing immediately before 1 April 2026
Collapse
Schedule 1—Repeals of instruments
My Health Records (Assisted Registration) Rule 2015
My Health Records (National Application) Rules 2017
My Health Records (Opt-out Trials) Rule 2016
My Health Records Rule 2016