Your Practice Connects to My Health Record — What Changes on 1 October 2026?
Last updated 18 September 2026 · 6 min read
Direct Answer
From 1 October 2026, every organisation registered with My Health Record must have a security and access policy meeting the My Health Records Rules 2026, regardless of size. The previous limited-size exemption has been removed. An existing practice should check more than breach response and account access: its policy must also cover authorised-user training before access, annually and after significant changes; identifying who accessed a record; physical, information and cyber security measures; system-related risks; and review at least annually, when material risks change or when the System Operator requests it. Keep the required supporting records and check the Agency's current policy guidance.
Detailed Explanation
My Health Record has, since it began, applied different security-policy expectations to different sizes of participating organisation — a large hospital network and a two-GP practice weren't held to an identical standard, on the reasoning that a much smaller organisation posed a smaller risk surface and had fewer resources to meet a heavier compliance burden. The My Health Records Rules 2026 changes that. From 1 October 2026, the "limited size" exemption is gone, and every registered participant — regardless of how small — must have a security and access policy meeting the same baseline.
The rules themselves commenced 1 April 2026, but they included a six-month grandfathering period for entities already registered before that date, which is why the practical deadline that actually affects an established small practice is 1 October 2026, not the earlier commencement date. A practice that registered after 1 April 2026 has already been expected to meet the new, single standard from day one; the grace period exists specifically for practices that registered under the old, size-tiered rules and now need to catch up.
What the Updated Security and Access Policy Must Cover
The Agency's Rule 21 guidance lists several required topics. For a practice that relied on the old limited-size exemption, check the complete policy against that guidance, including:
- Responding to a My Health Record data breach. A general cyber-incident response plan that doesn't specifically address what happens when the breach involves My Health Record data isn't sufficient on its own — the policy needs to name the specific reporting and containment steps for this system.
- User account management and training. Record how access is granted, suspended and revoked, including when staff leave. Authorised users need training before access, annually and after significant system or legislative changes. Keep training records for five years. See our IT person built all our automations and then left, what do we do now for the broader access-control problem.
- Access identification and security controls. Explain how the practice identifies each person who accessed a record, and document its physical, information, cyber and technical measures and responses to system-related security risks.
- Review and evidence. Review the policy at least annually, when material risks change and when requested by the System Operator. Keep the supporting access and policy records for the periods specified in the Agency's current guidance.
For a practice that previously relied on the lighter, size-based standard, this typically means writing or substantially expanding a policy document that didn't need to exist in this form before — not just updating a header date on an existing one.
A Related but Separate Change: Sharing by Default
Since 1 July 2026, a separate change has required in-scope pathology and diagnostic imaging reports to be uploaded to My Health Record within 24 hours after they are provided to the requesting or treating provider or patient, unless an exception or extension applies. The rule concerns reports, not the underlying images, and does not require GPs to upload consultation notes.
This is worth knowing about alongside the security-policy deadline because both changes affect the same system in the same year, but they're not the same requirement — sharing by default changes what data flows into My Health Record and when; the 1 October 2026 deadline changes the security standard every participant must meet regardless of what's being shared. A practice can be fully compliant with one and still behind on the other.
What This Means in Practice
- Confirm whether your practice was registered before or after 1 April 2026. If before, the six-month grace period is the deadline that applies to you, and it ends 1 October 2026.
- Check the policy against the Agency's full Rule 21 guidance, including breach response, accounts, recurring training, access identification, technical security, system risks and review.
- Write or update the policy now, not close to the deadline. A policy drafted under time pressure in the final week is more likely to miss the specific requirements than one given proper attention.
- Confirm who inside the practice actually owns this document going forward. A policy is only useful if someone is responsible for keeping it current as the practice's staff, systems, and access arrangements change.
Things to Consider
- This sits alongside, not instead of, the practice's other data-handling policies. A My Health Record security and access policy is a specific, named requirement — it doesn't replace a broader employee AI usage policy or general data-security practice, it adds a system-specific obligation on top of them.
- The exemption removal affects paperwork and process, not necessarily technology. Meeting the new standard is mostly about having a properly scoped written policy and following it, not about buying new security software — though it may reveal gaps in access controls worth fixing regardless of the deadline.
- This is a live compliance area with more change likely. The online-prescribing sharing extension flagged for 2027 and the broader direction of the My Health Record system suggest more changes are coming; treat this page, and your own policy, as something to revisit rather than a one-time fix.
- A practice already handling other clinical AI tools should look at this alongside those decisions. See can a practice use an AI scribe without patient audio leaving Australia for a related but distinct data-handling question many practices are working through at the same time.
Common Mistakes
- Assuming a small practice is still exempt because it always has been. The size-based exemption that a practice may have relied on for years is specifically what this change removes — past exemption status doesn't carry forward.
- Treating a general IT policy, or a two-item checklist, as sufficient. Compare the My Health Record policy against every required Rule 21 topic and the Agency's current guidance.
- Confusing this deadline with the 1 July 2026 sharing-by-default change. They're related but distinct — meeting one doesn't automatically mean the other is covered.
- Leaving the policy update until close to 1 October 2026. A rushed policy written under deadline pressure is more likely to miss the specific new requirements than one drafted with proper attention several weeks out.
- Not assigning clear ownership of the policy going forward. A document written once to meet a deadline and then never revisited stops reflecting how the practice actually operates within a year or two.
Frequently Asked Questions
- Does this apply to every kind of practice registered to My Health Record, or just GPs?
- It applies to every registered participant regardless of practice type or size — general practice, allied health, pharmacy, and specialist practices are all covered, because the change specifically removes the exemption that let smaller organisations meet a lighter standard. If your practice connects to My Health Record at all, this applies to you.
- What actually needs to be in the updated security and access policy?
- The Agency lists required topics under Rule 21, including user authorisation and deactivation, training before access and at least annually, identifying individual users, breach response, physical and cyber security measures, system-related risks, and policy review. It also describes record-keeping and requests from the System Operator. Use the Agency's current checklist or template rather than treating breach response and access management as the complete list.
- Is this connected to the 1 July 2026 'sharing by default' change for pathology and imaging results?
- They are separate changes. From 1 July 2026, in-scope pathology and diagnostic imaging reports must generally be uploaded within 24 hours after they are provided to the requesting or treating provider or patient, unless an exception or extension applies. The 1 October deadline concerns the security and access policy for My Health Record participants. The report upload rule does not itself require uploading the underlying images or GP consultation notes.
References
Related Questions
Can a Practice Use an AI Scribe Without Patient Audio Leaving Australia?
A practice can use an AI scribe with Australian-only audio processing, but must verify the vendor, plan and underlying model. Check the clinical guidance.
How Do Healthcare Practices Automate Patient Scheduling and Intake?
Healthcare practices cut admin time with online booking, automated appointment reminders, digital intake forms, and insurance verification checks.
Does It Matter Which Country an AI Tool Stores Your Data In (Data Residency)?
Where an AI vendor stores your data matters most under APP 8's overseas disclosure rules, for regulated industries and government contracts, less so elsewhere.
Is It Safe to Put Company Data into AI Tools?
It depends on the data, the plan, and the vendor's terms. Business/enterprise AI plans typically differ from free consumer tiers — here's how to check safely.
How Do Allied Health Practices Automate Bookings, Reminders and Medicare Claiming?
Allied health clinics automate booking, recall, and Medicare/DVA claiming through practice-management platforms like Cliniko, Halaxy, and Zanda Health.
Can Microsoft Purview Actually Stop Staff Pasting Client Data Into ChatGPT?
Microsoft Purview can block prompts pasted into ChatGPT, but real-time blocking only works fully in Edge, on managed devices, with the right licence.