Here is the honest situation. Healthcare provider organisations that connect to the My Health Record system carry real legal obligations under the My Health Records Act: a mandatory written security and access policy, use of the record only for authorised healthcare purposes, respect for the consumer's access controls and a ban on using the information for insurance or employment, a specific data breach notification scheme to both the System Operator and the OAIC, and correct use of healthcare identifiers. Penalties are civil and criminal. Building all of that and evidencing it is weeks of work, and a missing security policy or a mishandled breach is exactly where participants fall short.
This Kit removes the guesswork. It is every My Health Records obligation written as an adopt-ready control you personalize in a weekend, with the evidence a regulator examines.
What you get, the moment you buy
Grounded in the Australia My Health Records Act 2012 and its Rule, with the mandatory security and access policy, authorised use, the consumer controls and the specific data breach notification scheme called out. Editable Word and Excel files.
What one control looks like
This is the mandatory written security and access policy, the document every participant must hold. All 30 are built to this depth.
Why this is not another template pack
- The evidence is the point. An obligation you cannot evidence is a breach of the Act. This tells you what a regulator examines and where participants fall short, for every obligation.
- The security policy and breach scheme built in. The mandatory security and access policy and the My Health Record specific data breach scheme, notifying both the System Operator and the OAIC, are written into the controls.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The Act works alongside the Privacy Act and the Healthcare Identifiers scheme, so this feeds your wider health-information compliance.
Who buys this
Healthcare provider organisations and the service providers connecting to the My Health Record system, and the privacy, security and clinical governance leads who own it. Whether it is first participation or a compliance review, you save weeks and walk in with the policy, controls and evidence ready.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this legal advice? No. It is an implementation toolkit grounded in the Act and Rule. For a specific matter consult counsel; this gets your policy, controls and records in order fast.
Does it cover the security and access policy? Yes. Each mandatory policy area, authentication, access, training, physical and technical security, mobile devices and breach management, is built as a control.
Does it cover the data breach scheme? Yes. The My Health Record specific scheme, notifying the System Operator and the OAIC, is its own control group, distinct from the general breach scheme.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com