Under the My Health Records Rules 2026, every registered practice must hold, enforce and annually review a written security and access policy — and produce it within 7 days if the System Operator or OAIC asks.
Not just the document. Evidence that your practice actually follows it.
Access records. Patch status. Staff acknowledgments. Incident logs. If those don't exist, a policy template is worse than useless — it creates a paper trail showing you knew the obligation and ignored it.
What the 7-day rule actually requires
The My Health Records Rules 2026 came into effect on 1 July 2026. They formalise obligations that have existed informally under the original My Health Records Act, but with clearer audit teeth.
A compliant practice must be able to produce:
- A written security and access policy that covers who can access My Health Record data, under what conditions, and how access is logged
- Evidence that staff have been trained on and acknowledged the policy — typically signed acknowledgments, at minimum annual
- Access logs showing who accessed the system and when
- A record of any security incidents, even minor ones, and what was done in response
- Documentation of your patch and update status for systems that connect to the My Health Record system
The 7-day window is not generous. If you receive a request on a Monday, you need everything on the table by the following Monday. For a practice that hasn't actively maintained this documentation, that is not enough time to reconstruct it.
The compliance gap most practices don't know they have
Having a policy is not the same as complying with the policy.
Most practices that have addressed this at all have a policy document — often a template from the RACGP or a software vendor. That document typically says things like "staff will complete annual information security training" and "access logs will be reviewed quarterly."
The question is: can you prove it happened?
If an OAIC auditor asks for your last three quarterly access log reviews, what do you show them? If they ask for the date your last staff information security training was completed and who attended, where is that record?
This is the gap. The policy says the right things. The evidence trail doesn't exist.
What else changed on 1 July 2026
The MHR Rules changes weren't the only compliance shift that took effect this year.
Medicare assignment of benefit rules now require completed agreements to be kept for two years and produced on audit. If you use bulk billing or assignment of benefit arrangements, the paperwork supporting each claim must be retained and retrievable.
Privacy Act amendments have made penalties non-theoretical. A $5.8 million penalty has already been issued to an Australian healthcare organisation. Maximum penalties now sit at $50 million or 30% of annual turnover — whichever is greater. For a practice with $2 million in annual revenue, 30% of turnover is $600,000. For larger group practices, the maths gets worse quickly.
These aren't hypothetical risks. Regulators are actively enforcing.
What an audit request actually looks like
The OAIC doesn't always announce itself with a formal audit notice. Complaints from patients trigger investigations. A notifiable data breach triggers review. A Medicare audit can expand scope into privacy obligations.
When a request does arrive, the practice receives written notification requiring production of specified records within a set timeframe. 7 days is the baseline under the MHR Rules. Medicare audit requests typically allow 28 days but can request production within 7 for urgent matters.
The practices that respond well are not the ones with the best security. They're the ones with the best documentation.
The four things you need to have ready
1. A current, signed policy
Not a template. A document that reflects your actual practice — your systems, your staff, your access controls. Reviewed and signed off in the last 12 months.
2. Staff training records
A log of who completed information security training, when, and what it covered. For practices with high staff turnover, this needs to be part of the onboarding process, not an annual event you might get to.
3. Access logs
My Health Record access logs are available from the ADHA provider portal. You don't need to export them daily, but you need a documented process for reviewing them and a record that those reviews happened.
4. An incident register
Even if you've never had a serious incident, a register with zero entries and a note saying "reviewed quarterly, no incidents to record" is better than no register at all. It demonstrates the process is running.
Where to start
If you're not sure whether your practice can pass a 7-day audit request, the honest answer is to find out now rather than when the clock is running.
A compliance gap assessment will tell you exactly what documentation you have, what's missing, and what would need to be built before an audit request becomes a problem. For most practices, getting to a documentable baseline takes four to eight hours of structured work — not weeks.
That investment is considerably smaller than the alternative.
Not sure where your practice stands?
A Compliance Gap Assessment covers backup and DR posture, access controls, and compliance documentation — a written report with a prioritised roadmap.