Post-1 July 2026
Compliance Checklist
Thirteen items across four domains. If your practice cannot tick every box — with documentary evidence — you are exposed to regulatory action under the My Health Records Rules 2026, the Privacy Act, and Medicare AoB rules that came into force on 1 July 2026.
Security and access policy
My Health Records Rules 2026, Rule 21
Access controls and audit logs
Privacy Act 1988 (Cth) — APP 11; MHR Rules 2026
Backup, recovery and incident response
RACGP Standards 5th Edition; Privacy Act — NDB Scheme
Medicare assignment of benefit
Medicare Assignment of Benefit Rules 2026 (in force 1 July 2026)
How did your practice score?
13 of 13 — with evidence: You are in good shape. A Compliance Gap Assessment will confirm you can produce the evidence under pressure, not just tick the boxes from memory.
10–12: Partial compliance. You likely have the intention but gaps in documentation. Those gaps are exactly what an auditor or accreditation surveyor will find.
Under 10: Material exposure. The Privacy Act civil penalty for a serious breach is up to $50 million or 30% of adjusted turnover. A $5.8 million penalty has already been issued to a healthcare organisation in Australia.
Not confident you could produce the evidence?
A Compliance Gap Assessment gives you a written report of exactly what is missing and a prioritised roadmap to fix it — before an auditor asks.
Fixed-fee. Written report. Fee credited in full if you engage within 60 days.
This checklist is provided for general awareness only and does not constitute legal advice. Regulatory requirements may change — verify current obligations with your legal adviser or the relevant authority. ClinicGuard IT is an independent managed IT provider.