Free resource

Post-1 July 2026
Compliance Checklist

Thirteen items across four domains. If your practice cannot tick every box — with documentary evidence — you are exposed to regulatory action under the My Health Records Rules 2026, the Privacy Act, and Medicare AoB rules that came into force on 1 July 2026.

These obligations are currently live — not future requirements.

Security and access policy

My Health Records Rules 2026, Rule 21

Access controls and audit logs

Privacy Act 1988 (Cth) — APP 11; MHR Rules 2026

Backup, recovery and incident response

RACGP Standards 5th Edition; Privacy Act — NDB Scheme

Medicare assignment of benefit

Medicare Assignment of Benefit Rules 2026 (in force 1 July 2026)

How did your practice score?

13 of 13 — with evidence: You are in good shape. A Compliance Gap Assessment will confirm you can produce the evidence under pressure, not just tick the boxes from memory.

10–12: Partial compliance. You likely have the intention but gaps in documentation. Those gaps are exactly what an auditor or accreditation surveyor will find.

Under 10: Material exposure. The Privacy Act civil penalty for a serious breach is up to $50 million or 30% of adjusted turnover. A $5.8 million penalty has already been issued to a healthcare organisation in Australia.

Not confident you could produce the evidence?

A Compliance Gap Assessment gives you a written report of exactly what is missing and a prioritised roadmap to fix it — before an auditor asks.

Fixed-fee. Written report. Fee credited in full if you engage within 60 days.

This checklist is provided for general awareness only and does not constitute legal advice. Regulatory requirements may change — verify current obligations with your legal adviser or the relevant authority. ClinicGuard IT is an independent managed IT provider.