Skip to main content
ID
DH-3981:2024
Type
Component
Version
1.0
Status
Active
Created date
Updated date

Important Update

Following industry consultation, we invite you to review the proposed implementation timeline for the My Health Record Connecting Systems Security Conformance Profile, outlined in the table below, and encourage you to complete a brief survey.  The current scope requires fulfilling a minimum of five requirements – three conformance and two compliance, along with any applicable conditional requirements. While the remaining requirements are recommended, we strongly suggest implementing as many as possible, as they may become mandatory in the future. 

The survey is available from 24/09/2025 to 08/10/2025. 

To access the survey, please click on the following link: My Health Record Connecting Systems Security Conformance Profile v1.0 Proposed Implementation Timeline

Your feedback will help us assess any technical or conformance support you may require, allowing us to coordinate the necessary assistance to ensure both the Agency and the broader industry remain aligned in our shared goal in maintaining a safe and trusted healthcare ecosystem. 

We will aim to finalise and publish the implementation timeline in the second quarter of FY 25/26.

Proposed Implementation Timeline for My Health Record Security Conformance Profile

Category Segments Proposed Conformance Timeframe
Category A

All segments with existing connecting software

For example:

  • Public and Private Hospital
  • Software Developers
  • HIPS 
12 months*
Category B All segments under Industry Offer To be agreed with individual vendors *
Category C All segments with new connecting software As defined with MHR connection **

* All software developers, irrespective of their segment, who are part of an industry offer will adhere to the timeline defined by the industry agreement, which takes precedence over timelines applicable to other categories.
** All new connecting systems would need to gain conformance to the security profile as part of their MHR Production Access.

The Agency is cognisant of the inherent cyber security risks posed by systems connected to and accessing the My Health Record system, as well as potentially vulnerable aspects of the national infrastructure and all services under its care. To address this risk, a set of security requirements for systems connecting to the My Health Record system have been identified. The controls that are most relevant to the development of software for healthcare organisations, have been selected from the Australian Cyber Security Centre’s Information Security Manual (ISM).

The focus of this conformance profile is on incorporating the security control functionalities within software systems that are connected to the My Health Record system either directly or indirectly. This conformance profile sets a minimum standard or baseline level of cyber security that is expected of connecting systems, and that is consistently adopted. The requirements in this conformance profile are intended to strike an appropriate balance between strengthening the cyber security posture of all connecting systems and minimising potential impacts on software providers and overall system participation. In doing so, this conformance profile supports the overarching goals of improving security within healthcare software systems and fostering a secure and trusted healthcare ecosystem.

Benefits of the new security requirements:

The new requirements ensure that software developers of connected clinical information systems:

  • reduce the likelihood of cyber-attacks by disabling redundant technologies
  • strengthen system authentication and application timeouts
  • use contemporary encryption methods
  • perform third-party security testing (penetration testing and vulnerability testing)
  • reduce the risk of security vulnerabilities by keeping software up to date (patching)
  • securely back up personal and clinical information.

Conformance steps

steps of the conformance process

The below table describes the activities for each step of the conformance process.

Process Activity Description/Action
  1. Access and review all artefacts in Developer Portal
  • MHR Connecting Systems Security Conformance Profile is a prerequisite to a software product being connected to the My Health Record system.  All documentation is published on the Agency’s Developer Portal.
  1. Complete pre-conformance testing
  • Execute software pre-conformance testing based on the security profile conformance test specification.
  • Collect relevant test evidence (e.g., screenshot, recording) based on MHR Connecting Systems – Security Conformance Profile Conformance Test Specification.
  • Complete an MHR Software Vendor Product Details form, and make sure to update your software to the latest software version.
  • Schedule a mini-NOC (Notice of Connection) with relevant vendor e.g., Deloitte.
  • Arrange and secure either a penetration test, vulnerability test or both with an accredited third-party security organisation (if applicable). If the security organisation is not a member of CREST, please send a request to the Agency.
  1. Submit Conformance Assessment documents to the Agency 

 Send an email to help@digitalhealth.gov.au with the following information: 

  • Completed MHR Software Vendor Product Details form and ensure that the software version has been incremented.
  • Request access to Agency’s secure collaboration platform (e.g., GOVTEAMS), if not already granted. 

Upload the following documents for Conformance Assessment:

  • A completed My Health Record Connecting Systems – Security Conformance Profile Conformance Test Specification spreadsheet.
  • Collected test evidence to support My Health Record Connecting Systems – Security Conformance Profile Conformance Test Specification.
  • Penetration testing, vulnerability testing or both test reports, where applicable.
     
  1. Submit Conformance Vendor Declaration to the Agency

Submit the following documents for Conformance Declaration.

  • My Health Record Software Vendor Welcome Pack - Conformance Vendor Declaration Form
  • My Health Record Connecting Systems Security Conformance Profile – Test Completion Report.  This document is provided by the Agency upon successful assessment completion.
     

Questions and further information

Visit:

My Health Record Connecting Systems Security Conformance Profile - Frequently Asked Questions (FAQ)

Contact us:

If you require assistance during any stage of this process, please email the Agency at help@digitalhealth.gov.au 

Checksum: ec0b666aac73ef757f0f04b2326978c4b1f94f3b37c5ec6f553c7f14097204b4