Skip to main content
ID
DH-3981:2024
Type
Component
Version
1.0
Status
Active
Created date
Updated date

Overview

The Agency understands the potential cyber security risks posed by systems connected to and accessing the My Health Record system, as well as potentially vulnerable aspects of the national infrastructure and all services under its care. To address this risk, a set of security requirements for systems connecting to the My Health Record system have been identified. The controls that are most relevant to the development of software for healthcare organisations, have been selected from the Australian Cyber Security Centre’s Information Security Manual (ISM).

In consultation with a wide variety of stakeholders, valuable feedback was collated and used to publish the final security profile. The conformance profile sets a minimum standard or baseline level of cyber security that is expected when connecting to the My Health Record system, and that is consistently adopted.

The requirements in this conformance profile are intended to strike an appropriate balance between strengthening the cyber security posture of all connecting systems and minimising potential impacts on software providers and overall system participation. In doing so, supporting the overarching goals of improving security within healthcare software systems and fostering a secure and trusted healthcare ecosystem.

Benefits of the new security requirements

The new requirements ensure that software developers of connected clinical information systems:

  • reduce the likelihood of cyber-attacks by disabling redundant technologies
  • strengthen system authentication and application timeouts
  • use contemporary encryption methods
  • perform third-party security testing (penetration testing and vulnerability testing)
  • reduce the risk of security vulnerabilities by keeping software up to date (patching)
  • securely back up personal and clinical information.

Conformance steps

The conformance process is being reviewed. The steps that software developers will be required to complete in order to achieve conformance will be published on this web page by February 2025. 

Questions and further information

Have any questions?

Please visit:

My Health Record Connecting Systems Security Conformance Profile - Frequently Asked Questions (FAQ)

Contact us:

If you require assistance during any stage of this process, please email the Agency at [email protected]

You can or register to download Security Conformance Profile v1.0 PDF

Checksum: ec0b666aac73ef757f0f04b2326978c4b1f94f3b37c5ec6f553c7f14097204b4