Australian clinics: 12 steps to secure patient records and meet APP 11
Australian clinics: 12 steps to secure patient records and meet APP 11

Yes, secure patient records are achievable when layered technical, physical and organisational controls work together, backed by clear policies and a breach response plan. Australian practices need access controls, encryption, verified backups and staff training aligned to the Privacy Act, with the Office of the Australian Information Commissioner (OAIC) and My Health Record as your two reference points. If you do nothing else today, check your My Health Record access settings and read your provider’s privacy policy.
TL;DR:
- Most Australian health practices must regularly review and update access controls, encryption, backups, and staff training to maintain compliance with privacy laws.
- Using secure transfer methods such as patient portals or end-to-end encrypted services is crucial for preventing data leaks during record sharing.
- Physical and digital records should be securely stored, with routine destruction and accurate documentation to prevent accidental disclosures or improper disposal.
- Regularly reviewing My Health Record settings and updating security measures like MFA significantly reduce the risk of unauthorized access over time.
- In case of a breach, immediately secure accounts, assess the exposure, notify authorities, and follow a documented response plan to mitigate harm.
Table of Contents
- What “secure” actually means for patient records
- How My Health Record stores and protects your health information
- Your rights and a provider’s legal duties under Australian privacy law
- Practical steps to lock down digital and physical records
- Sending and sharing medical records without leaking them
- Retention rules, safe disposal, and staying connected to your history
- What to do if a breach happens
- Meddle’s approach to privacy, security and continuity
- Where HIPAA and ISO 27799 fit into an Australian practice
- Can blockchain or AI actually make patient records more secure?
- The particular risks of mobile devices and cloud storage
- Author perspective: three practical priorities to act on
- How Meddle helps you keep access when providers change
- Sources
- FAQ
What “secure” actually means for patient records
Health information sits in a different category to a name and email address. Under Australian privacy law, it counts as sensitive information, which means it carries a higher duty of care than ordinary personal data. A leaked appointment booking is embarrassing. A leaked mental health record or STI test result can affect someone’s job, relationships or safety.
That is why security experts talk about the information lifecycle rather than a single “secure it and forget it” moment. Records move through five stages: collection, holding, sharing, retention and eventual destruction. Each stage carries its own risks and its own controls.
Most frameworks group those controls into four categories:
- Governance — policies, contracts and documented responsibilities
- Technical — encryption, access controls, backups and monitoring
- Physical — locked storage, restricted premises and secure transport
- People — training, vetting and a culture that treats a shortcut as a risk, not a convenience
A record is only as secure as its weakest category. A clinic can spend heavily on encryption and still leak data through an untrained receptionist who emails a file to the wrong address.
How My Health Record stores and protects your health information
My Health Record is Australia’s national digital repository for health information, built so a patient’s history follows them between GPs, specialists, hospitals and pharmacies. It is run by a System Operator under the My Health Records Act, which sets out registration rules, access controls and penalties for anyone who collects, uses or discloses the data without authorisation.
The system’s real value shows up when continuity matters most. My Health Record can preserve your access to test results, prescriptions and clinical summaries even if the GP who created them retires or the practice closes down. That is a genuine gap it fills, because a private practice’s own records system offers no such guarantee once the practice itself disappears.
You control much of what happens inside your record:
- Set access controls to restrict which providers can view specific documents
- Choose whether emergency access applies if you’re unable to give consent yourself
- Review the default settings, which are more open than many people assume
- Link your usual GP, specialists and pharmacist so your record stays current
- Upload or request copies of key documents to keep in your own record
Pro Tip: Log into My Health Record once a year, even if nothing feels urgent. Default access settings shift over time as the system updates, and a five-minute check beats discovering an unwanted provider had visibility into a sensitive test result.
Your rights and a provider’s legal duties under Australian privacy law
Australian Privacy Principle 11 (APP 11) is the clause that does the heavy lifting. It requires any entity holding personal information, including every health provider, to take reasonable steps to protect it from misuse, interference, loss, unauthorised access, modification or disclosure. The OAIC’s guide to securing personal information treats “reasonable steps” as a moving target scaled to the sensitivity of the information and the size of the practice, not a fixed checklist.
Retention obligations vary by jurisdiction, and this catches people out constantly. According to RACGP guidance on medical records, practices typically own the physical or digital record while the patient owns the information contained in it. A few patterns hold across most states and territories:
- Adult records are usually kept for a minimum number of years from the last consultation
- Records for children often must be kept until the patient reaches adulthood, since the retention period starts later for minors
- Some states set their own minimums through health records legislation, so the national figure is a floor, not a ceiling
You have a standing right to request access to your own health information, and the OAIC’s guide to accessing health information points to a reasonable response time frame of about a month for most requests. Providers can offer access as a full electronic copy, a written summary, or through an intermediary such as another treating doctor if direct access could cause harm. A provider can charge a reasonable fee for retrieval but cannot use cost as a way to stall or deny access outright.
Practical steps to lock down digital and physical records
Compliance on paper means nothing if the daily habits behind it are sloppy. Break the work into three groups and tackle each one.
- Turn on multi-factor authentication (MFA) for every system that touches patient data, not just the main practice management software.
- Encrypt data at rest and in transit so a stolen laptop or an intercepted transfer is unreadable without the key.
- Use verified cloud providers with published security certifications rather than generic file-sharing tools.
- Run daily backups with offsite storage, following the Department of Health’s administrative record-keeping guidelines, which recommend a disaster recovery plan and routine testing of those backups.
- Patch systems and run antivirus software on a fixed schedule rather than an ad hoc one.
- Lock physical files in restricted-access cabinets and limit who holds the keys.
- Use secure transport methods for physical files, whether that’s a locked courier bag or hand delivery with a signed chain-of-custody log.
- Keep a destruction register recording what was disposed of, when and by what method.
- Write down your policies rather than relying on informal habits that live only in one staff member’s head.
- Train every new staff member on privacy obligations before they touch a single record, and refresh that training annually.
- Apply least-privilege access, so a receptionist doesn’t have the same visibility into clinical notes as the treating practitioner.
- Keep audit logs and check them periodically, not just after something has gone wrong.
Pro Tip: Audit logs are useless if nobody reads them. Set a recurring calendar reminder, monthly for a busy clinic, quarterly for a solo practitioner, to actually review who accessed what.
Backups deserve treatment as an auditable part of your security posture, meaning integrity checks and a documented recovery test schedule, not just a nightly job that runs unattended and unverified. A practice that can produce evidence of tested backups is in a far stronger position with the OAIC than one that simply asserts it “does backups.”
Sending and sharing medical records without leaking them
Ordinary email and SMS are the weak points most practices overlook, largely because they feel convenient. Neither offers reliable encryption in transit by default, and both leave a copy sitting in an inbox indefinitely with no audit trail of who opened it.
Better options exist and most are already within reach:
- Secure patient portals built into practice management software
- My Health Record’s own sharing functions, which keep the transfer inside a controlled system
- End-to-end encrypted file transfer services designed for sensitive documents, rather than consumer messaging apps
- Password-protected PDFs paired with a separate channel for the password itself
- Expiring links that close the access window automatically after a set period
Teleradiology services illustrate this well, because moving diagnostic images between a PACS system and a reporting radiologist demands the same discipline as any other health data transfer: secure, auditable workflows rather than a quick email attachment. When you request your own records, ask the provider to confirm the transfer method and whether an access log exists. A provider that can’t answer that question plainly hasn’t thought the process through.
Retention rules, safe disposal, and staying connected to your history
Records outlive the relationship that created them, which is exactly where continuity breaks down if nobody plans for it. The seven-year minimum for adults and the extended window for children’s records, discussed earlier, sets the floor, but individual states can extend it further through their own health records legislation.
Disposal has to be as deliberate as storage. RACGP guidance is clear that records must be securely destroyed or de-identified once the retention period has passed, not simply deleted or binned.
- Shred physical documents rather than placing them in general waste
- Use certified secure destruction services for bulk disposal
- Wipe digital storage using methods that prevent recovery, not a simple delete
- Maintain a destruction register recording what was destroyed, when, and by which method, a practice discussed in Avant’s guidance on storing and disposing of medical records
The most common failure point isn’t malicious hacking. It’s poor physical storage, records left in an unsecured back room or a temporary demountable building while a practice relocates. The OAIC has pursued cases over exactly this kind of oversight.
If your GP or specialist retires or the practice closes, don’t assume your history disappears with it. Request copies of your key records before the transition happens, and lean on My Health Record as a standing backup that isn’t tied to any single provider’s continued operation.
What to do if a breach happens
A breach is stressful, but a clear sequence of actions limits the damage on both sides.
- As a patient, secure your accounts immediately by changing passwords and enabling MFA anywhere it wasn’t already active.
- Ask the provider exactly what was exposed and in what format, rather than accepting a vague reassurance.
- Consider identity protections such as a credit alert if financial or identifying details were part of the leak.
- As a provider, contain the breach first, then assess whether serious harm is likely before deciding on next steps.
- Notify the OAIC if serious harm is likely, and notify the My Health Record System Operator separately if the breach touched that system.
- Follow a documented breach response plan rather than improvising, since the OAIC expects a privacy action plan as part of ongoing reasonable steps, not a document written only after something goes wrong.
Meddle’s approach to privacy, security and continuity
Some healthcare coordination platforms build their matching and coordination features around the same privacy and security obligations covered above, not around them as an afterthought. Practices using these platforms may get access to practical compliance resources rather than generic advice:
- A structured security questionnaire for healthcare software that clinics can work through before adopting any new system
- Direct guidance on My Health Record compliance for providers integrating with the national system
- Practical guidance on patient recall and audit readiness, which overlaps heavily with retention obligations
Continuity of access matters as much to a well-designed coordination model as it does to My Health Record itself. When a patient moves between practitioners through such a platform, secure messaging and referral records can travel with that match, so the relationship doesn’t reset to zero every time a new provider gets involved.
Where HIPAA and ISO 27799 fit into an Australian practice
Australian practices aren’t legally bound by HIPAA, since it’s US legislation governing American healthcare entities. But it comes up constantly in conversations about health data security because it’s the most widely referenced framework internationally, and its core principles, minimum necessary access, breach notification timeframes, administrative safeguards, map closely onto what APP 11 already demands here.
ISO 27799 is more directly relevant. It’s an international standard specifically written for health informatics security management, built as a health-sector extension of the broader ISO 27001 information security standard. A practice that aligns its controls with ISO 27799 is effectively demonstrating the same “reasonable steps” the OAIC expects under Australian law, just documented against a globally recognised benchmark rather than a purely domestic one.
For most solo practitioners and small allied health clinics, chasing formal ISO certification is overkill. The certification process is expensive and time-consuming, and the OAIC doesn’t require it. What’s worth borrowing from these frameworks is the discipline behind them: documented risk assessments, defined roles for who can access what, and regular internal review cycles rather than a “set and forget” security policy written once and never revisited.
Larger practice groups or software vendors serving multiple clinics are a different story. If you’re evaluating a practice management system or a coordination platform, asking whether the vendor references ISO 27799 or equivalent international standards in its own security documentation is a fair and useful question. It signals the vendor has thought about health data security as a distinct discipline from generic IT security, which not every vendor has.

Can blockchain or AI actually make patient records more secure?
Both technologies get discussed constantly in health IT circles, and both are more nuanced in practice than the marketing suggests.
Blockchain’s appeal for health records is its tamper-evident structure. Once a record is written to a properly designed blockchain, altering it without detection becomes extremely difficult, which matters for audit trails and proving a record wasn’t quietly modified after the fact. The catch is that most blockchain implementations aren’t actually storing the sensitive health data itself on the chain. They’re storing a cryptographic fingerprint of the data, with the actual record held elsewhere. That’s a sensible design choice for privacy, but it also means blockchain solves an integrity problem, not an access control or encryption problem. It won’t stop someone with legitimate system access from misusing a record.
AI’s role in security is currently more about detection than storage. Machine learning models can flag unusual access patterns, a staff account suddenly pulling hundreds of patient files at 2am, for instance, faster than a human reviewing audit logs manually ever could. AI-powered matching, the kind Meddle uses to connect patients with practitioners, also reduces one specific risk: it cuts down on the number of times a record needs to be manually re-entered or re-transmitted between systems as a patient moves between providers, and every manual re-entry point is a potential error or exposure.
Neither technology replaces the fundamentals. Encryption, access controls and staff training still do the bulk of the protective work. Treat blockchain and AI as additions to a solid foundation, not a substitute for one.
The particular risks of mobile devices and cloud storage
Mobile access and cloud storage have become standard in Australian healthcare, largely because they make coordination between providers genuinely faster. They also introduce risks that a purely on-premise paper system never had.
A lost or stolen phone is the most obvious one. If a practitioner’s mobile has access to a patient portal or messaging app and isn’t protected by a passcode or biometric lock plus remote-wipe capability, that device becomes a single point of failure for potentially hundreds of patient records. The fix is straightforward: mandatory device locks, remote wipe enabled by default, and a policy that personal devices accessing clinical systems meet the same security bar as practice-owned equipment.
Cloud storage carries a different risk profile. The data itself is usually well protected by major providers’ infrastructure, but misconfiguration is the more common failure, a storage bucket left open, permissions set too broadly, or a third-party integration granted more access than it needs. Verifying that a cloud provider holds relevant security certifications is a reasonable first check, but it’s not sufficient on its own. Someone at the practice still needs to review access permissions periodically rather than assuming the provider handles everything.
Public wifi is the quiet risk nobody thinks about until it’s a problem. A practitioner checking patient messages over a café’s open network, without a VPN, is transmitting data across a connection nobody’s vetted for security. The mitigation is simple and cheap: a practice policy against accessing clinical systems over unsecured public networks, full stop.

Author perspective: three practical priorities to act on
Most patients treat privacy settings as something to configure once, then never touch again. That’s the mistake. Priorities worth revisiting regularly:
- Check your My Health Record access settings and read your provider’s privacy policy at least once a year.
- Turn on MFA everywhere it’s offered, and confirm your backups actually run, not just that they’re scheduled to.
- Keep a simple record of who holds your history when you change providers, so nothing gets lost in the handover.
None of this requires technical expertise. It requires five minutes and the habit of not putting it off.
— Taylor
How Meddle helps you keep access when providers change
If you’ve read this far, you already know continuity of access is one of the hardest things to guarantee when you move between practitioners, and it’s exactly where Meddle earns its place. The platform’s matching and coordination tools keep referrals, messages and provider history connected as you move through the system, so a change in practitioner doesn’t mean starting your record from scratch.

Meddle’s matching platform pairs you with the right allied health practitioner while keeping the coordination between providers secure and documented. If you’re a practitioner or clinic looking to see how the platform handles secure messaging and practice coordination day to day, the how Meddle works page walks through the mechanics in plain terms. Whichever side of the relationship you’re on, keep the OAIC’s guidance and My Health Record’s official settings as your source of truth, and consider using AI-based healthcare coordination platforms to help put those principles into practice rather than leaving them as good intentions. Start by exploring a practitioner match to see how the coordination actually feels.
Sources
For anything you need to verify directly, go to the primary sources. The OAIC’s privacy action plan guide covers breach response planning, while My Health Record’s official pages explain access settings step by step. The RACGP’s record-keeping guidance is the clearest reference for clinical practices working through retention rules.
FAQ
What is the most secure way to send medical records?
Secure patient portals, My Health Record’s built-in sharing functions, or end-to-end encrypted file transfer services are all more secure than email or SMS, which lack reliable encryption and leave no audit trail.
Can I access my medical records from 10 years ago?
It depends on whether your provider was still required to retain them. Adult records are typically kept for a minimum of seven years from the last consultation, so records older than that may have already been legally destroyed.
How secure is My Health Record?
My Health Record operates under the My Health Records Act, with a System Operator managing access controls and penalties for unauthorised use, and you control much of your own record’s visibility through your personal access settings.
Who can access my medical records in Australia?
Your treating providers can access records relevant to your care, and you control additional access through My Health Record’s settings, while anyone else generally needs your consent or a specific legal authority to view them.