Site icon Auspreneur

ADHA creates new security guidelines for connecting My Health Record

Over the next two years, systems that connect to the government’s My Health Record will need to adhere to stricter security requirements that comply with the Essential Eight.

Late on Tuesday, the Australian Digital Health Agency (ADHA) announced that it would force clinical software manufacturers to adhere to a new, required “conformance profile” of security requirements.

The government stated in the release notes that “all clinical information systems that employ one or more My Health Record B2B web services will need to comply to the revised security profile.”

n order to mitigate this risk, a set of security requirements for systems connecting to the My Health Record system have been identified. These requirements include controls for web development and application development that are in line with the Essential Eight maturity model of the Australian Cyber Security Centre (ACSC).

The ACSC Information Security Manual (ISM) sections chosen for this control set are those that are most pertinent to the creation of software for healthcare organisations.

In order to get input from the industry, the conformance profile is presently in development. Only business participants with a login can see the complete details.

Each vendor having software products linked to My Health Record will need to provide a substantial body of supporting documentation to prove compliance with each criteria and take part in an observation session led by the [ADHA] specialist team.

In a statement, Dr. Holger Kaufmann, the interim chief digital officer of ADHA, stated that “safeguarding sensitive information is vital in the provision of healthcare services.”

According to Kaufmann, “[it] is a basic skill that is necessary to enable connected healthcare systems and safe, easy, secure, and private information sharing across all healthcare providers.”

Exit mobile version