Category Supplementary Resource Organisation Australian Digital Health Agency (ADHA) ID DH-3583:2022 Type Standard Component Version 1.0 Status Active Created date 19/12/2022 Updated date 07/09/2023 The Agency is cognisant of the inherent cyber security risks posed by systems connected to and accessing the My Health Record system, as well as potentially vulnerable aspects of the national infrastructure and all services under its care. To address this risk, a set of security requirements for systems connecting to the My Health Record system have been identified, comprising controls related to application development and web development, with controls aligned to the Australian Cyber Security Centre’s (ACSC) Essential Eight Maturity Model. These controls are selected as the areas of the ACSC Information Security Manual (ISM) that are most relevant to the development of software for healthcare organisations. The focus is on incorporating functionality within Clinical Information Systems (CIS) connected to the My Health Record system that will enable healthcare providers to implement better security within their organisations, while also balancing the potential impacts on software providers and on system participation. The Agency is in the process of updating the My Health Record System Conformance Assessment Scheme (CAS) for connecting systems that refers to conformance requirements in the profile. It is anticipated that the release of the updated CAS will coincide with the release of the final version of the new profile, following the review period. Security Requirements Conformance Profile - FAQs Download Conformance Profile v1.0 DH_3583_2022_SecurityRequirementsforMyHealthRecordConnectingSystems_ConformanceProfile_v1.0.pdf () Checksum: 374ba70e5e1d7b3990a26ffce01c680ffa68125605ee4b4091b61902d677d7a7 This component belongs to the following product: My Health Record Overviews, Guides and Conformance Material v1.6 - superseded Subsequent versions My Health Record Connecting Systems - Security Conformance Profile v1.0.1 - current My Health Record Connecting Systems - Security Conformance Profile v1.0 - superseded Security Requirements for My Health Record Connecting Systems - Conformance Profile - Draft v1.1 - superseded