Nabeel Al Nassir
October 1, 2026
8 Min read

My Health Record integration means connecting clinical software to the national digital health record so it can view documents and upload information such as reports and summaries. For Australian clinical software, integration depends on healthcare identifiers for patients, practitioners and organisations, secure authentication through NASH certificates, and conformance with the Australian Digital Health Agency's requirements. Since 1 July 2026, most pathology and diagnostic imaging reports are uploaded by default, which makes reliable integration more important than ever.
My Health Record is Australia's national digital health record system, operated by the Australian Digital Health Agency (ADHA). It holds a summary of an individual's health information, such as shared health summaries, event summaries, discharge summaries, pathology and diagnostic imaging reports, prescription and dispense records, and Medicare information.
Clinical software integrates with My Health Record so that healthcare providers can see relevant information about a patient, and contribute information to the record, from within the systems they already use. A general practice's clinical system might upload a shared health summary and view recent hospital discharge summaries. A pathology laboratory's system uploads reports. A hospital's system uploads discharge summaries and views information during admission.
For software vendors and healthcare organisations building or extending clinical systems, integration is not a single feature. It rests on three foundations: identifying the right patient, practitioner and organisation, authenticating the system securely, and meeting the ADHA's conformance requirements for what the software does with the record.
My Health Record depends on healthcare identifiers issued through the Healthcare Identifiers Service, which is operated by Services Australia. There are three main types. The Individual Healthcare Identifier, or IHI, uniquely identifies a patient. The Healthcare Provider Identifier for Individuals, or HPI-I, identifies a practitioner. The Healthcare Provider Identifier for Organisations, or HPI-O, identifies a healthcare organisation.
Before software can view or upload a record, it must usually retrieve and validate the patient's IHI, using demographic details such as name, date of birth, sex and Medicare or other identifiers. Getting this right is critical. An IHI matched to the wrong patient means information goes to the wrong record, which is a serious clinical and privacy risk. Software therefore needs careful matching logic, clear handling of partial matches and a record of how each IHI was validated.
Authentication uses National Authentication Service for Health certificates, known as NASH certificates. An organisation obtains a NASH certificate through Services Australia, and the software uses it to connect securely to national digital health services. Certificates have expiry dates, and an expired certificate stops the connection, so software should monitor and warn before expiry.
Software that connects to My Health Record must meet conformance requirements published by the ADHA, which set out how the software must behave: how it identifies patients, how it displays information, how it handles consent and access controls, how it records audit information, and how it produces documents in the required formats. Vendors test their software against these requirements and declare conformance before connecting in production, and the ADHA publishes information about software that has done so.
For an organisation commissioning custom clinical software, conformance shapes the project from the start. It affects the data model, the user interface for viewing records, error handling and audit logging. Treating conformance as a final checklist item, rather than a design input, usually leads to rework. Healthcare organisations using commercial software should also confirm which conformance profiles their vendor has met, because that determines what the software can do with My Health Record.
The Health Legislation Amendment (Modernising My Health Record—Sharing by Default) Act 2025 changed the expectations for uploading information. From 1 July 2026, most written pathology and diagnostic imaging reports authored by or on behalf of a pathologist or radiologist are to be uploaded to My Health Record by default. The diagnostic images themselves are not included.
There are exceptions. A report does not have to be uploaded where the patient does not have a My Health Record, where the patient or their representative asks that it not be uploaded, where the provider reasonably believes sharing it could pose a serious risk to someone's health, safety or wellbeing, where technical problems prevent upload, or in certain other defined circumstances. Organisations are expected to keep evidence of the exceptions they rely on, and guidance published for providers indicates that evidence should be retained for two years.
For software, sharing by default means upload is the normal path, not an optional extra. Pathology and imaging systems need to upload reports automatically, record when a patient has asked for a report not to be shared, capture the reason and evidence for any other exception, and report on upload success and failure so problems are fixed quickly. Requesting clinicians' systems also need to support conversations with patients about when results will become visible in their record.
My Health Record is only part of the interoperability picture. Clinical systems also exchange information directly with each other, through secure messaging, referrals, e-requesting for pathology and imaging, and electronic prescribing.
Fast Healthcare Interoperability Resources, or FHIR, is the international standard increasingly used for this exchange. In Australia, HL7 Australia publishes AU Base and AU Core FHIR profiles that adapt the international standard to local identifiers, terminology and practice, and national programs have been developing these profiles further with industry. For software being built or rebuilt now, designing data models and interfaces around FHIR resources makes future integrations considerably easier than bespoke formats.
Terminology matters too. Australian clinical systems use standard terminologies such as SNOMED CT-AU and the Australian Medicines Terminology, so that information means the same thing in every system that receives it.
Health information is among the most sensitive personal information, and clinical software handles it under several overlapping frameworks: the Privacy Act 1988 and Australian Privacy Principles, the My Health Records Act 2012 and its rules, and state health records laws where they apply.
For software, that means access controls that give each user only what their role requires, patient access settings respected when viewing a My Health Record, audit logs that record every view and upload with the user and time, and secure hosting. Many health organisations require data to be hosted in Australia, and hosting in an Australian cloud region with in-region backups is a sensible default. Our overview of Australia's 2026 compliance deadlines covers the Privacy Act changes that also affect health software, including automated decision disclosures from 10 December 2026.
| Requirement | Who it applies to | Software capability |
|---|---|---|
| Healthcare identifiers | All connecting organisations | IHI retrieval and validation, HPI-I and HPI-O records |
| NASH certificates | All connecting organisations | Secure connection, certificate expiry monitoring |
| ADHA conformance | Software connecting to My Health Record | Conformant behaviour, documents and audit |
| Sharing by default | Pathology and diagnostic imaging providers | Automatic upload, exception capture, evidence retention |
| FHIR interoperability | Systems exchanging clinical data | AU Base and AU Core profiles, standard terminology |
| Privacy and audit | All health software | Role-based access, logs of views and uploads, secure hosting |
A My Health Record integration project usually starts with a clear statement of what the software needs to do: view documents, upload specific document types, or both. That decision sets the conformance requirements that apply and the testing needed. The organisation then arranges its HPI-O and NASH certificate, the development team builds against the national test environment, and the software is tested against the relevant conformance requirements before production connection.
Two practical points save time. First, patient identity matching deserves early attention, because poor demographic data in an existing system will cause IHI validation failures regardless of how well the integration is built. Cleaning that data before go-live avoids a flood of exceptions. Second, upload monitoring should be part of the first release, not a later improvement, because failed uploads that nobody notices defeat the purpose of sharing by default.
Integrating clinical software with My Health Record requires correct healthcare identifiers, secure authentication through NASH, and software built to the ADHA's conformance requirements. Sharing by default, from 1 July 2026, makes upload the normal path for most pathology and diagnostic imaging reports, with exceptions that must be recorded. Beyond My Health Record, FHIR-based interoperability and strong privacy and audit design determine how easily clinical systems can work together.
| Area | Key point |
|---|---|
| Operator | Australian Digital Health Agency |
| Identifiers | IHI for patients, HPI-I for practitioners, HPI-O for organisations |
| Authentication | NASH certificates issued through Services Australia |
| Conformance | ADHA requirements for connecting software |
| Sharing by default | From 1 July 2026 for most pathology and imaging reports |
| Interoperability | FHIR with AU Base and AU Core profiles |
It is the connection between clinical software and the national My Health Record system that lets healthcare providers view information about a patient and upload documents such as reports and summaries from within their own systems.
A National Authentication Service for Health certificate is a digital certificate an organisation obtains through Services Australia. Software uses it to connect securely to national digital health services, including My Health Record.
Software that connects to My Health Record must meet the conformance requirements published by the Australian Digital Health Agency, covering matters such as patient identification, document formats, access and audit.
From 1 July 2026, most written pathology and diagnostic imaging reports authored by or on behalf of a pathologist or radiologist are to be uploaded to My Health Record by default, unless an exception applies, such as a patient request not to upload.
Fast Healthcare Interoperability Resources, or FHIR, is an international standard for exchanging healthcare information. In Australia, AU Base and AU Core profiles adapt it to local identifiers, terminology and practice.
An Individual Healthcare Identifier is a unique number that identifies a patient in Australia's digital health system. Software usually retrieves and validates the IHI before viewing or uploading to a patient's My Health Record.
Pixbit designs and builds clinical and health software with healthcare identifiers, secure authentication, audit logging and FHIR-based integration planned from the start, and hosts it in Australia. Adding an integration or upload workflow to an existing system sits at the lower end of the investment range, and a new clinical platform at the higher end. Explore our custom software development service or book a discovery session, and Pixbit scopes in a single discovery session.

Digital Marketer
Share on
Have an idea that needs to go mobile? Launch it with us!
Let's Talk
Explore insightful articles and tips from our experts on the latest trends in web development and marketing.
Tell us your business aspirations, and let's craft a custom solution that drives business growth, ensuring satisfaction and exceeding your goals with precision.
Let's Talk