This month, we are looking at My Health Record which has launched in Australia in July. There has been lots of information, and misinformation regarding this. With the help of an article from ABC Health, your questions will be answered on cybersecurity, police and privacy
Every Australian will soon have a My Health Record — an online summary of their health information — unless they opt out over the next three months.
From Monday, Australians will have until October 15 to tell the Government they don’t want one. Otherwise, a record will automatically be created.
The project aims to give patients and doctors access to timely medical information — test results, referral letters and organ donation information, for starters — but there are concerns about the safety of some of our most personal, sensitive data.
The following information is courtesy of ABC, who sat down with Tim Kelsey, the head of the Australian Digital Health Agency (ADHA) and the man in charge of the initiative, to get questions answered.
The way the record works
As a patient, how can I know if my My Health Record information is being maintained by my doctor?
You can choose to opt out and have no My Health Record.
But once you have one, doctors can upload health information into it unless you ask them not to.
When you see a doctor, you can discuss adding (or not) documents such as an overview of your health, a summary of prescribed medications and referral letters.
Remember, it’s not a comprehensive picture of your health — it will only contain what you and your doctors choose to upload, and will depend on the quality of those records.
When you first access the system, you’ll be asked to decide whether you want two years of Medicare Benefits Schedule, Pharmaceutical Benefits Scheme, Australian Immunisation Register, and Australian Organ Donor Register data to be uploaded.
But if your doctor accesses your record first before you make the selection yourself, this data will be uploaded automatically — unless you’ve opted to have no record at all.
If you want, you can delete or restrict access to those documents later.
Not all Australian hospitals and health services are connected to My Health Record yet, so that’s something to check during your next visit.
When I get a prescription, how do I know whether I need to ask to make an update to my My Health Record? Does this vary by provider?
Doctors can upload information about prescribed medications, but as discussed above, it’s worth discussing this each time you see your doctor.
What happens to your My Health Record after you die?
My Health Record information will be held for 30 years after your death. If that date isn’t known, then it’s kept for 130 years after your birth.
Will any private health insurance companies have access?
Insurers shouldn’t be able to access your record — it’s reserved for people who work for a registered healthcare provider and who are authorised to provide you with care.
There are plans to use aggregated, anonymised My Health Record data for research and other purposes — this is known as “secondary use”.
“My Health Record information can be used for research and public health purposes in either a de-identified form, or in an identified form if the use is expressly consented to by the consumer,” a Department of Health spokesperson said.
Currently, users of the platform can tick a box on the web portal to opt out of secondary use.
Secondary uses must be of public benefit and cannot be “solely” commercial, and insurance agencies will not be allowed to participate.
Australian organisations (and some overseas, in certain circumstances), including Australian pharmaceutical companies, will be able to apply to access My Health Record data for approved secondary purposes.
“We don’t expect any data to flow until 2020,” Mr Kelsey added.
How can I opt out?
There are three key ways:
By visiting www.myhealthrecord.gov.au and opting out using the online portal. Over the phone by calling 1800 723 471.
Or on paper by completing a form and returning it by mail. Forms will be available in 2,385 rural and remote Australia Post outlets, through 146 Aboriginal Community Controlled Health Organisations and in 136 prisons.
What happens to the people who end up with a My Health Record, and then decide to opt out?
If you don’t opt out between July 16 and October 15, then a record will be automatically created for you.
After October 15, there will be a “one-month reconciliation period” before new My Health Records are registered. These new records will be created mid-November.
You can then cancel that record, but the data it contained will still exist (although inaccessible to you or health providers) until 30 years after your death.
Is a record automatically generated if a doctor uploads a document during the opt-out period, even if you did not create one yourself?
According to the ADHA, doctors can’t upload any clinical documents to the My Health Record system unless the patient record exists.
What about children who aren’t born yet — can they opt out?
After the opt-out period, newly eligible healthcare recipients, such as immigrants to Australia and parents of newborn children, will be given the chance to elect not to have a My Health Record as part of their Medicare registration.
Protection of your data
Which service provider will manage the infrastructure to ensure it isn’t vulnerable to a cyber-attack?
The platform was built by the technology provider Accenture, however the ADHA is starting discussions about “re- platforming” it.
Independent third parties audit the system’s security and undertake penetration testing, according to Mr Kelsey, but security experts warn that it’s impossible to make any online database entirely bullet proof.
Remember too, that documents created or downloaded by your doctors may be stored in their local IT system too and depend on that system’s security.
If a doctor downloads files from My Health Record, what’s to stop her from sharing those files within the practice?
By default, your online documents will be accessible to your healthcare providers
To be honest, I got to this point, and thought WOW!! Unless you are reasonably technologically savvy, how is the average Australian going to manage their online Health Records? There are so many ifs and buts here….
I have studied management of health information at University, and in reading this article (with a few extra italics and bolding by myself thrown in to emphasize a point) I do wonder how safe my personal information is going to be.
I guess each of us needs to make our own decision and watch this space as My Health Record rolls out!
Read on for further privacy information, but otherwise, until next month,
P.S please email me with any requests for articles… firstname.lastname@example.org
If you have privacy concerns, you can log onto My Health Record and restrict who sees it:
You can set a Record Access Code and give it only to healthcare professionals you want to access your record. If you want to restrict certain documents, you can set a Limited Document Access Code.
These controls may be overridden in an emergency.
As mentioned above, if a document is removed from the My Health Record system, it’s beyond the reach of your access controls.
If a GP were to allow another staff member to access a record, what is the potential punishment?
If someone accesses your My Health Record without legal authorisation and the person “knows or is reckless to that fact”, criminal and civil penalties may apply.
Where can users see information about who has accessed their record?
My Health Record users will be able to see who has looked at their record by checking its access history online.
They’ll be able to see when it was accessed, which organisation accessed it and what was done — documents being added, modified or removed, for example — but not the individual doctor who accessed it.
You can also set up an email or SMS alert for when a healthcare organisation accesses your record for the first time.
The privacy commissioner recommends checking regularly for unexpected or unauthorised access. You can call the ADHA on 1800 723 471 if you think something’s gone wrong.
Several apps can connect to My Health Record. How will the ADHA ensure they are secure?
Apps such as Healthi and Health Engine, which recently ran into trouble, are authorised by the ADHA to “show” people their health record.
According to Mr Kelsey, third party app developers can only display your My Health Record — “at the moment, it’s view-only” — and cannot store that data.
These providers undergo “strict assessment” and must abide by a Portal Operator Registration Agreement, according to the ADHA.
The agreement demands they do not download or store My Health Record information on their own system, or pass that data on to a third party.
“We are not currently planning to provide access beyond ‘view-only’ to the app community,” he said.
Police and law enforcement
Which rules and policies guide the ADHA’s decision to grant access to law enforcement?
The ADHA is authorised by law to disclose someone’s health information if it “reasonably believes” it’s necessary for preventing or investigating crimes and protecting the public revenue, among other things specified under section 70 of the My Health Records Act.
The agency was unable to provide a definition of “protecting the public revenue” by deadline.
When it receives a law enforcement request, the ADHA will need to determine that it’s a legitimate request from an enforcement body.
“While the Agency assesses each formal request on a case by case basis, our operating policy is to release information only where the request is subject to judicial oversight,” the ADHA said.
“If the access does not support public confidence and trust in the System and the object of the My Health Record Act then the Agency will deny the request.”
Law enforcement bodies will not be granted direct access to the My Health Record: The ADHA said any disclosure would be limited to what is necessary to satisfy the purpose of the request.
Has the ADHA received any requests from law enforcement to access records?
Mr Kelsey said no police requests have been received yet.
Will users be informed if their data has been released to law enforcement?
If personal information is disclosed to law enforcement, the decision about whether to notify the My Health Record holder will be decided “case-by-case”.
Likewise, healthcare provider organisations won’t be informed if their patient’s data is accessed. The release to police will be recorded in a written note and stored by the ADHA