CTHIn ForceAct
Healthcare Identifiers Act 2010
Division 4Unauthorised use and disclosure of healthcare identifiers and other information obtained under this Act
Start here
Get a plain-English read of Division 4
Turn the raw legal text into a practical explanation grounded in Healthcare Identifiers Act 2010.
An Act to enable the safe and accurate exchange of information about healthcare and support services through unique healthcare identifiers and data standards, and for related purposes
## Part 1—Preliminary
#### 1 Short title
This Act may be cited as the Healthcare Identifiers Act 2010.
#### 2 Commencement
This Act commences on the day after this Act receives the Royal Assent.
#### 3 Purpose of this Act
The purpose of this Act is to enable the safe and accurate exchange of information about healthcare and support services by:
(a) assigning unique identifiers to healthcare providers and recipients; and
(b) authorising the collection, use and disclosure of healthcare identifiers and identifying information by trusted entities for health, health‑related and health administration purposes; and
(c) providing for a comprehensive Healthcare Provider Directory to facilitate communication between healthcare providers and manage information about healthcare and support services; and
(d) providing for the making of data standards about health information and other clinical data.
#### 3A Simplified outline of this Act
Under this Act, healthcare identifiers are assigned to healthcare recipients, individual healthcare providers, healthcare provider organisations and healthcare support service providers.
There are strict rules on:
(a) the verification of a person’s identity before a healthcare identifier is assigned; and
(b) the purposes for which a healthcare identifier can be collected, used and disclosed; and
(c) the purposes for which the identifying information of a healthcare recipient, an individual healthcare provider, a healthcare provider organisation or a healthcare support service provider can be collected, used and disclosed.
This Act facilitates the use of healthcare identifiers for the purposes of communicating and managing health information about a healthcare recipient (including through the My Health Record system) and for health administration purposes that support the delivery of healthcare and support services.
This Act also facilitates:
(a) the creation of a Healthcare Provider Directory, to allow healthcare providers to check the professional and business details of healthcare providers; and
(aa) the making of data standards about health information and other clinical data; and
(b) the use of authenticated electronic communications by healthcare providers.
#### 4 Act to bind the Crown
(1) This Act binds the Crown in right of the Commonwealth, of the States, of the Australian Capital Territory and of the Northern Territory.
> Note: The Minister must, in certain circumstances, declare that certain provisions of this Act do not apply to the public bodies of a specified State or Territory: see subsection 37(4).
(2) This Act does not make the Crown liable to be prosecuted for an offence.
#### 4A External Territories
This Act extends to every external Territory.
#### 5 Definitions
(1) In this Act:
> Aged Care Department means the Department administered by the Aged Care Minister.
> Aged Care Minister means the Minister administering the Aged Care Act 2024.
> Australian law has the same meaning as in the Privacy Act 1988.
> authorised representative of a healthcare recipient has the same meaning as in the My Health Records Act 2012.
> Chief Executive Medicare has the same meaning as in the Human Services (Medicare) Act 1973.
> civil penalty provision has the same meaning as in the Regulatory Powers Act.
> contracted service provider, of a healthcare provider or a health administration entity, means an entity that provides:
(a) information technology services relating to the communication of health information; or
(b) health information management services; or
(c) business or administrative support to assist in the delivery of healthcare, support services or health administration;
to the healthcare provider or health administration entity under a contract with the healthcare provider or health administration entity.
> court/tribunal order has the same meaning as in the Privacy Act 1988.
> data standard means a data standard made under subsection 31AC(1).
> date of birth accuracy indicator means a data element that is used to indicate how accurate a recorded date of birth is.
> date of death accuracy indicator means a data element that is used to indicate how accurate a recorded date of death is.
> Defence Department means the Department that:
(a) deals with matters arising under section 1 of the Defence Act 1903; and
(b) is administered by the Minister who administers that section.
> employee, of an entity, includes:
(a) an individual who provides services for the entity under a contract for services; or
(b) an individual whose services are made available to the entity (including services made available free of charge).
> entity means:
(a) a person; or
(b) a partnership; or
(c) any other unincorporated association or body; or
(d) a trust; or
(e) a part of another entity (under a previous application of this definition).
> funded aged care service has the same meaning as in the Aged Care Act 2024.
> health administration: see section 7A.
> health administration entity means an entity, or an entity included in a class of entities, determined by the Minister under subsection 7B(1).
> healthcare means health service within the meaning of subsection 6(1) of the Privacy Act 1988.
> healthcare identifier has the meaning given by section 9.
> healthcare provider means:
(a) an individual healthcare provider; or
(b) a healthcare provider organisation; or
(c) a healthcare support service provider.
> Healthcare Provider Directory has the meaning given by subsection 31(1).
> Healthcare Provider Directory Operator has the meaning given by section 6A.
> healthcare provider organisation means an entity, or a part of an entity, that has conducted, conducts, or will conduct, an enterprise that provides healthcare (including healthcare provided free of charge).
> Note: Example: A public hospital, or a corporation that runs a medical centre.
> healthcare recipient means an individual who has received, receives, or may receive, healthcare or a support service.
> healthcare support service provider means an entity that:
(a) provides:
(i) healthcare; or
(ii) a support service; and
(b) does not, in the ordinary course of business, employ an individual employee who satisfies subsection 9(2) or paragraph 9A(1)(a), (b) or (c).
> Health Chief Executives Forum has the same meaning as in the My Health Records Act 2012.
> health information has the meaning given by subsection 6(1) of the Privacy Act 1988.
> Human Research Ethics Committee has the meaning given by:
(a) the National Statement on Ethical Conduct in Human Research issued in March 2007 by the Chief Executive Officer of the National Health and Medical Research Council under the National Health and Medical Research Council Act 1992; or
(b) if that Statement is amended—that Statement as amended.
> Note: In 2010, the text of the Statement was accessible through the National Health and Medical Research Council website (www.nhmrc.gov.au).
> identified healthcare provider means:
(a) an identified healthcare provider organisation; or
(b) an identified healthcare support service provider; or
(c) an identified individual healthcare provider.
> identified healthcare provider organisation means a healthcare provider that has been assigned a healthcare identifier under paragraph 9(1)(a) on the basis of subsection 9A(2), (3) or (9) (which deal with healthcare provider organisations).
> identified healthcare support service provider means a healthcare provider that has been assigned a healthcare identifier under paragraph 9(1)(a) on the basis of subsection 9BA(1) (which deals with healthcare support service providers that are not otherwise eligible to be assigned a healthcare identifier).
> identified individual healthcare provider means a healthcare provider that has been assigned a healthcare identifier under:
(a) paragraph 9(1)(a) on the basis of subsection 9A(1) (which deals with healthcare identifiers assigned to individuals by the service operator); or
(b) subsection 9(2) (which deals with healthcare identifiers assigned to individuals by a national registration authority).
> identifying information has the meaning given by section 7.
> individual healthcare provider means an individual who:
(a) has provided, provides, or is to provide, healthcare; or
(b) is registered by a registration authority as a member of a particular health profession.
> law includes:
(a) an Act or legislative instrument; or
(b) an Act or legislative instrument of a State or Territory.
> linked: an individual healthcare provider is linked to a healthcare provider organisation if:
(a) the individual healthcare provider is an employee of the healthcare provider organisation; or
(b) the healthcare provider organisation provides services or facilities to the individual healthcare provider, to facilitate the provision of healthcare by the individual healthcare provider.
> Ministerial Council means a body (however described) that consists of the Minister of the Commonwealth, and the Minister of each State and Territory, who is responsible, or principally responsible, for matters relating to health.
> My Health Record has the same meaning as in the My Health Records Act 2012.
> My Health Records Act means the My Health Records Act 2012.
> My Health Record system has the same meaning as in the My Health Records Act 2012.
> My Health Record System Operator means the System Operator within the meaning of the My Health Records Act 2012.
> National Disability Insurance Agency has the same meaning as in the NDIS Act.
> national registration authority has the meaning given by section 8.
> NDIS Act means the National Disability Insurance Scheme Act 2013.
> network of healthcare provider organisations has the meaning given by subsection 9A(4).
> network organisation within a network has the meaning given by subsection 9A(6).
> nominated representative of a healthcare recipient has the same meaning as in the My Health Records Act 2012.
> organisation maintenance officer:
(a) for a healthcare provider organisation—has the meaning given by subsection 9A(8); and
(b) for a healthcare support service provider—has the meaning given by subsection 9BA(3).
> participant in the My Health Record system has the same meaning as in the My Health Records Act 2012.
> personal information has the same meaning as in the Privacy Act 1988.
> professional body means an organisation that:
(a) is a separate legal entity under a law of the Commonwealth or a State or Territory; and
(b) has all of the following characteristics:
(i) represents members or individuals to whom it provides credentials (or both);
(ii) has enough members, or provides credentials for enough individuals, to be considered representative of the healthcare profession practised by the individuals it represents;
(iii) sets and publishes standards of practice and ethical conduct for, and aims to maintain the standing of, the healthcare profession practised by the individuals it represents.
> registered NDIS provider has the same meaning as in the NDIS Act.
> registered portal operator has the same meaning as in the My Health Records Act 2012.
> registered repository operator has the same meaning as in the My Health Records Act 2012.
> registration authority means an entity that is responsible under a law for registering members of a particular health profession.
> Regulatory Powers Act means the Regulatory Powers (Standard Provisions) Act 2014.
> responsible officer:
(a) for a healthcare provider organisation—has the meaning given by subsection 9A(7); and
(b) for a healthcare support service provider—has the meaning given by subsection 9BA(2).
> retirement, for a healthcare provider organisation’s or a healthcare support service provider’s healthcare identifier, means a state imposed by the service operator on the healthcare identifier so that it may no longer be used by the healthcare provider organisation or the healthcare support service provider to identify the healthcare provider organisation or the healthcare support service provider, as the case requires.
> Secretary means the Secretary of the Department.
> seed organisation for a network has the meaning given by subsection 9A(5).
> service operator has the meaning given by section 6.
> sole practitioner means a person who is both an individual healthcare provider and a healthcare provider organisation.
> State or Territory authority has the meaning given by the Privacy Act 1988.
> subcontracted service provider, of a healthcare provider, means an entity:
(a) that is a party to a contract (the subcontract) with a contracted service provider for the healthcare provider; and
(b) who is responsible under the subcontract for the provision of:
(i) information technology services relating to the communication of health information; or
(ii) health information management services;
to the healthcare provider, or to the contracted service provider for the healthcare provider.
> support service means any of the following:
(a) a funded aged care service;
(b) a support or service provided by a registered NDIS provider under the NDIS Act;
(c) a support or service, or a support or service included in a class of supports or services, prescribed by the regulations.
> under this Act includes under the regulations.
> Veterans’ Affairs Department means the Department that:
(a) deals with matters arising under:
(i) section 1 of the Australian Participants in British Nuclear Tests and British Commonwealth Occupation Force (Treatment) Act 2006; or
(ii) section 1 of the Military Rehabilitation and Compensation Act 2004; or
(iia) section 1 of the Treatment Benefits (Special Access) Act 2019; or
(iii) section 1 of the Veterans’ Entitlements Act 1986; and
(b) is administered by the Minister who administers that section.
(2) To avoid doubt, a healthcare provider is not an identified healthcare provider throughout any period when the healthcare identifier assigned to the healthcare provider is in a state of retirement.
#### 6 Identity of service operator
The service operator is:
(a) the Chief Executive Medicare; or
(b) if a body established by a law of the Commonwealth is prescribed by the regulations to be the service operator—that body.
> Note: Section 33 provides that the Minister must consult with the Ministerial Council before making regulations.
#### 6A Identity of Healthcare Provider Directory Operator
The Healthcare Provider Directory Operator is:
(a) the service operator; or
(b) if a body established by a law of the Commonwealth is prescribed by the regulations to be the Healthcare Provider Directory Operator—that body.
> Note: Section 33 provides that the Minister must consult with the Ministerial Council before making regulations.
#### 7 Meaning of identifying information
(1) Each of the following is identifying information of a healthcare provider who is an individual, if the service operator or Healthcare Provider Directory Operator requires it for the purpose of performing the service operator’s or Healthcare Provider Directory Operator’s (as the case may be) functions under this Act in relation to the healthcare provider:
(a) the name of the healthcare provider;
(b) the address of the healthcare provider;
(ba) the email address, telephone number and fax number of the healthcare provider;
(c) the date of birth, and the date of birth accuracy indicator, of the healthcare provider;
(d) the sex of the healthcare provider;
(e) the type of healthcare provider that the individual is;
(f) if the healthcare provider is registered by a registration authority—the registration authority’s identifier for the healthcare provider and the status of the registration (such as conditional, suspended or cancelled);
(g) other information that is prescribed by the regulations for the purpose of this paragraph.
(2) Each of the following is identifying information of a healthcare provider that is not an individual, if the service operator or Healthcare Provider Directory Operator requires it for the purpose of performing the service operator’s or Healthcare Provider Directory Operator’s (as the case may be) functions under this Act in relation to the healthcare provider:
(a) the name of the healthcare provider;
(b) the address of the healthcare provider;
(ba) the email address, telephone number and fax number of the healthcare provider;
(c) if applicable, the ABN (within the meaning of the A New Tax System (Australian Business Number) Act 1999) of the healthcare provider;
(d) if applicable, the ACN (within the meaning of the Corporations Act 2001) of the healthcare provider;
(e) other information that is prescribed by the regulations for the purpose of this paragraph.
(3) Each of the following is identifying information of a healthcare recipient, if the service operator requires it for the purpose of performing the service operator’s functions under this Act in relation to the healthcare recipient:
(a) if applicable, the Medicare number of the healthcare recipient;
(b) if applicable, the Veterans’ Affairs Department file number of the healthcare recipient;
(c) the name of the healthcare recipient;
(d) the address of the healthcare recipient;
(e) the date of birth, and the date of birth accuracy indicator, of the healthcare recipient;
(f) the sex of the healthcare recipient;
(g) for a healthcare recipient who was part of a multiple birth—the order in which the healthcare recipient was born;
Example: The 2nd of twins.
(h) if applicable, the date of death, and the date of death accuracy indicator, of the healthcare recipient;
(i) other information that is prescribed by the regulations for the purpose of this paragraph.
#### 7A Meaning of health administration
(1) In this Act, health administration means any of the following:
(a) the creation and maintenance of a record about healthcare or support services provided to a healthcare recipient;
(b) assessing a healthcare recipient’s level of, need for or access to healthcare or support services;
(c) monitoring an individual’s level of, need for or access to healthcare or health programs or support services;
(d) reporting on an individual’s level of, need for or access to healthcare or health programs or support services;
(e) verifying healthcare identifiers and identifying information, including for the purposes of providing healthcare or support services;
(f) the creation and maintenance of a record about any of the following:
(i) a healthcare recipient’s participation in health related programs;
(ii) support services that are being, are to be, or have been provided to a healthcare recipient;
(g) the governance and operation of health and health related programs and registries, including oversight, reporting, administration, complaints handling, billing and payment of costs or claims associated with the provision of healthcare and support services;
(h) health surveillance activities including, but not limited to, contact tracing, and monitoring, analysing and disseminating data for the purposes of implementing public health responses;
(i) monitoring or analysis (or both) of individual or system‑wide healthcare or support services needs, demands, performance and outcomes, including, but not limited to the following:
(i) by means of statistical research, data and reporting services;
(ii) to inform health workforce planning and management;
(iii) for other population health purposes;
(iv) to inform reporting on, or responses to, an adverse health event;
(j) linking or connecting data about healthcare recipients and or healthcare providers across different data sets.
(2) For the purposes of subparagraph (1)(i)(iv), an adverse health event is an event, act or omission related to the provision of healthcare to a healthcare recipient that results in, may result in, or could have resulted in, an unintended or harmful effect on the safety, health or welfare of the healthcare recipient.
#### 7B Minister may determine health administration entities
(1) The Minister may determine, in writing, that an entity, or an entity included in a class of entities, is a health administration entity.
(2) A determination made under subsection (1) is a legislative instrument.
(3) Before the Minister makes a determination under subsection (1), the Minister must consult an appropriate subcommittee of the Ministerial Council.
(4) A failure to consult does not affect the validity of the determination.
(5) The Minister may, in writing, delegate the power to make a determination under subsection (1) to:
(a) the Secretary of the Department; or
(b) an SES employee, or acting SES employee, in the Department.
(6) In exercising any powers under a delegation under this section, the delegate must comply with any directions of the Minister.
> Note: Sections 34AA to 34A of the Acts Interpretation Act 1901 contain provisions relating to delegations.
#### 8 Meaning of national registration authority
A national registration authority is a registration authority that is prescribed by the regulations for the purposes of this section.
## Part 2—Assigning healthcare identifiers
#### 9AA Simplified outline of this Part
Healthcare identifiers are assigned to healthcare recipients, individual healthcare providers, healthcare provider organisations and healthcare support service providers.
The service operator assigns healthcare identifiers to healthcare recipients. A national registration authority will usually assign a healthcare identifier to an individual healthcare provider, although there are a number of cases in which a healthcare provider is not registered by such an authority. In those cases, the healthcare identifier is assigned by the service operator. The service operator assigns a healthcare identifier to a healthcare provider organisation.
For a healthcare provider organisation to be assigned a healthcare identifier, the organisation must have at least one employee who is an individual healthcare provider providing healthcare as part of his or her duties, a responsible officer and an organisation maintenance officer. The responsible officer may also be the organisation maintenance officer. If the organisation is part of, or subordinate to, another healthcare provider organisation, it need not have its own responsible officer.
For a healthcare support service provider to be assigned a healthcare identifier, the provider must not otherwise be eligible, must have a responsible officer and must meet any other prescribed requirements.
A sole practitioner may be registered as a healthcare provider organisation.
If the service operator refuses to assign a healthcare identifier, a person whose interests are affected by the decision may ask the service operator to reconsider the decision. A person may apply to the Administrative Review Tribunal for review of the service operator’s reconsidered decision.
The service operator must keep a record of the healthcare identifiers assigned, and other information relating to the healthcare identifiers including details of requests to the service operator to disclose a healthcare identifier.
#### 9 Assigning healthcare identifiers
(1) The service operator is authorised to assign a number (a healthcare identifier) to uniquely identify:
(a) a healthcare provider to whom section 9A or 9BA applies; or
(b) a healthcare recipient.
(2) A national registration authority is authorised to assign a number (a healthcare identifier) to uniquely identify a healthcare provider, if:
(a) the healthcare provider is an individual who is a member of a particular health profession; and
(b) the national registration authority is responsible under a law for registering members of that health profession.
(3) The types of healthcare identifiers include:
(a) an identifier that is assigned to an individual healthcare provider; and
(b) an identifier that is assigned to a healthcare provider organisation; and
(ba) an identifier that is assigned to a healthcare support service provider; and
(c) an identifier that is assigned to a healthcare recipient.
> Note: A sole practitioner may be assigned:
(a) a healthcare identifier of the type mentioned in paragraph (3)(a); and
(b) a different healthcare identifier of the type mentioned in paragraph (3)(b).
(4) In exercising a power under subsection (1), the service operator is not required to consider whether a healthcare provider or healthcare recipient agrees to having a healthcare identifier assigned to the healthcare provider or healthcare recipient.
(6) A healthcare identifier of a healthcare recipient or of an individual healthcare provider is a government related identifier for the purposes of the Privacy Act 1988.
#### 9A Classes of healthcare provider that may be assigned a healthcare identifier by the service operator—individual healthcare providers and healthcare provider organisations
Healthcare identifiers for individual healthcare providers
(1) The service operator may, under paragraph 9(1)(a), assign a healthcare identifier to an individual healthcare provider if:
(a) the individual healthcare provider is registered by a registration authority as a member of a health profession; or
(b) the individual healthcare provider is represented by a professional body through which the individual healthcare provider is:
(i) provided with the credentials required to practice the healthcare profession, having regard to the admission requirements and tertiary qualifications set by the professional body, which must be a qualification at level 7 or above of the Australian Qualifications Framework (within the meaning of the Higher Education Support Act 2003) or at an equivalent level prescribed by the regulations; and
(ii) regulated and subject to oversight by the professional body that satisfies the requirements of subsection (11); or
(c) the individual healthcare provider is included in a class of individual healthcare providers prescribed by the regulations.
Healthcare identifiers for a healthcare provider organisation that is a seed organisation, or is not part of a network
(2) The service operator may, under paragraph 9(1)(a), assign a healthcare identifier to a healthcare provider organisation that is a seed organisation for a network, or that is not part of a network, if:
(a) at least one of the linked individual healthcare providers of the organisation is an individual who:
(i) is an identified healthcare provider; and
(ii) provides healthcare as part of his or her duties or with the support, or using the facilities, of the organisation; and
(b) one, and only one of the employees of the organisation is the responsible officer for the organisation; and
(c) either:
(i) the organisation has at least one other employee who is an organisation maintenance officer for the organisation; or
(ii) the responsible officer for the organisation is also the organisation maintenance officer for the organisation.
Healthcare identifiers for network organisations
(3) The service operator may, under paragraph 9(1)(a), assign a healthcare identifier to a healthcare provider organisation that is a network organisation within a network if:
(a) the seed organisation for the network:
(i) has been assigned a healthcare identifier that has not been retired; and
(ii) does not object to the network organisation being assigned a healthcare identifier under this subsection; and
(b) the responsible officer for the seed organisation for the network is also the responsible officer for every network organisation within the network; and
(c) there is an organisation maintenance officer for the network organisation; and
(d) the organisation maintenance officer for the network organisation is:
(i) an employee of the network organisation (the first network organisation); or
(ii) an employee of the seed organisation for the network; or
(iii) an employee of another network organisation within the network that is hierarchically superior to the first network organisation.
What is a network of healthcare provider organisations?
(4) A network of healthcare provider organisations is a group of healthcare provider organisations each of which satisfies one of the following criteria:
(a) the healthcare provider organisation is part of, or subordinate to, another healthcare provider organisation within the group;
(b) another healthcare provider organisation within the group is part of, or subordinate to, the healthcare provider organisation.
What is the seed organisation for a network?
(5) A healthcare provider organisation is the seed organisation for a network if:
(a) there is at least one other healthcare provider organisation that is part of, or subordinate to, the organisation; and
(b) the organisation is not itself part of, or subordinate to, another healthcare provider organisation.
What is a network organisation within a network?
(6) A healthcare provider organisation is a network organisation within a network if it is part of, or subordinate to, another healthcare provider organisation within the network.
Responsible officers
(7) A person is the responsible officer for a healthcare provider organisation if the duties of the person include the following:
(a) nominating the organisation maintenance officer or officers for the organisation to the service operator;
(b) requesting the assignment or retirement of a healthcare identifier for the organisation;
(c) if there is a network organisation of the organisation:
(i) nominating the organisation maintenance officer for the network organisation to the service operator; and
(ii) requesting the assignment or retirement of a healthcare identifier for the network organisation;
(d) if the organisation is part of a merger or acquisition—requesting the merger or reconfiguration of a healthcare identifier for the organisation.
Organisation maintenance officers
(8) A person is an organisation maintenance officer for a healthcare provider organisation if the duties of the person include the following:
(a) nominating to the service operator at least one additional person to be an organisation maintenance officer of the organisation, if required;
(b) maintaining information that is held by the service operator about the organisation;
(d) providing any other information requested by the service operator about the organisation for which the organisation maintenance officer is responsible;
(e) if the organisation (the seed organisation) has a network organisation:
(i) nominating to the service operator another person who meets the employment criteria in paragraph (3)(d) to be the organisation maintenance officer for the network organisation—either on the initiative of the seed organisation or if required by the service operator to do so;
(ii) requesting the assignment or retirement of a healthcare identifier for the network organisation;
(iii) maintaining information that is held by the service operator about the network organisation;
(v) providing any other information requested by the service operator about the network organisation for which the organisation maintenance officer is responsible;
(vi) if the network organisation is part of a merger or acquisition—requesting the merger or reconfiguration of a healthcare identifier for the organisation.
Sole practitioners
(9) The service operator may assign a healthcare identifier under paragraph 9(1)(a) to a healthcare provider organisation that is a sole practitioner even though subsection (2) is not satisfied, if the sole practitioner:
(a) provides healthcare as part of his or her duties; and
(ab) has been assigned an individual healthcare provider identifier:
(i) under paragraph 9(1)(a) on the basis of subsection 9A(1); or
(ii) under subsection 9(2); and
(b) performs the duties of a responsible officer and organisation maintenance officer.
Duties of the responsible officer performed by another person
(10) For the purposes of subsection (7), a person does not cease to be a responsible officer for a healthcare provider organisation if a duty mentioned in subsection (7) is performed by another employee of the organisation on behalf of the person.
When a professional body satisfies requirements
(11) In order for a professional body to satisfy the requirements of this subsection as mentioned in subparagraph (1)(b)(ii), regulation or oversight must at a minimum include all of the following in relation to individuals whose credentials are provided by the professional body:
(a) requirements for such individuals to comply with the standards of practice and ethical conduct set by the professional body and expected of such individuals;
(b) requirements for such individuals to comply with any written constitution, rules, articles of association, by‑laws or codes of conduct;
(c) requirements for such individuals to maintain professional skills and knowledge by continuing professional development;
(d) the ability for the professional body to impose sanctions on such individuals for a contravention of a requirement mentioned in paragraph (a), (b) or (c).
#### 9BA Classes of healthcare provider that may be assigned a healthcare identifier by the service operator—healthcare support service providers
(1) The service operator may, under paragraph 9(1)(a), assign a healthcare identifier to a healthcare support service provider if the service operator is satisfied that:
(a) the healthcare support service provider is not otherwise eligible to be assigned a healthcare provider identifier under that paragraph on the basis of subsection 9A(2), (3) or (9); and
(b) the healthcare support service provider has a responsible officer; and
(c) the healthcare support service provider meets any other requirements that are prescribed by the regulations.
Responsible officers for healthcare support service providers
(2) A person is the responsible officer for a healthcare support service provider if the person is authorised to act on behalf of the healthcare support service provider in performing the following duties:
(a) nominating the organisation maintenance officer or officers for the healthcare support service provider to the service operator;
(b) requesting the assignment, retirement, merger or reconfiguration of a healthcare identifier for the healthcare support service provider;
(c) any other duties of a responsible officer for the healthcare support service provider.
Organisation maintenance officers for healthcare support service providers
(3) A person is an organisation maintenance officer for a healthcare support service provider if the person has been nominated by the responsible officer for the healthcare support service provider, as mentioned in paragraph (2)(a), to perform the following duties:
(a) nominating to the service operator at least one additional person to be an organisation maintenance officer of the healthcare support service provider, if required;
(b) maintaining information that is held by the service operator about the healthcare support service provider;
(d) providing any other information requested by the service operator about the healthcare support service provider for which the organisation maintenance officer is responsible.
Duties of the responsible officer performed by another person
(4) A person does not cease to be a responsible officer for a healthcare support service provider if a duty mentioned in subsection (2) is performed by another employee of the provider on behalf of the person.
#### 9B Information that may be requested before assigning healthcare identifiers
(1) The service operator may request an individual healthcare provider to provide the following information before assigning the healthcare provider a healthcare identifier:
(a) identifying information of the healthcare provider;
Note: Identifying information is defined in section 7.
(b) information that shows that section 9A applies to the healthcare provider.
(2) The service operator may request a healthcare provider organisation or a healthcare support service provider to provide the following information before assigning the healthcare provider a healthcare identifier:
(a) identifying information of the healthcare provider;
Note: Identifying information is defined in section 7.
(b) information that shows that section 9A or 9BA applies to the healthcare provider;
(c) information identifying the healthcare provider’s responsible officer and organisation maintenance officer, including the person’s name, work address, work email address, work telephone number or work fax number.
(3) The healthcare provider must give the information in any form requested by the service operator.
> Note: Example: A healthcare provider may be asked for original documentation, or for the information to be given in writing or in a statutory declaration.
(4) If the service operator is not satisfied by the information given, it does not have to assign a healthcare identifier to the healthcare provider.
#### 9CA Professional bodies may facilitate the assignment of healthcare identifiers for individual healthcare providers
(1) A professional body may:
(a) facilitate the assignment of healthcare identifiers for individual healthcare providers who are provided with credentials by the professional body; and
(b) assist the service operator to establish and maintain a record of a kind mentioned in section 10.
(2) A professional body must not facilitate the assignment of a healthcare identifier for an individual healthcare provider, or assist the service operator in relation to such a healthcare identifier, unless the provider has consented to the facilitation and assistance.
(3) The regulations may make provision for and in relation to the facilitation by professional bodies of the assignment of healthcare identifiers, and assisting the service operator to establish and maintain a record of a kind mentioned in section 10, including, but not limited to, as follows:
(a) specifying requirements in relation to obtaining the consent of individual healthcare providers in relation to that facilitation, and ensuring the maintenance of that consent;
(b) specifying requirements relating to ensuring that information held by the service operator is accurate.
#### 9C Review of decision not to assign a healthcare identifier
(1) This section applies to a decision by the service operator not to assign a healthcare identifier to a healthcare provider under paragraph 9(1)(a).
> Note: This section does not apply to a decision to assign a healthcare identifier to a healthcare recipient under paragraph 9(1)(b), or a decision by a national registration authority not to assign a healthcare identifier to an individual healthcare provider under subsection 9(2).
(2) The service operator must give written notice of the decision to a person whose interests are affected by the decision, including a statement:
(a) that the person may apply to the service operator to reconsider the decision; and
(b) of the person’s rights to seek review under subsection (8) of a reconsidered decision.
(3) A failure of the service operator to comply with subsection (2) does not affect the validity of the decision.
(4) A person whose interests are affected by the decision may, by written notice to the service operator within 28 days after receiving notice of the decision, ask the service operator to reconsider the decision.
(5) A request under subsection (4) must mention the reasons for making the request.
(6) The service operator must:
(a) reconsider the decision within 28 days after receiving the request; and
(b) give to the person who requested the reconsideration written notice of the result of the reconsideration and of the grounds for the result.
(7) The notice must include a statement that the person may apply to the Administrative Review Tribunal for review of the reconsideration.
(8) A person may apply to the Administrative Review Tribunal for a review of a decision of the service operator made under subsection (6).
#### 10 Service operator must keep record of healthcare identifiers etc.
The service operator must establish and maintain an accurate record of:
(a) healthcare identifiers that have been assigned; and
(b) the information that the service operator has that relates to those healthcare identifiers, including details of requests made to the service operator for the service operator to disclose those healthcare identifiers under Division 2 or 3 of Part 3.
## Part 3—Collection, use and disclosure of healthcare identifiers, identifying information and other information
### Division 1—Simplified outline of this Part
#### 11 Simplified outline of this Part
This Part authorises the collection, use and disclosure of healthcare identifiers, identifying information and other information.
Healthcare identifiers and other information relating to healthcare recipients
The service operator may collect information about a healthcare recipient from various sources for the purpose of assigning a healthcare identifier to the recipient. Once a healthcare identifier is assigned to a healthcare recipient, the service operator may disclose it to healthcare providers and health administration entities to assist in communicating and managing health information or for the purposes of health administration. The healthcare identifier may also be disclosed to other entities to assist in the operation of the My Health Record system.
A healthcare provider or health administration entity can obtain the healthcare identifier of a healthcare recipient from the service operator to communicate and manage health information or for the purposes of health administration. The healthcare provider or health administration entity can use the healthcare identifier in providing healthcare or in health administration, for example, by using it for a purpose related to the My Health Record system.
Healthcare identifiers and other information relating to healthcare providers
Under Part 2, the service operator must keep a record of the healthcare identifiers that have been assigned and other information relating to healthcare identifiers. As a national registration authority assigns healthcare identifiers to most healthcare providers, the service operator may obtain information for the record from a national registration authority.
Under Part 2, the service operator assigns healthcare identifiers to healthcare providers in a number of cases. The service operator may collect information about a healthcare provider from various sources for the purposes of assigning those identifiers.
The service operator may disclose the healthcare identifiers of healthcare providers to healthcare providers and healthcare administration entities to assist in communicating and managing health information for health administration purposes. The healthcare identifier may also be disclosed to other entities to assist in the operation of the My Health Record system.
A healthcare provider or health administration entity can obtain the healthcare identifier of a healthcare provider from the service operator, to communicate and manage health information or for the purposes of health administration. This includes the use of the identifier in electronic transmissions. The collection, use and disclosure of identifying information and healthcare identifiers is permitted for the purposes of authenticating a healthcare provider’s identity in electronic transmissions.
A person must not use or disclose information collected for the purposes of the Act or healthcare identifiers, except where required or authorised to do so under the Act or in other limited circumstances. Criminal and civil penalties apply if this obligation is breached.
### Division 2—Healthcare recipients
#### 12 Collection, use and disclosure—assigning a healthcare identifier to a healthcare recipient
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of assigning a healthcare identifier to a healthcare recipient</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:52.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identified healthcare provider</span></p><p class="Tabletext"><span>health administration entity</span></p></td><td style="width:74.25pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of assisting the service operator to assign a healthcare identifier to the healthcare recipient</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>Chief Executive Medicare</span></p><p class="Tabletext"><span>Veterans’ Affairs Department</span></p><p class="Tabletext"><span>Defence Department</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of assisting the service operator to assign a healthcare identifier to the healthcare recipient</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>3</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from:</span></p><p class="Tablea"><span>(a) an identified healthcare provider; or</span></p><p class="Tablea"><span>(aa) a health administration entity; or</span></p><p class="Tablea"><span>(b) the Chief Executive Medicare; or</span></p><p class="Tablea"><span>(c) the Veterans’ Affairs Department; or</span></p><p class="Tablea"><span>(d) the Defence Department</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection or use is for the purpose of assigning a healthcare identifier to a healthcare recipient</span></p></td></tr></tbody></table>
```
#### 13 Collection, use and disclosure—establishing and maintaining a record of healthcare identifiers for healthcare recipients
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of establishing and maintaining a record of healthcare identifiers for healthcare recipients</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:52.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>any entity that has access to the healthcare identifier of a healthcare recipient</span></p></td><td style="width:74.25pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of the healthcare recipient</span></p><p class="Tabletext"><span>information that relates to the healthcare identifier of the healthcare recipient</span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purposes of assisting the service operator to establish and maintain a record mentioned in section</span><span> </span><span>10 (a record of healthcare identifiers assigned and other matters, such as requests made to the service operator to disclose those identifiers)</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from any entity that has access to the healthcare identifier of a healthcare recipient</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of the healthcare recipient</span></p><p class="Tabletext"><span>information that relates to the healthcare identifier of the healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection or use is for the purposes of establishing and maintaining a record mentioned in section</span><span> </span><span>10 (a record of healthcare identifiers assigned and other matters, such as requests made to the service operator to disclose those identifiers)</span></p></td></tr></tbody></table>
```
#### 14 Collection, use and disclosure—providing healthcare to a healthcare recipient
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of providing healthcare to a healthcare recipient</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:52.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identified healthcare provider</span></p><p class="Tabletext"><span>health administration entity</span></p></td><td style="width:74.25pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare recipient</span></p><p class="Tabletext"><span></span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of assisting the service operator to disclose the healthcare identifier of the healthcare recipient to the healthcare provider or health administration entity</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from an identified healthcare provider or health administration entity</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to an identified healthcare provider or health administration entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is for the purpose of disclosing the healthcare identifier of the healthcare recipient to the healthcare provider or health administration entity</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>3</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to an identified healthcare provider or health administration entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of:</span></p><p class="Tablea"><span>(a) communicating or managing health information, or information about support services, as part of providing healthcare or support services to the healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>4</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identified healthcare provider</span></p><p class="Tabletext"><span>health administration entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from the service operator</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection is for the purpose of:</span></p><p class="Tablea"><span>(a) communicating or managing health information, or information about support services, as part of providing healthcare or support services to the healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>5</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identified healthcare provider</span></p><p class="Tabletext"><span>health administration entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from another entity</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to another entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare recipient</span></p><p class="Tabletext"><span>identifying information of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>The collection, use or disclosure is for the purpose of:</span></p><p class="Tablea"><span>(a) communicating or managing health information, or information about support services, as part of providing healthcare or support services to the healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration; or</span></p><p class="Tablea"><span>(c) the provision of indemnity cover for a healthcare provider; or</span></p><p class="Tablea"><span>(d) communicating or managing health information or information about support services provided to a healthcare recipient, as part of the conduct of research that has been approved by a Human Research Ethics Committee</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>6</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>entity to whom healthcare identifier of a healthcare recipient is disclosed for a purpose mentioned in column 4 of item</span><span> </span><span>5</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare recipient</span></p><p class="Tabletext"><span>identifying information of a healthcare recipient</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is for the purpose for which the information was disclosed</span></p></td></tr></tbody></table>
```
#### 15 Collection, use and disclosure—My Health Record system
The service operator is authorised to collect, use and disclose:
(a) identifying information of a healthcare recipient, an authorised representative of a healthcare recipient or a nominated representative of a healthcare recipient; and
(b) the healthcare identifier of a healthcare recipient, an authorised representative of a healthcare recipient or a nominated representative of a healthcare recipient;
for the purposes of the My Health Record system.
#### 15A Collection, use and disclosure—research
An entity may collect, use or disclose the healthcare identifier of a healthcare recipient if:
(a) the collection, use or disclosure is for the purpose of assisting the entity to conduct research that has been approved by a Human Research Ethics Committee or is authorised by another Australian law; and
(b) the healthcare recipient has consented to the collection, use or disclosure.
#### 17 Adopting the healthcare identifier of a healthcare recipient etc.—general
An entity mentioned in column 1 of an item of the following table, may adopt the healthcare identifier of a healthcare recipient, an authorised representative of a healthcare recipient or a nominated representative of a healthcare recipient, for a purpose mentioned in column 2 of the item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="3" style="width:343.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Adopting the healthcare identifier of a healthcare recipient</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Purpose</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:148.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare provider</span></p></td><td style="width:148.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>for use as the healthcare provider’s own identifier of the healthcare recipient, the authorised representative of a healthcare recipient or the nominated representative of a healthcare recipient</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>My Health Record System Operator</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>for use as the My Health Record System Operator’s own identifier for the purposes of the My Health Record system</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>3</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>registered repository operator</span></p><p class="Tabletext"><span>registered portal operator</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>for use as that operator’s own identifier for the purposes of the My Health Record system</span></p></td></tr></tbody></table>
```
#### 17A Adopting the healthcare identifier of a healthcare recipient—health administration entities
A health administration entity may adopt the healthcare identifier of a healthcare recipient for use as the health administration entity’s own identifier.
#### 18 Disclosure of the healthcare identifier of a healthcare recipient to the healthcare recipient etc.
Any of the following entities may disclose the healthcare identifier of a healthcare recipient to the healthcare recipient, or a responsible person (within the meaning of the Privacy Act 1988) for the healthcare recipient:
(a) the service operator;
(b) the My Health Record System Operator;
(c) a healthcare provider;
(d) a health administration entity.
#### 19 Other information relating to the healthcare identifier of a healthcare recipient may be disclosed by the service operator
The service operator may disclose information included in the record the service operator maintains under section 10 in relation to a healthcare recipient to:
(a) the healthcare recipient; or
(b) a responsible person (within the meaning of the Privacy Act 1988) for the healthcare recipient.
#### 20 Regulations relating to the healthcare identifier and identifying information of a healthcare recipient etc.
Collection, use or disclosure for other purposes
(1) The regulations may authorise the collection, use or disclosure of the following information:
(a) identifying information of a healthcare recipient, authorised representative of a healthcare recipient or nominated representative of a healthcare recipient;
(b) the healthcare identifier of a healthcare recipient, authorised representative of a healthcare recipient or nominated representative of a healthcare recipient.
Adoption for other purposes
(2) The regulations may authorise the adoption of the healthcare identifier of a healthcare recipient, authorised representative of a healthcare recipient or a nominated representative of healthcare recipient in the circumstances prescribed by the regulations.
Purposes for which regulation‑making powers in subsections (1) and (2) may be used
(3) However, the regulations may only authorise the collection, use, disclosure or adoption of that information for purposes related to one or more of the following:
(a) providing healthcare to healthcare recipients, or a class of healthcare recipients;
(b) determining whether adequate and appropriate healthcare is available to healthcare recipients, or a class of healthcare recipients;
(c) facilitating the provision of adequate and appropriate healthcare to healthcare recipients, or a class of healthcare recipients;
(d) assisting persons who, because of health issues (including illness, disability or injury), require support;
(e) the My Health Record system.
Procedures relating to the disclosure of healthcare identifiers
(4) The regulations may prescribe rules about the process for disclosing the healthcare identifiers of healthcare recipients, including rules about requests to the service operator to disclose healthcare identifiers of healthcare recipients.
(4A) Without limiting subsection (4), the regulations may prescribe rules about requirements that must be complied with, including any requirements specified in a data standard:
(a) before a request may be made to the service operator to disclose the healthcare identifier of a healthcare recipient; or
(b) if the service operator discloses a healthcare identifier of a healthcare recipient.
Information about disclosures by service operator
(5) If the service operator discloses a healthcare identifier of a healthcare recipient to an entity, the regulations may require the entity to provide prescribed information to the service operator in relation to the disclosure.
### Division 3—Healthcare providers
#### 21 Collection, use and disclosure—assigning a healthcare identifier to a healthcare provider
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of assigning a healthcare identifier to a healthcare provider</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:52.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from:</span></p><p class="Tablea"><span>(a) the Chief Executive Medicare; or</span></p><p class="Tablea"><span>(b) the Veterans’ Affairs Department; or</span></p><p class="Tablea"><span>(c) the Defence Department</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection or use is:</span></p><p class="Tablea"><span>(a) for the purpose of assigning a healthcare identifier to the healthcare provider; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>Chief Executive Medicare</span></p><p class="Tabletext"><span>Veterans’ Affairs Department</span></p><p class="Tabletext"><span>Defence Department</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purpose of assisting the service operator to assign a healthcare identifier to the healthcare provider; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>3</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from a healthcare provider</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>information requested by the service operator under section</span><span> </span><span>9B</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection or use is:</span></p><p class="Tablea"><span>(a) for the purpose of assigning a healthcare identifier to the healthcare provider; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>4</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>a registration authority</span></p><p class="Tabletext"><span>a professional body</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from the service operator</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator or a healthcare provider</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purpose of assigning a healthcare identifier to the healthcare provider; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>5</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from a registration authority or a professional body</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the registration authority or a professional body</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purpose of assigning a healthcare identifier to the healthcare provider; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>6</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>Aged Care Department</span></p><p class="Tabletext"><span>National Disability Insurance Agency</span></p><p class="Tabletext"><span>an entity prescribed by the regulations</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>disclose to the service operator</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare support service provider</span></p><p class="Tabletext"><span>identifying information of a healthcare support service provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purpose of assisting the service operator to assign a healthcare identifier to the healthcare support service provider; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>7</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>Service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from the Aged Care Department, the National Disability Insurance Agency or an entity prescribed by the regulations</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare support service provider</span></p><p class="Tabletext"><span>identifying information of a healthcare support service provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection or use is:</span></p><p class="Tablea"><span>(a) for the purpose of assisting the service operator to assign a healthcare identifier to the healthcare support service provider; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr></tbody></table>
```
#### 22 Collection, use and disclosure—establishing and maintaining a record of healthcare identifiers for healthcare providers
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of establishing and maintaining a record of healthcare identifiers for healthcare providers</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:52.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>a national registration authority</span></p></td><td style="width:74.25pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span>information that relates to the healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purposes of assisting the service operator to establish and maintain a record mentioned in section</span><span> </span><span>10 (a record of healthcare identifiers assigned and other matters, such as requests made to the service operator to disclose those identifiers); or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1A</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>a professional body</span></p><p class="Tabletext"><span>a registration authority</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from the service operator</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span>information that relates to the healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purposes of assisting the service operator to establish and maintain a record mentioned in section</span><span> </span><span>10 (a record of healthcare identifiers assigned and other matters, such as requests made to the service operator to disclose those identifiers); or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from a registration authority or a professional body</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span>information that relates to the healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection or use is:</span></p><p class="Tablea"><span>(a) for the purposes of assisting the service operator to establish and maintain a record mentioned in section</span><span> </span><span>10 (a record of healthcare identifiers assigned and other matters, such as requests made to the service operator to disclose those identifiers); or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>4</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>Service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from the Aged Care Department, the National Disability Insurance Agency or an entity prescribed by the regulations</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare support service provider</span></p><p class="Tabletext"><span>identifying information of a healthcare support service provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purposes of assisting the service operator to establish and maintain a record mentioned in section</span><span> </span><span>10 (a record of healthcare identifiers assigned and other matters, such as requests made to the service operator to disclose those identifiers)</span></p></td></tr></tbody></table>
```
#### 23 Collection, use and disclosure—providing healthcare
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of providing healthcare</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:52.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identified healthcare provider</span></p><p class="Tabletext"><span>health administration entity</span></p></td><td style="width:74.25pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of:</span></p><p class="Tablea"><span>(a) assisting the healthcare provider to communicate or manage health information or information about support services, as part of providing healthcare or support services to a healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from an identified healthcare provider or a health administration entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection is for the purpose of:</span></p><p class="Tablea"><span>(a) assisting the healthcare provider to communicate or manage health information or information about support services, as part of providing healthcare or support services to a healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>3</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to an identified healthcare provider or a health administration entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of:</span></p><p class="Tablea"><span>(a) assisting the healthcare provider to communicate or manage health information or information about support services, as part of providing healthcare or support services to a healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>4</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identified healthcare provider</span></p><p class="Tabletext"><span>health administration entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from the service operator</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of:</span></p><p class="Tablea"><span>(a) assisting the healthcare provider to communicate or manage health information or information about support services, as part of providing healthcare or support services to a healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>5</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identified healthcare provider</span></p><p class="Tabletext"><span>health administration entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to another entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is for the purpose of:</span></p><p class="Tablea"><span>(a) communicating or managing health information or information about support services, as relating to healthcare or support services to a healthcare recipient; or</span></p><p class="Tablea"><span>(b) health administration; or</span></p><p class="Tablea"><span>(c) the provision of indemnity cover for a healthcare provider; or</span></p><p class="Tablea"><span>(d) communicating or managing health information or information about support services provided to a healthcare recipient, as part of the conduct of research that has been approved by a Human Research Ethics Committee or under another Australian law</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>6</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>an entity to which the healthcare identifier of a healthcare provider has been disclosed under item</span><span> </span><span>5</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to another entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span>identifying information of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is for the purpose for which the information was disclosed under column 4 of item</span><span> </span><span>5</span></p></td></tr></tbody></table>
```
#### 24 Collection, use and disclosure—My Health Record system
The service operator is authorised to collect, use and disclose:
(a) identifying information of a healthcare provider; and
(b) the healthcare identifier of a healthcare provider;
for the purposes of the My Health Record system.
#### 25 Collection, use and disclosure—enabling authentication in electronic communications
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of facilitating electronic communications</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:66.65pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:60.1pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:66.65pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p><p class="Tabletext"><span>registration authority</span></p></td><td style="width:60.1pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to any entity</span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of enabling the healthcare provider’s identity to be authenticated in electronic transmissions</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:66.65pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>an entity to whom information is disclosed for the purposes of enabling a healthcare provider’s identity to be authenticated in electronic communications</span></p></td><td style="width:60.1pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from any entity</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to any entity</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is for the purpose of enabling the healthcare provider’s identity to be authenticated in electronic transmissions</span></p></td></tr></tbody></table>
```
#### 25A Collection, use and disclosure—sharing information with registration authorities
An entity mentioned in column 1 of an item of the following table, is authorised to take action of the kind described in column 2 of that item with information of the kind described in column 3 of that item in the circumstances described in column 4 of that item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="5" style="width:343.35pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Collection, use and disclosure for the purpose of sharing information with registration authorities</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Permitted action</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 3</span></p><p class="TableHeading"><span>Information</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 4</span></p><p class="TableHeading"><span>Circumstances</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:52.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to a registration authority</span></p><p class="Tablea"><span></span></p></td><td style="width:60.05pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p><p class="Tabletext"><span></span></p></td><td style="width:88.45pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the use or disclosure is for the purpose of assisting the registration authority to register the healthcare provider</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>registration authority</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect</span></p><p class="Tabletext"><span>use</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection or use is for one of the following purposes:</span></p><p class="Tablea"><span>(a) registering the healthcare provider;</span></p><p class="Tablea"><span>(b) performing any other function of the registration authority under an Australian law</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>3</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>service operator</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from a registration authority or professional body</span></p><p class="Tablea"><span>use</span></p><p class="Tabletext"><span>disclose to a registration authority or professional body</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purpose of ensuring that information held by the service operator, the registration authority or the professional body is accurate, up</span><span>‑</span><span>to</span><span>‑</span><span>date and complete; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>4</span></p></td><td style="width:52.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>registration authority</span></p><p class="Tabletext"><span>professional body</span></p></td><td style="width:74.25pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>collect from the service operator</span></p><p class="Tabletext"><span>use</span></p><p class="Tabletext"><span>disclose to the service operator</span></p></td><td style="width:60.05pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>identifying information of a healthcare provider</span></p><p class="Tabletext"><span>healthcare identifier of a healthcare provider</span></p></td><td style="width:88.45pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>the collection, use or disclosure is:</span></p><p class="Tablea"><span>(a) for the purpose of ensuring that information held by the service operator, the registration authority or the professional body is accurate, up</span><span>‑</span><span>to</span><span>‑</span><span>date and complete; or</span></p><p class="Tablea"><span>(b) for a purpose relating to the Healthcare Provider Directory</span></p></td></tr></tbody></table>
```
#### 25B Adopting the healthcare identifier of a healthcare provider
An entity mentioned in column 1 of an item of the following table, may adopt the healthcare identifier of a healthcare provider for a purpose mentioned in column 2 of the item.
```html
<table cellspacing="0" cellpadding="0" style="margin-left:0.25pt; border-collapse:collapse"><thead><tr><td colspan="3" style="width:343.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Adopting the healthcare identifier of a healthcare provider</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Item</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 1</span></p><p class="TableHeading"><span>Entity</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="TableHeading"><span>Column 2</span></p><p class="TableHeading"><span>Purpose</span></p></td></tr></thead><tbody><tr><td style="width:24.9pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>1</span></p></td><td style="width:148.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>My Health Record System Operator</span></p><p class="Tabletext"><span></span></p></td><td style="width:148.5pt; border-top:1.5pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>for use as the My Health Record System Operator’s own identifier for the purposes of the My Health Record system</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>2</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>registered repository operator</span></p><p class="Tabletext"><span>registered portal operator</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:0.75pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>for use as that operator’s own identifier for the purposes of the My Health Record system</span></p></td></tr><tr><td style="width:24.9pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>3</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>a participant in the My Health Record system to whom the healthcare identifier is disclosed by a registered repository operator or a registered portal operator under section</span><span> </span><span>58A of the My Health Records Act</span></p></td><td style="width:148.5pt; border-top:0.75pt solid #000000; border-bottom:1.5pt solid #000000; padding-right:5.4pt; padding-left:5.4pt; vertical-align:top"><p class="Tabletext"><span>for use in authenticating the identity of the healthcare provider in electronic transmissions</span></p></td></tr></tbody></table>
```
#### 25C Disclosure of the healthcare identifier of a healthcare provider to the healthcare provider
Any entity who knows the healthcare identifier of a healthcare provider may disclose the healthcare identifier to the healthcare provider.
#### 25CA Collection, use and disclosure of the healthcare identifier of a healthcare provider organisation or healthcare support service provider
Any entity (including the service operator) may collect, use and disclose to another entity the healthcare identifier or identifying information of an identified healthcare provider organisation or an identified healthcare support service provider for the purpose of:
(a) communicating or managing health information, or information about support services, as part of providing healthcare or support services to a healthcare recipient; or
(b) health administration.
#### 25D Regulations relating to the healthcare identifier and other information of a healthcare provider
Collection, use or disclosure for other purposes
(1) The regulations may authorise the collection, use or disclosure of the following information:
(a) identifying information of a healthcare provider;
(b) the healthcare identifier of a healthcare provider.
Adoption for other purposes
(2) The regulations may authorise the adoption of the healthcare identifier of a healthcare provider in the circumstances prescribed by the regulations.
Purposes for which regulation‑making powers in subsections (1) and (2) may be used
(3) However, the regulations may only authorise the collection, use, disclosure or adoption of that information for purposes related to one or more of the following:
(a) providing healthcare to healthcare recipients, or a class of healthcare recipients;
(b) determining whether adequate and appropriate healthcare is available to healthcare recipients, or a class of healthcare recipients;
(c) facilitating the provision of adequate and appropriate healthcare to healthcare recipients, or a class of healthcare recipients;
(d) assisting persons who, because of health issues (including illness, disability or injury), require support;
(e) the My Health Record system.
Procedures relating to the disclosure of healthcare identifiers
(4) The regulations may prescribe rules about the process for disclosing the healthcare identifiers of healthcare providers, including rules about requests to the service operator to disclose healthcare identifiers of healthcare providers.
(4A) Without limiting subsection (4), the regulations may prescribe rules about requirements that must be complied with, including any requirements specified in a data standard:
(a) before a request may be made to the service operator to disclose the healthcare identifier of a healthcare provider; or
(b) if the service operator discloses a healthcare identifier of a healthcare provider.
Information about disclosures by service operator
(5) If the service operator discloses a healthcare identifier of a healthcare provider to an entity, the regulations may require the entity to provide prescribed information to the service operator in relation to the disclosure.
Information to be provided to the service operator about the healthcare identifier of a healthcare provider
(6) The regulations may require an identified healthcare provider to provide to the service operator information that:
(a) relates to the healthcare provider’s healthcare identifier; and
(b) is prescribed by the regulations for the purposes of this section.
#### 25E Obligation to keep information accurate, up‑to‑date and complete
(1) If a healthcare provider organisation or a healthcare support service provider becomes aware that information held by the service operator in relation to the organisation or provider is not accurate, up‑to‑date and complete, the organisation or provider must:
(a) give the service operator, in writing, accurate, up‑to‑date and complete information; and
(b) do so within 20 business days after the organisation or provider becomes aware that the information held by the service operator is not accurate, up‑to‑date and complete.
(2) Subsection (1) does not apply if:
(a) the information that is no longer accurate, up‑to‑date and complete is personal information that the service operator was only able to lawfully obtain with the consent of the person to whom the information relates; and
(b) instead of giving accurate, up‑to‑date and complete personal information within the period specified in that subsection, the healthcare provider organisation or healthcare support service provider notifies the service operator within that period, in the manner and form approved by the service operator, that the person to whom the information relates has withdrawn consent for the information to be given to the service operator.
(3) Subsection (1) does not apply if:
(a) the healthcare provider organisation, or an individual healthcare provider who is linked to the healthcare provider organisation, is required by an Australian law, or by a lawful requirement of the national registration authority, to give the national registration authority the accurate, up‑to‑date and complete information; and
(b) the healthcare provider organisation, or the individual healthcare provider, complies with the requirement.
(3A) Subsection (1) does not apply to a healthcare support service provider organisation if:
(a) the healthcare support service provider is required to give the accurate, up‑to‑date and complete information to any of the following:
(i) the National Disability Insurance Agency;
(ii) the Aged Care Department;
(iii) an entity prescribed by regulations made for the purposes of item 6 of the table in section 21; and
(b) the healthcare support service provider complies with the requirement.
(4) A person is liable to a civil penalty if:
(a) the person fails to give the service operator information in the circumstances mentioned in subsection (1); and
(b) the person knows or is reckless as to those circumstances.
Civil penalty: 100 penalty units.
### Division 4—Unauthorised use and disclosure of healthcare identifiers and other information obtained under this Act
#### 26 Use and disclosure of healthcare identifiers and other information obtained under this Act
(1) A person must not use or disclose information if:
(a) the person obtains the information in response to a request under section 9B; or
(b) the person obtains the information in the course of establishing or maintaining a record for the purposes of section 10 (a record of healthcare identifiers assigned and other matters, such as requests made to the service operator to disclose those identifiers); or
(c) the information is identifying information about an individual and the person obtains the information in circumstances covered by a requirement or authority under this Act; or
(d) the information is the healthcare identifier of a healthcare recipient or an individual healthcare provider.
(2) A person must not use or disclose information if the information is disclosed to the person in contravention of subsection (1).
(3) This section does not apply to the use or disclosure of a healthcare identifier if:
(a) the use or disclosure of the healthcare identifier is required or authorised under this Act; or
(b) the use or disclosure of the healthcare identifier is required or authorised under another Commonwealth law or a court/tribunal order; or
(c) the use or disclosure is:
(i) by the person to whom the healthcare identifier relates; and
(ii) for the purposes of, or in connection with, the personal, family or household affairs of that person (within the meaning of section 16 of the Privacy Act 1988); or
(d) a permitted general situation of the kind described in item 1, 2, 4 or 5 of the table in subsection 16A(1) of the Privacy Act 1988 exists in relation to the use or disclosure, or would exist if the person were an APP entity for the purposes of that Act; or
(e) without limiting the exceptions under this subsection, the use or disclosure is required or authorised by the Information Commissioner, or an equivalent officer or agency of a State or Territory, in exercising powers or performing functions in relation to privacy.
> Note: A defendant bears an evidential burden in relation to the matters in subsection (3): see subsection 13.3(3) of the Criminal Code.
(4) This section does not apply to the use or disclosure of information other than a healthcare identifier if:
(a) the use or disclosure of the information is required or authorised under this Act; or
(b) the use or disclosure of the information is required or authorised under another Australian law or a court/tribunal order; or
(c) the information is personal information and the use or disclosure would not be an interference with the privacy of the individual for the purposes of the Privacy Act 1988, or would not be an interference with the privacy of the individual for the purposes of that Act if the person were an agency or an organisation for the purposes of that Act; or
(d) without limiting the exceptions under this subsection, the use or disclosure is required or authorised by the Information Commissioner, or an equivalent officer or agency of a State or Territory, in exercising powers or performing functions in relation to privacy.
> Note: A defendant bears an evidential burden in relation to the matters in subsection (4): see subsection 13.3(3) of the Criminal Code.
(5) A person commits an offence if the person contravenes subsection (1) or (2).
Penalty: Imprisonment for 2 years or 120 penalty units, or both.
(6) A person is liable to a civil penalty if:
(a) the person uses or discloses information in circumstances under which the use or disclosure would contravene subsection (1) or (2); and
(b) the person knows or is reckless as to those circumstances.
Civil penalty: 600 penalty units.
### Division 5—Protection of healthcare identifiers
#### 27 Protection of healthcare identifiers
An entity must:
(a) take reasonable steps to protect healthcare identifiers the entity holds from:
(i) misuse and loss; and
(ii) unauthorised access, modification or disclosure; and
(b) comply with any requirements prescribed by the regulations for the protection of healthcare identifiers the entity holds.
> Note: The regulations may provide for the imposition of a penalty for contravention of a regulation: see subsection 39(2).
## Part 4—Interaction with the Privacy Act 1988
#### 28AA Simplified outline of this Part
If a person is authorised to collect, use or disclose information under this Act, the person will not interfere with the privacy of an individual for the purposes of the Privacy Act 1988 in doing so.
Section 26 imposes a higher standard of privacy in relation to healthcare identifiers than is imposed in relation to other information. If a person uses or discloses a healthcare identifier in circumstances that are not permitted under that section, the person will not only be subject to criminal and civil penalties. That action will also be an interference with privacy for the purposes of the Privacy Act 1988, and can be dealt with as such under that Act.
#### 28 Interaction with the Privacy Act 1988
An authorisation to collect, use or disclose a healthcare identifier or identifying information under this Act is also an authorisation to collect, use or disclose the healthcare identifier or identifying information for the purpose of the Privacy Act 1988.
#### 29 Functions of Information Commissioner
Breach of this Act is an interference with privacy
(1) An act or practice in connection with a healthcare identifier of a healthcare recipient or an individual healthcare provider that contravenes this Act or the regulations, or would contravene this Act or the regulations but for a requirement relating to state of mind, is taken to be:
(a) for the purposes of the Privacy Act 1988, an interference with the privacy of the healthcare recipient or individual healthcare provider; and
(b) covered by section 13 of that Act.
> Note: The act or practice may be the subject of a complaint under section 36 of that Act.
(2) For the purpose of applying Part V of that Act (Investigations) in relation to the act or practice, treat a State or Territory authority as if it were an organisation (within the meaning of that Act).
Assessment by Information Commissioner
(3) For the purpose of paragraph 33C(1)(a) of the Privacy Act 1988, a healthcare identifier of a healthcare recipient or of an individual healthcare provider is taken to be personal information.
#### 30 Annual reports by Information Commissioner
(1) The Information Commissioner must, as soon as practicable after the end of each financial year, prepare a report on the Information Commissioner’s compliance and enforcement activities under this Act during the financial year.
(2) The Information Commissioner must give a copy of the report to the Minister, and to the Ministerial Council, no later than on 30 September after the end of the financial year to which the report relates.
(3) The Minister must table a copy of the report in each House of Parliament within 15 sitting days after the Information Commissioner gives a copy of the report to the Minister.
## Part 5—Healthcare Provider Directory
#### 30A Simplified outline of this Part
The Healthcare Provider Directory is a directory available to healthcare providers to allow them to find information about other healthcare providers, such as:
(a) the healthcare identifier of a healthcare provider; and
(b) whether an individual healthcare provider is linked to a healthcare provider organisation; and
(c) whether a healthcare provider is registered under the My Health Record system; and
(d) whether a healthcare provider is registered with a registration authority and the status of that registration (such as whether it is conditional, suspended, cancelled or lapsed); and
(e) the type of healthcare provider that an individual is.
#### 31 Healthcare Provider Directory
(1) The Healthcare Provider Directory Operator must establish and maintain a record (the Healthcare Provider Directory) of the professional and business details of identified healthcare providers.
(2) The purposes of the Healthcare Provider Directory are the following:
(a) to make professional and business details of healthcare providers available to entities that are authorised to access the directory;
(b) to enable communication between entities that are authorised to access the directory and healthcare providers about:
(i) healthcare and support services; and
(ii) health administration;
(c) any other purpose prescribed by the regulations.
(3) Subject to subsection (8), the Healthcare Provider Directory may be kept in any form that the Healthcare Provider Directory Operator considers appropriate.
(3A) The Healthcare Provider Directory Operator is authorised to:
(a) collect and use the following information:
(i) a healthcare identifier of an identified healthcare provider;
(ii) identifying information of an identified healthcare provider;
(iii) professional and business details of an identified healthcare provider;
for the purposes of the Healthcare Provider Directory; and
(b) disclose that information on the Healthcare Provider Directory to the following:
(i) an identified individual healthcare provider;
(ii) an identified healthcare provider organisation;
(iii) a health administration entity;
(iv) an entity prescribed by the regulations;
for the purposes of the Healthcare Provider Directory.
(3B) The service operator is authorised to disclose the following information to the Healthcare Provider Directory Operator for the purposes of the Healthcare Provider Directory:
(a) a healthcare identifier of an identified healthcare provider;
(b) identifying information of an identified healthcare provider;
(c) professional and business details of an identified healthcare provider.
> Note: Subsections (3A) and (3B) provide an authorisation for the purposes of the Privacy Act 1988 and other laws.
(4) A person to whom the professional and business details of a healthcare provider is disclosed on the Healthcare Provider Directory is authorised to collect, use and disclose that information:
(a) for the purpose of communicating or managing health information or information on support services, as part of providing healthcare or support services to a healthcare recipient; or
(aa) for the purpose of health administration; or
(b) in any other circumstances in which the collection, use or disclosure of the information is required or authorised by or under an Australian law or a court/tribunal order; or
(c) in any other circumstances in which the collection, use or disclosure of the information would not be an interference with privacy under the Privacy Act 1988.
(5) An identified healthcare provider may request the Healthcare Provider Directory Operator not disclose personal information of the identified healthcare provider on the Healthcare Provider Directory.
(6) A request under subsection (5) must comply with any requirements prescribed by the regulations.
(7) If an identified healthcare provider makes a request under subsection (5), the Healthcare Provider Directory Operator must comply with the request.
(8) The regulations may make provision for, or in relation to, the establishment and maintenance of the Healthcare Provider Directory for the purposes of the Healthcare Provider Directory.
(9) Without limiting subsection (8), the regulations may do the following:
(a) prescribe requirements in relation to the disclosure of information on the Healthcare Provider Directory;
(b) prescribe requirements for the administration of the Healthcare Provider Directory;
(c) prescribe requirements for access to the Healthcare Provider Directory;
(d) prescribe requirements in relation to dealing with requests made under subsection (5).
#### 31A Healthcare Provider Directory—sharing information with the My Health Record System Operator
(1) The Healthcare Provider Directory Operator and the service operator are authorised to collect from the My Health Record System Operator, use and disclose to the My Health Record System Operator:
(a) identifying information of a healthcare provider; and
(b) the healthcare identifier of a healthcare provider;
for the purposes of the Healthcare Provider Directory.
(2) The My Health Record System Operator is authorised to use and disclose to the Healthcare Provider Directory Operator or the service operator:
(a) identifying information of a healthcare provider; and
(b) the healthcare identifier of a healthcare provider;
for the purposes of the Healthcare Provider Directory.
#### 31AA Information to be provided to the Healthcare Provider Directory Operator for the purposes of the Healthcare Provider Directory
The regulations may, for the purposes of the Healthcare Provider Directory, require an identified healthcare provider to provide to the Healthcare Provider Directory Operator information that:
(a) relates to the healthcare provider; and
(b) is prescribed by the regulations for the purposes of this section.
## Part 5AA—Data standards
#### 31AB Simplified outline of this Part
The Secretary may make data standards about health information and other clinical data.
#### 31AC Making data standards
(1) The Secretary may, by writing, make, for publication on the internet under section 31AD, one or more data standards about each of the following matters:
(a) the format and description of health information or other clinical data;
(b) the storage and disclosure of health information or other clinical data;
(c) the interoperability of clinical or health information management systems;
(d) health or clinical terminology;
(e) the implementation of data standards;
(f) any other matter prescribed by the regulations for the purposes of this paragraph.
Complying with determinations when making data standards etc.
(2) The Secretary must comply with any determination in force under section 31AE when making a data standard (including a data standard varying or revoking a data standard), including complying with any related requirements specified in such a determination about:
(a) approval; or
(b) consultation; or
(c) the formation of committees, advisory panels and consultative groups.
> Note: The determination could, for example, require a proposed data standard to be approved by a specified person or body before it is made.
(3) Without limiting subsection (2) of this section, the Secretary must make, under subsection (1), a data standard about a particular matter mentioned in subsection (1) if a determination in force under section 31AE so requires.
Consultation with Health Chief Executives Forum
(4) Before the Secretary makes a data standard under subsection (1), the Secretary must consult the Health Chief Executives Forum.
(5) Subsection (4) does not limit the Minister’s power to determine additional requirements about consultation under section 31AE.
Data standards are not legislative instruments
(6) A data standard made under subsection (1) of this section is not a legislative instrument.
#### 31AD Data standards must be published on internet
The Secretary must publish on the internet each data standard made under subsection 31AC(1).
> Note: Once published, the data standards will be available for free.
#### 31AE Requirements for making data standards
The Minister may, by legislative instrument, determine:
(a) requirements relating to making a data standard (including a data standard varying or revoking a data standard); or
(b) any other matters that the provisions of this Part provide may be specified, or otherwise dealt with, in a determination made under this section.
#### 31AF Application of the Acts Interpretation Act 1901
The Acts Interpretation Act 1901 applies in relation to the power to make a data standard under subsection 31AC(1) of this Act in the same way as the Acts Interpretation Act 1901 applies in relation to a power to make an instrument of an administrative character (other than a legislative instrument, a notifiable instrument or a rule of court).
## Part 5A—Enforcement
#### 31B Simplified outline of this Part
The civil penalty provisions of this Act and the regulations are enforceable under Part 4 of the Regulatory Powers Act. The provisions of this Act and the regulations are also enforceable using enforceable undertakings under Part 6 of the Regulatory Powers Act, and injunctions under Part 7 of the Regulatory Powers Act.
#### 31C Civil penalty provisions
Enforceable civil penalty provisions
(1) Each civil penalty provision of this Act and the regulations is enforceable under Part 4 of the Regulatory Powers Act.
> Note: Part 4 of the Regulatory Powers Act allows a civil penalty provision to be enforced by obtaining an order for a person to pay a pecuniary penalty for the contravention of the provision.
Authorised applicant
(2) For the purposes of Part 4 of the Regulatory Powers Act, the Information Commissioner is an authorised applicant in relation to the civil penalty provisions of this Act and the regulations.
Relevant court
(3) For the purposes of Part 4 of the Regulatory Powers Act, each of the following courts is a relevant court in relation to the civil penalty provisions of this Act and the regulations:
(a) the Federal Court of Australia;
(b) the Federal Circuit and Family Court of Australia (Division 2);
(c) a court of a State or Territory that has jurisdiction in relation to the matter.
Extension to external Territories
(4) Part 4 of the Regulatory Powers Act, as that Part applies in relation to the civil penalty provisions of this Act and the regulations, extends to every external Territory.
Liability of the Crown
(5) Part 4 of the Regulatory Powers Act, as that Part applies in relation the civil penalty provisions of this Act and the regulations, does not make the Crown liable to a pecuniary penalty.
#### 31D Enforceable undertakings
Enforceable provisions
(1) The provisions of this Act and the regulations are enforceable under Part 6 of the Regulatory Powers Act.
> Note: Part 6 of the Regulatory Powers Act creates a framework for accepting and enforcing undertakings relating to compliance with provisions.
Authorised person
(2) For the purposes of Part 6 of the Regulatory Powers Act, each of the following persons is an authorised person in relation to the provisions of this Act and the regulations:
(a) the service operator;
(b) the Information Commissioner.
Relevant court
(3) For the purposes of Part 6 of the Regulatory Powers Act, each of the following courts is a relevant court in relation to the provisions of this Act and the regulations:
(a) the Federal Court of Australia;
(b) the Federal Circuit and Family Court of Australia (Division 2);
(c) a court of a State or Territory that has jurisdiction in relation to the matter.
Enforceable undertaking may be published on website
(4) An authorised person in relation to a provision of this Act and the regulations may publish an undertaking given in relation to the provision on the authorised person’s website.
Extension to external Territories
(5) Part 6 of the Regulatory Powers Act, as that Part applies in relation to the provisions of this Act and the regulations, extends to every external Territory.
#### 31E Injunctions
Enforceable provisions
(1) The provisions of this Act and the regulations are enforceable under Part 7 of the Regulatory Powers Act.
> Note: Part 7 of the Regulatory Powers Act creates a framework for using injunctions to enforce provisions.
Authorised person
(2) For the purposes of Part 7 of the Regulatory Powers Act, each of the following persons is an authorised person in relation to the provisions of this Act and the regulations:
(a) the service operator;
(b) the Information Commissioner.
Relevant court
(3) For the purposes of Part 7 of the Regulatory Powers Act, each of the following courts is a relevant court in relation to the provisions of this Act and the regulations:
(a) the Federal Court of Australia;
(b) the Federal Circuit and Family Court of Australia (Division 2);
(c) a court of a State or Territory that has jurisdiction in relation to the matter.
Extension to external Territories
(4) Part 7 of the Regulatory Powers Act, as that Part applies in relation to the provisions of this Act and the regulations, extends to every external Territory.
## Part 6—Oversight role of Ministerial Council
#### 31F Simplified outline of this Part
The Minister may give directions to the service operator about the performance of the service operator’s functions under this Act, after consulting the Ministerial Council.
The Minister must also consult the Ministerial Council before regulations are made under this Act.
#### 32 Directions to service operator
(1) After consulting the Ministerial Council, the Minister may, by legislative instrument, give directions to the service operator about the performance of the service operator’s functions under this Act.
> Note 1: Section 42 (disallowance) of the Legislation Act 2003 does not apply to the direction—see regulations made for the purposes of paragraph 44(2)(b) of that Act.
> Note 2: Part 4 of Chapter 3 (sunsetting) of the Legislation Act 2003 does not apply to the direction—see regulations made for the purposes of paragraph 54(2)(b) of that Act.
(2) The service operator must comply with a direction given under subsection (1).
#### 33 Consultation with Ministerial Council about regulations
Before the Governor‑General makes a regulation for the purpose of this Act, the Minister must consult with the Ministerial Council.
#### 34 Annual reports by service operator
(1) The service operator must, as soon as practicable after the end of each financial year, prepare a report on the activities, finances and operations of the service operator during the financial year, so far as they relate to this Act and the regulations.
(2) The service operator must give a copy of the report to:
(a) the Minister; and
(b) either:
(i) the Ministerial Council; or
(ii) if the Ministerial Council directs the service operator to give the report to another entity—that other entity;
no later than on 30 September after the end of the financial year to which the report relates.
(3) The Minister must table a copy of the report in each House of Parliament within 15 sitting days after the service operator gives a copy of the report to the Minister.
(4) If the service operator is required under section 46 of the Public Governance, Performance and Accountability Act 2013 to prepare and give to the Minister an annual report for all or part of a financial year, the service operator is not required to also give a report in relation to that financial year under this section.
#### 35 Review of the operation of this Act
(1) The Minister must, after consulting the Ministerial Council, appoint an individual to review the operation of this Act and the regulations.
(2) The individual appointed must give a report to the Minister within 3 years after the commencement of Schedule 1 to the Health Legislation Amendment (eHealth) Act 2015.
(3) The Minister must:
(a) provide a copy of the report to the Ministerial Council; and
(b) table a copy of the report in each House of Parliament within 15 sitting days after the report is given to the Minister.
## Part 7—Miscellaneous
### Division 1—Simplified outline of this Part
#### 36AA Simplified outline of this Part
If an entity is authorised to collect, use or disclose information under this Act, an employee, contracted service provider or subcontracted service provider of the entity is authorised to do that, provided the duties of the employee, contracted service provider or subcontracted service provider involve implementing the purpose for which the collection, use or disclosure is authorised.
If an entity is authorised to disclose information to a healthcare provider, the entity is authorised to disclose the information to an employee, contracted service provider or subcontracted service provider of the healthcare provider, provided the duties of the employee, contracted service provider or subcontracted service provider involve implementing the purpose for which the disclosure is authorised.
Certain authorisations under this Act extend to providers of electronic services.
This Act applies to partnerships, unincorporated associations and trusts in the same way as it applies to persons.
The service operator may delegate functions and powers under this Act.
This Part also:
(a) provides for the concurrent operation of State and Territory law; and
(b) deals with the effect Parts 3 and 4 are to have in certain constitutionally significant circumstances.
The Governor‑General may make regulations prescribing matters that are required or permitted to be prescribed by this Act, or that are necessary or convenient to be prescribed for carrying out or giving effect to this Act.
### Division 2—Employees, contractors, subcontractors, partnerships, providers of electronic services, unincorporated associations and trusts
#### 36 Extent of authorisation
An authorisation under this Act to an entity (the first entity) for a particular purpose is an authorisation to:
(a) an individual:
(i) who is an employee of the first entity; and
(ii) whose duties involve implementing that purpose; or
(b) a contracted service provider of the first entity, if:
(i) the first entity is a healthcare provider; and
(ii) the duties of the contracted service provider under a contract with the healthcare provider involve implementing that purpose by providing information technology services relating to the communication of health information, or health information management services, to the healthcare provider; or
(baa) a subcontracted service provider of the first entity, if:
(i) the first entity is a healthcare provider; and
(ii) the duties of the subcontracted service provider under a contract with a contracted service provider for the healthcare provider involve implementing that purpose by providing information technology services relating to the communication of health information, or health information management services, to the healthcare provider or to the contracted service provider for the healthcare provider; or
(ba) a person (the contractor) performing services under a contract between the contractor and the first entity, if:
(i) the first entity is a participant in the My Health Record system, other than a healthcare provider or a contracted service provider; and
(ii) the purpose relates to the My Health Record system; or
(bb) a person (the subcontractor) performing services under a contract between the subcontractor and another person (the contractor), if:
(i) the first entity is the My Health Record System Operator or the operator of the National Repositories Service (within the meaning of the My Health Records Act 2012); and
(ii) the first entity has a contract with the contractor; and
(iii) the contract between the subcontractor and the contractor relates to the My Health Record system; or
(c) an individual:
(i) who is an employee of a contracted service provider to which paragraph (b) applies, a subcontracted service provider to which paragraph (baa) applies, a contractor to which paragraph (ba) applies or a subcontractor to which paragraph (bb) applies; and
(ii) whose duties involve implementing that purpose as mentioned in whichever of those paragraphs applies.
#### 36A Authorisation to disclose to employees, contracted service providers and subcontracted service providers of a healthcare provider
An authorisation under this Act to an entity to disclose information to a healthcare provider for a particular purpose is an authorisation to disclose the information to:
(a) an individual:
(i) who is an employee of the healthcare provider; and
(ii) whose duties involve, or are reasonably connected to, implementing that purpose; or
(b) a contracted service provider of the healthcare provider, if the duties of the contracted service provider under a contract with the healthcare provider involve, or are reasonably connected with, implementing that purpose by providing information technology services relating to the communication of health information, or health information management services, to the healthcare provider; or
(ba) a subcontracted service provider of the healthcare provider, if the duties of the subcontracted service provider under a contract with a contracted service provider for the healthcare provider involve, or are reasonably connected with implementing that purpose by providing:
(i) information technology services relating to the communication of health information; or
(ii) health information management services;
to the healthcare provider or to the contracted service provider for the healthcare provider; or
(c) an individual:
(i) who is an employee of a contracted service provider to which paragraph (b) applies or of a subcontracted service provider to which paragraph (ba) applies; and
(ii) whose duties involve implementing that purpose as mentioned in that paragraph.
#### 36BA Authorisation of healthcare provider to which an individual healthcare provider is linked
An authorisation under this Act to an individual healthcare provider to collect, use or disclose information for a particular purpose is an authorisation for a healthcare provider organisation to which the individual healthcare provider is linked to collect, use or disclose the information for that purpose on behalf of the individual healthcare provider.
#### 36B Treatment of partnerships
(1) This Act applies to a partnership as if it were a person, but with the changes set out in this section.
(2) An obligation that would otherwise be imposed on the partnership by this Act is imposed on each partner instead, but may be discharged by any of the partners.
(3) An offence against this Act that would otherwise have been committed by the partnership is taken to have been committed by each partner in the partnership, at the time the offence was committed, who:
(a) did the relevant act or made the relevant omission; or
(b) aided, abetted, counselled or procured the relevant act or omission; or
(c) was in any way knowingly concerned in, or party to, the relevant act or omission (whether directly or indirectly and whether by any act or omission of the partner).
(4) This section applies to a contravention of a civil penalty provision in a corresponding way to the way in which it applies to an offence.
#### 36BB Authorisations extending to providers of electronic services
An authorisation under this Act for a healthcare provider, or a health administration entity, to collect, use or disclose information extends to a provider of an electronic service (within the meaning of the Online Safety Act 2021) if the collection, use or disclosure is done by means of the service.
#### 36C Treatment of unincorporated associations
(1) This Act applies to an unincorporated association as if it were a person, but with the changes set out in this section.
(2) An obligation that would otherwise be imposed on the unincorporated association by this Act is imposed on each member of the association’s committee of management instead, but may be discharged by any of the members.
(3) An offence against this Act that would otherwise have been committed by the unincorporated association is taken to have been committed by each member of the association’s committee of management, at the time the offence was committed, who:
(a) did the relevant act or made the relevant omission; or
(b) aided, abetted, counselled or procured the relevant act or omission; or
(c) was in any way knowingly concerned in, or party to, the relevant act or omission (whether directly or indirectly and whether by any act or omission of the member).
(4) This section applies to a contravention of a civil penalty provision in a corresponding way to the way in which it applies to an offence.
#### 36D Treatment of trusts with multiple trustees
(1) If a trust has 2 or more trustees, this Act applies to the trust as if it were a person, but with the changes set out in this section.
(2) An obligation that would otherwise be imposed on the trust by this Act is imposed on each trustee instead, but may be discharged by any of the trustees.
(3) An offence against this Act that would otherwise have been committed by the trust is taken to have been committed by each trustee of the trust, at the time the offence was committed, who:
(a) did the relevant act or made the relevant omission; or
(b) aided, abetted, counselled or procured the relevant act or omission; or
(c) was in any way knowingly concerned in, or party to, the relevant act or omission (whether directly or indirectly and whether by any act or omission of the trustee).
(4) This section applies to a contravention of a civil penalty provision in a corresponding way to the way in which it applies to an offence.
### Division 3—Delegations
#### 36E Delegations by the service operator
(1) The service operator may, by writing, delegate one or more of his or her functions and powers to any of the following:
(a) an APS employee in the Department;
(b) if the service operator is not the Chief Executive Medicare—the Chief Executive Medicare;
(c) any other person with the consent of the Minister.
(2) If the service operator is not the Chief Executive Medicare the service operator may only delegate a function or power of the service operator:
(a) to an APS employee in the Department with the agreement of the Secretary; and
(b) to the Chief Executive Medicare with the agreement of the Chief Executive Medicare.
(3) Each of the following must comply with any written directions of the service operator:
(a) a delegate;
(b) if the Chief Executive Medicare delegates under subsection 8AC(3) of the Human Services (Medicare) Act 1973 a function delegated to him or her under this section—a subdelegate.
#### 36F Delegations by Secretary
(1) The Secretary may, by writing, delegate one or more of the Secretary’s functions or powers under Part 5AA to an SES employee or acting SES employee in the Department.
(2) A delegate must comply with any written directions of the Secretary.
### Division 4—Constitutional matters
#### 37 Relationship to State and Territory laws
Relationship to State and Territory laws
(1) A law of a State or Territory has effect to the extent that the law is capable of operating concurrently with this Act or the regulations.
(2) However, if:
(a) a person’s act or omission is both:
(i) an offence under this Act; and
(ii) an offence under the law of a State or Territory; and
(b) that person is convicted of either of those offences;
the person is not liable to be convicted of the other offence.
(3) Nothing in this Act or the regulations limits, restricts or otherwise affects any right or remedy that a person would have had if this Act had not been enacted.
Declarations that Act does not apply
(4) A provision of this Act or the regulations does not apply to the public bodies of a State or Territory if a declaration made under subsection (5) is in force in relation to that provision and that State or Territory.
(5) The Minister must, by legislative instrument, declare that specified provisions of this Act and the regulations do not apply to the public bodies of a specified State or Territory if:
(a) a Minister of the State or Territory, by written notice, requests the Minister to make the declaration; and
(b) the Minister is satisfied that a law in force in the State or Territory contains provisions that have been agreed to by the Ministerial Council.
(6) The Minister may, by legislative instrument, revoke the declaration if:
(a) a Minister of the State, by written notice, requests the Minister to do so; or
(b) a provision in the State or Territory law, which had been agreed to by the Ministerial Council, is amended without the agreement of the Ministerial Council.
(7) Section 42 (disallowance) of the Legislation Act 2003 does not apply to a declaration or revocation made under subsection (5) or (6) of this section.
> Note: Part 4 of Chapter 3 (sunsetting) of the Legislation Act 2003 does not apply to such a declaration or revocation (see subsection 54(1) of that Act).
#### 38 Severability—additional effect of Parts 3 and 4
(1) Without limiting their effect apart from each of the following subsections of this section, Parts 3 and 4 have effect in relation to a collection, use or disclosure of information as provided by that subsection.
(2) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure taking place in the course of, or in relation to, trade or commerce:
(a) between Australia and places outside Australia; or
(b) among the States; or
(c) within a Territory, between a State and a Territory or between 2 Territories.
(3) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure using a postal, telegraphic, telephonic or other like service (within the meaning of paragraph 51(v) of the Constitution).
(4) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure in relation to census or statistics (within the meaning of paragraph 51(xi) of the Constitution).
(5) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure in relation to aliens (within the meaning of paragraph 51(xix) of the Constitution).
(6) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure by, or to, a trading, foreign or financial corporation (within the meaning of paragraph 51(xx) of the Constitution).
(7) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure in relation to the provision of:
(a) sickness or hospital benefits; or
(b) medical or dental services (but not so as to authorise any form of civil conscription);
(within the meaning of paragraph 51(xxiiiA) of the Constitution).
(8) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure:
(a) in relation to which the Commonwealth is under an obligation under an international agreement, including, the International Covenant on Civil and Political Rights, and in particular Article 17 of the Covenant; or
Note: The text of the Covenant is set out in Australian Treaty Series 1980 No. 23 (\[1980\] ATS 23). In 2010, a text of a Covenant in the Australian Treaties Series was accessible through the Australian Treaties Library on the AustLII website (www.austlii.edu.au).
(b) that is of international concern, including the international concern reflected by the Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data, recommended by the Council of the Organisation for Economic Co‑operation and Development on 23 September 1980.
Note: In 2010, the text of the Guidelines was accessible through the Organisation for Economic Co‑operation and Development website (www.oecd.org).
(9) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure by, or to, the Commonwealth or a Commonwealth authority.
(10) Parts 3 and 4 also have the effect they would have if their operation in relation to a collection, use or disclosure of information were expressly confined to a collection, use or disclosure taking place in a Territory.
### Division 5—Regulations
#### 39 Regulations
(1) The Governor‑General may make regulations prescribing matters:
(a) required or permitted to be prescribed by this Act; or
(b) necessary or convenient to be prescribed for carrying out or giving effect to this Act.
> Note: Before the Governor‑General makes a regulation for the purpose of this Act, the Minister must consult with the Ministerial Council: see section 33.
(2) Without limiting subsection (1), the regulations may provide for the imposition of a penalty of not more than 50 penalty units for contravention of a regulation.
Incorporation by reference
(3) Despite subsection 14(2) of the Legislation Act 2003, the regulations may make provision in relation to a matter by applying, adopting or incorporating, with or without modification, any matter contained in an instrument or other writing as in force or existing from time to time.